Resilient Cyber
Resilient Cyber brings listeners discussions from a variety of Cybersecurity and Information Technology (IT) Subject Matter Experts (SME) across the Public and Private domains from a variety of industries. As we watch the increased digitalization of our society, striving for a secure and resilient ecosystem is paramount.
Resilient Cyber
The Real Price Tag On Cyber Breaches
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Alex Pinto, who leads Verizon's DBIR team, joins me to break down the new Breach Impact Study and what data breaches actually cost organizations.
For years the industry has argued past itself on breach costs. One camp says the market doesn't care, the other says a single breach ends your business. Alex and his team finally got their hands on roughly 70,000 cyber insurance claims through CyberAcuView, and the Breach Impact Study puts real numbers behind the question. In this conversation we dig into what the data shows, where it stops, and how a security leader should actually use it.
Alex Pinto runs the Data Breach Investigations Report team at Verizon Business and has been building the report for close to a decade. The Breach Impact Study is the team's first focused spin-off from the DBIR.
In this episode:
- How the Breach Impact Study came together and why the DBIR team finally got cyber insurance claims data
- Why the study measures insurable loss as a floor, not a ceiling, of real economic impact
- The case for reporting medians over averages, and why the team refuses to publish the average
- Business interruption versus contingent business interruption, and why downtime moves the needle
- Whether an $83,000 median breach impact sends executives the wrong message
- The SMB paradox, where the smallest companies take the hardest proportional hit
- What the claims data does and does not show about AI on offense and defense
- Third-party risk, coverage sub-limits, and the single biggest takeaway for security leaders
Chapters
0:00 Intro
0:24 Meet Alex Pinto and the DBIR team
2:51 Launching the Breach Impact Study
3:26 Getting cyber insurance claims data
7:32 Why insurable loss is a floor, not a ceiling
11:14 Medians over averages, and why the average is meaningless
15:13 Business interruption vs contingent business interruption
19:49 Does an $83K median send the wrong message?
22:44 The SMB paradox and the cybersecurity poverty line
26:05 Where AI shows up, offense vs defense
34:48 The CVE explosion and marketing hype
36:59 Third-party risk and coverage limits
41:34 Wrap-up
Guest links
Alex Pinto on LinkedIn: https://www.linkedin.com/in/alexcpsec/
Alex Pinto on X: https://x.com/alexcpsec
Verizon DBIR and Breach Impact Study: https://www.verizon.com/business/resources/reports/dbir/
More from Resilient Cyber
Substack: https://www.resilientcyber.io
Subscribe for more conversations with security practitioners and leaders.
#cyberrisk #databreach #cyberinsurance #ransomware #aisecurity #dbir
How do you answer for like a to a CFO who may read it that way and say, oh well, you know, 283,000, you're asking for X number of dollars from us, for security it's just cheaper for us to just eat it.
SPEAKER_02Maybe it's not the CFO that should be getting that figure, right? But the operational risk folks, because they would have a better understanding of what a distribution like that potentially means.
SPEAKER_01I call the cybersecurity delusion problem, where we often think like cybersecurity is the only thing that matters. And like whether you're a big business or to your point a small business, like whatever the case is, like, you have many competing incentives or competing priorities I should say. Again, rather than just cybersecurity, like, yes, it matters.
SPEAKER_02Undoubtedly, offensive AI augmentation is way, way ahead of the curve than the defensive one.
SPEAKER_00And everybody talks about, oh yeah, it's gonna be AI versus AI.
SPEAKER_01I found that small businesses can use up to 77% of their revenue in communications, where large enterprises rarely cost two percent. Thank you for joining the Resilience Cyber Show. My name is Chris Hughes, and today I'm joined by Alex Pinto. Alex, thanks for being here. Oh, thanks for having me. Yeah, I've been trying to get you on the chat for a while. Granted, it's been my fault. I've missed you for several weeks at this point due to logistical failures on my part. But for folks that don't know you and the team at Verizon, some of the reports and research and so on that you all do, can you tell us a bit about yourself and the team? Yeah, for sure.
SPEAKER_02So um I I run the team that puts together the data breach investigations report in Verizon. And I've been in this role, I've been in Verizon for almost 10 years now, which is kind of scary to say out loud. But um I've been in this role for six to seven years. The first one I helped put together was the 2019 one, the first one I actually wrote in, right? And so that's when the trouble started, it's 2020. If you if you didn't like 2020 onwards, it's it's definitely my fault. Um, but uh we put together this report uh every year, right? And uh it's been around for a very long time. It's been around for 19 years. And it's not the first one that ever happened, but it's definitely the longest running now, right? And uh I think the main reason for its longevity, the main reason why people continue to care, is that this for a very long time, like since year three, this is not just Verizon data, right? We actually put a lot of work into getting data from absolutely everybody who would be willing to compete uh uh work with us, including several competitors of Verizon as well. And really, it's kind of a great community thing, as in everybody's chipping in. We're working with them, trying to understand the data, we're figuring out what I mean, what's happening, right? What's the message? What do we want people to learn and be aware of, and and you know, to help them make better decisions at the end of the day, right? And so it's a bit a journey. It's it's it's uh it is incredibly energizing, right? Because we're never quite sure what's gonna come up and uh what we're gonna have to research. So we gotta really gotta kind of think on our feet. And uh to to uh to your kind of like more more immediate uh conversation we've been having, right? Uh one of the things we're exploring now is uh you know, really kind of like branching out a little bit from the DBIR and actually leverage the same theme and write some smaller reports, focused reports on specific topics. And uh we did just launch, just I mean it's been a month ish. Uh we launched uh for us it's like yesterday because we think of like annually, but um uh uh what we call the the breach impact study, the BIS, which is a very much DBIR-like publication, right? And uh, but it's really focused on, you know, what is the actual damage, what are the actual loss involved with data breaches and things of that nature, which is again a topic we wanted to write for years, maybe a decade. Um, and if you go like 20, like DBR 2014, 2015, there's like, you know, the people we tried to do it with the data that we had, but we never really quite had the data set we trusted. That wasn't gonna be, you know, nobody was putting their finger on the scale or something like that. Right? We didn't have to rely on surveys or things of that nature. So we we finally did, and so we finally wrote it, right?
SPEAKER_01And so that's exactly why I was excited to chat with you as I dug into the report. And like I'm uh like everyone else, like all the practitioners and folks in the community, like uh, you know, I'm an annual reader of the DBIR, and its themes the last couple of years have been great in terms of the rise of uh vulnerability exploitation, the rise of uh the role of AI and uh its impact on vulnerability discovery and like all these kind of themes that we see. Uh, but the breach impact study, you know, does something different where it tries to put some numbers to some of these things because you know how it is. Like you've been in this industry for some time, uh it's all over the place. You can have some folks saying, oh, cyber's not a big deal, the market doesn't care, blah, blah, blah. Other people saying, you know, if you get hacked, it's gonna be the end of your existence and like you will be financially out of business. And I'm assuming, you know, uh, like many other, I assume the truth is somewhere in between. And like, of course, there's there's tails on both sides of that, of that, you know, spectrum of of data. And so, you know, the team says that the breach impact study exists because readers kept asking why the DBR didn't go deeper into uh the financial impact of breaches. So, you know, as it came together, you you know, what did it take in terms of getting like insurance claims data and things like that that the DBIR just historically hasn't had access to?
SPEAKER_02So I for again, I I've always had the chip on my shoulder that I wanted to write something like this. Uh and uh and so one of the kinds of relationships that I've been fostering as uh for data contributors for the DBR has been cyber insurance companies. And I got the opportunity to start going to cyber insurance uh events, right? Like we we usually think a lot about like you know, RSA or Black Hat, but they have their own and they go there and they're talking about all sorts of interesting uh aspects and liabilities. And and again, just by hearing the presentations there, and again, I'm absolutely a beginner on all the terminology and all of those things, but you could tell, no, there's some very interesting things here that I I we I don't believe. I mean, they are clearly experts on it, but it it's not widely understood or shared inside kind of the CISO or security practice community, right? So there was a real opportunity to make that bridge. And then I I got connected with um Mark, who's the CEO of Cyber EcuView. And CyberEcuView is this kind of like organization that was founded by kind of the top cyber insurers in the US. And uh, I think it started like six or seven of them. You know, you go to the website, you got the AIGs and Beasley's and all of the big guys. I think they're they have over 20, 20 members now. But really, the the their mission was to put together hey, we're gonna send you our data, right? Uh, of course, anonymized, et cetera, because we're gonna be pulling all our data together. We need you guys to figure out what's going on, right? So we need you to do analytics for us, things that are gonna help us, uh, you know, have better actuarial tables, right? Have a better understanding of where the market is going. And so when we met each other, it was kind of like a matchmade in heaven, because we had a very similar mission. We were trying to do the same things, right? And the way I the way we approach this is that look, we we think we'd be a great partner, and we think we could tell, put some a spotlight in this story in a way that will not only help your folks on the insurance side, right? I don't think they they they probably not have had this kind of like, you know, breakdown of analysis, right? But also, I I know this is data that the security folks are hungry for, right? Everything we get, everything we see, incredibly anecdotal. And of course, anything that makes the media is always gonna be kind of like the worst cases. Like nobody reports, you know, the thousand dollar loss, you know. The, you know, it's like this joke, like, oh, there's a there's a tornado somewhere, and then someone posts a picture of a uh chair that fell down their backyard. We will we will reveal, right? Nobody writes about those, but those happen and those are, you know, they are a part of the story, they're a part of what what the reality is on the set on the threat landscape.
SPEAKER_01Yeah, definitely. And your point, like it definitely, you know, it we lean into the media hype cycle and then the big breaches, the big impacts make all the noise and get all the headlines, get all the attention. And of course, like, you know, vendors and marketers are partly responsible for leaning into those and ambulance casing and things like that. Um, but you know, the there is a much broader ecosystem and landscape of attacks that needs to be accounted for and reported on. And it the study was very upfront in the sense that it only measures insurable loss. Uh and you called it in the report, I believe, the the ceiling of true economic impact. Or I'm sorry, the floor of the floor of real economic impact rather than the ceiling. You know, why did you choose to anchor everything around actual dollars paid through real policies, um, knowing that it leaves out maybe reputational damage, uninsured losses, and the long tail of costs that keep rolling in. Is it just because that data, of course, is probably much harder to get and quantify and capture? Or, you know, in a nutshell.
SPEAKER_02In a nutshell, yes. If I if I knew how to get those, I would have added those pretty much, right? So uh first of all, the brand reputation thing is incredibly hard to measure. Nobody, no one, no one, you know, we have you ask, you know, three people, you'll get five opinions on what's the best way to measure something like that. We even tried, we tried this, I don't remember, like three or four years ago, right? We were trying to like, we actually used like uh so known data breaches at a specific year, and then we cross-reference. So these guys have like, you know, uh, they are listed on the stock exchange. We try to measure like, you know, stock variations and like no, it's just negligible, right? There's no real drift, no real distribution. And uh one of my thesis, quote unquote, right? One of the one of the motivations also also that I had is that I mean, to put it very bruntly, quote unquote, no one cares anymore. As an as an individual, right? We as I I think there is still reputation on kind of the B2B side, right? I think there are still, you know, there are there are contracts that get canceled or liability-related to contracts that can be damaging, but from the the the individual side, from the consumer side, nobody cares anymore, right? I probably have like a couple lifetimes of uh you know credit monitoring from every single company that lost my data. And so, you know, it becomes very diluted in in that regard, as far as how much does it really is. And I've always my my hypothesis has always been, oh no, the thing that moves, the thing that will move decision making is business interruption. You know, have some good old, you know, revenue sexation there, revenue suppression. Oh man, everybody's now, okay. Now we have to take care of this problem. This is a very important problem that we have to take care of. So and unsurprisingly, right, like business interruption was, at least in 2024, was like a third of uh all the known losses that we could identify based on the on the cyber policies that we have. But yeah, I mean, incredibly difficult to collect those other and you know, other uh kinds of data in in bulk, right? One other avenue we've always tried to tap into is law enforcement, right? Because it kind of becomes, you know, it's kind of a push and pull in the sense that, you know, they go to law enforcement and they declare what's going on, and that becomes a basis for whatever the adjuster from the insurance company goes there and figures out. So it's one of those things. The answer is in between those two, right? But um, you know, I still need more. I definitely don't have the the kind of the law enforcement data to the the volume that I have, the cyber insurance data as well, if that makes sense.
SPEAKER_01Yeah, no, it definitely does. And I think it's a good point. Uh, I just wanted to call that out because people may read this and think, oh, well, that's it. And it's like, well, there's other things that are hard to capture, hard to quantify, um, you know, hard to kind of detail. And another thing you did in the report is you made a poor uh a point of um reporting medians instead of averages. And there was a footnote saying you won't even publish the average on purpose. Uh so they'll get picked up by LLMs or aggregators and post around social media. No, I'm assuming that this is that was an intentional thing so that people, again, don't sensationalize like the the tail end, the largest, you know, most insane aspects of potential breaches and things like that, or you know, why why that decision basically?
SPEAKER_02So it's it's not even sensationalized. It's just that the information is meaningless for decision making. That's kind of the point that I'm trying to make. So let me give you an example. This is actually, you know, we took a long time to uh to get the to get this going. But you know, actually the time is perfect. The the IBM report, I think, just came out yesterday or something like that. And it's like, okay, five million-ish average, I think. Before was four and change. I think it went like 500k or something like that. But you know, here I am a company. What does five million tell me? Right? What do I know? Is it, you know, is is it if I'm an SMBs, does five million make sense, right? So uh of course, we're not looking at the same data, right? There's no way to directly compare the results they have to the results that we have. We're sampling from the same distribution or completely different, we're fishing on a large lake, right? I caught some fish, they catch some fish, right? But uh from my perspective, right, I think it's way more useful for a large enterprise to understand, look, on the most extreme cases that we saw for companies over 250 million of revenue, right? Again, being trying to be very precise, like the top 2.5 cases were above 22 million, right? And so the conversation now you can have with your board is look, if I want to be covered for, you know, 97.5% of all observed cases, right? I probably want to make sure, you know, you know, this is kind of how much loss we we would be looking at. But of course, what's the chance? And then then you go on the on the on the whole like fair stuff and all of that, right? But uh no one, no one, the median is a again, it's a good midpoint. It kind of anchors the expectations on, oh yeah, of course, there's there's always there's always this the smaller guys or or the non-critical things, but everybody else, I think the again, the top 2.5% data, those numbers are even larger than the than the averages, but they provide you so much more information on, and you kind of get to choose as a kind of a risk, uh an operational risk guy, right? Okay, how much do I want to be prepared against? Right? Am I very conservative and I want to make sure I'm covered from you know the vast majority of possible cases, right? Or you know what, I'm fine with the median, you know, maybe I'm just an average company or I think but it's way more information. The five million doesn't tell you any of that as far as how much risk you're accepting, how much risk you're you're considering. So it's more of a it's really more of a and again, this has always been uh uh a kind of a very clear mentality on anything DBIR related, which is what's the next step? How can the information that I'm writing down here, right? And it's 120 pages, right? Every year they try to, can you make it less than 100? And every year I fail, right? We're asking so much of our readers, uh, you know, at least let them get something, you know, act something actionable out of that, right? They can make the, you know, oh no, okay, I understand what I have to do now, or at least I understand what's the next step of what I have to do is now.
SPEAKER_01Yeah, it makes sense and it makes it uh you know much more actionable to try to like uh orient around like your point, it gives them a real concrete figure to kind of think about in terms of the median rather than an average, which to your point uh isn't as useful. You know, the data also shows that like you you mentioned this earlier, business interruption uh was kind of a key aspect. And it it jumped from 21% of known losses in 2023, I think it was, to 32 in 2024. Uh and you separated it from contingent business interruption tied to third parties as well. You know, help people understand the distinction between the two, like why downtime uh quietly became the single largest loss driver rather than the ransom payment, for example, or something like that.
SPEAKER_02Yeah, it's it's interesting. Uh it's a very interesting thing. And uh we saw we saw a huge preeminence of the and again, a huge growth in 2024, because there was a lot of cases in 2024 where you know uh companies had impact on on their on their business delivery because of partners that they had. So that's what what the terminology means when we talk about contingent business interruption. It means well, not your systems were okay, but your third party that you depend on to do your day-to-day business, they were offline. And so suddenly you couldn't you couldn't operate anymore. And so we had like, I mean, 2024, uh Change Healthcare, right? You may remember that one, where you know, again, a lot of hospitals they just couldn't, they have to go. CBK Global was for the car dealerships, right? There was PowerSchool, um, which was kind of like late 24. I'm not sure, even sure if they they they it was 24 or 25. But a lot of those cases, they all hit very quickly. And it kind of shifted. And again, it it kind of shifted because of resumer operators as well, because they understood that, okay, uh, you know, business interruption moves the needle, as in it puts pressure on the organizations to pay to really consider paying the ransom because they're against a different time pressure. Uh business interruption where all their customers are affected as well, puts even more pressure, right? So there was a there was uh I'm not gonna say it was a trend 2024. I think it's something that we we have seen start to happen there, and it's been something that's been carried through, right? It's kind of became a part of the the kind of the modus operandi of that kind of attack. But uh it's funny because the it was something that the the insurance, and this is something we talk about in the report, right? There was no meaningful distinction in the the policies and on the payouts between those two. And uh it was such a hard swing on 2024 that they decided accounting those things separately, right? And policies from that time forward, they started, okay. Now let's understand here you have a limit for a sublimit for business interruption, a sublimit for uh contingent business interruption, right? Because here was here was the scary part from all of this data that we capture, and um that uh even those numbers being that percentage being so high, this was one of the places where the data was failing us because we were hitting the sub-limits all the time, right? So it was not like, you know, okay, I'll only pay you $50,000 for contingent business interruption. I'm sure the damages were way higher, right? But you see, you can see the the charts there, and we do this kind of like the this kind of like uh bubble chart, we call it the dot plot, where we're kind of trying to describe things like like uh uh bell curve, right? Everything is kind of like, you know, what are the most likely? The median is always in the middle, and so you see it has this very weird shape where wait a minute, why did everybody hit 10,000 and then it like goes down and then it builds up again, and then there's another wall here. These are the sublim being hit, right? And so it shows that whatever data we show, whatever study we showed, the reality is potentially much worse, right? But again, that is an important data point. It's an important thing to identify, right? It's definitely a place of active uh research and adaptation by the insurance policies and the insurance providers on what's the best way to handle this kind of thing, given that it's becoming more and more uh common, right?
SPEAKER_01I yeah, I wanted to also kind of steel man a concern that you know I don't necessarily have myself, but I have heard people raise it when I was discussing the report with some folks, is like, and get your honest reaction to this. Like when you put a median breach impact of around, say, 83,000 in front of an executive, um, you know, there's a real risk that they walk away thinking, well, breaches are survivable and it might not be uh that big of a deal. And maybe it's just cheaper to eat the consequences rather than invest in security. Um are you worried that the study, you know, kind of hands that argument to the wrong people or you know, creates some friction for security leaders, you know, seeking budgets and things like that? Or you know, how do you answer for like uh to a CFO who may read it that way and say, oh, well, it's you know it's only it's only 83,000. You're you're asking for X number of dollars from us for security. It's just cheaper for us to just eat it, you know, like eat the incident or something like that.
SPEAKER_02Yeah, I think if you are I think that's a that's a bad CFO. That's kind of what I what I think. Uh the and maybe it's not the CFO that should be getting that figure, right? But the operational risk folks, because they would have a better understanding of what the what a distribution like that potentially means, right? One of the ways we tried to to mitigate against this, right, is of course we had to show the what the whole data set looks like, but oh no, let's break it down through company size and all sorts or or different types of breaches, right? Is the the kind of the mediums and worst case scenarios for something like supply chain or third party breaches are way higher. All sorts of different ways you can uh cut and slice uh the data set, right? I I mean we we we consistently make the point on the report that the the best way to think about all of this is really to think about the extreme cases, right? If you really want to take seriously what is the potential impact uh on your organization, right? And uh I mean if people want to kind of misrepresent, and again, it's not just so much misrepresent the data, it's exactly as it's written, but um to really not try to engage with the story that it's it's writing, just just picking up the number, right? I I mean there's there's very little that I that I can do. But I think it's a fair concern, right? I also thought I when I looked at the number, I also thought it was small, right? And so it's actually one of the things that got me to write the no guys, if you if you do the the average here, I know the number looks small, but if you do the average here, it's just the same as the any other averages that you saw. It's just that we didn't have the this the visibility of this distribution. But again, if you are again a Fortune hundred company and uh you're looking at something like that, and you don't understand that you only by size alone you're gonna fall on the extreme cases of this, right? There's not a, you know, I don't think you're doing your job properly as far as like operational risk and things of that nature.
SPEAKER_01Yeah, that's a good call out. And I just wanted to, yeah, because it's uh, you know, I'm sure some people may look at it and get the wrong impression rather than, you know, you're just objectively sharing the data and it's easy for people to misuse it for good or bad ways. Um and there was another uncomfortable finding in there that uh you know, I found that small businesses can lose up to 77% of their revenue in extreme cases, where large uh enterprises rarely cross 2%. So it seemed like the organizations, you know, with the least expertise and the fewest resources and maybe the smallest budget and so on uh take the hardest proportional hit. And and this is something I've written about, you know, and and what others like uh Wendy Nathers and others call it the cybersecurity poverty line, if you will. You know, what does your data say that we should actually do about the segment that's most exposed but least equipped?
SPEAKER_02That's a good question. Um I mean, we don't we're not we're not really dealing with recommendations there in that's that in in that specific report, right? But we really wanted to highlight the the kind of the increased exposure. And uh it's it's again, it's another data point in the conversation we were having as far as and if you look at the the the kind of the SMB section there that we put, which is like less than 25 uh million, oh, the median is like 38,000. You're like, that's nothing, right? But then you put it against revenue, you kind of get the 7% numbers. And again, 7% for a company where you know cash flow is important, that's usually the case for SMBs, it can become quite especially because you know, you don't, you don't, you insurance is not automatic, right? You kind of have to survive until you kind of get the payout, the payout back, right? But uh I think it kind of brings the to the forefront that the, and again, in conversation with the kind of security poverty line uh from Wendy, is that you know, it's been a it's been a handful of years uh until uh like the last time anybody could actually afford to think, ah, I'm too small, right? I'm not gonna get, I'm not gonna get reached, or I'm not a target, right? Something that ransomware, especially like ransomware automation, ransomware services teams, right? And how that became incredibly, you know, professionalized and like, you know, automated, you know, really kind of like industrial line, industrial production line, is that doesn't matter, you know, they they they've moved down market a long time ago. And the only difference is how much money they're gonna ask from you. They're gonna ask you a uh uh a dollar amount, they believe that you can pay. Because I mean, otherwise, I mean, what's the point, right? Why? Let's just get some money. And um again, if you are, if you are in the kind of the lower scale there of you know, not had thought about resilience and finding ways of protecting yourselves, right? You can be really vulnerable uh to something like that. Again, it's it's it's very easy for me, or you know, even for a kind of like a uh, you know, again, top, top 100, top 500 fortune uh Cs of like, oh yeah, no, everybody should be concerned about security. But it's incredibly hard. It's incredibly incredibly hard to operationalize, right? And it might not be kind of the first priority, or the second, or the third, or the fourth priority of uh of a smaller company. But that doesn't make the problem go away. Yeah, yeah.
SPEAKER_01I guess I just wanted to say I really love what you said there because uh this is something I talk about in in cybersecurity in some of my blogs and stuff, is like I call it the cybersecurity delusion problem, where we often think like cybersecurity is the only thing that matters. And like whether you're a big business or to your point, a small business, like where cash flow is tight and you're just trying to, you know, keep and retain your customers or get, you know, product market fit or whatever the case is, like you have many competing incentives or or competing priorities, I should say, um, against rather than just cybersecurity. Like, yes, it matters, but so does your so does your bottom line, so does your revenue, so does making payroll. So, you know, all these kind of things matter incredibly well too. And it's I feel like sometimes as practitioners in security, like we forget, like, you know, risk of of cyber is just one of many risks that the business is facing. Uh and it's we we got to keep that in mind. Uh and you uh the report was also very measured on a couple of things that I thought was cool and I wanted to kind of dig a little deeper with you on is, you know, everywhere we turn right now, you can't miss miss the hype of AI and AKINT and LLMs and these kind of things, AI uh uh industrializing vulnerability discovery, you name it. The study covered claims through October 2025 and it showed breach costs uh growing in real terms, outpacing inflation, I think roughly three to one. Um, but I didn't really necessarily see AI as an obvious fingerprint anywhere in the lost numbers yet in the report. And even DBIR, you know, which I know you're involved with too, was pretty measured about AI hype uh when a lot of the industry honestly hasn't been. There's been a lot of hype. Uh based on what you're seeing in the actual data, do you think AI is playing an outsized role right now in either the offensive or defensive side, or are we still kind of, is the hype kind of running ahead of what the claims data shows?
SPEAKER_02So let me let me this I have a long answer. It's like maybe a three, four-part answer to that. Um because of course this is a very this is I I I uh we actually are spending a lot of time thinking about that right now, as far as as we we forecast and we kind of put together what this first 2027 report is going to be like. So thing number one, the for the BIS, we really had zero to none details on the the kind of the actual breach that actually happened, so to speak, right? So any of those numbers, you know, uh by quote unquote AI augmented attacks, not that we are doing a good job in 2024 of actually figuring out if it was an AI augmented attack or not, right? Uh so wouldn't show up in the data. So this is actually, again, one of the one of the biggest challenges we have on the DBIR as a whole, because we can get data about almost anything, but each one of these things, they are anonymized independently. So we can never cross-correlate effectively, right? And so even if we had data of kind of AI assisted attacks from the DBIR, we would never be able to make sense with the claims data, right? So we kind of end up being siloed, right? But there are, if you see like, oh, both these lines are trending up, right? There is an argument to be made that there may be some correlation there. It might not be one-to-one, but something of that nature. So that's that's part number one. Around the DBIR, this is something that uh I think it's important. We wrote all of that in February. This was before OMESOS or anything like that. And we were kind of calling the shot in the sense that, hey guys, vulnerabilities is a mess right now, and it's actually getting worse from last year significantly. It's now the number one thing. And here's another topic where we talk about how actual evidence at scale of uh like industrialized uh you know AI assistance in in attack techniques. And kind of our bottom line there on that analysis was that oh, it's okay. Look, if they're just like reinventing the wheel and they're like, oh, let me just write another ransomware, we're gonna be fine because we know how to defend against, I mean, we should know how to defend against ransomware. But if they're doing like novel stuff, like net new stuff, things we don't have defenses for, now we're in trouble, right? And so you cross those two wires and you get something like, you know, the AI uh uh argument, you know, AI assisted vulnerability research on on kind of the frontier models, right? And so, you know, it is it's definitely something of concern. We're we're see I I've been following some amazing research about all of this. I just saw one very cool about undoubtedly the volumes of vulnerabilities being found are skyrocketing, right? You can see uh we have as many in July as we had the whole CVEs, just CVEs, right? Forget the stuff that's not being recorded. As much today as we had the whole year of 2025, but the amount of individual exploits, or I mean, if you're being just like, you know, doing the bare minimum following the the amount of stuff that gets into the CISA catalyst is not growing that much. And so what's going on? Are we made are we actually finding the things first before the attack is found? So all sorts of different analysis. It's very hard to tell where it's all gonna end up, right? And uh, I see a lot of the industry. Look, first things first, there is impact, things are happening right now, and every time, you know, where were you when you heard about the huggy face thing? Where were you, right?
SPEAKER_00Yeah, I was uh I was at my kids, my kids' uh field hockey game, actually. Yeah, and then so I heard about it and I'm like, you know, God, how?
SPEAKER_02Okay, how did they know it was an AI attack, right? Nobody, everybody I asked, nobody knows that, nobody can figure it out. How was it? And then I'm like, another marketing stunt, right? It's these guys need to keep it in. How are we gonna make sure what's going on? And then OpenAI shows, and then, oh yeah, sorry guys, it was this. And I'm like, come on, is everything, is everything just marketing? And then I remembered, right, that every single time I got one of those news and I got very upset like that, was like, oh, it's all marketing. And then I went to dig and I called my my you know, my contacts and people I know, hey, what's really going on? It was like, oh no, it was actually, it was actually it. And again, and again, the all the Hugging Face stuff was actually it, right? And the Hugging Face actually published a fantastic uh summary, very it's all I could hope for to kind of understand and to show people, hey, this is what you should be looking for. But um, you know, it's not a discussion anymore. Oh, is AI doing something? Is gonna do something or not, or is it doing something or not? But it's really like, okay, what are the possible outcomes that we have now? The one of the things I've been telling the folks, uh, again, I I I didn't have time to write that on the DBIR, right? It's something that we kind of I've I it kind of became more clear to me now. But it's really that, you know, you know, maybe, you know, until we get to, because undoubtedly uh offensive AI augmentation is way, way ahead of the curve than the defensive one, right? And everybody talks about, oh yeah, it's gonna be AI versus AI. Yeah, sure, but this guy, we're still figuring out, right? This one, you know, has a mean left hook, but this one doesn't quite know, you know, uh it hasn't even quite, you know, figured their footing yet. So, you know, if is the texturing response in crisis now, will it be, can we can can detecture response as it's is today handle that kind of thing until we figure that out? Or should we be like putting all our chips into uh resiliency and uh you know prevention, right? Oh, am I gonna be able to figure out the the the volume of vulnerabilities that are gonna show up on my kind of uh uh edge firewall or VPN device? Well, should that thing be on the internet at all? Can you just take it off? Can this be kind of like a private circuit or something like that? Because maybe that's the thing we should be thinking about. If we don't know what the volume is going to be, right? And it all all evidence points to, yeah, it's gonna be, might be a lot, we should be rethinking architecture. You know, everybody talks about we shouldn't have flat networks and we should re-architecture network. You know, best time to do that was 15 years ago. Maybe the second ex time now. Maybe now we have an excuse to actually look at that uh, you know, head on, so to speak.
SPEAKER_01Yeah. Yeah, there was a lot in your answer right there that, you know, that that jumped out to me is like a few things I was gonna touch on. One is that, you know, inevitably we are seeing massive rises in CVE data from organizations in the industry. I had uh uh Gary Gamblin on who helped uh first do that. No, no, no, I think it's more of it. Yeah, and uh you know he showed that yes, we are on trend to have 66, 70, maybe 100,000 CVEs at the end of this year. Of course, the MVD and all the kind of infrastructure that supports that is buckling underneath the load. Uh, but there is some nuance that exploitation rates are still one to two percent of CVEs. So it it maybe autonomous exploitation isn't here yet, but to your point, uh it is probably coming. Uh, you know, we maybe we have some time to rethink how we do architecture, you know, be more resilient, uh, think about how we architect our systems, design our systems, et cetera. But things are likely to come in that time. And I suspect in the future, you know, out years of the breach impact study and DBIR, you all will likely have more data to pull on, unfortunately, on that front. So, you know, I look forward to checking those out as well. Um, and then the last piece I was gonna touch on was like your thing about the marketing thing. It's like that's the unfortunate downside of uh some of the you know labs and and vendors in general of like leaning into this AI wave and the hype is that uh sometimes we see things and we want to write them off, or we go, we're just kind of like you know, burnt out on like, oh, this is just this is just marketing. This is messaging of trying to like hype things up for the latest model or for whatever whatever. But then you dig in, like you realize in many cases this is legitimate. This wasn't an incident. It did involve an LLM and/or an H and et cetera. Um so that's just the downside of trying to sift through the noise of marketing hype first, you know, real world uh data activities, incidents, things like that too. Um so I was gonna ask you last question, you know. Uh if a security leader, like, you know, checked out the report and and they closed it, right? They they've went through it and could do one thing differently on on Monday. Uh you all flagged that supply chain incidents, for example, uh are the single most likely to fully exhaust a policy, mean the recorded loss is a coverage cap, uh, not the real impact necessarily. You know, what's the real concrete takeaway that you'd want them to walk away with about things like coverage limits or tail scenarios and so on, rather than just the median, for example?
SPEAKER_02So I think that the the kind of the third, the third party angle, right, and the the relationship angle has always something that has been very interesting from a research perspective for us. It's something we've been chasing, I think it's been two or three years on the DBR, we have been reporting. And it really kind of speaks the complexity of uh of anybody's job, right? Right. It's a hard enough job to make sure your systems are secure, right? But um, and so thinking about all the relationships with third parties becomes an even bigger problem, right? Kind of what the the these finals in the DVIR and the finals in the BS kind of converge to is that it is still very much a blind spot as far as you know, what are the potential, like like you said, worst case scenarios of a relationship, right? Uh and um, you know, do I have contractual in place or do I have a good understanding? Is my vendor willing to partner with me, right? And I remember this is a conversation I had like way back then on the kind of the Move It. Uh, those move those those those times, right? Because we had a lot of um, it was not just like kind of the the the the the the CVE itself, right? But there are so many companies who were service providers using that with their customers' data, right? That got hit indirectly. And so the the question, and again, if that was a really eye-opening moment for the industry, is that okay, how how much do you trust your and again, it's not like it's not uh, you know, what's the word I'm looking for here? So like what's the what's the so the five five a five star or a four point five star you know review, right? If you if you are if you work with someone and they never give you a problem, you're gonna give them a four and a half. But if you had a problem with them and they responded admirably, right, and they really follow through, those are the ones that get the five stars, so to speak, right? And so do you believe your your your the customers you work with will partner with you to solve those kind of those issues expediently, right? And of course, like trust but verify a lot, right? So any considerations the folks might have on if you're dealing with third parties, uh, which go beyond sending them a uh a questionnaire to answer if they're doing stuff, right? And uh companies have gotten way more uh open to being kind of quote unquote audited in real time, especially if they're they're serving critical types of business like finance and things of that nature, right? I think the biggest takeaway is that you know do not underestimate the impacts that your third party can have, right? Many companies have, many insurers have as well, which again are people who should know. Uh uh, you know, they they they they have a much broader understanding of risk than we do, right? And so there's still a lot of kind of unexplored space there as far as uh you know how much how much of a better work we can do together and collaborate in order to get this kind of thing. So I'm definitely not telling anyone to go and get a you know a $50 million policy. No, that's not what I'm telling. But you we need to understand, you know, what's the relationships, what are the exposures, right? And um it has to become a sorry to add more work, right, to everybody's plate, but it's always also something that we should be very much aware of.
SPEAKER_01Yeah, it's such a fascinating uh problem space because you know, both on the technical front in terms of supply chain of like software supply chain and and uh you know vendors and open source and things like that, but also business partnerships, uh third-party service providers, like all these kind of interconnections, interrelationships, whether technically or you know, in the the human realm or personally, like with your business relationships and so on, open a door or an attack factor or a complicated aspect of your attack surface that didn't exist before. And we have to account for all of them because they can have a massive impact as the uh as the data shows, you know. Um so Alex, thanks so much for jumping on with me. I really appreciated it. I enjoyed the report a lot because it put some you know concrete numbers between behind the things that we discussed in the industry. And I look forward to following the report in the years to come. And thank you so much for joining me. Awesome. Thanks for having. This was great. Absolutely. Take care.