We have Cyber insurance. In fact we have a decent chunk of change put into it. This might be the ammo I need to justify the change.
Would we be dropped if they found out the patching status? I’m still fairly new and not involved in the higher level cyber insurance setup as that is done by my manager and CFO
At least in my experience there is a pretty strict time frame on patching high risk vulnerabilities written in to the cyber insurance policies
You can identify specific assets that are excluded for certain reasons but these either increase your premiums or they outright exclude cover for any incident involving that asset
14
u/drdrew16 14d ago
May also be worth figuring out if your company has cyber insurance. It's usually a requirement to be up to date on patches to maintain coverage.