'Cyber is Uncharted Territory And It’s Going To Get Worse…’

During the recent shareholder’s meeting of the celebrated investment firm Berkshire Hathaway the company’s CEO Warren Buffett warned that there’s about a 2% risk of a $400 billion disaster occurring as a result of a cyber-attack

“This is uncharted territory and it’s going to get worse, not better. You’re right in pointing that out as a very material risk that didn’t exist 10 to 15 years ago, and will get more intense as time goes on,” Buffett said, replying to a question about how he prepares for a big cyber-related disaster.

Berkshire Hathaway’s insurance arm offers professional liability with cyber insurance, but Buffett said he doesn’t want his company to be a pioneer in the arena, since it’s largely unpredictable.

A Known Unknown

“I think anybody that tells you now that they think they know in some actuarial way either what general experience is likely to be in the future, or what the worst case would be is kidding themselves. And that’s one of the reasons I say that a $400 billion event I think has a roughly 2% probability per year of happening.”

Buffett said that while insurance companies have a pretty good idea of the probability of an earthquake happening in California or a major hurricane hitting Florida, cyber disasters are still an unknown.

“Frankly, I don’t think we or anybody else really knows what they’re doing when writing cyber [insurance],” Buffett said. “It’s just really, really early in the game. We don’t know the interpretation of the policies will be. We don’t know the degree to which they’ll be correlated.”

The Bad Guys Are Always Ahead
Buffett also explained that when he speaks to cyber-security experts, they tell him that the offense is always ahead of the defense, and that will continue to be the case. That’s a smart call, and exactly how big tech companies currently think of the cybersecurity landscape. To offset this, the companies actively hunt for ways attackers could penetrate their systems and plug those holes before hackers can find them.

After all, the world runs on software, and software is written by humans who are just as flawed as you and me. No matter how much they try, they’ll still end up accidentally inserting some kind of error into their code that can be exploited. That’s just how the system works.

This isn’t the first time Buffett has opined on cybersecurity. In 2017, the CEO said he doesn’t understand much about cyber-attacks, but said that it is “the number one problem with mankind.” He even went so far as to compare cyber-attacks to nuclear and biological weapons.

That might seem like an exaggeration, but cyber-attacks can impact everything from elections, like the Russian meddling campaign during the 2016 elections, all the way up to nation state attacks on critical infrastructure like nuclear power plants. 
And unlike nuclear and biological weapons, cyber weapons are being created and used regularly.

But it’s not all doom and gloom, as Buffett pointed out that while a $400 billion cyber-attack will destroy companies, Berkshire would still likely turn a profit in the same year.

Yahoo Finance

You Might Also Read: 

About Cyber Insurance:

Global Cyber Attack Could Cost $53Billion:

Will Cyber Insurance Providers Reward Good Security?:
 

 

« How Do Hackers Hide Their IP Address?
NSA Spies Triple Text and Phone Collection »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

SecurityMetrics

SecurityMetrics

SecurityMetrics is leader in data security, PCI, and HIPAA compliance solutions

Saviynt

Saviynt

Saviynt is a leading provider of Cloud Security and Identity Governance solutions.

Information Systems Security Partners (ISSP)

Information Systems Security Partners (ISSP)

ISSP is a specialized system integrator focused on the information security needs of its corporate clients and providing best in class products and services for securing organizational information.

Very Good Security (VGS)

Very Good Security (VGS)

VGS is the modern approach to data security. Our SaaS solution gives you all the benefits of interacting with sensitive and regulated data without the liability of securing it.

ubirch

ubirch

The ubirch platform is designed to ensure that IoT data is trustworthy and secure.

TekSek Cyber Security

TekSek Cyber Security

Preparing you for tomorrow's security threats.

Next Peak

Next Peak

Next Peak provides cyber advisory and operational services based on deep business and national security experience, thought leadership, and a network of front-line defenders.

ClearHub

ClearHub

The aim of ClearHub is simple: to give businesses like yours access to the best talent, all screened and technically tested by Clearvision’s expert team.

PhishProtection

PhishProtection

We created Phish Protection to prevent all types of phishing including spear phishing protection and office 365 email protection for your small business.

Willyama Services

Willyama Services

Willyama Services is a certified Information Technology and Cybersecurity professional services business providing services to government and private sector clients.

ActiveFence

ActiveFence

ActiveFence enables Trust & Safety teams to be proactive about online integrity so they can keep their users safe from online harm – across content formats, languages, and abuse areas.

Orchestrate Technologies

Orchestrate Technologies

Orchestrate Technologies provides computer network and IT managed services for small and mid-market clients as well as small enterprise businesses.

RightCue Assurance

RightCue Assurance

RightCue Assurance identify opportunities for improvement in the Information Security for your organisation and work with you to reduce cyber risk.

CESAR

CESAR

CESAR is one of the premier R+D and innovation centers in Brazil and a designated Cybersecurity Competence Center.

Security Solutions Services (S-3)

Security Solutions Services (S-3)

S-3 specialize in crafting tailored network design, security hardware, software, and storage solutions for businesses of all sizes.

NetDescribe

NetDescribe

NetDescribe, part of Xantaro Group, advises and supports companies in building secure and stable IT environments.