Black Hat USA 2025: Is a high cyber insurance premium about your risk, or your insurer’s?
ID: 03410ee0-8169-5f75-a935-68a420d49a62
STIX ID: report--03410ee0-8169-5f75-a935-68a420d49a62
Feed Name: WeLiveSecurity (ESET Research)
A Black Hat USA 2025 write-up argues that sky-high cyber insurance premiums can reflect an insurer’s portfolio risk limits for certain vendors, not necessarily an insured’s security posture. Claims data shared (e.g., 45% of new H1 2025 claims tied to SSL VPNs lacking MFA; 55% of ransomware starting at perimeter devices; credential theft leading) underscores basic control gaps, while insurers increasingly provide targeted threat intelligence, CVE-based alerts, and funds clawback services—and may even buy compromised credentials or zero-days—to proactively reduce risk and financial exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
