Menu

  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
Podnion
No Result
View All Result
Subscribe
  • Login
Podnion
No Result
View All Result
PassW0rd, Insuring the Future

PassW0rd, Insuring the Future

Play

Speaker A: Hello and welcome to a new season of Password here on Resonance FM with me, Peter Warren. And in this month’s program, we’re examining cyber insurance. And the massive role that it will play in our 21st century future. We also have an announcement to make, and as many people using social media will know, the default position is to be excited. And today we’re excited because for the first time we’ve been sponsored by the cybersecurity company ESET, one of the leaders in protecting home and office computer systems from cyberattacks. It may sound unlikely that insurance could play such a role, but cyber insurance has been creating tremors in the cybersecurity industry for over a year now because of announcements by underwriters that they will not pay out for attacks involving nation-states that they could define as acts of war. They’ve also been refusing to pay out for ransomware attacks. A change in attitude that is spreading panic because many observers in the cybersecurity industry admit that they expect many businesses and institutions to fall victim to a data breach, with most involving ransomware. Top of those under threat is the educational sector because of the risks posed by pupils and students for whom cybersecurity is not a top priority. At a cyber security conference hosted by the New Statesman in November of last year, one of the advisers to the higher education sector confirmed that all UK universities expected to be attacked. “It’s not if, it’s when,” he told me. Now, we are in back-to-school month, and we are already seeing the consequences of those poorly protected laptops, computers and USB sticks coming into classrooms. Already, news has broken that the St Augustine Academy, a secondary school in Maidstone, has been hit by a cyberattack with pupil and parental data encrypted. Quite literally closer to home for Password, news is circulating of a similar event in a secondary school in Debenham in Suffolk, where children have been told to bring in laptops and mobile phones because the school’s computer system’s not working. Once again provoking fears that parental data of past and present students may have been compromised. According to a school representative, up-to-date safeguards had meant that no personal information had been lost and restoration was happening quickly. A version of events disputed by parents who said that they were aware of problems with the system halfway through August when pupils were unable to log in to carry out holiday assignments. And those schools were not alone. It’s also emerged that a North London school and a Berkshire schools group have also become the victims of serious cyber attacks, according to local reports. Highgate Wood School in Crouch End will now begin accepting pupils on September 11th rather than September 5th. Though according to the head, the attack had not been as devastating as those in other parts of the country. In an email sent to parents, Patrick Kosier stated: Having carried out investigations, we are extremely confident that our data has not been breached. On the face of it, the situation is bad enough, but it masks another even more disturbing reality, because cyberattacks on poorly protected school technology networks will soon become a tax on our future due to the urgent need for schools to quickly integrate artificial intelligence into virtually every part of the curriculum. A point made by Dr. Tim Daisy, an AI expert who worked at the famed Massachusetts Institute of Technology for 30 years and who has just brought out a book on the AI revolution destined for education called Wisdom Factories. According to Daisy, in the future, we will not need to acquire knowledge in the way that we’ve been used to doing for centuries. AI removes that need. What we will have to do is acquire the ability to effectively interrogate that data and decide how to use it. We might ask AI to supply us with all of the relevant information on climate change, supplying the technology with a motive. We will then manipulate the data to extract additional insight from it, and then importantly, we will make a decision based on those findings.

Speaker B: Well, that’s true. And you know, I think about this a lot, which is if we seed our knowledge to AI and if AI itself can continue to add to that knowledge, at some point do we become incapable of doing things that AI— and it puts us in a vulnerable situation as humans. You lose the internet, you lose your ability to do anything, for example.

Speaker A: Knowledge is power.

Speaker B: So, you know, it isn’t clear. We still need knowledge, right? You can’t make judgments without some forms of knowledge. It’s just different knowledge than what we once had.. And it’s not necessarily the details. It’s more about the meta-knowledge, the knowledge about how learning occurs in humans, how biases kick in when we try to make judgments, what processes will help us mitigate those biases. That becomes knowledge that is really critical. So we’re not giving up on knowledge. There isn’t really much understanding. On what knowledge we need to be able to do to be wise. But certainly there is. I think that’s going to be something we have to learn as we move forward.

Speaker A: In the book that I wrote, we put in 7 what we considered to be rules that had to be abided by. One of them was that primacy of interest must be respected and device sanctity assured, i.e., that phone that you’re holding in your hand, What we were saying was that the data that relates to you, you own that data. You own the rights to the use of that data. If you have a little bot in your phone that’s saying you need to go and get this particular education, you need to do this course, you need that, you need to make this decision, that’s got to be pinned to you as an individual in this new world, hasn’t it?

Speaker B: That’s right. I mean, we all have our own context, right? Again, if we think of AI as a decision-making technology, we have our own decision context, and that includes us as an individual. What is our personality? What are our abilities? I have a little bit of ADHD as an example, right? So I am going to need some tools to keep me on target in my scheduling and assignments and to make sure that I don’t go into la-la land where I’m inside my head too much. Or it may mean I need prompts to get me out and, and get a lot of exercise to deal with hyperactivity. That doesn’t— isn’t what other people need, right? That, that’s particular to me. When we come into a decision realm, we’re, you know, self-awareness becomes an asset maybe for the first time in work history, other than, let’s say, for, for those in leadership. We better know ourselves. And I think there’s some attempt to do that in our educational system, but it certainly isn’t center to try to make each student understand themselves individually. It’s more about trying to give people the things that everybody seems to need, or they think everyone will need. And the future with an AI that can do a lot is really almost the opposite. It’s about feeding people the things that make them unique and growing those.

Speaker A: Right. So it means that we’re going to reevaluate our concepts of data ownership, because we’re going to be asserting our ownership of data, as opposed to governments and large corporations asserting that they own our data because they’ve collected it.

Speaker B: That’s right, we’ve got fundamental structural problems in the tech world.

Speaker A: Daisy’s views are not unique. As he says, AI promises a revolution in education that will shake it to its roots. He argues that in the very near future, we will build huge databases of information, and that education will require the teaching of AI skills to interrogate them. Thinking and being able to make decisions on the basis of those searches, Daisy says, will lead to wisdom, a process of augmentation that will be continued by the AI systems. It was a point underlined to me at the beginning of this month at the House of Lords at an evidence-giving session about the challenges the technology presents for education. According to University College of London Professor Rose Luckin, who has been researching AI in education for the last 30 years, the potential of AI means that every child could have a bot or an avatar assigned to them that will work on helping them to fulfill their potential. It’s an idea of a future world taken up by a lot of people, such as internet innovator and pioneer Louis Halpin, chairman of the conversational AI company Ami. As far as Halpin is concerned, in the future we should control our own data and license it back to the government, a development that would mean that many of us would, as some commentators are suggesting, look to take out personal cyber insurance.

Speaker C: There’s two facets to it. The first facet is how the teachers should teach. The second facet is more about human rights. So we have in this country We have the Human Rights Act that universally our children have the right to education. I strongly believe that universally our children should have the right to utilize AI. But I don’t think that it should be supplied by large faceless organizations and a further consolidation of power and control by those organizations. And that especially came to mind when I received a letter from the NHS. And the NHS says you are one of 5 million very carefully chosen people ‘Who would like to use all your health data to improve the NHS?’ So of course my first whim was that, of course I’ll support the NHS. And then 10 seconds later it was, ‘Well, who’s doing this research? Who’s using this data? Who am I giving access to that data?’ And I thought, well, I should be rewarded for that like a kid. I should be rewarded in the same way as the teachers write the textbooks, or you as a journalist write your newspaper. If I use your IP as part of my information source We know in society that we will get paid for that piece of creativity or that piece of knowledge. But all of the data, like the NHS study, can be very small data elements. It’s exactly the same at school. I go to school, I hit the register on time every day, I do my homework, I ask for help from the teacher, I move around the building in a certain way. All those are data elements which come out to make my personality. So what I want to happen is I want, first of all, everyone who provides their data or creates knowledge to be rewarded throughout their whole life for how that data is used. Now, it’s easy to do that without being boring about it, but you can use blockchain, you can use digital currencies, and you can reward infractions and trace transactions. So when we get back to schools, the question is, how do we achieve that? And the way we practically achieve it is twofold. The first is there’s something called a small language model. And it’s not small in terms of its power, but it’s small in terms of its footprint. So it allows us very easily to set it up. It doesn’t always have to be online. You can run it on your phone, but it has access to all the knowledge, all the skills of generative technology. It can also be set to access your textbook. That the teacher’s written. And then if you use a technology like ours on top of it, which is called automated reasoning, we can work out where the best place to take that information from to give you a result to a goal. I’ve got to pass my geography GCSE. That’s going to be a goal. And we can use all your data, all the heuristic knowledge you get in generative AI so that you can best tailor your experience to meet that goal. And you can choose for your favorite teacher to be looking in on you and helping you with your exercise, or even bringing it in from an external source like another textbook, another school, whatever you want to do it. But put you in control, make it private, make it personal, make it safe to you, and keep that knowledge— is your knowledge for the rest of your life, something you’ve worked on in education. So here’s the next bit of the thinking. And possibly the most radical part of the thinking. The government will pay for your education in this country. The government will pay for your health service in this country. I think the government should pay for your AI small language model and give that to you as a student in the school for you to use, use in a mature way as you go on throughout your entire education. And that’s the model we should be solving. We were the first country where we weren’t, but we were the first country in modern times to have an NHS. And it was, it was transformative in our society. And we have another opportunity to do something similar.

Speaker A: And do you think that this model should— in a sense, it’s a mentor, isn’t it? Do you think that it should be taking all of that information about you, making suggestions, saying, hey, you didn’t do too well on the geography GCSE, but you did pretty well on physics, so why don’t we concentrate on that and we could be going in this particular career. Do you think that that’s the sort of relationship that you should be building?

Speaker C: Yes, something my father always said to me, I repeat to my children: work extra hard on your best subject and work extra hard on your worst subject because the rest of it will fall out. You can then have that kind of influence. It’s especially important for the kids in, um, who have more difficult backgrounds. They’re going to need that extra help, you know, if they’re sleeping on the sofa the whole time for whatever reason, or you’re going through a divorce, you need some level of constancy. You also need the ability to reach out for help within you. We have amazing social services which are much maligned, but they also should give the opportunity for you to choose, not for them to look in, but for you to choose to do it. Because you have to be— if you’re not in control of it, you won’t trust it, and you won’t get the freedom that depends on you trusting it.

Speaker A: AI visionary Louis Halpern of Ami on why we should look after our own data. In our current world though, the battle is for that data that Halpern wants us to reclaim. Like many, Halpern also sees this as a potential moneymaker in the future. Instead of letting big tech make money from our data, the argument goes, we should be sharing in the profits of our progress through life instead of the companies that have nothing to do with us. It’s a concept that’s beginning to get some traction in the business world where people have talked about companies in customer-client relationships opening up their data with each other to create transparency and supply chain efficiencies to make business processes more streamlined. The theory goes that in so doing that you should share in the proceeds. But if you’re going to do that, You’ll have to ensure that your data is clean, because in the event of a small company’s compromised data going to somewhere it should not be, the losses due to liability could be huge. It’s a scenario that digital evangelists say will see the insurance industry beginning to demand minimum standards of cybersecurity to obtain insurance. Demands that will also insist on companies and individuals understanding how their data will be used and where. The difference between driving in East Anglia and the Cairngorms. They will also insist that you are aware of the risks associated in business relationships. A cleaning company for a washing machine manufacturer will obviously not be of as much interest to a Chinese government hacking agency as a cleaning company for a computer chip manufacturer. Insurance, goes the argument, would drive up awareness of attack and lead to companies deploying proper protective measures. Because to be on the World Wide Web means that the world is on your doorstep. Holding data makes you a target. A computer with access to a school network may be useful for a ransomware attack. A computer with access to a university research lab working on quantum will attract an altogether different sort of attacker. Informally, a government advisor at the Lords event told me that following the initial attacks on schools, that the government was now bracing itself for attacks on universities when the students return next month. A comment mirroring that made to me at the New Statesman event almost a year ago. In this fast-approaching future AI world, Attacks on the databases of the education system, then, represent an incredibly real threat to our future and therefore our economies, another point picked up on at the Lords evidence session, where speakers noted that governments had to be in control of the databases that defined cultural attitudes and values. Poisoning a database, for example, could lead to the adoption of extremist views or reinforce misleading information. —a possibility given some credence by the activities of the company Cambridge Analytica, which interfered with social media in favour of Donald Trump in the run-up to his election as US president. A potential pointed out by Mark Hughes, president of security for DXC, a global multinational that provides cloud services and cybersecurity to companies. Possibly better known to the general public for its sponsorship of the football club Manchester United. As Huw says, maintaining the integrity of databases is a significant issue.

Speaker D: Indeed, large language models are no exception to the fact that they are, they are based upon datasets. And if that data, you know, that data is typically scraped from the open internet in vast amounts, if that then, if that then includes, as it probably does, offensive and inaccurate or controversial material, that will have an output. So basically, you know, and then maliciously motivated people may actually tamper with that information to produce those undesirable outcomes. So there are a number of things, therefore, that the way in which things are being responded to this, which is again trying to find that balance of having those truly large, massive datasets taken straight from the internet to inform the types of AI tools versus having closed datasets that are just very specifically associated with that type of activity. So for example, in cyber, there’s an initiative that we at DXC have launched with some of our software partners that we work with closely to say, well, look, where we are, where we have machine learning and LLM models using those datasets, let’s specifically make them for the thing that we’re trying to do in cyber. So let’s create systems where we can, we can exploit all the available information around cyber, but not widen that to everything out there because that then has an impact of potentially corrupting the validity of the use of AI in the first place. And I don’t want to talk specifically about completely closed groups ’cause that sort of defeats the object in some respects, but equally just be narrowing down a bit so you don’t get this absolute vast amount of data into, as you say, educational, models that then can include a load of content that just isn’t relevant and then really undermine the value of it in the first place. So I think that’s the approach that we’re certainly taking at DXC. We’ve seen others doing as well to almost focus on those datasets which are really applicable for the task in hand and then constrain, if you want, the AI and the LLMs to those to get the best results that you can. Now, that’s an approach that we’ve taken and that we are taking that we’re seeing some success with, and I think that will go into other areas as well.

Speaker A: I mean, this also does beg, though, that there is a need for a more universal protective approach because it’s September. This is back-to-school month. Already there have been several examples of schools that have been hit by ransomware attacks very, very close to home in the village that I’m in in Suffolk. The school here is trying to keep quiet the fact that it’s undergone a ransomware attack because it’s been asking the pupils to bring in laptops and mobile phones so that they can actually do their schoolwork. That is going to be an issue because we do need educated people. We do need education systems to keep going as a society. We are as valuable as the education levels in our society. So unless we do this fairly universal protection against the attack that you’re talking about, we could be in a bit of trouble.

Speaker D: I really do think that. And I’m really sorry to hear about your local school having been hit by these criminals. At the end of the day, let’s never forget these are criminal this is criminal activity against these types of organizations that they know to be vulnerable, and they are specifically exploiting them because they know that they aren’t necessarily the biggest, the biggest organization that protect themselves against the, uh, the type of activity. That said, I also say that here at DXC, I see many different organizations being impacted by malicious activities, small and huge, all the way through the spectrum. And the bottom line is that they really, really need to just concentrate on the very basic things. There’s a scheme that the NCSE publishes called Cyber Essentials. Again, look that up on the website. There are some really good pointers there, which any organization can implement. And they’re often quite simple things to do and to get right. So we really do have to concentrate and all your listeners, really, I would urge them all to just check that the basic, the basic things are in place. And I don’t want to be over-technical, but passwords, password sharing. Multi-factor authentication, that thing where we get those prompts before we can log in. All those things are really important. If you need to, often if you think that you might be impacted by something, can you recover? Can you back up? If you do spot something strange, can you respond and react to it? So those are really basic things that I think everyone can get right. And sadly, those criminals are exploiting the fact that we haven’t got all of those things right yet. So I think there’s a lot that can be done and continue to do. Which is not hugely sophisticated, which we can all get better at to stop these things which are causing real harm. I never want to get away from that. We should never get away from the fact that, you know, the example you just gave, there are many examples of those where innocent people are being impacted by this type of activity. The better we can get, the quicker we can get at the basics, the more we’ll stop that type of stuff. And it doesn’t change the fact that there will also be activity associated with some of this more emerging technology around AI as well. But we mustn’t forget that basics also count for a lot as well.

Speaker A: Mark Hughes, who is president of security for DXC, is in charge of 3,500 cybersecurity staff needed because the criminal onslaught Hughes mentions is not only unrelenting, it is huge. Here’s Jake Moore, global cybersecurity advisor for ESET, painting an all-too-familiar picture of the frightening levels of cybercrime currently facing UK schools, businesses, and households.

Speaker E: 50% of all crime is cybercrime and fraud, and that’s been roughly the statistic that I’ve seen constant over the last 5 years. But when you put into place the amount of crime, that’s huge. Crime increases every year, so to have 50% of it in cybercrime and fraud, then we’re talking massive numbers.

Speaker A: So are we talking about, what, trillions of attacks? I mean, if they’re automated by artificial intelligence, then Presumably they’re coming in all of the time where everybody is seeing them. I see emails all of the time from enormously wealthy people in Nigeria who are wanting to send me money.

Speaker E: Yeah, I think if we come to the numbers side of things, then yeah, we probably are talking in the trillions or more. It’s heading towards infinite. Some companies tell me that they are constantly attacked in all shapes and forms. Phishing is the thing that’s quite visual, but of course we’ve got bots hitting in the background that just automate their business and trades for them. And this is it. The automation is becoming so much better. And with AI powering it and with the data that fuels it, we’ve got— these numbers are just going to continue.

Speaker A: Lots and lots of companies have been complaining about ransomware, but Ransomware seems to be tailing off according to reports that I’ve just been sent. They say that people are now after data, that there is this attempt to basically create a huge stockpile of information, whether that be information about individuals or whether it’s information looted from companies and governments.

Speaker E: Ransomware is still around, but I think it’s slightly changed and being called or dubbed ransomware 2.0, where they go for the data as well, which was always part of how ransomware works. But to be able to take that data and extort them for potentially more money— I kind of see the turning point, what was it, 2018, when GDPR rules came out, particularly in the UK. You’ve got that turning point where data became such a huge currency in itself. But on top of that, data is what fuels AI. The— these language models that, that are so fused together by, by millions of lines of data, that becomes even more of a powerful currency. And so if there are criminals out there that can use that data to either create their own models or still go down the financial threat, then of course that becomes what they’re after. But criminals work in different ways. We’ve got different ways that they’re— how they work, what they’re function is and what their motivators are. And some are financial, but of course you’ve still got nation-state attacks which are going after governments as well, and they’re particularly difficult to locate and find any information on them. Some of these nation-state groups just typically get called a number or a name, and that’s as much as the police environments know about them.

Speaker A: And some people are thinking or claiming that this is an attempt to almost build a criminal mirror, that what the criminals or what these criminal elements of governments are trying to do is essentially create lists of all of the inhabitants of a country, what they do, what their contact details are, things like that. This has been suggested as one of the reasons why the electoral roll was of great use to criminals so that they can use that data to actually home in on individuals who they consider to be worth targeting.

Speaker E: I think we’ve, we’ve seen data, very personal data, on the dark web for many years now. If we look at websites such as Have I Been Pwned, they’ve been showcasing the amount that our email address gets compromised. But on the dark web I’ve seen it, I’ve been there to actually locate many multiple lines of data including home address, phone number, bank details that correspond with the name and the email address. That’s still there. Maybe if they’re putting it all into one database, that’s a huge task in itself when we’re talking about billions and trillions of lines of data. But yes, that is essentially what they could be after. But rather than looking at what they are trying to make. We’ve just got to instill this awareness with people and make them understand those risks, because particularly younger people don’t see this as a worry for their future, particularly ones that haven’t gone through the larger credit checks when they might want a mortgage or to take out a large loan. But on the stories of those people that have, they have found that the problems occur once their details have been put out there, and they might have very bad credit due to other problems that have happened without their knowledge in the the past.

Speaker A: And of course, this is something that we’re seeing manifested in these attacks on schools. Students go back to university, children go back to schools, and we see that the schools become compromised because they’ve gone in with devices that will probably have very, very poor cybersecurity practices.

Speaker E: Well, that also tends to follow a little bit of a pattern here. We have tended to see in the past This is very anecdotal, but we have seen schools targeted in the first term of the season around September, October in the past. So the other motivator that I didn’t mention could also be what we call script kiddies, young people who are testing their, their skills, and of course they want to test their skills on their local environment, which is naturally their school. And local habitat. And so unfortunately, they are the one of the first targets to suffer. And as they are funded by local government, they tend not to have the best securities and protections in place, and therefore big problems can occur.

Speaker A: That was Jake Moore, global cybersecurity advisor for ESET, our sponsors of this program. It’s a situation that is forcing organizations working online to accept the inevitable. Their computer systems will be breached, and they will have their data locked by software illegally introduced to their systems by cybercriminals who demand a ransom to return access to it, a criminal activity known as ransomware. Or increasingly, they will have their data stolen so the criminals can exploit its value. In either case, it is the business equivalent of a car crash. It’s an issue that not even government agencies are immune to, as we discovered in the recent attack on the Electoral Commission’s computers, which saw the data of 40 million UK voters compromised. An event prompting some commentators to suggest that either crime gangs or the criminal elements of rogue cyber-states like Russia, China, North Korea or some South American countries were building a crime mirror of the UK, the aim of which, they said, was to map out the UK’s population in an underworld version of Facebook, complete with character profiles, so that people can be targeted for further lucrative crime. As ESET’s Moore pointed out, 50% of all crime is now computer-based fraud. In this world of wholesale data Everyone and everything is under attack, whether it be by spam emails at home or at work, only sent because they are successful as the route into a company’s computer that could quite easily be in a home office. It’s a world that is leading to an uptake in businesses seeking cyber insurance, though unlike car insurance, cyber insurance is not so straightforward, as AJ Thompson, the chief commercial officer of the information technology company North Door, points out.

Speaker F: Well, I, I think the announcements yesterday and, uh, I think the day before and today are just a great example of issues that companies face where they are not in control of the process and they find themselves in a very difficult position. Which is that they are, they are responsible for something out of their hands that they know will cost them an awful lot of money. It will cost some reputational damage, and they need— it’s like having car insurance. You can, you can drive around without car insurance and it’s all fine until you have an accident, and all of a sudden you’ll be very pleased you bought your car insurance because these things cost an awful lot of money. I think the, the reason that people went for cyber insurance initially was that it bought them a little bit of a security blanket. In the early days of cybersecurity, it was relatively inexpensive. At one point, I think it was a £1,000 premium for a million pounds cover, and it was a look what we’ve done, aren’t we clever people. But so people want it because they know it’s the right thing, but I think the problem is there have been so many claims now that All of a sudden, cyber insurance isn’t as free and easy as it used to be at a time when more and more people need it. So it’s a comfort blanket right now, but it’s becoming increasingly expensive.

Speaker A: You mentioned car insurance. I take out car insurance. Everybody knows what you insure against. Everybody knows what the risks are. What seems to be the problem with cyber is that it’s very difficult for people to work out what their risks are in a particular particular area?

Speaker F: It’s incredibly difficult to work out what your risks are, and, and what people tend to do is traditionally they will look from their network in, and they will look to protect themselves from the network to inside the business. So you put your firewalls up, that’s your basic stuff, you have a bit of antivirus software, you, you tell people not to be idiots and to click on links and what have you. And really, that’s the limit of most organizations. Clearly not necessarily big organizations and big banks. They take it far more seriously. But average organization will look at that and think, you know what, we’ve done our piece, we should be okay. And that’s about the limit. But no one thinks about the external position of their cybersecurity, and that’s where the problems occur. I mean, you still have people within a business doing silly things, and sometimes you can, you can manage that, and sometimes you can’t. But predominantly, and what’s happening, you see more and more now, is there are groups of people out there purposefully looking to attack organizations, any organization. And that’s where the confusion comes, because people think, oh, you know, I’m secure, I’ve got my network and I’ve got my passwords in place, what have you, we should be okay. So there’s a massive confusion and things like GDPR were brought in to try and bring a structure to that confusion. And there was a massive to-do a few years back about GDPR. And honestly, I don’t think I’ve heard anything about GDPR ever since. People started off the program, did a little bit, and then actually filed it away under, we’ve started, we just won’t finish. So yeah, it’s not regulated. And you’re playing with people who don’t play by the rules.

Speaker A: But herein lies the sort of issue, doesn’t it? Because ostensibly we have something, two topics that may seem to be a little boring to the public at large. Computer security or computer security, that’s those people who always get in my way when I’m at work and try to tell me that I shouldn’t do this. And insurance. These are not things that people really want to talk about. Insurance is something that they sit there and think, ‘Blast, I’ve got to have this because if I don’t, then I could be done by the police.’ It’s a grudge spend, isn’t it?

Speaker F: It’s a grudge spend. You only buy it really if you have to have it and if you— and you’re annoyed about it. And if you don’t have to have it, you don’t—

Speaker A: don’t go for it. And so, but the problem with this is that the flip side of this is that what’s happening is there are lots of people in other parts of the world who are looking to find out information about particular organizations and sell that. And they don’t really care about what that information is. They just want to sell it. So they want to sell, I’ve got your passwords, I’ve got your vulnerabilities, and they sell it on an open market. Market. It’s a bit like saying, okay, I’ve got a load of radishes and I’ve got some parsnips here at the different prices for them on my vegetable stall in the market. However, what’s happening is that you then have somebody— I could extend this food analogy and make it pretty awful— but, um, who’s sitting there thinking, yeah, I’m going to subject all of this to a bit of analysis because there are particular companies that I’m interested in and those particular companies can give me access to other companies. It’s basically the people are looking at a list of ingredients and seeing what they can make out of them. And that’s what we haven’t had before, isn’t it? And that’s why this cybersecurity picture is getting a little— and the cyber insurance picture is becoming a little alarming.

Speaker F: Yeah, well, I think some of these big gangs have realized there’s an awful lot of money to be made. If you, you know, find the right people, they will pay. There was a recent breach with a software house in the City of London. It affected lots of clearing banks. Allegedly, the fine was paid by a mysterious benefactor, and everything was returned back to normal. It’s a big business. It can be done by a single person with a laptop, and, and you can rent the code and you can send it out to hundreds of thousands of companies with a view to just landing one, and that could be your, your meal ticket. And that’s the problem. And again, recently, talking about cyber insurance, they’re starting to change the rules and legislation around cyber insurance, and I believe that Lloyd’s of London are going to change theirs so that they’re not going to pay any ransoms from gangs that they believe are state-sponsored. So all of a sudden, you know, you get some fairly significant restrictions there. Because like I say, these things can cost an awful lot of money to fix. It’s not just the fine or the embarrassment. You know, some of these, if you don’t pay your fine, you’ve got to rebuild your systems. We were speaking to a business a couple of weeks back, and they were attacked. They were given a chance to pay a fine of several hundred thousand pounds, and they refused, and they had to rebuild from scratch. Scratch. They lost everything. And, you know, they were a smallish business and they could do that. It still costs them an enormous amount of time and effort to do it, but they could do it. But a big corporate can’t, can’t do that. They can’t rebuild. These things are too complicated. And like I say, going back to the driving analogy, you’re right that you’ve got insurance and you drive on the road. Typically, everyone on the road has rules to follow and they follow those rules. Typically, ordinarily, you know, everyone knows you drive on the left and blah blah blah, but you’re not playing in a regulated controlled space like you are with that. It’s a free-for-all. I mean, I was speaking with a company that does managed detection, and they say that every month they track 1 trillion attacks.

Speaker A: AJ Thompson of North Door. On an utterly Wild West situation that many people are utterly oblivious of as they gleefully document their lives and loves and career moves on Facebook and LinkedIn. Something that, once again, the government is not immune from. Only a week ago, the recently appointed Chief Technology Officer for the UK government’s flagship cyber defence force, the National Cyber Security Centre, flagged up his new role was instantly applauded. Over 348 people commented and 1,534 waved their best wishes, handily setting out a number of acquaintances that could be used as online body doubles to any criminal wanting to attempt to find a way to the top cyber executive’s inbox. It’s a carefree attitude to providing what the intelligence community call OSINT, open source intelligence, that most hardly ever thought about. An attitude that Pete Bowers, the chief operating officer of cybersecurity and insurance consultancy Norm Cyber, says is getting in the way of companies when they try to obtain cyber insurance.

Speaker G: Well, they are, and of course in the, in the world we live in today, and people are very quick to post on social media where they’ve been, what they’re up to, what their interests are. Open source intelligence, as it’s known as, is very easy to get hold of, and that arms the criminals and arms the hackers to be able to go and leverage somebody’s social world in terms of exploiting them in their professional world, because those boundaries are no longer— there’s no boundary there between your personal world and your work world, really, today. So I think you’ve got some challenges in there in terms of how you address that. But I think if you come at it from accepting the fact that humans make mistakes no matter how much you train and educate them, security isn’t all about a single fix. So we, we in NORM say there is no silver bullet to addressing cyber risk. You have to put a measure, a series of controls in place, and it’s all about putting those controls in place that are commensurate with your risk appetite as an organization, and also of course your budget. You know, you want to try and get yourself in an adequate position as quickly as possible and then gradually evolve and measure that over time and improve it. Accept the fact humans will make mistakes. Okay, how do I mitigate that? Well, I isolate— I put an agent on their device, I put endpoint detection response capabilities on their device, and I isolate the device if they make a mistake. And so you’re trying to come at it from those proactive measures and reactive measures.

Speaker A: But an insurer will want to say, we want to know that this is a risk, this has been identified as one of the biggest risks. We want to make sure that these people have been properly educated or that they have actually been informed, because if not, and we find that it was the, the individual’s fault, then we’re going to say, no, you’ve mitigated your insurance policy?

Speaker G: Well, they will put in a series of prerequisites. So I think one of the challenges for the insurance industry— and we work quite closely with several insurance, both directly in terms of just understanding what their requirements are and also helping customers to obtain insurance— and I think one of the biggest challenges for organizations, particularly up until the very last months of last year, was the goalposts kept moving. And so insurers like to rely on their own empirical evidence, they like to rely on their own statistics. They just don’t have that level of data today in terms of what measures actually, from their perspective, not from a logical perspective and what the NCSC say, what the security providers will say will reduce risk, actually what do their numbers tell them. They just don’t have that data pool to say if Company A does this, we know the risk will reduce by, by Y. And so what they’re having to rely on is putting in a series of prerequisites in order to obtain a policy that they assume will work effectively. Of course, until they’ve got the empirical data against that, they start to move those goalposts. So you had quite a lot of scenarios last year whereby customers were going to get their cyber insurance renewed, didn’t have any controls in place, because there’s a lot of organizations like that who were told they need to go and put a certain bunch of measures in place. They go back, take them 6 months to go and do it, They would go and then go back for the premium. The insurer would say the goalposts have moved slightly, you now need to do X, or you need to step up a little bit more and put these controls in place because we’ve seen that what we asked for last time— for example, early last year, the years before, they would say, well, you must have an information security policy. Well, just because you have an information security policy written down doesn’t mean it’s implemented. And so they would start to reject this, discount that that control is actually being effective. And then they would start stepping forward and saying, well, actually, you need to demonstrate— have you got a certificate that’s evaluated your information security policy? Have you got Cyber Essentials Plus? Have you got ISO 27001? So we know somebody independently has verified what you’re doing. And it’s all those measures that the insurer will say, have you got these in place? And yes, you’re right, in the instance of a breach The insurer will look to see, we’ve asked for these criteria, have you fulfilled them? And if you haven’t, then there will be quite likely to be an event whereby you’ll struggle to get the COVID that you think you’ve got.

Speaker A: It’s a problem that has become a pattern as both businesses and cyber insurance companies start to feel their way in this new world of online remote working and AI, because the insurers have suddenly realized that for once They’ve got their figures wrong. In a world where everyone expects to be breached, some 90% of businesses worth over £5 million say that they’ve been hit. Yet the average cost of a cyber breach last year, according to IBM, was £3 million, while the cost of an insurance premium for a small and medium-sized business was around £15,000 a year. As you can see, It doesn’t add up. Here’s Brian Banbury, the Chief Executive Officer of the Nottingham insurance brokerage Russell Scanlan, on the teething issues the companies and insurers are facing.

Speaker H: I don’t think we’re different to any other regional broker when it comes to cyber. We’ve done quite well in terms of raising its profile, but I think it’s come around because the insurance market for many years would have a cyber product available to help clients, but they were never very good at providing what we would call the services that were necessary. So the insurers would say, we’ve got a nice cyber policy that you can sell to your clients, but they never convinced us that if the client had a cyber event, that they could provide the— what the client needed to recover. To me, it’s all about the recovery and the service that you get when you get a breach or some kind of ransomware attack. So I guess I couldn’t tell you the exact year that it happened, but a few years ago, maybe 10, maybe less, probably a little bit less than that, the insurers started to really deliver services. You find yourself locked down by ransomware, or you find yourself having had a breach or an issue with your network, you think there’s been a breach, you can now phone a helpline and the insurers have got experts ready to go to help you. But well, I’d say every policy that we, that we’ve arranged will have that service. And I think that’s— we’ve had our own data breach where it was absolutely key that we had somebody that could talk us through it, explain what had happened, explain what issues that we had, and provide the services to take us through it and recover. And that’s where insurers started to get better. And I think that’s where we try to explain to clients that that’s the key to it. It’s not The policies can be different if you like. There’s differences in the coverage, but for the most part it’s relatively similar. But it’s that service that you get which is the key to me.

Speaker A: How important is it to have cyber insurance for a business? And you know, it’s a relatively new concept for many small and medium-sized enterprises. They’re going to be sitting there thinking, oh, my business is about the work I do and the computers are just you know, they’re just an adjunct to that. They allow me to send my email. So how important is it to them to have that cover?

Speaker H: It depends what they do, but what I would say is most businesses rely to an extent on their computer network, even if you just use it for emails. And you can’t communicate with your customers or with your suppliers very well because your network’s down because you’ve been locked down. Even that’s going to have a knock-on effect on your business. But obviously, if you use your network, if you have important software on there and you’re selling online and you can’t sell online anymore because of that, that’s obviously a big issue. If you use software for design work and you can’t get that design work finished or you lose all the work you’ve done, you’ve got to start contracts again, things like that. So it’s— it really depends what you do. If you were a haulier, and you use software to understand where all your vehicles have got to go and where they’re going to be tomorrow, and your network’s locked down, you don’t— probably don’t know where all your vehicles are and you don’t know where they’ve got to be. So it immediately has a knock-on effect on your business.

Speaker A: So how do you go about providing cover? Somebody comes up to you and they say, we want cyber insurance. Do you then say to them, well, what cybersecurity products have you got? What have you got to look after yourself?

Speaker H: Most insurers have either a form— you sometimes can’t get by having to complete a proposal form, an old-fashioned insurance proposal form, and it will go through the security measures that they ask you about that. There are some insurers that are quite slick and you can get quotations online where they don’t ask too many questions, and it can depend on what type of business you are. If you’re an insurance broker, you’ve probably got to have better security overall because you hold a lot of personal data. Some clients don’t hold a lot of personal data, so they possibly don’t need quite as robust security to protect that, but obviously they need it to protect the network in general. So you can fill a form in, you can go online, you get a statement of fact very often after you’ve spoken to a client. You can send a statement of fact and say does this reflect correctly your security or does it reflect correctly your business? And if it does, then the quotation that you have will stand. I saw a client yesterday, there were a couple of the questions we needed to change where things like multi-factor authentication is quite important to most insurers. So this client had got some of that in place and not a full suite of it, if you like. So we refer that back to insurers and see if that changes anything.

Speaker A: I’ve been to a number of cyber insurance events. In fact, I was speaking at one, I think, just about threats, because I’ve written two books about cybersecurity, and I wrote the first articles ever about cybersecurity, which obviously I’m terribly proud about.

Speaker H: You should be. You obviously know more about it than we do. The security side is still, to an extent, a little bit of a mystery because it’s very difficult for Insurance is not too difficult to get your head around, but the detailed security aspects of it are quite hard to understand at times.

Speaker A: But at those cyber insurance events, one of the things that— and there were people from Lloyd’s, there were people from Switzerland there— a discussion took place about whether the insurance industry should put together a list of products or a list of threats and the solutions to those threats that people should have. And people suddenly started started saying, no, it should not, because if it did, and then it gave a tick box for cybersecurity incidents. And one of the things about cybersecurity is it’s a very, very moving playing field. The threats are changing and evolving all of the time. And they were saying that if they did provide such a service, that it could lead them liable to very heavy claims.

Speaker H: What do you think about that? I tend to agree. I think it’s just thinking about it quickly. I think the insurance companies do work with other businesses who have cybersecurity knowledge and expertise, and they can provide services for clients that work, that go hand in hand with the insurance. There are businesses that will, for example, have a consultant sit with the board or sit with the IT guys and the board and go through a questionnaire, quite a detailed a detailed questionnaire to collect knowledge, if you like, on cybersecurity of the business. And those people can probably give advice as well in terms of how to avoid the issues, but they’re also qualified to help if, if something crops up. Part of the issue you sometimes have if the business is quite complex and their IT is quite complex is the proposal forms. To a layman, you’d have to be— if you were the MD or an FD of a business, the likelihood is you wouldn’t understand, and you shouldn’t have to understand, the terminology in relation to cybersecurity on a proposal form. So you, you relay that back to your IT guys, if you like. So you can fill in up to a point in terms of what the business is, what it does, where it is, its industry, that kind of thing. But then when it comes down to the nitty-gritty of the security aspects, then they’ll need the IT people. I think the insurers probably are better sticking to what they know in terms of a client will, will buy an intruder alarm, fire alarm, good locks, and they’ll still insure against fire and theft. But they, they won’t necessarily buy cyber because they’ve got virus protection, firewalls, and so forth. And insurance is there as your, as your last backup if all else fails. And if you, you don’t buy cyber insurance knowing you’re going to use it, you buy cyber insurance because it’s there if an employee clicks on the wrong link in an email, which is often where the claims come.

Speaker A: Brian Banbury, the head of Nottingham insurance brokers Russell Scanlan. So where are we? It’s a question that everyone is now asking as the world balances on the edge of a frightening new reality. The education system is on the verge of revolution. Many fear their jobs will be lost to AI, while many of us are at the mercy of an unchecked crime wave. Or we could be more positive. We could be at the dawn of a golden era for humanity, where a metaverse composed of our physical and virtual existences allows us to achieve unimagined heights because we can unleash our potential using AI, our data, and the knowledge of the known world that will simultaneously use some of the more sensible systems systems that we have evolved to ensure that we are not brought down to earth with a bang when our lofty dreams bust. You have been listening to Password, written and presented by me, Peter Warren, produced by Blue Buffery, and brought to you by Future Intelligence and the program sponsors, the cybersecurity company ESET, on why cyber insurance could be the essential component to ensure the success of her future.

Speaker D: Thanks for listening. Goodbye.

ShareTweet
podnion.com

© Sociaall Inc.

Navigate Site

  • Home
  • Privacy Policy
  • Contact Us

Follow Us

No Result
View All Result
  • Home
  • Trending
  • New Release
  • AI
  • Automation
  • Cloud
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Privacy Policy
  • Contact Us

© Sociaall Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00