'Cyber is Uncharted Territory And It’s Going To Get Worse…’

During the recent shareholder’s meeting of the celebrated investment firm Berkshire Hathaway the company’s CEO Warren Buffett warned that there’s about a 2% risk of a $400 billion disaster occurring as a result of a cyber-attack

“This is uncharted territory and it’s going to get worse, not better. You’re right in pointing that out as a very material risk that didn’t exist 10 to 15 years ago, and will get more intense as time goes on,” Buffett said, replying to a question about how he prepares for a big cyber-related disaster.

Berkshire Hathaway’s insurance arm offers professional liability with cyber insurance, but Buffett said he doesn’t want his company to be a pioneer in the arena, since it’s largely unpredictable.

A Known Unknown

“I think anybody that tells you now that they think they know in some actuarial way either what general experience is likely to be in the future, or what the worst case would be is kidding themselves. And that’s one of the reasons I say that a $400 billion event I think has a roughly 2% probability per year of happening.”

Buffett said that while insurance companies have a pretty good idea of the probability of an earthquake happening in California or a major hurricane hitting Florida, cyber disasters are still an unknown.

“Frankly, I don’t think we or anybody else really knows what they’re doing when writing cyber [insurance],” Buffett said. “It’s just really, really early in the game. We don’t know the interpretation of the policies will be. We don’t know the degree to which they’ll be correlated.”

The Bad Guys Are Always Ahead
Buffett also explained that when he speaks to cyber-security experts, they tell him that the offense is always ahead of the defense, and that will continue to be the case. That’s a smart call, and exactly how big tech companies currently think of the cybersecurity landscape. To offset this, the companies actively hunt for ways attackers could penetrate their systems and plug those holes before hackers can find them.

After all, the world runs on software, and software is written by humans who are just as flawed as you and me. No matter how much they try, they’ll still end up accidentally inserting some kind of error into their code that can be exploited. That’s just how the system works.

This isn’t the first time Buffett has opined on cybersecurity. In 2017, the CEO said he doesn’t understand much about cyber-attacks, but said that it is “the number one problem with mankind.” He even went so far as to compare cyber-attacks to nuclear and biological weapons.

That might seem like an exaggeration, but cyber-attacks can impact everything from elections, like the Russian meddling campaign during the 2016 elections, all the way up to nation state attacks on critical infrastructure like nuclear power plants. 
And unlike nuclear and biological weapons, cyber weapons are being created and used regularly.

But it’s not all doom and gloom, as Buffett pointed out that while a $400 billion cyber-attack will destroy companies, Berkshire would still likely turn a profit in the same year.

Yahoo Finance

You Might Also Read: 

About Cyber Insurance:

Global Cyber Attack Could Cost $53Billion:

Will Cyber Insurance Providers Reward Good Security?:
 

 

« How Do Hackers Hide Their IP Address?
NSA Spies Triple Text and Phone Collection »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall And Why Does It Matter

See how to use next-generation firewalls (NGFWs) and how they boost your security posture.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Chatham House

Chatham House

Chatham House is an independent policy institute based in London. Topics cover foreign affairs and defence including cyber security.

Owl Cyber Defense

Owl Cyber Defense

Owl patented DualDiode Technology enables hardware-enforced network segmentation and deterministic, one-way transfer of all data types and file sizes.

Engineering Ingegneria Informatica

Engineering Ingegneria Informatica

Ingegneria Informatica is a leading Italian provider of Information Technology consulting, services and solutions including cyber security.

Wibu-Systems

Wibu-Systems

Wibu-Systems is a leading provider of solutions for the Digital Rights Management (DRM) and anti-piracy industry.

Cobalt Labs

Cobalt Labs

Pen Testing as a Service for Modern SaaS Businesses. Cobalt is redefining the modern pen test for companies who want serious hacker-like testing built into their development cycle.

TunnelBear

TunnelBear

TunnelBear is a Virtual Private Network services provider offering secure encrypted access to the internet.

Combis

Combis

COMBIS is a regional high-tech ICT company focused on the development of application, communication, security and system solutions and the provision of services.

DigiByte (DGB)

DigiByte (DGB)

DigiByte (DGB) is a rapidly growing global blockchain with a focus on cybersecurity for digital payments & decentralized applications.

AXELOS

AXELOS

AXELOS develops best practice frameworks and methodologies used globally by professionals working primarily in IT management and cyber resilience.

Genius Guard

Genius Guard

Genius Guard specializes in DDoS Protection, DDoS Protected Webhosting, HYIP Hosting, Bitcoin Hosting, Cryptocurrency Hosting.

nexSecurity

nexSecurity

neXSecurity is an IT and Information security consulting company with more than 2 decades worth of software development and security experience.

Sec-Ops

Sec-Ops

Sec-Ops is a forward thinking cyber security company, formed by a group of security enthusiasts with years of experience and backgrounds in the technology and the government industries.

Protect AI

Protect AI

Protect AI is a cybersecurity company focused on AI & ML systems. Through innovative security products and thought leadership in MLSecOps, we help our customers build a safer AI powered world.

Atlas Cloud

Atlas Cloud

Atlas Cloud is a UK-wide provider of managed services based in Newcastle. Our ‘research-led’ approach to IT services helps leaders make better decisions about IT for their businesses.

Buguard

Buguard

Buguard is a multi-award-winning supplier of Application Security Assessments and GRC services.

ZEUSS

ZEUSS

ZEUSS is a diversified data center, cybersecurity, and green energy company.