David Derigiotis on the Complex World of Cyber Insurance episode artwork

EPISODE · Jan 23, 2023

David Derigiotis on the Complex World of Cyber Insurance

from Info Risk Today Podcast · host InfoRiskToday.com

In this episode of "Cybersecurity Unplugged," David Derigiotis of insurtech Embroker discusses the complex world of cyber liability insurance, including the collapse of crypto exchange FTX, recent breaches, and improvements in the cyber insurance industry.

Episode metadata supplied by the publisher feed · Published Jan 23, 2023

Embed this episode

NOW PLAYING

David Derigiotis on the Complex World of Cyber Insurance

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Welcome to Cyber Security Unplugged, the cyber Theory podcast, where we explore issues that matter in the world of cyber security. Good day, everyone. This is Steve King. I'm the managing director for Cyber Theory.

And our podcast today is going to explore the world of cybersecurity insurance. And toward that end, David Dergiottis is the chief insurance officer for Imbroker and he's going to join us. He's previously served as a corporate senior vice president and national professional liability practice group leader for international wholesale brokers and knows a lot about complex cybersecurity exposures and data privacy law and regulatory requirements and like that. He also knows a lot about emerging technologies like blockchain and defi and crypto crypto.

Been a guest on Fox Business and CNBC talking about complexity and value in the cyber liability insurance world, which is going, if it's not already really important, is going to be very important in the coming months here. So welcome, David. I'm glad you could join us today. Thanks, David.

Great to be here. Thank you. Let's dive right in. You know, it's been an exciting week and a half or so.

What, what is the impact of Young Sam and FTX and Alameda in the insurance insurance industry? Well, the insurance industry as it relates to really any type of cryptocurrencies, blockchain, it's already a very difficult space and I think there's still a lot that needs to be learned from an insurance company standpoint, ensuring all the risks. And we're talking about a broad spectrum of things. When you have Bitcoin, you have the broader cryptocurrency space, you have blockchain, you have decentralized finance where really these are technology service providers that are tied in utilizing different types of blockchain technology to provide different financial services.

So I think that the market was already very difficult to begin with. And then you have the collapse of one of the largest cryptocurrency exchanges and no doubt tied to fraud, misappropriation of customer funds, and the domino effect that it's had just across the broader industry. This isn't just one organization that operated in a vacuum. They were tied to so many different players in the crypto space.

And you look at others, you know, with blockfi, for example, they were depending on them for open line of credits, not having an impact on them. So it's really poisoned a lot of other very good organizations because you have the criminal acts of a small few who, who really were using deposits for their own personal gain, using for their own personal Financing purchases of homes and all sorts of incredible things that you just heard come out of the bankruptcy letter. So it made an already difficult area of insurance that much more I think, complicated and it's gonna take a little bit time to get out of this. I think there are a lot of people that lost money who are depositors and depending on FTX to be able to transact and acquire various crypto.

Now you have people that lost that, in some cases life savings. And you know, I think it serves as an expensive commercial for why really cryptocurrency was, was developed to begin with Bitcoin being the kind of reigning king within that space. It was to really thorough it or get around, I think a corrupt system to be able to take destiny in your own hands for controlling your own money, being able to transact with, with people all over the world getting financial freedom to people that are unbanked. So I think it's very expensive commercial really for Bitcoin.

And what really the thought behind having a crypto country like Bitcoin was intended to do. Yeah, and it'll be interesting kind of to see what happens to that whole market going forward. I'm not sure that it has any remaining viability, at least from an investor point of view, do you? I think it does.

I think it's going to take some time to really earn back that trust. And I think that's what's so important in knowing what you're investing and knowing the people that are behind these different projects, knowing that they're properly backed with enough collateral, not just minting their own really made up currency like ftx, they had their own cryptocurrency that they were just minting on an unlimited basis value behind that. So if you're using this made up, fake funny money, Internet money to be able to transact and acquire real currency or Bitcoin, you know, it's some of the hardest money that that's been developed. I think that you're on very slippery, a very slippery slope.

You're on thin ice. You need to know that the organization has actual assets, real legitimate assets that are backing the investments and the money that's being given. Yeah, I guess that create, I don't know, creates a, you know, a market for sort of middle folks that can manage that part of the transaction, I suppose. But our understanding was that this was not, you know, some big, you know, cyber attack hack, but rather compromise credential and somebody got a hold of and was able to, you know, get, get through all that without ringing Any bells?

Right. Well, I mean we've seen constant hacks in the crypto space. A lot of times, Steve, they have to do what we're called, bridges, where you're bridging between two different blockchains. That's usually the weak spot.

And that's where we've seen hundreds of millions of dollars of worth of various cryptocurrency being taken. And after you have that unauthorized movement into other wallets, they're watching it, you know, they're trying to hide their tracks. It's just interesting. You get FTX, they were valued at $32 billion.

They've gone from that to nothing, to wiping out people's life savings. And it makes me think back to Enron. You look at the rise and fall of Enron, that's what really instituted the whole Sardanes, Oxley, being having that financial transparency with accounting practices. I think, you know, this could be the Enron moment for the crypto industry where we see now some type of regulation, where you see more transparency.

But again, you know, even with proper regulation, even with all the technical safeguards and protections in place, that doesn't necessarily protect you from fraud, from criminal activity. That's what really happens quite a bit in the traditional financial system. Yeah, I'm sure it does. And you know, then if it's, if the regulators get their hands on this, then you know, it won't be any fun for the, for the kids anymore.

Right. So what fun is it for guys like Sam if you can't, you know, right. Do the magic thing. So it's just crazy.

But leads me to another question about the, you know, the cybersecurity insurance space at large. I mean, where is it going? It looks to me so many breaches and so much unrecoverable money that is leaving the house here is are we ever going to be able to get a cybersecurity policy hearing like in a year or so? That's a great question.

I know that for small mid sized organizations it's been a very painful process. I can tell you in working with a wide variety of clients, I've seen 100% plus increases on premiums. And those are very difficult conversations to have with a client. Even if they've been doing everything right, there have been no losses, they've tendered no claims against the policy.

To go back to them and say that, you know, hey, sorry, the rest of the marketplace has gone through a real corruption and your premiums went from 200,000 to 400,000 because you've been caught up in some of those changes. Those have been difficult conversations over the past couple of years. I think it's been a real transformation that the cyber insurance market has gone through for so many years. It really has been a race to the bottom.

Who can ask fewer questions, who can charge the least amount of policy premium and attract the most business. And that worked for a while, until it suddenly it didn't. And if you look back at the last couple of years, the frequency and severity ransomware attacks, and this is nothing new to anybody in the cybersecurity space, you know that ransomware has been a ranking problem for the last couple of years. You look at the social engineering attacks, business email compromise, just take a look at the FBI data.

They release great statistics on Internet crime every single year. Business email compromise is always the leading loss leader. When you look at all the complaints, you know, up to 6.9 billion in losses that were reported last year, nearly 2.4 billion were due to business email and email account compromise. And that was up from 1.9 billion roughly the year before.

Saying all that, there's been a real transformation that the insurance marketplace has gone through. It's gone through a correction. Whereas now I think the rates are starting to stabilize. We're seeing a lot more partnerships with a variety of risk management, risk management providers, cybersecurity providers, and broker B1 in particular.

We partnered with LastPass to be able to offer really top line leading edge password management, financial protection options for our clients. So with the rise of interest tax, we're seeing many more proactive services being offered to actually help the customer, help the client harden their cyber security posture, which is a win win. They're able to operate a more efficient, stronger business with having data collection practices in mind, having better privacy controls in place, making sure that they're compliant with whether state or federal privacy laws. And it's a win win for the cyber insurance provider because obviously that's gonna be a lower risk to take on and insure.

So like in broker partnering with LastPass, we're seeing more partnerships across the board where it benefits both the policyholder but as well as the insurer. So that's what we're seeing now. It's gonna become a thing more affordable going forward because the security posture and the requirements that an organization has to have in place is a much higher bar from where it was a couple of years ago. So it's just getting the insurance industry getting their arms around properly underwriting and evaluating these types of risks and insuring them from A standpoint that makes sense.

You can't be a small business and pay $100,000 per premium if you don't even have that type of cash flow available. So it's gotta be cost effective for the insured. But it also makes sense for the insurance provider as well from a risk management standpoint and loss leader. Yeah, and if I were a provider, it would be hard for me to rationalize why I would provide, you know, any sort of coverage that wasn't bracketed with a lot of loss limitation around, you know, any, any of these companies.

I mean, you know, well, what happens to, I don't know if you guys underwrote Uber or not, but what happens in an Uber situation where, you know, and what if they get, what if they get breached again tomorrow? I mean, who pays for that? How does that work? Uber is a very interesting organization.

You look at some of the things that have taken place over the last couple of years. You had the Uber security chief that, you know, arguably he was found to have covered up and really obstructed FTC investigation. He was guilty on one account of obstructing the FTC's investigation that they had. He was also guilty of a kind of what's called misprison that's actually conceal a felony from authorities.

So you have him doing things that are unethical and immoral. When they were breached a couple of years ago, he was going through, or they were going through Uber, a FTC investigation with regards to a prior data breach that they experienced. And he essentially took unauthorized access, a hack, and he tucked it under their bombing program and paid $100,000 to the criminal actor. So he concealed data breach and he can steal unauthorized access from the general public and from the FTC's regulators.

But then you also have an Uber owned company, Drizly, and this one's pretty fascinating to me. Again, owned by a subsidiary of Uber and you have the CEO that's being held personally accountable by the ftc. So again they. Uber and the CEO are now Uber.

Drizly and the CEO were warned a couple of years after security practices were inadequate. They didn't make any necessary changes. They get popped again. And you know, no surprise.

Now the FTC stepping in, saying, you need to do these things to better protect your insurance, to take privacy more seriously. And they institute a number of things that they typically do against an organization. You need to destroy unnecessary data. You need to limit future data collection from any of the customers and clients that you're working with.

You need to implement an info security program. You typically see those types of things, but what's unique about this particular case is that they're going to follow him around as an individual. So if the CEO moves on to any other company, you know, from Drizzly, they're telling him that you need to make sure that you're implementing a cybersecurity program for whatever company you go to. So now we have all your actions that are not only taken against organization, but they're going to follow that individual round whatever company he goes to at any point in the future.

Those things are very fascinating. We're seeing a lot of advancements in types of actions that are being taken against individuals. You know, you look at the CEO or the chief information security officer at Uber, he's going to be pursued now at this point for criminal charges. So we haven't seen that before.

We haven't seen a company executive be held responsible for criminal prosecution over data, reach over a hack. So it's just all these things are very fascinating. Insurance is never intended to cover, you know, the CDL or C Suites, intentional or illegal action. So I don't think it's going to change the perspective of insurance because the cards never would have existed if it was something that was intentional or legal to begin with.

Now it's going to cover an employee's actions. Forget the CEO for a second. But if you have an employee who's stealing cardholder data or is malicious insiders stealing some type of information providing access, the policy is meant to cover those types of exposures and threats. But now it's an intentional action that's coming from a C suite member such as Uber's very interesting company.

Some of the things they have going on right now. Yeah. And we could argue for a while about whether that verdict was a reasonable verdict or not, and whether Joe, you know, did a good job or bad job or any kind of, you know, what he thought was the right thing to do there. And if they got, you know, whether they got the right guy or the wrong guy, you know, they initially went after everybody but Joe.

But, you know, as they sorted through that, and the Justice Department is certainly compliant in this, that, yeah, those prosecutors are much more, have been much more difficult. So Joe, everybody, everybody got a plea deal. They all testified against Joe. And now we get looking at eight years now, they better be careful here because, you know, I don't know too many folks and I've served, you know, six years as a CISO myself for a really large bank.

And I don't know, too many folks that are willing, would be willing to take that job today. You know, we have, we sort of have this weird implied fiduciary responsibility that, you know, as far as I'm concerned, the quote chief Information Security officer shouldn't really have. Right. It's not a true officer of the corporation.

And if anybody, if they think there's a liability there, nobody spelled it out for Joe or anybody else that I know of, for example. And so I think it's overly aggressive for the FTC to pursue. Hasn't been done before. And it's just interesting, like you said, who in the world is not only want that job in particular, but you think about the responsibility that sits on your shoulders in any organization to keep them in a sound environment, to properly protect data, to make sure that you're giving consumers proper notice and transparency if a data breach occurs.

What we've seen in the past, you see the CISO get bounced immediately. They're terminated, they're thrown over the coals. It's just a very difficult position to be in to begin with. The responsibility of organizational security, that's required.

And all it takes is one employee to make a mistake, to use a password, to click on a link, to open an attachment, whatever it may be. And the organization, it just opens up to an incredible exposure. So it's already a tough job. And now you have individuals that are being held personally liable or criminally liable.

It's just, it really makes you rethink. Is this a position that I really want to take on both professionally or personally for that matter? Well, yeah, and negligence is one thing, but you know, I don't think that, you know, that wasn't the essence of the case here, nor was the case in Drizzly. And you got a CEO of a company who now is going to be following around for like 10 years.

Was that the deal to make sure that, you know, he makes they puts in these systems or plans or whatever in place, which by the way, are. None of those things are going to prevent a big breach going forward. That's kind of the irony of all this, right, Is that, you know, MFA is easily worked around. So mfa, you know, the FTC kind of makes a big deal out of mfa, but you know, it's not going to prevent breach, period.

And we've proven that, you know, a lot. And so, you know, so I don't know, I certainly want a contract that specified all that stuff very clearly. If I were to go back and do that job again and noting that I wouldn't want to, that's for sure. It's very hard.

It was hard then, now it's much harder for. Were you guys involved in Cap 1, by the way, in the Capital One bridge at all? We were not Capital One. You look at some of these judgments and some of these payouts across multiple organizations, what was capital?

190 million? Yeah, yeah, yeah. It was AWS engineer kind of insider threat type type thing where 100 million individuals had their data compromised. But again, this is nothing new.

You look at the capital 190 million payment, look back to some of the others that have just been within the last couple of years. Equifax, the largest 700 million t mobile, 350 million based on that data breach and another 150 million, by the way, that has to be spent incrementally over the next two years for updating their cybersecurity posture. Talked about Uber relatives at the beginning for that data breach that was covered up by the CISO. You know, they paid out 148 million on that, by the way.

There was a 50 state settlement that went out with all the attorney generals. Yeah. On top of the FTC investigations that taking place, they already paid $150 million a few years back for that data breach. Yeah, things are nothing new.

Well, you guys had, you guys, meaning the industry, sorry, at one point had kind of flirted with this idea where I think you were when he was marsh and I think it was 8200 in Israel and Urgana and Microsoft, I think. And you were all going in that they were going to kind of create a standard or what a company must do in order to, you know, qualify for like the classic cybersecurity insurance policy. That kind of went by the wayside, I think. And I don't know if there's any.

You know, there are a bunch of things wrong with that, of course, but I don't know if there's a. If there's a comparable movement going on today, but what do you do? I mean, you know, we're only talking about the riches that reported here. There's like 10 to 1 that aren't.

And so how can you guys protect yourself? Yeah, I think that the industry as a whole has collectively raised the bar across what they're expecting an organization to do from a cybersecurity standpoint, from a regulatory standpoint, it's. There hasn't been any one group that's driven it, but it's really born on necessity due to the losses. Just you look at what organizations charge for so many years.

When you talk about loss ratio, for every dollar of premium that you charge a policyholder, there are some companies that were paying out A$10. So they were losing money on every single, you know, account or their portfolio at a larger scale. So it's just that type of underwriting was not sustainable. So really, collectively, over the last couple of years.

And you're right, by the way you look at the number of big headline ransomware attacks, you know, for every colonial pipeline that you see, I mean, there are countless others that never hit the headlines that you never hear about that cause real financial harm and destruction. But collectively, what's been done over the last couple of years, there are a number of things that insurance companies now at this point are requiring. And it's interesting, so you mentioned mfa. That is one of the things that an organization almost universally now has to have in place.

But we know there are varying degrees of MFA that can be applied. You have somebody that's using, you know, their personal cell phone for mfa, but that's one of the easiest ways to get around. You pulled out somebody's number, you had essentially their phone access shut off. The number gets ported into a criminal, and then they instantly have access to the code that was being sent.

Then of course, you have software options that are being provided to hardware that can be used like Yubikey. So there's many different variations of that. But broadly speaking, MFA is one of probably the lowest hanging fruit in terms of what's being required of organizations. Having sound data backup strategies in place and data recovery methods in place has been a big one.

I've personally seen cases where somebody says, yeah, we back up all of our data, and then three months later they experienced a ransomware attack and they weren't doing an effective job or they weren't doing it on a regular basis. So the data that they had was either out of date or they never practiced going through the scenario and recovering all that information. So they might as well not have even been doing it to begin with. So I've seen cases where even with data backup, it wasn't effective, they weren't practicing, and the ransom still had to be paid because of that.

So having stronger controls around data backup, how long, you know, how often are you instituting data backup? Are you using multiple methods? Whether it's a cloud, off site? Those are questions that a carrier is asking.

You know, endpoint detection is an important area that a lot of insurance carriers are taking a closer look at to making sure that that's in Place that you have logs that you can look at, you know, different behavioral characteristics as people move through a network, being able to spot unauthorized access, closing open ports. If you're using Microsoft Office, they want to know that you're, you're locking down some of the access points, some of those access points from anyone getting in from outside the organization. So some of those things around data backup, data recovery, mfa, closing open ports, those are a lot of questions that carriers are really digging into and asking where it really was an afterthought going back before 2020. Yeah, yeah, you're right.

And it's getting only more complex as we go ahead here. I mean, assuming that you accept the fact that there's going to be a breach and what you're really looking for is, you know, improved resiliency on behalf of your customer, it would seem to me that if you know that there are a lot of independent, sort of independent research firms around, like Mandiant, for example, or Kaspersky, you know, that you could hire to, you know, do kind of a audit, if you will, of, you know what, and then give you a report that says, here's our view, here's where the weaknesses are, and then you could write policy based upon, you know, those weaknesses and corrections to them, et cetera. It seems to me that if you had more of a structured approach and we're using a respected third party like those two companies to do that sort of thing, that you, you would a be much better off in terms of your maintaining those incredible margins that you guys have over BNC business, but also that your likelihood of success would be improved too. Completely agree.

Going back, looking back at the insurance, cyber insurance industry, part of 2020, to put in perspective, it's almost like underwriting property policy, offering property insurance, but not asking what type of structure you have or is it located in an area that's prone to hurricanes? I mean, that's like the equivalent of what was being done because you have to be looking at what type of resiliency does the organization have? Are they training their employees regularly on phishing? Are they providing data backup?

On recovery, disaster recovery on an annualized basis at least. Do they have the proper security protocols in place? Do they have a firewall? Do they have a cadence for updating security vulnerabilities and pat or a different cadence for critical vulnerabilities?

A lot of that was just swept under the rug. And you're right, with the rise of venture tax and broker as one of those we have, and we're seeing more Partnerships with reputable, very reputable cybersecurity firms that are able to do active monitoring, that are able to take a look at the perimeter, that are able to offer a variety of training and development services to make the organization more secure, to give them more resources on the front end so that the policy just doesn't become important when a claim occurs. Because what happens is most people purchase insurance in Africa. You throw the policy on the shelf and dust collects on it.

You only need it when something bad happens. But what we're seeing inside insurance, what we've been focused on is having that policy work for you, having a number of services that are being provided up front that are actually useful and will benefit, they're beneficial to the organization. So it's almost like looking at cyber insurance as an investment in your organization, investment in improving your security. And that's particularly critical for that small and mid sized business space where they don't have all the relationships, they don't have necessarily the budget, they don't have all of the resources to be able to invest in foreign to the company from cybersecurity or regulatory standpoint.

So the cyber insurance company is an inch, they've begun now for the last couple of years to focus more on that because if the business can be more resilient, it'll be a better risk for the insurance carrier. Everybody wins in that scenario. So that's what we've seen quite a bit of. It's been a rise in the offering of resources, a rise in offering services to make an organization more secure.

And I think that's very important. Yeah, sure. No, you're right and that's a great point. We can leave this at I think today and you know, I'd love to pick this up again maybe midway through the first quarter just to kind of see what by that time of the continued fallout from SBF and FTX have been and talk about that some more.

I'm sure that they'll, I just, you know, if we're not careful, the government will be running all of this for us and that's not a good outcome, my humble point of view. So I agree. So thank you David, it was a real pleasure and thanks for taking the time to visit with us today. David De Giotis, there you go.

Is the chief insurance officer once again for a broker. I hope that our audience enjoyed this half hour. There's a lot to talk about here and there's a lot going on in the space and it's going to get more interesting as time goes on. So we'll talk again in a few months, David.

And so thank you to our audience as well for taking the time out of your day to join us. Until next time, I'm your host, Steve King, signing off. Thank you for joining us for another episode of Cybersecurity Unplugged. You can connect with us on LinkedIn or Facebook @Cybertheory, or send us an email @SocialybertheoryIO.

For more information about the podcast, visit Cybertheory IO podcast until next week. Thanks again.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on January 23, 2023.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!