# Assessing Cyber Security Risk: 10 New Questions UnderwritersShould be Asking
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-08-04
Category: TECHNOLOGY
Category URL: https://financedigest.com/category/technology
Meta Title: 6 Crucial Questions Underwriters Should Ask When Assessing
Meta Description: Understand the challenges of data innovation and security in today&#039;s landscape. Ask about data type, security culture, staff, C-level roles, company age,
URL: https://financedigest.com/assessing-cyber-security-risk-10-new-questions-underwritersshould-be-askinghtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/sh8-5247-826-1736843619990-compressed.jpg)

By **Tom Beale**, CTO, [Corax](https://www.coraxcyber.com/)

Today, companies are facing the difficult challenge of encouraging employees to innovate with data while managing the tricky security conundrum this has become. Underwriters are faced with the even bigger challenge of understanding and assessing potential business interruption introduced by dozens of new dependencies that didn’t exist five, ten years ago.

Here are ten of the new questions underwriters should be considering when assessing risk in today’s new cyber security insurance landscape.

## 1\.    How Much Data has the Client Got, and What Type of Data is it?

Many organisations actively collecting data [don’t know](https://www.financedigest.com/women-in-technology-that-you-should-know-but-probably-dont.html "Women In Technology That You Should Know (But Probably Don’t)") what they’ve got or why they’ve got it, which is a dangerous situation to be in.

So underwriters need to be asking: is this business in the data collection business or not? Case in point, many large retail organisations that have been collecting credit card related data for [years have recently begun outsourcing their credit card processing in a way that means that credit card data never touches their own network](https://www.financedigest.com/a-network-of-networks-will-ceos-be-replaced-by-ai-in-the-next-10-years.html "A Network of Networks: Will CEOs be Replaced by AI in the Next 10 Years?"). It means reducing liabilities associated with credit cards while [lowering risk](https://www.financedigest.com/evergrande-jitters-pull-risk-currencies-lower-dollar-gains-on-safety-bid.html "Evergrande jitters pull risk currencies lower, dollar gains on safety bid").

## 2.   What is the Client’s Security Culture?

Security culture is quite complex and pervades every element of a business.  It’s definitely not just an IT issue or a function of your security department. It’s contractual and a function of purchasing and legal, and it starts at [board level](https://www.financedigest.com/electronic-board-level-underfill-and-encapsulation-material-market-to-expand-at-a-cagr-of-5-5-by-during-the-forecast-period-of-2020-2030.html "Electronic Board Level Underfill And Encapsulation Material Market to expand at a CAGR of 5.5% by during the forecast period of 2020-2030") as well. What does the tone from the top look like when it comes to promoting a solid security culture?

## 3.   What About Staff and Third Party Contracts?

If you’re looking at an organisation and [trying to understand its approach to security](https://www.financedigest.com/five-ways-bad-bots-are-trying-to-crack-your-virtual-vaults-by-erez-hasson-strategist-application-security-at-imperva.html "Five Ways Bad Bots Are Trying To Crack Your Virtual Vaults"), the people that it employs are very important. Companies that don’t [think about this structural and cultural element of a business](https://www.financedigest.com/why-mentoring-does-more-for-your-business-than-you-think.html "Why mentoring does more for your business than you think") are more frequently the victims of attack.

Human error accounts for a huge amount of vulnerability, and it’s not even necessarily your own people. Often [companies find themselves in weak positions because their software providers can’t patch systems because they may be using an older operating system or running](https://www.financedigest.com/elon-musk-who-runs-four-other-companies-will-now-be-twitter-ceo.html "Elon Musk, who runs four other companies, will now be Twitter CEO") some sort of custom software.

## 4.   Does the Organisation Have a CIO, CDO and CSO?

If a company has senior people in these roles, they may be in a better position to make informed decisions surrounding data.

Not every company can afford a [Chief Security Officer](https://www.financedigest.com/inmobi-names-inderbir-singh-pall-as-chief-technology-officer-of-inmobi-advertising-platform.html "InMobi Names Inderbir Singh Pall as Chief Technology Officer of InMobi Advertising Platform"), but we’re starting to see more third party outsourced CSOs and security monitoring services, especially amongst SMEs.

## 5.  How Long Has the Organisation Been Around?

Age and size are important criteria when it comes to security. Youngerorganisations are more likely to have grown up with more security conscious [systems and practices and more likely to secure data](https://www.financedigest.com/interoperability-of-data-to-accelerate-the-whole-slide-imaging-systems-market.html "Interoperability of data to accelerate the Whole Slide Imaging Systems Market") in the cloud.

Age and size may not be a problem if a company is serious about its view to [investing in the business](https://www.financedigest.com/japanese-businesses-pledge-uk-investment-ahead-of-sunak-meeting.html "Japanese businesses pledge UK investment ahead of Sunak meeting") for the purpose of security, robust infrastructure and training.

## 6.  How Many Systems Does the Company Have?

Similarly to the point above, bigger, older organisations are likely to have more assets and less idea of exactly how many they have. This is a major concern as it only takes one asset to become vulnerable for malware to be introduced.

It’s also critical to drill down further and look at whether an organisation has systems that were built in isolation from one another. When an organisation does not take a [global approach to building its systems](https://www.financedigest.com/intelligent-transport-systems-its-market-2021-by-global-key-players-types-applications-countries-industry-size-and-forecast-to-2027.html "Intelligent Transport Systems (ITS) Market 2021 by Global Key Players, Types, Applications, Countries, Industry Size and Forecast to 2027"), they may be more vulnerable to threats.

## 7.   Attitudes and Approaches to Security IT

Today, underwriters should be very interested in understanding what percentage of [revenue a company](https://www.financedigest.com/surgical-blades-market-global-leading-companies-analysis-revenue-trends-and-forecasts-2027.html "Surgical Blades Market Global Leading Companies Analysis, Revenue, Trends and Forecasts 2027") spends on security related IT. It’s useful to watch if that percentage goes up or down in order to gauge how committed a company is to security.

## 8.  Are Their Own Products Secure?

It’s also useful to watch whether organisations are [building security into the products](https://www.financedigest.com/why-building-new-products-for-a-circular-economy-is-essential-if-we-are-to-preserve-the-earths-finite-resources.html "Why building new products for a circular economy is essential if we are to preserve the Earth’s finite resources") they are creating. It’s understandable that companies want to get new products out to [market quickly](https://www.financedigest.com/zeal-to-move-through-settlements-anew-to-drive-the-individual-quick-freeze-fruits-market.html "Zeal To Move Through Settlements Anew To Drive The Individual Quick Freeze Fruits Market"), but if they are not being built with security in mind, this is a real concern.

## 9.  How is Outsourcing Handled?

Outsourcing is not bad – it’s a fact of life. It is how a company manages its outsourcing relationships and its third parties’ access to its infrastructure that help us in assessing its vulnerability.

Underwriters [must also try to find ways to look at the ripple effect and the inherited risk](https://www.financedigest.com/ecb-must-be-prudent-with-rates-hikes-as-recession-risk-rises-panetta.html "ECB must be prudent with rates hikes as recession risk rises: Panetta") from all third parties and their respective third parties.

## 10\. The Infrastructure to Employee Ratio

When looking at large businesses, it’s also useful to apply an ‘infrastructure to employee ratio,’ which looks at the business from an asset perspective, investigating how a [company invests](https://www.financedigest.com/the-benefits-of-investing-in-healthtech-and-medtech-companies.html "The Benefits of Investing in Healthtech and MedTech Companies") in technology in line with the number of employees it has. If a business has a large number of employees but also invest significantly in its infrastructure regularly, this is a positive sign.

## In Summary

[Cyber risk](https://www.financedigest.com/using-threat-intelligence-to-minimise-cyber-insurance-risks.html "Using Threat Intelligence to Minimise Cyber Insurance Risks") can no longer be considered just an IT problem. When assessing the immediate financial loss that might result in a client suffering some form of business interruption event, underwriters are [moving beyond](https://www.financedigest.com/the-high-strength-rtd-malt-beverages-market-to-move-beyond-the-monotony.html "The High Strength Rtd Malt Beverages Market To Move Beyond The Monotony") IT and considering whether companies have a proactive security culture, and whether they have put the right people in place to understand data and how to best keep it safe.  It’s also about looking at the people within, the outsourced agreements and how these are managed.

The ten questions above represent only a few of the new complexities underwriters are considering within today’s new threat landscape, but combined with the use of technology to make [cyber risk](https://www.financedigest.com/minimising-supply-chain-cyber-risks-by-asking-the-right-questions.html "MINIMISING SUPPLY CHAIN CYBER RISKS BY ASKING THE RIGHT QUESTIONS") analytics more transparent, underwriters are better prepared than ever before to ensure they fully understand the scope of cyber risk.


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

