{"id":5089,"date":"2024-08-29T16:31:27","date_gmt":"2024-08-29T21:31:27","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/cyber-insurance-security-technologies-premiums"},"modified":"2024-08-29T16:31:27","modified_gmt":"2024-08-29T21:31:27","slug":"cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/08\/29\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums\/","title":{"rendered":"Cyber Insurance: A Few Security Technologies, a Big Difference in Premiums"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/bltfd1b2cdcda3f19e0\/66d0e2c3b0646f5080fae718\/money-Oleksandr_Perepelytsia-Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">When the BlackCat ransomware gang compromised healthcare-billing services firm Change Healthcare in February, several security controls failed: The company did not adequately protect its Citrix remote-access portal, did not require employees to use multifactor authentication (MFA), and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/unitedhealth-congressional-testimony-rampant-security-fails\" rel=\"noopener\">failed to implement a robust backup strategy.<\/a><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The subsidiary of UnitedHealth also <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.csoonline.com\/article\/2098997\/change-healthcare-went-without-cyber-insurance-before-debilitating-ransomware-attack.html\" rel=\"noopener\">had no cyber insurance<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, meaning its parent company had to foot the bill, at least $872 million, and \u2014 in hindsight, perhaps just as important \u2014 missed the benefit of a cyber insurer&#8217;s focus on what strategies can minimize claims. Both insurers and &#8220;insursec&#8221; firms, which combine insurance and security services, are awash in data on the current threat landscape and the technologies that appear to make the most difference \u2014 among them, backups, MFA, and protecting remote-access systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Finding the right security technologies for the business is increasingly important, because ransomware incidents have accelerated over the past few years, says Jason Rebholz, CISO at Corvus Insurance, a cyber insurer. Attackers posted the names of at least 1,248 victims to leak sites in the second quarter of 2024, the highest quarterly volume to date, according the firm.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Without a doubt, attacks are increasing in terms of frequency and severity \u2014 the data is pointing to that,&#8221; he says. &#8220;We also see that when you focus on specific security controls, you can have a meaningful impact on both preventing those incidents, but also in just recovering from the incident [with fewer costs].&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cyber insurance has become a security best practice, with the vast majority of security-mature companies (84%) retaining a cyber-insurance policy while another 9% are in the process of obtaining a policy, according to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.at-bay.com\/press_releases\/insursec-can-drive-an-effective-proactive-cybersecurity-strategy-new-analyst-report\/\" rel=\"noopener\">a recent survey<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> of 400 security decision makers by insursec firm At-Bay and analyst firm Omdia, a sister company to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_italic\">Dark Reading<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Overall, 72% of all firms consider cyber insurance to be critical or important to their organization, the survey found.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Three (or Five) Defenses Every Company Needs\">Three (or Five) Defenses Every Company Needs<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More than 60% of insurance claims involve a ransomware incident, while email-based fraud accounts for another 20% of claims, according to At-Bay. Because most successful attacks use vulnerable or misconfigured remote-access points or compromise an individual system through email, improving security on those two vectors is paramount, says Roman Itskovich, chief risk officer and co-founder at At-Bay.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The insurer charges less to customers who <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/when-it-comes-to-email-security-the-cloud-you-pick-matters\" rel=\"noopener\">use email systems with better security, such as Google Workspace<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and more for on-premise email systems, because Google users have filed fewer claims. The insursec firm also found that companies who use self-managed virtual private networks <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.at-bay.com\/articles\/why-vpn-can-be-small-business-weakest-link\/\" rel=\"noopener\">have a 3.7 times greater likelihood of filing a ransomware claim<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We take VPNs very seriously in how we price [our policies] and what recommendations we give to our companies &#8230; and this is mostly related to ransomware,&#8221; says Itskovich.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For those reasons, businesses should take a look at their VPN security and email security, if they want to better secure their environments and, by extension, reduce their policy costs. Because an attacker will eventually find a way to compromise most companies, having a way to detect and respond to threats is vitally important, making managed detection and response (MDR) another technology that will eventually pay for itself, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;How do you catch someone who just made the beachhead before they access your database, or before you get to your accounting system?&#8221; Itskovich says. &#8220;For that, we find that EDRs are very, very effective \u2014 more specifically, EDRs that are managed.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Backup, But Verify\">Backup, But Verify<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">For smaller companies, email security, cybersecurity-awareness training, and multi-factor authentication are critical, says Matthieu Chan Tsin, vice president of cybersecurity services for Cowbell. In addition, secure data storage can help get a company back up and running quickly, minimizing the business impact of a ransomware attack, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We look at encryption and how we help our policyholders better store the data,&#8221; Tsin says. &#8220;Having good backups, having some cloud backups, some in-house backups [are critical], because that&#8217;s truly the one thing that will get them back to business as quickly as possible.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies with robust backups are about 2.4 times less likely to need to pay a ransom, according to Corvus Insurance. The cyber insurer recommends a &#8220;3-2-1 policy,&#8221; where the business makes three different backups to at least two different types of media, with at least one backup kept offsite. The company found that policy holders with strong backup strategies claimed 72% lower damages than businesses who did not maintain robust backups, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link ContentText-BodyTextChunk_italic\" target=\"_blank\" href=\"https:\/\/www.prnewswire.com\/news-releases\/global-ransomware-attacks-demands-and-payments-rose-in-second-quarter-according-to-corvus-insurance-cyber-threat-report-302228081.html?tc=eml_cleartime\" rel=\"noopener\">according to its Q2 2024 Cyber Threat Report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The strategy is effective enough that attackers have moved to double-ransom techniques, where they not only encrypt data to make it unusable, but also steal the data to extort the business. In 2024, nearly all ransomware incidents (93%) involved data theft, a sharp increase from 2022 when less than half of incidents involved data theft.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Backups can have a pretty meaningful impact as a kind of line of last defense, if you are getting getting attacked via ransomware,&#8221; Corvus&#8217; Rebholz says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Dark Horse: Disruption Risk From Third Parties\">The Dark Horse: Disruption Risk From Third Parties<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Attackers also seem to be focused on compromising aggregators \u2014 those third-party firms have some sort of privileged access to a host of other companies: Firms such as network-monitoring service <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/solarwinds-critical-rce-bug-requires-urgent-patch\" rel=\"noopener\">SolarWinds<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, healthcare billing provider <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/round-2-change-healthcare-targeted-second-ransomware-attack\" rel=\"noopener\">Change Healthcare<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and auto dealership services firm <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cloud-security\/cdk-attack-contingency-planning-critical-saas-customers\" rel=\"noopener\">CDK Global<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. In the second quarter of 2024, third-party breach events accounted for about 40% of all claims processed, up from 20% in the last quarter of 2023, according to Corvus.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We call out IT services as one of the industries that are getting hit, and that&#8217;s one of those reasons \u2014 it&#8217;s just kind of a one-to-many [relationship], right?&#8221; Corvus&#8217;s Rebholz says. &#8220;What we can see from this year \u2014 in particular, the first half of the year \u2014 is there are some big names out there that were third parties that got hit, and we can see a subsequent increase in the frequency because of that.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Major destructive attacks, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/three-years-after-wannacry-ransomware-accelerating-while-patching-still-problematic\" rel=\"noopener\">WannaCry<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and SolarWinds, can lead to significant costs for cyber insurers, and in some ways are analogous to natural catastrophes. However, determining the right risk ratings for such events is more difficult, because the causes \u2014 and probability of occurrence \u2014 are far from simple, says At-Bay&#8217;s Itskovich.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[SolarWinds] was a threat actor delivering malicious software through the update mechanism; <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/crowdstrike-outage-losses-estimated-staggering-54b\" rel=\"noopener\">CrowdStrike<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> was a software error in the update; CDK Global was was a ransomware attack on the company; WannaCry was a widespread vulnerability,&#8221; he says. &#8220;If you [think about] natural catastrophes, you deal with hurricanes and earthquakes and maybe a couple other secondary perils \u2014 it&#8217;s much simpler.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/cyber-insurance-security-technologies-premiums\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When the BlackCat ransomware gang compromised healthcare-billing services firm Change<\/p>\n","protected":false},"author":12,"featured_media":5090,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/08\/cyber-insurance-a-few-security-technologies-a-big-difference-in-premiums-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5089"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5089\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5090"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5089"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}