Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

Is buying Cyber Insurance a Must Now?

Published: 2022-03-26
Last Updated: 2022-03-26 20:43:57 UTC
by Guy Bruneau (Version: 1)
1 comment(s)

"Cyber attacks are organizational risks that businesses can be exposed to with just an errant click of a mouse."[2]

I wrote a diary over 2 1/2 year ago about Cyber Insurance and I do see more articles about the benefits of getting it. This is based on the needs, the entities that requires protection and finally transfer some of the risks to an insurance company. This mean identify which data is critical to protect clients, partners and customers, where gaining unauthorized access to this data would result in business interruption. 

What are the things it can cover?

  • Covering direct costs responding to an incident 
    • Forensic analysis
    • Identify which records were leaked (personal or otherwise)
    • Containment
  • Lawsuits or claims resulting from a cyber incident
    • Legal fees (defence expenses)
  • Reputation management
    • Dealing with public relation 
  • Regulatory fines payments
    • Government penalties
    • Settlements 
  • Business interruption

More organizations are now dealing with ransomware and recovering from this type of attack is very costly and time-consuming. Cyber insurance cost will depend on the type of business and the level of cyber risks it is exposed to.

What is the cost of Cyber Insurance? AdvisorSmith Solution Inc. found that the average cost of a cyber liability policy in 2020 was $1,500 per year for $1 million in coverage, with a $10,000 deductible.[3]

According to Cloudwards, the cost of ransomware in 2021 cost the world $20 billion and expected to reach $265 billion by 2031. 32% of the victims paid the ransom and only 65% get their data back (it doesn't say in what condition).

I went back to the Cyber insurance website Zensurance that I used the last time to get a basic quote for a small IT company for 1 million in liability. This time around, this insurance company has way more categories & options to pick from. Here are a few of the options:

Finalize the policy

Are you using cyber insureance and for what kind of protection?

[1] https://isc.sans.edu/forums/diary/Are+there+any+Advantages+of+Buying+Cyber+Security+Insurance/25266/
[2] http://www.ibc.ca/nu/business/risk-management/cyber-liability
[3] https://advisorsmith.com/cyber-liability-insurance/cost/
[4] https://www.zensurance.com/cyber-liability-insurance
[5] https://www.cloudwards.net/ransomware-statistics/
[6] https://isc.sans.edu/forums/diary/A+Review+of+Year+2021/28098/

-----------
Guy Bruneau IPSS Inc.
My Handler Page
Twitter: GuyBruneau
gbruneau at isc dot sans dot edu

1 comment(s)
Diary Archives