[H|Cr]acker Insurance
Spellbinder writes "yahoo has an article on
Hacker insurance, also known as "network risk insurance," has been on the market for about three years, but is expected to explode from a $100 million sideshow into a $2.5 billion behemoth by 2005, according to insurance industry projections."
If they'll pay that much for insurance, I wonder how much they'd pay for a SysAdmin that secures things properly.
what about product liability? automakers, drug manufacturers and every other manufacturer is liable for their products in some way. How come software companies are exempt from this?
the *best* insurance is a competent admin...
nothing else will do!
---
Information wants...you to shut your pie hole.
I can see it now: company tries to claim a loss due to having their network compromised.
Insurer: I'm sorry but we have rejected your claim.
Insured: What the hell do you mean? This is why we bought hacker insurance!!
Insurer: Yes, but you bought "hacker" insurance. If you wanted to be reimbursed for a loss like this, you should have bought our "cracker" insurance! But you're in luck! We've got a special offer now! If you buy cracker insurance and already have purchased hacker insurance from us, you will save 10%! I guess today is your lucky day after all!
Insured: You insurance companies are vultures! Profiting off our loss! Well, okay, I don't want to think any more about it. Just sell me whatever insurance you think is best for me.
Insurer: Just what I was hoping you'd say! Sign here, here, and here, please! No, don't bother reading that. It's just a bunch of legal jargon...
GMD
watch this
The interesting thing is that if companies followed the requirements of the insurance company to get the hacker insurance, their security would improve tremendously. Many companies don't even perform the simple tasks the insurance companies will require. That alone would help tremendously.
:-)
Ironically, if more companies would conduct assessments, patch vulnerable systems, setup security policies, etc. the demand for this type of insurance might actually diminish. Little chance of that.
Better yet, how do you even determine the losses? The only science I've seen of it to date is: Company A says, "We lost $x amount when we lost our connection for 2 hours because of this attack," with nothing to back up the dollar figure.
This insurance idea could be a good one, simply because it might force businesses to justify their losses when network attacks occur. I'm not going to hold my breath, though.
!#@%*)anks for hanging up the phone, dear.