Winging It · Implausible Deniability
For most of my career, once a year, somewhere down the corridor from me, a document got signed that described my security programme in more detail, and with a good deal more confidence, than anything I ever put in front of a board. More often than not I wasn't shown it, because it was the cyber insurance renewal and it belonged, by some ancient and unwritten law of corporate filing, to legal.
I saw enough of them over the years to know they arrived looking like a vendor security questionnaire that had been left to grow unsupervised over a long weekend, with hundreds of questions, most of them yes or no, every one of them about a system the person answering had never logged into. They landed in legal's inbox because they were attached to a contract and contracts went to legal. Time after time, legal then set about completing as much of the thing as humanly possible without asking me, or anyone in GRC, a single thing, with the quiet determination of someone assembling flat-pack furniture who'd decided the instructions were for other people.
As far as I could make out, legal approached the whole thing the way lawyers approach everything, by reading. They read the question about whether multi-factor authentication was enforced for all remote access, then read my information security policy, which said in clear, board-approved language that it must be, and wrote yes with the untroubled conscience of someone who'd checked their source. The question about offline, tested backups went to the backup standard, which said they were. The question about endpoint detection on every device went to the EDR contract, where the licence count covered every device in the building and there was an invoice to prove it. And so it went on, page after page, each answer a faithful and carefully referenced summary of what we'd written down about ourselves, submitted in response to a form that had been asking, the whole time, about our servers.
Legal had a point, and I'll concede it, because I made an appalling witness. Anyone who asked me whether MFA was enforced for all remote access got some version of a guided tour of the break-glass account, the contractor VPN nobody was allowed to switch off, a service account that was older than the intern, and finally a request to reword the question before I committed to anything in writing. Every one of those caveats either pushed the premium up or put the cover itself in doubt. Legal's brief, handed down by a CFO who was looking at a renewal date and very little else, was to get a policy bound at a price the business was prepared to pay, and keeping me out of the room was by some distance the fastest way of doing that. By the only measure anybody applied in the month of a renewal, it worked a treat.
The insurer, as far as I could see, was in no great hurry to complain either, since the underwriter priced the column of yeses, sent over a quote and moved on to the next applicant. Once the premium was paid, the form went into a folder on a shared drive, where it sat for the rest of the year like a tax return everyone was fairly sure was right, read by nobody, waiting for the day it might be needed.
I had a fair idea what that day would look like. It would have arrived a few days after the ransomware, with half the company working off a whiteboard and personal Gmail accounts, and the insurer would have sent someone round. I'd have met the most attentive reader any security document of mine ever had, a person who'd gone through every one of those hundreds of answers with a highlighter and the forensic report open beside them. They'd have read the answer about MFA on all remote access and been very interested in the word "all", which nobody in legal had lingered over at the time. They'd have read the answer about tested backups and asked to see the last restore test, and the one before that, and the one before that. They'd have read the answer about endpoint detection on every device and brought a list of the laptops the agent never got installed on, one of which would inevitably have been where the attackers came in. By the end of the week they'd have found the information security policy legal was quoting from, and wanted somebody to explain why it said MFA was mandatory everywhere when the servers appeared never to have read it.
Their job, and I don't hold it against them, is to find the answer that wasn't true, and on a form with hundreds of confident yeses written by someone who'd never logged into anything, they'd have found one. Once they had, the conversation about paying out would have got very short at the exact moment the company needed the money most, with the systems down, payroll due and customers ringing. And nobody who'd touched the form would have done anything they'd recognise as dishonest.
Looking back, I'd have taken the form off legal and given it to security, which legal would have hated. Wherever we couldn't prove a yes, I'd have written an honest no with a paragraph of explanation, which the CFO would have hated even more because it put the premium up. It always struck me as odd that the SOC 2, which at worst cost me an awkward conversation with a sales prospect, got a project manager, a readiness assessment and a platform subscription. Meanwhile the one document that decided whether we got paid after a breach got whoever in legal had a free afternoon, on the understanding that a policy nobody can claim on is the cheapest insurance money can buy.
The instructions, it turns out, are for other people, and the other people work in the insurer's claims department.
— Chris
