APCIA to Feds: Not So Fast with a “Cyber TRIP” 

American Property Casualty Insurance Association’s response to the federal government’s request for comment on cyber insurance issues: “We believe it is premature to explore the details of a federal insurance response without conducting a thorough study of the threshold questions raised above to determine where, if at all, such a response is needed. Nevertheless, experience … Read more

TSA Asks: How Could Cyber Insurance Fit into Regs for Rails and Pipelines? 

You’ve got until Jan. 17th to weigh in. See instructions in the embedded document at the link below. Requested feedback includes: “Address incentivizing cybersecurity adoption and compliance. TSA wrote that it ‘is particularly interested in comments on types of incentives, such as liability protection, insurance, commercial contracts, or other private- or public-sector options, that would … Read more

Are Municipalities Prime Targets for Hackers?

The report concerns a March 2022 attack on the Canadian tourist town of Banff, which apparently cost over $500,000. “Municipalities can be favoured targets of cybersecurity attackers because their cyber defences aren’t as sophisticated as higher levels of government. Attackers believe cities and towns may be more willing to pay ransoms than other organizations because … Read more

Most K-12 Schools Have Cyber Insurance, But Still Lack Basic Security Measures:  MS-ISAC Report 

In our opinion, the report’s authors are diplomatic in their summary: “The K-12 community displayed an overall average maturity score of 3.55 on the 2021 NCSR’s 1 through 7 maturity scale. Results from the Nationwide Cybersecurity Review (NCSR) risk-based assessment have shown the K-12 sector is improving in its cybersecurity capabilities over time, though the … Read more

K-12 Schools Having Trouble Getting & Maintaining Cyber Insurance: GAO

“Additional federal coordination is needed to enhance K-12 cybersecurity,” says the report from the United States Government Accountability Office (GAO). But it looks as if many school districts are failing to do their part, from failing to report all cyber attacks to not instituting MFA and training. Note the reference to one school district being … Read more