Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - New Insurance Cybersec Ratings Service – Experts Views
News & Analysis

New Insurance Cybersec Ratings Service – Experts Views

ISBuzz TeamBy ISBuzz TeamMarch 29, 2019Updated:April 1, 20194 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

As reported by the Wall Street Journal this week, Insurers Creating a Consumer Ratings Service for Cybersecurity Industry. The collaborative effort led by Marsh & McLennan would score best products for reducing hacking risk, and some of the world’s biggest insurers plan to work together on an assessment of the best cybersecurity available to businesses, an unusual collaboration that highlights the rising dangers posed by digital hackers. The program, which was launched Tuesday will evaluate cybersecurity software and technology sold to businesses. Marsh will collate scores from participating insurers, which will individually size up the offerings, and identify the products and services considered effective in reducing cyber risk. The results will be available to the public on Marsh’s U.S. website.

Matan Or-El, CEO & Co-founder at Panorays:  

“We applaud this new initiative taken by the insurance industry. Such an initiative should be a win-win situation for all. Customers will need to up their cyber security program, thus reducing their cyber risk to attacks while cyber insurers will process less claims due to the higher standard of security.   

That said, there will undoubtedly be bumps along the way to assess the cyber security technologies. From the time it takes to evaluate the thousands of existing technologies, and new ones as they are introduced to market, to the testing methodology around each technology. To ensure that this initiative takes off the ground and becomes effective, enforcing the collaboration between the insurers is mandatory. Second, keeping up to date with the ever evolving threatscape is necessary to determine the efficacy of products against new threats. This means that traditional and well-established technologies must be evaluated in a similar manner as innovative technologies that address the newer challenges. Third, the assessment process must be able to scale to accommodate the evaluation of thousands of cyber security products.” 

Jonathan Deveaux, Head of Enterprise Data Protection at comforte AG:

“Research and analyst firms already provide some sort of rating system for the cybersecurity industry. Gartner uses the ‘Magic Quadrant,’ KuppingerCole uses the ‘Leadership Compass,’ and Forrester uses the ‘New Wave’ rating system.  Now, with global insurers collaborating on a rating system, this leaves a lot of open questions on how this could impact organizations today.   

When it comes to evaluating cybersecurity products, what approach would this collaborated effort by global Insurers undertake?  There are hundreds of products and solutions available which offer various ways to approach cybersecurity. Some solutions are more effective than others in terms of what the solution does and where it actually secures.    

For example, under the general category of “data security,” the data protection methods vary when it comes to actually securing the data – security professionals today know about Encryption, Tokenization, Data Masking (both dynamic and static) – all of which provide various way to protect, de-identify, anonymize, or pseudonymization of data.   

Also under the general category of “data security,” some solutions secure access to the data, rather than provide the protection mechanisms to the data itself. These are commonly known as Identity Access Management (IAM) or Privileged Access Management (PAM) solutions, which enable or restrict users from accessing data based on policies, defined roles, “need-to-know,” and other requirements.   

In addition to products, there are also frameworks and regulations around data security compliance (such as NIST, PCI DSS, HITECH, CCPA, and more) that provide guidance to organizations on how to approach data security as a whole with strict consideration to governance, internal policy, detection, prevention, and response.     

In terms of cybersecurity Insurance, take this scenario for example – if Company X follows their Insurance company’s rating system, and still suffers a data incident which fails to meet GDPR requirements, what coverage will the Insurance company meet?  Will the GDPR fine of up to 4% annual revenue be covered and paid by the Insurance company?   

At the end of the day, from a consumer point of view, we want to know that companies are securing our data, and ensuring our data privacy in the best way possible. It is hopeful that a collaborated rating system leads to this result because one thing is for sure… cyber attackers and bad actors don’t care about rating systems.” 

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}