'Cyber is Uncharted Territory And It’s Going To Get Worse…’

During the recent shareholder’s meeting of the celebrated investment firm Berkshire Hathaway the company’s CEO Warren Buffett warned that there’s about a 2% risk of a $400 billion disaster occurring as a result of a cyber-attack

“This is uncharted territory and it’s going to get worse, not better. You’re right in pointing that out as a very material risk that didn’t exist 10 to 15 years ago, and will get more intense as time goes on,” Buffett said, replying to a question about how he prepares for a big cyber-related disaster.

Berkshire Hathaway’s insurance arm offers professional liability with cyber insurance, but Buffett said he doesn’t want his company to be a pioneer in the arena, since it’s largely unpredictable.

A Known Unknown

“I think anybody that tells you now that they think they know in some actuarial way either what general experience is likely to be in the future, or what the worst case would be is kidding themselves. And that’s one of the reasons I say that a $400 billion event I think has a roughly 2% probability per year of happening.”

Buffett said that while insurance companies have a pretty good idea of the probability of an earthquake happening in California or a major hurricane hitting Florida, cyber disasters are still an unknown.

“Frankly, I don’t think we or anybody else really knows what they’re doing when writing cyber [insurance],” Buffett said. “It’s just really, really early in the game. We don’t know the interpretation of the policies will be. We don’t know the degree to which they’ll be correlated.”

The Bad Guys Are Always Ahead
Buffett also explained that when he speaks to cyber-security experts, they tell him that the offense is always ahead of the defense, and that will continue to be the case. That’s a smart call, and exactly how big tech companies currently think of the cybersecurity landscape. To offset this, the companies actively hunt for ways attackers could penetrate their systems and plug those holes before hackers can find them.

After all, the world runs on software, and software is written by humans who are just as flawed as you and me. No matter how much they try, they’ll still end up accidentally inserting some kind of error into their code that can be exploited. That’s just how the system works.

This isn’t the first time Buffett has opined on cybersecurity. In 2017, the CEO said he doesn’t understand much about cyber-attacks, but said that it is “the number one problem with mankind.” He even went so far as to compare cyber-attacks to nuclear and biological weapons.

That might seem like an exaggeration, but cyber-attacks can impact everything from elections, like the Russian meddling campaign during the 2016 elections, all the way up to nation state attacks on critical infrastructure like nuclear power plants. 
And unlike nuclear and biological weapons, cyber weapons are being created and used regularly.

But it’s not all doom and gloom, as Buffett pointed out that while a $400 billion cyber-attack will destroy companies, Berkshire would still likely turn a profit in the same year.

Yahoo Finance

You Might Also Read: 

About Cyber Insurance:

Global Cyber Attack Could Cost $53Billion:

Will Cyber Insurance Providers Reward Good Security?:
 

 

« How Do Hackers Hide Their IP Address?
NSA Spies Triple Text and Phone Collection »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

Snyk

Snyk

Snyk is the leader in developer security. We empower the world’s developers to build secure applications and equip security teams to meet the demands of the digital world.

QSecure

QSecure

QSecure specializes in the provision of information security and risk management services.

CipherTrace

CipherTrace

CipherTrace develops cryptocurrency Anti-Money Laundering, cryptocurrency forensics, and blockchain threat intelligence solutions.

Syskode Technologies

Syskode Technologies

Sykode Technologies is a next-generation global technology company offering an integrated portfolio of advisory services, products and solutions in areas including AI, IoT and Cyber Security.

CryptoSec.info

CryptoSec.info

CryptoSec.info is a web resource focused on educating the beginners in the cryptocurrency space on how to properly secure their online assets from hackers and scammers.

CyberClan

CyberClan

CyberClan’s carefully selected team of experts is capable of solving complex cyber security challenges – keeping your data secure and your businesses running as usual.

Earlybird Venture Capital

Earlybird Venture Capital

Earlybird is a venture capital investor focused on European technology innovators.

Green Radar

Green Radar

Green Radar is a next generation cybersecurity company which combines technologies and services together to deliver Threat Detection for Emails and Deep Threat Analytics and Response.

Intigriti

Intigriti

Intigriti is Europe's leading bug bounty and vulnerability disclosure platform, connecting organizations with a global community of ethical hackers to enhance cybersecurity through continuous testing.

People Driven Technology

People Driven Technology

People Driven Technology is a customer-obsessed organization. We leverage our decades of business, technology, and engineering experience to deliver outcomes for our clients.

Imprivata

Imprivata

Imprivata is the digital identity company for life- and mission-critical industries, redefining how organizations solve complex workflow, security, and compliance challenges.

Exacom

Exacom

Exacom is a leading provider of multimedia logging/recording solutions across public safety, government, DoD, energy, utilities, transportation, and security applications.

Resemble AI

Resemble AI

Resemble AI is an innovator in Generative Voice AI technology and tools to combat AI fraud including audio watermarking and deepfake detection.

Umbrella Cyber

Umbrella Cyber

Umbrella Cyber specialises in Cyber Essentials and Cyber Essentials Plus Certification and penetration testing.

CYNC Secure

CYNC Secure

CYNC boosts cybersecurity remediation by consolidating fragmented data and optimizing operational processes.

Servadus

Servadus

Servadus help organizations with their cybersecurity and compliance programs through management and sustainability, consulting, and assessing.