Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Thanks, I know that "it depends", but a few thousands a year is just a (vague) number, as well as how much small is the small business is to be agreed upon and - very likely - small businesses are "easy wins" for insurance companies, not because they have better security, but rather because they are very unlikely probable targets.

I wondered about what would be rates (order of magnitude) and on what they would be calculated.

To give you an example, AFAIK if you were to get insurance, so called "Contractors All Risk" for a building project, you could expect anything between 0.7 and 1.5 % of the value of the project, on average around 1.1-1.2 % over the usual 5-6 years of duration, with the lower end about (relatively) low risk projects (roads without particularly complex contructions and normal houses) and the higher end on (relatively) high risk ones (roads with bridges, tunnels, skyscrapers).

These can be negotiated a bit, based on experience on past projects, internal safety and quality assurance procedures, but the order of magnitude remains in that range, but in case of an accident/claim, not entirely unlike the car theft example, but much more complex, you need to prove that you followed all safety and employment regulations, respected building codes, that machinery was efficient, etc..

In the case of IT, rates for a given firm/institution would depend on the invoicing or on the amount of personal data?

I mean, you can make 1,000,000 US$/year with 10,000 customers (personal data) at 100 US$ each/year or with 50 customers at 20,000 US$ each/year.

And what kind of "good practice" would you need to prove (if any)?



I'm sure it depends on revenue, the amount of personal data, and the nature of the business. I don't know how the rates are calculated but I've helped fill out the paperwork on a few applications and it's not dissimilar to what you might have to go through to become an approved technology partner with a Fortune 100 company. Do you have a disaster recovery policy? If so, when was it last tested? Do you get pen tests? What was the result of the last one? Are there any open items? Describe the technical access controls around customer data. Describe the physical security measures in place around your servers and IT infrastructure.

Keep in mind that you don't need to necessarily "prove" things that can be checked later. The insurance company is happy to take your word that there's no PCI card data on your network and cash your premiums. If there is and it gets stolen in a hack they simply won't pay out.


>Keep in mind that you don't need to necessarily "prove" things that can be checked later. The insurance company is happy to take your word that there's no PCI card data on your network and cash your premiums. If there is and it gets stolen in a hack they simply won't pay out.

Yep, this is exactly what I expect, similar to the original car theft example:

"Ahh, you left the car unlocked, sorry, you cannot be reimbursed as you didn't exercise the expected diligence"




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: