A week ago (which seems like a world ago given everything that’s happened with SolarWinds) Phil Venables -- formerly CISO of Goldman Sachs and now CISO of Google Cloud -- posted an interesting expose on security ratings this week. Phil has a better perspective than most on the value and challenges of ratings not only because of the positions that he’s held but also because he is one of the authors of the Principles of Fair and Accurate Security Ratings. These principles also guide how Bitsight thinks about our rating overall.
Phil’s post is excellently written and I agree with almost all of it. I wanted to take a few minutes and add some additional thoughts and things for people to think about.
The security industry has changed dramatically over the past week with the announcement of the SolarWinds breach and the focus on the importance of the supply chain as a vector of attack. It’s certain to continue to evolve. Security leaders, executives and boards of directors are already starting to evaluate how to assess the damage and what solutions they need to put in place to enhance the security of their environment. Visibility into 3rd and 4th party risk and a common language to communicate the impact to all stakeholders need to be a part of that solution.
Security is missing a common language
Phil starts his post by asking if ratings are necessary and cites many examples of ratings -- imperfect and improving -- in other industries. Ratings are necessary both for the quantification aspect and because security has a fundamental challenge: We lack a common language that can be understood by all constituents, not just the technically sophisticated.
Let’s take an example from another industry: The balance sheet was created in 1494 by Luca Pacioli, a friend of Leonardo da Vinci’s, and was one of the first ways of communicating the financial health of a company. More than 500 years later, this tool is well-embedded in our financial conversations -- it’s a common language that boards, investors, and operators can use to understand the health of a company. Security is not more complicated than finance (as anybody who has had to model a t-account can tell you!) However, we have not given those outside of the security domain a language for communicating with other stakeholders. This language -- and that understanding -- is a fundamental requirement to help to assess, monitor, quantify, and accept a certain level of cyber risk. There is never perfection but we, as a security industry, owe it to our constituents to make it possible to manage cyber risk in the same way that the business is empowered to manage other risks.
Ratings are one way of delivering that common language, giving people a degree of benchmarking, insight, and guidance on which changes are going to make the largest difference to a company’s performance as a whole.
A solid signal, but not the only signal
One milepost for success for any rating is whether it helps to create, advance or reduce friction in a given market. Phil cites the examples of credit ratings (more about that later) which allow for trade and risk understanding in the massive consumer credit market. We’re starting -- but only starting -- to see security ratings take on that same importance.
One only needs to spend a few minutes with the news over the past months to see an increase in cyber attacks from ransomware, phishing, and third-party breaches. All of these are being pushed to the background by the SolarWinds breach highlighting supply chain risk, but they’re all still important.
According to AON, U.S. cyber insurers saw a 10% loss ratio increase due to ransomware in 2019. Cyber insurers are forced to pay out more in claims than they had anticipated, leading to worsening loss ratios and ultimately, diminishing profitability. Security performance ratings are one of the tools which will -- in the long run -- help to guide insurance premiums and to guide the insureds on how to adjust their programs to manage these ratings. Changes in insurance have forced substantial changes in other industries such as the addition of seat belts, and the low costs of “well visits.” As cyber insurance becomes a bigger piece of the insurance pie, executive interest in security is sure to grow.
Bitsight is also seeing examples that companies with well-run security performance management programs perform well in other areas as well. In conjunction with Solactive -- a German financial index provider -- we’ve found that companies that do well on their cyber ratings outperform their stock market peers by an average of 7% with lower volatility.