Cybersecurity Insurance: Key Insights with Hamesh Chawla at QSC24
The cybersecurity industry has evolved, revealing challenges in risk assessment due to outdated data and the need for continuous monitoring. Best practices highlight ongoing training and security protocol adherence to manage rising premiums. Qualys aims to improve cyber insurance through continuous risk monitoring, emphasizing collaboration between security and finance teams for effective risk management.
Transcript
This is Textron tv. Hey everyone, it's Alan Shimmel and we're back here at, uh, Quala Security Conference. We just grabbed this gentleman off the main stage.
We pulled him in here. He was, uh, part of a panel. His name is, and I, I'm gonna try my best this right.
Hamesh. Chala. He's CEO of a company called Mulberry.
If you're not familiar with Mulberry, they are a leading cybersecurity insurance provider. Is that the right term? I think they're very right.
Yep. Very right. So before we go any further hamesh for people who maybe are not familiar with Mulberry Sure.
What's the website? io. And how do you spell Mulberry?
M-U-L-B-E-R-R-I. It's Like that's an I not a y, right? Exactly.
You're absolutely right. That's, I want to make sure we got that. Alright.
Now that we've got that out of the way, let's jump in here. Yep. So I've always had a belief that the cybersecurity industry, maybe five years ago Yep.
Became the big stick in enforcing cyber hygiene. Sure. Right.
I, I frankly, you know, I've been in security 30 plus years Yep. Who have, who's been able to enforce cybersecurity, hygiene and process best practices? Well, the government tried not so great.
Yeah. In some cases they're okay, I guess, but Sure. For the most part Yeah.
I call it least common denominator security. Right. Yeah.
Because they, they tend to go low. Then you had sort of the private, like pci I Sure. Right.
Payment card industry, PCI stuff. Uh, you had nerc, ferc, which was quasi-governmental. You had these sort of agencies Yeah.
A lot of them private Yeah. That said, Hey, this is what I need from you. Yeah.
But now we've got a genuine insurance industry, a real, this is a classic Yes. Right. Kind of industry.
Yeah. Who can, who says, look, if you want to get cyber insurance and you really need cyber insurance today to operate, this is what we need from you. Yes.
And they were able to enforce this over the last five years. Yes. You've become the enforcer.
Yes. But as we were talking off camera, all good things come to an end, right? Yes.
And we're coming now to maybe the next stage. Sure. Give me your thoughts on this.
I think you summarized it very well. I mean, let me just back up a little bit. Sure.
Fundamental element of any insurance, and now you take it cyber insurance is determination of risk. Right. Risk determines how much premium you write, whether you decline or accept, um, or what's, and an accurate detection of risk also helps in, you know, what's going to be my loss ratio, just like you said.
Mm-Hmm. There could be a big claim or, or you know, that, that hands and the falls from the carriers. So typically this process, what we call underwriting or determination of risk is done by asking a bunch of questions.
That's been a traditional method in any insurance. Um, plus in case of cyber, what started to happen was, well, let's go and do these external scans. Let's collect some data points from these public sources.
But however, cyber is an evolving threat. The, the metrics, the, I would say the instruments keep changing every day. So unless you're continuously monitoring or getting the data, you know, it's difficult to say, make any decision of a snapshot in time, which is where we feel the more the sources of data, such as the true risk score by Qualys and combined with inside outside conditions in a continuous manner, is where the insurance and protection needs to come together.
Right. And, and, and which is, and which is to your point, you know, if it doesn't, then I think you are, your loss ratios are gonna go up. You are not being able to, to accurately detect risk.
Um, and, and, and, and that's where we feel the industry will shape towards. You know, let me, let me make an analogy to kind of mainstream insurance house. We live in Florida.
I'm from Florida. Hurricane wind insurance is impossible to get right now. Yes.
But for a long time when you would apply for a wind insurance policy, just like you said, they'd send you that questionnaire. Yep. How old is your roof?
Yeah. Does it, is it free of leaks? Yeah.
Do you have storm proof windows doors? Yep. Do you, uh, you know, do you have a wooden frame, cement frame?
Are you building co complaint? And you would just answer yes, no. Yes, no.
Yes. No. The idea being that if you lied or you didn't answer truthfully or Right.
Sure. When it came time to make a claim and they found out you were wrong. Yeah.
They could deny your claim, but then litigation ensues. Yeah. And litigation is no one's friend.
Yes. Right now, it's a very different thing when you go get insurance. Yeah.
In Florida, how old is your roof? What kind of shape is it in? Well, they send a drone.
Yeah. That flies over your house and takes pictures Yes. Of your roof and it's attached to your file.
Yes. You know, trust, but verify if you will. I, Yeah.
It's very Just where we're going and it's the same thing we're doing now with cyber. Yeah. I mean, look, I mean, you said it's very, very succinctly.
I mean, it's like the zero trust framework, right? Yeah. In cyber, the only difference that I will put together is the roof.
Let's say the drone takes a picture and it is cement today, but in case of cyber, it may become as fault the next day. Yeah. And that's the problem we have.
Yeah. Right. And so con you know, like I, I've seen many examples wherein their premium is written to a firm.
They answer those 10 questions and as you said, somebody could lie, somebody could, you know, say the truth and we get some point of scan data, right. And we write premium. Right.
Two months down the line, that point of scan data is invalid or even the next day That it's a point in time. That's, but security's I always used to say with the PCI industry, right? Yeah.
Do you know A PCI compliant com company was never breached because the moment they were breached, they were no longer PCI compliant. That's true. It's the same thing.
That's thing, you know, it's the same thing here. Yes, yes. You didn't have any known vulnerabilities yesterday.
Yes. But today a known vulnerability came out And, and that's where then the carriers get there. And I think you brought up another good point when we were chatting.
You know, one thing is to say, do you follow best practices? And your answer could be Yeah. Yeah, That's right.
But the other thing is to say, are you following them every quarter? Do you have training programs in place every quarter? Because guess what?
A new employee comes in. Yeah. You followed best practices the last quarter, you get an email, which is a phishing email clicks there gets to a ransomware.
Cyber insurance is called. Right. But we wrote the premium.
There you go. We wrote the premium based on that. Well, and, and I think that's another problem here is I think a lot of organizations say, Hey, I pay my premium.
That's why I've got insurance. Instead of saying, that's so shortsighted because your premium's gonna be twice that next year. A Hundred percent.
If you get it a hundred percent. If you don't take steps to keep best practices up to date to get new employee training in. And again, to me, this is something where the cyber insurance industry has to be the big stick.
I love it. I love how you're saying, in fact, I'm gonna borrow that in my future, you know, conversations, it's a big stick. And I think you're right because that's where, otherwise what happens is, yes, oh, I have got cyber insurance, I'm protected, but guess what, it's gonna double next year, much like any other insurance.
Second, what, what you're not realizing is there is reputational damage, there is other sorts of damage that are happening. Absolutely. That is not covered Then you're not covered.
Right. Right. Uhhuh.
And so just like you said, just having feeling that cyber insurance is there, but using that as a stick. Right. And, and, and, and, well, you Could use the carrot too.
If you do it, your premiums are less. Love it. Right.
Absolutely. That's What we are trying to, and that's classic sticking carrot. Yeah.
I mean, with Qua now we are saying that we can, if you're a Quais customer, we can offer you a discount just because we know that, that, that it's a carrot and, and we'll help people with good practices. Absolutely. Right.
So we are trying to give small, medium businesses an incentive. Uh, I, I loved it. Uh, this is a good path to go down.
We'll, we'll talk more about it. I wanna ask a little question about using the t qualy, uh, true risk. Do you, because again, we don't want a moment in time.
I want an ongoing, is it built in or can you have it built in that if you're a, a, let's say a Mulberry customer, an Qualys customer, you get daily, weekly, quarterly updates on true risk. Yes. I think the, the, at least the vision they have, and from what I understand is they are having a vision of being able to continuously monitor provider states.
So we will build adapters to, to sort of ingest that score. Right. No, I'm thinking Right.
They, you know, one of the nice, I, I followed Qualys for many. I've been in security 30 years. I knew Philippe very well.
One of the nice things Qualys always did was have different views for different personas. Right. I'm thinking if they don't have a cyber risk, uh, dashboard for a cyber insurer, right.
I think this is what now they're trying to do, in which I, which I feel is absolutely the right vision. Um, you know, they're also putting together a vision of risk, determination of risk. Yeah.
Right. Because if you look at, if I, if I sit up with my board, or if any board sits together, yeah, you have, they talk about security. We talk about security, but at the end of the day, we talk about risk.
And risk can have six different things. There could be three C cyber risks, there could be three other risks. So they're going after the risk persona.
And then when you go after the risk persona that has a direct intersection with any underwriting that you do in insurance industry. Absolutely. Because that becomes a business.
That becomes a business Decision. Not the security guy. Exactly.
Yeah. Exactly. And the moment you talk about risk, it's not a CISO decision, it's more like a, the CCFO Or a Agreed.
We are having words there. Each other's, You know, that's always been a, a source of friction, right? 'cause you got the cs, the cso who's with the CIO with it.
And then you got the risk team pill here from the CFO. And you know, there there is that. And so this new CRO thing that came, the, the, uh, security, the risk operation center, excuse me.
ROC is I think a way that we can bridge that too. Again, by having different ones for every, for everything. Yes.
Yes. No, I, I couldn't agree more. This is been great.
Hames. One more time. Mulberry.
com. Dot io. Do io.
All right. There. We got it.
We'll put it down on, well it's gonna be on the bottom with your name and title, so we'll put it in there for you. All righty, thanks. Pleasure, pleasure, pleasure.
Really pleasure. You really thank you for being here. Thank you for talking here at the Quala event as well.
And Thank you for your insights. I mean, I caught that line. It is a big stick Insurance company.
I'll carry life A big stick. Thanks. We're live, we're live here in uh, San Diego.
We'll be back in just a moment.