Based on my experience reading lots of cyber insurance questionnaires: this paper is not wrong.
However, it misses some things like:
- this happens because many brokers/carriers don’t hire cyber experts
- they’re basing what they ask on historical claims data which… can be a challenge by itself
- carriers don’t always get to use their own questionnaire; they get whatever data the broker sends them
- while they alluded the effects, they don’t seem to understand how market cycles work
https://infosec.exchange/@ravirockks/113513643537133620