Building on awareness foundations
Cyberinsurance is one way to treat some cyber risks. Which ones?
That disarmingly simple question has taken next month's management seminar down a couple of interesting avenues.
The first concerns the nature of cyber risks that one might reasonably expect to fall within the remit of cyberinsurance. Most don't. Insurers are particular about the kinds of risks they accept, actively managing their own risks and businesses.
Second is the distinction between insurance customers' 'reasonable expectations' and the reality of how policy terms and conditions are actually interpreted by the insurance companies and industry, the legal profession including the courts, and the regulators.

That's cool! It applies very broadly, not just in this specific case. A security-aware workforce starts at or above the ground floor in knowledge terms, not down in some cold, dark, damp and smelly basement.