

Let’s Talk: Cybersecurity prevention
October 13, 2022
By Carlos Rodriguez Sanz and Jos茅 Ferreira Costa
Carlos Rodriguez Sanz, AXA XL’s cyber product manager for APAC & Europe and Jos茅 Ferreira Costa, SecurityScorecard’s regional director for Southern Europe/LATAM
Today, all companies - regardless of size, industry segment or location - are vulnerable to cyber-attacks. So are governments, public and private utilities, universities, hospitals and non-profit organizations. Moreover, cyber-criminals are continually creating new tools and methods to exploit vulnerabilities in the systems and technologies that power our economies and enrich our lives.
Fast Fast Forward recently spoke with Carlos Rodriguez Sanz, AXA XL’s cyber product manager for APAC & Europe and José Ferreira Costa, SecurityScorecard’s regional director for Southern Europe/LATAM about how 色多多视频works with SecurityScorecard to help companies identify where and how they could be vulnerable to cyber-attacks.
Carlos, could you start by outlining what organizations can do to combat this ongoing and evolving threat?
Carlos Rodriguez Sanz (CS): Cyber-security professionals commonly recommend a three-pronged approach:
- Prevention: this encompasses assessments of potential threats along with appropriate measures to protect against breaches and detect them quickly
- Response: having mechanisms in place to limit the scope of the attack and to swiftly restore the data and affected systems
- Mitigation: taking out appropriately structured insurance policies to transfer financial losses.
Like a three-legged stool, all are essential; take one away, and the stool topples over. Or, in the case of cyber, when an organization is the victim of a data breach, the direct and indirect costs, including reputational impacts, can be devastating when one of these elements is lacking.
Prevention is first and foremost. I can’t stress this enough. And that’s why 色多多视频has partnered with SecurityScorecard to help companies assess their vulnerabilities and identify where their defenses need strengthening.
Regarding response, our team is ready to help if a breach occurs. We have partnered with leading breach response providers to provide access to a 24/7 hotline to help organizations navigate these sensitive situations. Our cyber coverages also include access to firms specializing in computer forensics, legal issues, public relations, and credit and ID monitoring.
Finally, using insurance to transfer risk. While the pros and cons of different coverage options are topics for another day, I would note that 色多多视频is prepared to assess organizations’ cyber exposures and partner with clients in collaborative efforts to reduce and mitigate the threats. Our goal is to help clients get back to business and resolve covered claims as soon as possible.
I would also add that all three prongs—prevention, response, mitigation—must be regularly reviewed and refreshed. Cyber-risk is constantly evolving and mutating as cyber-attackers continually search for vulnerabilities in organizations’ IT systems while developing new tools and tactics to carry out their attacks.
José, what is SecurityScorecard, and how does it help companies prevent cyber-attacks?
José Costa (JC): Founded in 2013, SecurityScorecard is the global leader in cybersecurity ratings and the only service with millions of organizations continuously rated. Our mission is to make the world a safer place by transforming the way organizations understand, improve, and communicate cybersecurity risk to their boards, employees, and vendors. With support from AXA Venture Partners, our offerings now include a comprehensive suite of cybersecurity solutions.
Cybersecurity ratings are analogous to financial credit ratings: just as a poor credit rating is associated with a greater probability of default, a poor cybersecurity rating indicates an organization’s greater likelihood of experiencing a data breach or other adverse cyber event.
SecurityScorecard collects and analyzes global threat signals that give organizations instant visibility into the security posture of vendors and business partners as well as the capability to do a self-assessment of their own security posture. SecurityScorecard continuously monitors 10 groups of risk factors to instantly deliver an easy-to-understand A-F rating. The risk factors include: network security exposures, DNS health, patching cadence, endpoint security, application security, IP reputation, and social indicators like hacker chatter and whether an organization has exposed passwords or credentials.
The ten factor scores are weighted according to their relative severity, and the weighted scores are aggregated to produce an overall score from 0 to 100. We then assign a letter grade from A to F, which provides a simple, intuitive indication of the probability an organization will experience a cyber-attack. At the same time, the individual factor scores help IT teams identify the vulnerabilities that warrant further analysis and, as need be, remediation. In other words, the scorecard is meaningful and actionable for an organization’s IT team and its board of directors and C-Suite executives.
Prevention is first and foremost. That’s why 色多多视频has partnered with SecurityScorecard to help companies assess their vulnerabilities and identify where their defenses need strengthening.
How do companies use this information?
CS: Organizations use our security ratings in several ways. IT teams tend to focus more on the factor scores as an ongoing diagnostic tool to help them pinpoint vulnerabilities. At the same time, the letter grades offer boards of directors and C-Suite executives snapshots of how well protected their organizations are from cyber-attacks, which helps them in their strategic decision-making.
Companies also use the ratings to assess their suppliers. This application is becoming even more relevant as more and more hackers target smaller players deeper down the supply chain and then work their way up toward the primary target. As a result, companies’ extended ecosystems of suppliers or vendors represent an additional vulnerability they need to investigate and monitor.
Lastly, financial institutions and investors use the ratings to understand the types of cyber risk they may inherit.
How does 色多多视频use the scorecards?
CS: The scorecards are an invaluable tool for us, and SecurityScorecard’s data are integrated into our underwriting platforms. Not surprisingly, we start with the letter grades; these help our underwriters with risk selection. For instance, if a company receives a C or B, that signals an opportunity to work together to reduce the vulnerabilities and, when addressed satisfactorily, to discuss coverage options.
SecurityScorecard also continuously monitors the threat landscape, which helps us manage larger-scale risk, i.e., the possibility that a single event causes massive disruption. When a widespread cyber event occurs, the SecurityScorecard can help us identify clients that are likely exposed so we can alert them of the need to take preventive measures.
Are there any other points you’d like to make?
JC: While our discussion has focused on prevention, incident response—Carlos’s second leg of the stool—is also becoming increasingly critical. When there is a breach, a company needs to respond swiftly and effectively to stop additional data losses. And once the breach is contained, they should document and record the incident, perform digital forensics and, based on those investigations, fix vulnerabilities and implement necessary measures to prevent further attacks.
CS: That’s right. Fast, effective incident response is vitally important for clients and insurers. Clients want to limit the impacts and restore their data as quickly as possible. Actions that quickly and effectively contain a breach and reduce the damages will help clients get back in business sooner and with less disruption.
To contact the author of this story, please complete the below form
More Articles
- By Product
- By Region
Quick Links
Related Resources
- View All


Building Smarter: How contractors are facing into inflation, labor shortages, and other risks head-on

The hacks just keep on coming: How design professionals can respond to cyber incidents
Global Asset Protection Services, LLC, and its affiliates (鈥溕喽嗍悠礡isk Consulting鈥) provides risk assessment reports and other loss prevention services, as requested. In this respect, our property loss prevention publications, services, and surveys do not address life safety or third party liability issues. This document shall not be construed as indicating the existence or availability under any policy of coverage for any particular type of loss or damage. The provision of any service does not imply that every possible hazard has been identified at a facility or that no other hazards exist. 色多多视频Risk Consulting does not assume, and shall have no liability for the control, correction, continuation or modification of any existing conditions or operations. We specifically disclaim any warranty or representation that compliance with any advice or recommendation in any document or other communication will make a facility or operation safe or healthful, or put it in compliance with any standard, code, law, rule or regulation. Save where expressly agreed in writing, 色多多视频Risk Consulting and its related and affiliated companies disclaim all liability for loss or damage suffered by any party arising out of or in connection with our services, including indirect or consequential loss or damage, howsoever arising. Any party who chooses to rely in any way on the contents of this document does so at their own risk.
US- and Canada-Issued 色多多视频 Policies
In the US, the 色多多视频insurance companies are: Catlin 色多多视频 Company, Inc., Greenwich 色多多视频 Company, Indian Harbor 色多多视频 Company, XL 色多多视频 America, Inc., XL Specialty 色多多视频 Company and T.H.E. 色多多视频 Company. In Canada, coverages are underwritten by XL Specialty 色多多视频 Company - Canadian Branch and AXA 色多多视频 Company - Canadian branch. Coverages may also be underwritten by Lloyd’s Syndicate #2003. Coverages underwritten by Lloyd’s Syndicate #2003 are placed on behalf of the member of Syndicate #2003 by Catlin Canada Inc. Lloyd’s ratings are independent of AXA XL.
US domiciled insurance policies can be written by the following 色多多视频surplus lines insurers: XL Catlin 色多多视频 Company UK Limited, Syndicates managed by Catlin Underwriting Agencies Limited and Indian Harbor 色多多视频 Company. Enquires from US residents should be directed to a local insurance agent or broker permitted to write business in the relevant state.
色多多视频 as a controller, uses cookies to provide its services, improve user experience, measure audience engagement, and interact with users鈥 social network accounts among others. Some of these cookies are optional and we won't set optional cookies unless you enable them by clicking the "ACCEPT ALL" button. You can disable these cookies at any time via the "How to manage your cookie settings" section in our cookie policy.