'Cyber is Uncharted Territory And It’s Going To Get Worse…’

During the recent shareholder’s meeting of the celebrated investment firm Berkshire Hathaway the company’s CEO Warren Buffett warned that there’s about a 2% risk of a $400 billion disaster occurring as a result of a cyber-attack

“This is uncharted territory and it’s going to get worse, not better. You’re right in pointing that out as a very material risk that didn’t exist 10 to 15 years ago, and will get more intense as time goes on,” Buffett said, replying to a question about how he prepares for a big cyber-related disaster.

Berkshire Hathaway’s insurance arm offers professional liability with cyber insurance, but Buffett said he doesn’t want his company to be a pioneer in the arena, since it’s largely unpredictable.

A Known Unknown

“I think anybody that tells you now that they think they know in some actuarial way either what general experience is likely to be in the future, or what the worst case would be is kidding themselves. And that’s one of the reasons I say that a $400 billion event I think has a roughly 2% probability per year of happening.”

Buffett said that while insurance companies have a pretty good idea of the probability of an earthquake happening in California or a major hurricane hitting Florida, cyber disasters are still an unknown.

“Frankly, I don’t think we or anybody else really knows what they’re doing when writing cyber [insurance],” Buffett said. “It’s just really, really early in the game. We don’t know the interpretation of the policies will be. We don’t know the degree to which they’ll be correlated.”

The Bad Guys Are Always Ahead
Buffett also explained that when he speaks to cyber-security experts, they tell him that the offense is always ahead of the defense, and that will continue to be the case. That’s a smart call, and exactly how big tech companies currently think of the cybersecurity landscape. To offset this, the companies actively hunt for ways attackers could penetrate their systems and plug those holes before hackers can find them.

After all, the world runs on software, and software is written by humans who are just as flawed as you and me. No matter how much they try, they’ll still end up accidentally inserting some kind of error into their code that can be exploited. That’s just how the system works.

This isn’t the first time Buffett has opined on cybersecurity. In 2017, the CEO said he doesn’t understand much about cyber-attacks, but said that it is “the number one problem with mankind.” He even went so far as to compare cyber-attacks to nuclear and biological weapons.

That might seem like an exaggeration, but cyber-attacks can impact everything from elections, like the Russian meddling campaign during the 2016 elections, all the way up to nation state attacks on critical infrastructure like nuclear power plants. 
And unlike nuclear and biological weapons, cyber weapons are being created and used regularly.

But it’s not all doom and gloom, as Buffett pointed out that while a $400 billion cyber-attack will destroy companies, Berkshire would still likely turn a profit in the same year.

Yahoo Finance

You Might Also Read: 

About Cyber Insurance:

Global Cyber Attack Could Cost $53Billion:

Will Cyber Insurance Providers Reward Good Security?:
 

 

« How Do Hackers Hide Their IP Address?
NSA Spies Triple Text and Phone Collection »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Webroot

Webroot

Webroot delivers next-generation endpoint security and threat intelligence services to protect businesses and individuals around the globe.

Q-CERT

Q-CERT

Q-CERT is the National Computer Security Emergency Team of Qatar.

IS Decisions

IS Decisions

IS Decisions builds affordable and easy-to-use Access Management software solutions, allowing IT teams to effectively secure access to Active Directory infrastructures, SaaS apps and data within.

Dcoya

Dcoya

Dcoya's complete security awareness training program gives you out-of-the-box compliance with PCI-DSS, HIPAA, SOX and ISO regulations.

MailXaminer

MailXaminer

MailXaminer is an advance and powerful email investigation platform that scans digital data, performs analysis, reports on findings and preserves them in a court validated format.

2Keys

2Keys

2Keys designs, deploys and operates Digital Identity Platforms and Cyber Security Platforms through Managed Service and Professional Service engagements.

Collins Aerospace

Collins Aerospace

Collins Aerospace provides cybersecurity services and systems to protect critical infrastructure facilities and railroad operations.

Cyber Security Cloud (CSC)

Cyber Security Cloud (CSC)

Cyber Security Cloud provides web application security services worldwide using world's leading cyber threat intelligence and AI technology.

Appgate

Appgate

Appgate is the secure access company. We empower how people work and connect by providing solutions purpose-built on Zero Trust security principles.

Nexum

Nexum

Nexum takes a comprehensive approach to security, from detecting and preventing network threats, to equipping you with the information, tools and training you need to effectively manage IT risk.

Wisetek

Wisetek

Wisetek is a global provider of end-to-end IT Asset Disposition (ITAD), reuse and secure data destruction management services to the world’s leading IT Corporations, data centres and manufacturers.

ISECURION Technology & Consulting

ISECURION Technology & Consulting

ISECURION is an information security consulting company. We provide a unique blend of services to our customers catering to the current information security landscape.

Tuta

Tuta

Tuta (formerly Tutanota) is an all-in-one email, calendar and contacts app which protects your data with full end-to-end encryption and it requires zero personal information.

Mayer Brown

Mayer Brown

Mayer Brown is a global law firm. We have deep experience in high-stakes litigation and complex transactions across industry sectors including the global financial services industry.

Epoch Concepts

Epoch Concepts

Offering a full line of IT services, solutions, and integration capabilities, Epoch Concepts is the trusted partner of the US military, federal agencies, private enterprises, and systems integrators.

Two Candlesticks

Two Candlesticks

Two Candlesticks is a global cybersecurity service provider delivering high level consultancy, strategy, and frameworks to governments, regulators and midsized companies.