Insurance
Home›Insurance›Industry & Deals›Clean incident histories may mislead cyber risk assess…
Clean incident histories may mislead cyber risk assessments
Cyber experts warn that low findings can reflect narrow testing or reporting choices, not actual security resilience.
Insurance Business highlights the limits of using incident counts as a proxy for cyber readiness, noting that a quiet record can reflect detection and disclosure practices rather than what attackers may have already reached internal systems undetected.
The outlet cites Ashu Savani, co-founder of TryHackMe, a browser-based cybersecurity training platform, who argues risk managers, insurers, and security teams should look beyond incident history when assessing security posture.
Insurance Business also points to a principle from the Payment Card Industry Data Security Standard, saying a low finding count from a security assessment is rarely proof of genuine security, and may instead indicate that the assessment was too narrow.
Savani is quoted as saying a clean record can either signal resilience or simply result from narrowly scoped testing, quietly adjusted severity for findings, or failure to report incidents that occurred.