Hacker News new | ask | show | jobs
by DontGiveTwoFlux 2618 days ago
Most insurers require customers to limit their risk in all kinds of ways.

I’m curious if there are cyber mitigation’s that are out there, such as mandatory two factor authentication, requiring up to date software and OSes or other measures. It seems like any insurance company would Be highly Interested in forcing these best practices.

3 comments

You can do 1,000 things right, but one thing wrong may still sink you.

With cybersecurity, there is an active adversary. I'm not sure insurance ever wants to take on that kind of risk. If they don't want that risk they shouldn't sell insurance.

This particular attack wouldn't have been mitigated by any of that. This is why you also have insurance in addition to doing everything you can to prevent an attack.
Mandatory snake oil