Denied Now, Approved Later
CF: If a business is unable to get cyber insurance, what can they do to increase their chances later?
JS: I would recommend organizations follow best practices that are out there for cybersecurity aligned to a framework. So things like SOC 2 or ISO/IEC 27001, or PCI are great examples of what to follow. Obviously, like with any insurance, a track record of being in business for awhile without having any events is … what insurers would typically look for. I’d say primarily it’s the determination of what type of data you have in place, the volume of it, and what the risk might be to your organization if that were to be exposed.
Tags: