Insurance coverage firms mustn’t neglect the altering technological panorama
For a lot of within the insurance coverage area, technological developments might current a brand new calibre of vulnerabilities to be involved of. Nonetheless, a extra risk-based method to cyber safety that’s rooted in a maturity-based mannequin will permit the business to maintain up with the tempo of recent life with out sacrificing its hard-earned vigilance.
“These improvements are an opportunistic danger,” stated Benjamin Dulieu, the chief data safety officer at Duck Creek Applied sciences. “There definitely is a yin and yang to adopting new applied sciences, however the advantages are starting to outweigh the drawbacks.”
Talking with Insurance coverage Enterprise, Dulieu outlines how one can get a agency footing within the ever-evolving world of cyber threats how his coaching in the USA navy helped put together him for the world of insurance coverage.
Cyber safety is a continuing battle
All through the previous decade, the necessity for strong cyber safety for companies each giant and small has solely gained momentum, turning into some of the talked about phenomena throughout industries.
This has additionally turn out to be a sizzling matter amongst insurers, because the panorama is ever evolving and requires safety professionals to all the time be forward of the curve.
“As soon as a vulnerability has been dealt with by cyber safety professionals, a brand new code is written months later that builds upon the weaknesses of its earlier iteration,” Dulieu stated. “Which means that menace actors are getting much more attentive on how one can sidestep protections and safety measures which are put in place.”
“These ‘script kiddies’ are realizing it’s truly fairly straightforward to assault weak companies with out having an intensive cyber menace background,” Dulieu stated.
Companies should be ready for the chance, and responses ought to embody motion grounded in ingenuity.
“Having a foundational cyber safety program that’s rooted in a maturity-based mannequin is extra very important than ever,” Dulieu stated.
He highlighted the Nationwide Institute of Requirements and Expertise (NIST) and Management Aims for Info and Associated Applied sciences (COBIT) frameworks as fashions for superior safety measures that ought to be used for cyber safety measures. “If you happen to comply with any of those frameworks, you’ll organically and intentionally have information hygiene and will probably be following safety greatest practices.”
A more moderen improvement is zero belief structure, which requires authentication and authorization throughout every stage of interplay between a consumer and a community, which may create hurdles for menace actors to navigate.
“The business is the final to faucet into innovation and alter”
For Dulieu, the insurance coverage business has an notorious repute for its luddite tendencies, and whereas this can be warranted in sure regards, it units the business again when it comes to a holistic evolution.
“The business continues to be utilizing antiquated know-how and old style databases,” he stated. “There’s a complete reservoir of untapped potential that these developments can provide, and so they definitely may be adopted with out dropping sight of the larger, risk-aware framework of insurance coverage.”
Generative AI applied sciences similar to ChatGPT provide one alternative that may assist streamline productiveness and help in bolstering safety measures; one other alternative is the adoption of cloud-based safety.
“The ‘migration to the cloud’ is an previous time period now but it surely brings a complete new method to take a look at safety structure,” Dulieu stated.
“If you happen to don’t have that have right now, you’re falling behind. You’ll want to discover ways to defend that cloud atmosphere, which isn’t the picture of a fort with fortified partitions like on-premises safety infrastructure.”
“Understanding, empathy and compassion drive a crew in the direction of a standard goal”
Dulieu’s foray into the insurance coverage business was slightly happenstance, however there are foundational connections to his coaching as a command and management methods officer in the USA Marine Corps.
“I truly thought I used to be going to go into the gross sales realm, however my coaching within the Marine Corps primed me for a enterprise into cyber safety,” Dulieu stated. “My basis in know-how actually opened these doorways for me to interrupt into governance, danger and compliance kind roles.”
Dulieu’s time within the Marine Corps instilled the values of collective crew constructing and accountability. “As a frontrunner, I’m chargeable for every part I do and fail to do, together with the crew that I oversee,” Dulieu stated.
“This necessitates a necessity for understanding, empathy and compassion to drive a crew in the direction of a standard goal.”
Dulieu additionally discovered the significance of turning every part right into a course of. “If you happen to don’t make issues repeatable, then you possibly can by no means determine efficiencies and inefficiencies he stated.”
“That is very true for cyber safety, the place every part must be formalized and scalable, with the flexibility to adapt, however reliability is vital.”
Associated Tales
Sustain with the newest information and occasions
Be a part of our mailing record, it’s free!