Insight #1: CISOs, you need insurance coverage
According to German multinational insurance company Munich Re, the global cyber insurance market is expected to rise from $14 billion to $29 billion by 2027. CISOs will increasingly need to “tell their story” to make sure they are properly insured, as most policies are stand-alone and not carte blanche.
Insight #2: The public can’t/won’t/shouldn’t need to protect themselves from cyber threats
According to the latest “Consumer Cyber Readiness Report” from Consumer Reports (PDF), the general public knows there are online threats, yet their behaviors haven’t changed. This all comes full circle: I believe, and will always believe, that it is not up to consumers to protect themselves from online threats. Rather, the onus is on the providers to do so: e.g., require multifactor authentication (MFA) for all accounts, as a starting point.
Insight #3: We should review security policies more often
How often are you reviewing your security policies? I would say the general consensus is to do it annually, but with the way the legal world is coming down on businesses that have had a breach, as well as the ever-changing threat landscape, should we be reviewing these more frequently?
*** This is a Security Bloggers Network syndicated blog from AppSec Observer authored by David Lindner, Director, Application Security. Read the original post at: https://www.contrastsecurity.com/security-influencers/cybersecurity-insights-wit1h-contrast-ciso-david-lindner-10/11/24