<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cyber Insurance used to increase security in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Cyber-Insurance-used-to-increase-security/m-p/46257#M5516</link>
    <description>&lt;P&gt;Interesting paper from the Royal United Services Institute (RUSI) titled: Cyber Insurance and the Cyber Security Challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Mission Statement of RUSI&lt;/STRONG&gt;: As an independent institution, we produce evidence-based research, publications and events on defence, security and international affairs to help build a safer UK and a more secure, equitable and stable world.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://rusi.org/about" target="_blank" rel="noopener"&gt;About | Royal United Services Institute (rusi.org)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentially the rough steps on improving overall security posture by way of Cyber Insurance:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Insurance companies all agree on minimum baseline security standards, e.g., NIST, ISO, Cyber Essentials, etc.&lt;/LI&gt;&lt;LI&gt;Make cyber coverage mandatory for all government agencies and their suppliers.&lt;/LI&gt;&lt;LI&gt;Enact legislation to make cyber insurance mandatory for large and SME, just like professional liability insurance coverage&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Proposed &lt;STRONG&gt;Pre-Incident&lt;/STRONG&gt; Services Insurance Companies can provide in partnership with MSSP’s:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Staff Training&lt;/STRONG&gt;: This generally involves phishing-focused training. For larger businesses, training may also include scenario-based tabletop exercises with senior management.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Cyber risk rating services and vulnerability scanning&lt;/STRONG&gt;: Rather than using these tools as part of an initial risk assessment, some insurers use them off cycle to monitor internet-facing IT infrastructure or provide organizations with direct access to them.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Threat intelligence services&lt;/STRONG&gt;: These types of services might involve deep and dark web monitoring to identify specific mentions of an organization, or using claims incidents to create security alerts or identify trends&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Access to a virtual CISO&lt;/STRONG&gt;: This provides organizations without a senior cyber security manager with access to expertise&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Password management solutions&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Of course, there are issues involved with this plan and are detailed in the paper here: &lt;A href="https://static.rusi.org/247-op-cyber-insurance-v2.pdf" target="_blank" rel="noopener"&gt;Cyber Insurance and the Cyber Security Challenge (rusi.org)&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2021 18:16:06 GMT</pubDate>
    <dc:creator>tmekelburg1</dc:creator>
    <dc:date>2021-07-01T18:16:06Z</dc:date>
    <item>
      <title>Cyber Insurance used to increase security</title>
      <link>https://community.isc2.org/t5/Industry-News/Cyber-Insurance-used-to-increase-security/m-p/46257#M5516</link>
      <description>&lt;P&gt;Interesting paper from the Royal United Services Institute (RUSI) titled: Cyber Insurance and the Cyber Security Challenge.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Mission Statement of RUSI&lt;/STRONG&gt;: As an independent institution, we produce evidence-based research, publications and events on defence, security and international affairs to help build a safer UK and a more secure, equitable and stable world.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://rusi.org/about" target="_blank" rel="noopener"&gt;About | Royal United Services Institute (rusi.org)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Essentially the rough steps on improving overall security posture by way of Cyber Insurance:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Insurance companies all agree on minimum baseline security standards, e.g., NIST, ISO, Cyber Essentials, etc.&lt;/LI&gt;&lt;LI&gt;Make cyber coverage mandatory for all government agencies and their suppliers.&lt;/LI&gt;&lt;LI&gt;Enact legislation to make cyber insurance mandatory for large and SME, just like professional liability insurance coverage&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Proposed &lt;STRONG&gt;Pre-Incident&lt;/STRONG&gt; Services Insurance Companies can provide in partnership with MSSP’s:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Staff Training&lt;/STRONG&gt;: This generally involves phishing-focused training. For larger businesses, training may also include scenario-based tabletop exercises with senior management.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Cyber risk rating services and vulnerability scanning&lt;/STRONG&gt;: Rather than using these tools as part of an initial risk assessment, some insurers use them off cycle to monitor internet-facing IT infrastructure or provide organizations with direct access to them.&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Threat intelligence services&lt;/STRONG&gt;: These types of services might involve deep and dark web monitoring to identify specific mentions of an organization, or using claims incidents to create security alerts or identify trends&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Access to a virtual CISO&lt;/STRONG&gt;: This provides organizations without a senior cyber security manager with access to expertise&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Password management solutions&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Of course, there are issues involved with this plan and are detailed in the paper here: &lt;A href="https://static.rusi.org/247-op-cyber-insurance-v2.pdf" target="_blank" rel="noopener"&gt;Cyber Insurance and the Cyber Security Challenge (rusi.org)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 18:16:06 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Cyber-Insurance-used-to-increase-security/m-p/46257#M5516</guid>
      <dc:creator>tmekelburg1</dc:creator>
      <dc:date>2021-07-01T18:16:06Z</dc:date>
    </item>
  </channel>
</rss>

