Turning Cyber Risk Into a Decision You Can Defend
Season 4 - Episode 4
Host: Patrick Miller
Guest: Scott Kannry
Patrick Miller sits down with Scott Kannry, co-founder and CEO of Axio, to work through cyber risk quantification as a security decision tool for OT and critical infrastructure. Scott came up in the insurance industry at Aon in the early days of cyber coverage. He founded Axio with Dave White to close the gap between a technical security program and a number a CFO and a board can act on.
The conversation stays practical. Why you start on the impact side instead of arguing about probability. How NERC CIP already thinks in consequence. Why the events that matter most are rare, huge, and short on data. How to compare controls, insurance, and compliance spend on the same dollar scale. What AI and quantum do to the "it will never happen" excuse. And a new D&O option for CISOs built on top of consistent quantification.
Topics covered:
The founding of Axio and the insurance-meets-frameworks origin
A short history of cyber insurance, from data breach to business interruption to cyber-physical
The four loss categories Axio uses, first and third party, financial and tangible
Coverage gaps for industrial facilities and the danger of assumed coverage
Impact-first quantification versus probability-first modeling
NERC CIP and consequence-only risk rating
Fiduciary duty, duty of care, and defensible decisions
Security decision support versus vanity security metrics
The art and science of pricing control ROI
AI and quantum, and why low-probability high-impact events deserve attention now
A D&O insurance option for CISOs tied to consistent quantification
Scott's core argument is that quantification is not an insurance exercise and not a compliance checkbox. It is decision support. Start by mapping the worst-case impact of a handful of scenarios, put dollars on them, and only then work backward into likelihood, controls, and transfer. In OT, where there is almost no actuarial data and the biggest events are the rarest, that order matters. It gets you to a defensible, prioritized decision in hours instead of burning weeks arguing over a decimal point.
Chapter markers
00:00 Intro and welcome
00:56 Meet Scott Kannry, Aon, and founding Axio with Dave White
03:10 The real question, turning system knowledge and fear into a fundable decision
05:34 A short history of cyber insurance, breach to business interruption to cyber-physical
09:15 Where industrial coverage breaks, downtime, property, and exclusions
10:40 The four loss categories, first and third party, financial and tangible
15:23 Buying less insurance, controls, regulation, and NERC CIP removing probability
17:51 Start with impact, maximum foreseeable loss, and the billion-dollar event
22:02 The probability ripcord, risk acceptance, and the missing OT data
23:34 Fiduciary duty and the $20B at 0.5% example
27:36 Risk appetite in critical infrastructure and proving diligence
30:28 Security decision support versus vanity metrics
31:51 The art and science of control ROI, segmentation, backup, transfer
35:12 Using AI to make quantification faster
38:26 AI and quantum on the attacker side, rethinking low-probability events
42:44 D&O for CISOs, the Axio, AEGIS, and Lloyd's partnership
46:57 One message for infrastructure boards
48:16 Close
Pull Quotes from Scott Kannry
"I brought the dollars-and-cents perspective, Dave brought the security-leader perspective, and we felt like we met in the middle."
"It makes sense to start on the impact side of the equation first."
"Organizations that start on the probabilistic side usually end up going down esoteric rabbit holes and won't accomplish anything useful."
"A 0.5% likelihood doesn't give you a free pass to flat-out ignore a $20 billion event."
"Plants are plants. They're valued at what they're valued at, and then you work backwards."
"There's a higher likelihood that the 0.5% scenario could happen tomorrow morning. And it's happening right now."
"It puts this whole discipline on the same plane as every other organizational discipline that comes under governance."
Podcast Transcript
Host: Patrick Miller, Ampyx Cyber. Guest: Scott Kannry, co-founder and CEO, Axio. Lightly edited for readability. Speaker names and technical terms corrected from the raw transcript.
Patrick Miller (00:00): This is the Ampyx Cyber Critical Assets Podcast. Each episode, we cover important OT and ICS security topics with an eye toward standards and regulation, to keep you ahead of your adversaries and your auditors. Hello. Good morning, good afternoon, good evening, wherever you are in the world. This is Patrick Miller with the Critical Assets Podcast, and today I have got Scott Kannry with me. I've been chewing on the idea of risk quantification and the various things that surround it when it comes to risk management, so I decided to bring on someone who knows this super well and super deep. I'm just going to pepper him with questions to satisfy my curiosity. So Scott, with that, give us an intro and a little bit of bio for yourself.
Scott Kannry (00:56): Well Patrick, thank you so much. I really appreciate the opportunity to be here. I'm going to try to live up to that introduction and keep you curious, or maybe eliminate some curiosity, given the nature of the topic. In real quick thrift, I'm the co-founder and CEO of Axio, along with my great and esteemed co-founder Dave White, who is very well known in the infrastructure and OT world. The genesis of Axio is really the combination of both of our backgrounds.
I grew up in the insurance industry. It's the only other professional job I've had. For almost 10 years I worked for one of the large insurance brokerage firms, Aon. My job was basically to help companies understand what cyber exposure looked like for them, and what type of insurance coverage to buy for those exposures. Interestingly enough, a big recurring question I'd contend with all the time, especially in the early days of cyber insurance, was whether we should really be buying cyber insurance coverage at all. My security leaders were telling me we were an impenetrable fortress, the best security team on the planet, nothing can ever happen to us, so we don't need this insurance thing. I could use those funds to buy an upgraded firewall, or EDR capability, or you name it from a shiny-object standpoint.
That's what really prompted the notion of, does the world need a better way to understand cyber risk from a business standpoint? A better way to adjudicate those decisions, and to give the CFOs of the world confidence that when the risk manager asks for insurance, I can equate that to the other things. Fast forward 10 years, and here's Axio. Dave brought the technical perspective to bear, being the author of so many cybersecurity frameworks and models. So to put a wrapper around the story, I brought the dollars-and-cents perspective, Dave brought the technical, call it security-leader, perspective, and we felt like we met in the middle. And here we are.
Patrick Miller (03:10): Awesome. Part of the itch I'm trying to scratch is that there's a lot of intersection between the cyber insurance components and risk quantification, and it goes beyond just "do we need cyber insurance, what can we get with it." When we do our risk modeling, are we doing it based on gut? Are we using some super-secret special framework? What do we do when we actually have to go prove it? That's the part I'm trying to satisfy.
In the OT space we end up with a bit of a different approach. Our operators know the vulnerabilities in their systems. They know these systems super well, they built them, the engineering components for example. If they're paying attention, they generally know what the threats are. But they still can't make a decision on what to do about it. And when they try to get funding, because maybe they heard about some technology they want, they're up against everything else in the organization for that funding. So where does that dollar go? That's the decision I'm trying to help people understand. How do you get to that decision based on real numbers, real math? How do you turn knowledge of the system and fear of the risks into a decision a leader can actually make? That's the nexus of what I wanted to get to, and this is basically what you do.
The way we used to do this, we'd buy a bunch of tech, we didn't have a lot of risk numbers, and then we'd cover the rest with insurance. So take me from that stage, where we buy a bunch of tech, we don't really know if it will solve the risk, and we think we'll cover the rest with insurance, to actually using real math to solve this problem. Let's start with the insurance component. As you mentioned, you started at Aon. Correct me if I'm wrong, but they were one of the first, if not the first, to actually do cyber insurance.
Scott Kannry (05:34): Well, that could be a contentious topic, because there are various folks in the insurance industry who are proud to take credit for the first cyber insurance policy. Admittedly, I am not one of them. I started my career in 2003. Based on industry anecdotes, the first true cyber insurance policy dates back to the late 90s, and I happen to know a couple of the folks who lay claim to that. But being one of the large brokerage firms, what is true is that when I started at Aon in 2003, I was employee number seven on the team that handled cyber insurance. So I go pretty far back.
Even on the insurance side, it has been anything but a straight line in the genesis and evolution of the product. Yes, the industry sells policies called cyber insurance policies. Historically they were tailored and focused on data breach risk, especially in the States. Think back to 2003, when California passed the first breach disclosure law and opened up that can of worms. In the aftermath of a breach of personally identifiable information, you have to notify, you offer credit monitoring, and all that comes with a cost. That's what the policies were designed to cover.
Fast forward a bit, and the recognition hits that a cyber event can take systems down. If those systems are revenue generating, no different than your building burning down and not being able to sell goods from your storefront, you will lose revenue if your online store is unavailable for days or weeks. So we get the policies involved to cover that. Fast forward even more to the present, and one of the hallmarks of the insurance industry is that it continues to slice, dice, and compartmentalize risk, putting things in different places depending on a whole load of factors. And we'll fast forward even further to the now reality. We're talking a week after awareness was raised about the latest attempts at impacting our infrastructure, meaning water utilities, and today a port.
Patrick Miller (08:08): So today, a port.
Scott Kannry (08:10): The modern reality is that a cyber event can cause operational and physical impacts, and that raises another flavor of cyber insurance, or other types of insurance. So one lesson, at least on the insurance side, is that simply purchasing cyber insurance is not as easy as that. You need to understand what the policy does. What are the terms and conditions? What are the coverage grants? How does that relate to the things that can happen to you? And if those things happen, where do the losses and impacts fall? Is it costing you money? Damaging your property? Hurting your people? Hurting somebody else's people or property? All of those might fall into different flavors of cyber insurance, or other types of insurance products that still might cover those losses.
Patrick Miller (09:15): So for the industrial space, they can have everything from downtime, calculated in dollars per minute, per second, per day, and then the potential catastrophic loss of the facility itself. The revenue loss and the property loss are two different policies, I assume. They're not bundled into one thing. Maybe, maybe not. Because I've heard situations where people bought policies, had an incident, tried to recover, and found they were completely not covered for the thing they really needed to be covered for. It's gotten a bad rap for wartime clauses and other force majeure issues. Whether you'll actually be covered was a question a lot of organizations were mulling over in the aftermath of several things considered nation-state events. So it's been anything but a straight-line path. This will age quickly, but today, if you're an industrial facility, what should you at least have in your insurance perspective?
Scott Kannry (10:40): Sure. There are a couple of larger buckets, plus a couple of considerations you hit on that changed very recently. Number one, if you have some type of event, at a minimum you're going to have some forensics cost. Money you incur to conduct forensics, and additional money to activate backups and recovery systems. In terms of how Axio thinks about it, we consider all of that in what we call the first-party financial category. That is the cost you incur to do the things in the aftermath of the event, like forensics.
That event might also cost your customers money, because you can't deliver products or components they were counting on. You might have a contractual clause that says you can't deliver within certain timeframes, and they can recover contractual penalties. That ends up being a trickier area of insurance, because insurers often don't like to be a backstop to a contractual guarantee. There are different flavors of it, so it's not a hard yes or no. But if that event causes others to suffer financially, we consider that in the third-party financial bucket.
There are two more. Number three is damage to your own plant, property, and equipment, or people. Equipment that needs to be replaced or is destroyed, or your own employees who are injured. We put that into the first-party tangible category. Even though it all equates to dollars and cents, the category is first-party tangible. The last one is third-party tangible, meaning somebody else's plant, property, equipment, or people is hurt. Think about, and thank God it hasn't happened yet, medical devices in the stream of commerce, such that if something goes catastrophically awry, people could get hurt or worse. Or if you operate a facility that discards used chemicals and there's a spill that causes environmental damage to somebody else's property, that also falls into third-party tangible.
So those are the four categories. And without spending five more minutes on the coverage side, everything I just discussed probably falls into three or more categories, depending on terms and conditions. This is a key piece to going in with eyes wide open. Anything from a cyber insurance policy, to a property policy, an environmental policy, a workers' comp policy, a casualty policy, or any number of other policies could cover those loss categories. So the process of understanding all of this, which we have analytics for and partner with brokers and insurers on, is to help the end-user company understand what types of things can happen, and if they do, what the actual line-item impacts and costs are.
Scott Kannry (14:54): Where do they all fall according to the rubric I just laid out? That provides the roadmap for coverage. Do my current commercial policies cover any or all of that? If I don't buy anything, which is usually not the case, what might I need to buy, or what do I need to tweak with my insurer?
Patrick Miller (15:23): So as an asset owner, what I want to do is buy less insurance. I want to get that cost down. That's where I've looked at risk quantification and the risk management picture in general. Insurance is your last-resort stopgap. If you can do things up front, you don't have to rely on it as much, because leaning on the insurance component pretty much means everything else has failed.
Coming from the background of a recovering regulator, here's a maybe ill-fitting example. If you're trying to reduce fire, there are building codes that say you have to build a certain way to reduce the potential for fire or damage. There are also smoke detectors and fire extinguishers that go on top of that. If you didn't do any of those things, you're probably not going to get a claim on your fire policy.
So when I add in building codes and regulations, those translate into regulation. I look at NERC CIP, the TSA pipeline security directives, and some maritime stuff. In this space, at least in North America, we've got something that says you have to do at least these things. The one I'm most familiar with is NERC CIP, and they decided on that one with, we took probability completely out of the equation. Our risk modeling throws probability all the way over so that it's going to happen. When it happens, what is the consequence? Classically it's likelihood and consequence. In this case, if we shift probability out to "it's going to happen," and lean more on a consequence or impact assessment, how do we factor that in for risk quantification? How does that shift the risk quant model? Because you're trying to get to dollars of risk, and if one of the components is set to "it's going to happen," how does that shift the mindset?
Scott Kannry (17:51): Right. First and foremost, and any of us at Axio would be consistent on this, in order to use this discipline most effectively, it makes sense to start on the impact side of the equation first. The practical benefit is that it's a much easier starting point. Organizations find it much easier to understand the various types of things that can happen to them. Just by understanding their operations and putting numbers into a model, if a breach happens, what's the worst case? If an errant wire transfer happens, what's the worst case based on wiring authorities? If there's a cyber-physical damage event, what's the worst that can happen, based on the largest facility that could be maliciously attacked and destroyed?
Mapping out that worst case for an appropriate sample size of events is fairly easy and straightforward. It's done in the risk world all the time. In the traditional property world it's a tried-and-true discipline, one of the longest-standing areas the insurance industry has done a pretty good job at. It's easy to get to what the industry calls maximum foreseeable loss, or probable maximum loss. If you start there, you've got a confident starting point, and you can already prioritize more effectively.
If you take probability out to begin with, and a breach event is going to cost you a million dollars, a network business disruption event $10 million, and a facility destruction event a billion dollars, where are you going to spend more time? Probably the billion-dollar event, because that's what keeps you up at night. Now work backwards. Based on that scenario and that facility, what are the enabling technologies that support the operation? What security capabilities are in place to protect them? What do we know about the threat and risk universe, whether people are actually going after it, and whether there are attack kits that target those technologies? Then you come up with a pretty good relative understanding of how likely that thing is to happen, and you go down the priority list from there.
Within a very short amount of time, especially today, we're talking hours, not weeks or months or years. You can make more effective decisions about what to do, where to focus, and what to prioritize. On the other side, organizations that start on the probabilistic side usually end up going down esoteric rabbit holes and won't accomplish anything useful for even one scenario, let alone the several I just described, which can be done in a couple of hours. Then you're off to the races improving your security program and lowering your risk.
Patrick Miller (22:02): Right, and that's been one of my bigger frustrations. Typically in a risk-management situation, I hear risk acceptance, and they almost always use the probability ripcord to trash the conversation and say, well, this has never happened, or this is the data we have, so we're not really worried because probability is low. When you have super high-impact but super low-frequency events, you probably still want to focus on that, it still matters. But it's a dramatically skewed perspective, because we don't have any real data there. We don't have actuarial data. At best it's what made it to the news.
The example I use: if Patrick eats bacon cheeseburgers every day, never exercises, and smokes, we know I'm probably going to die at 45 from those causes, almost down to the year, maybe the month, with the data we have now. We have hundreds of years of actuarial data there. In the OT space we've got nothing but avoidance when it comes to reporting incident data. So at best we're guessing on probability. It's good to hear that based on all your expertise, you've shifted it over to consequence, and it actually moves the needle much better.
Scott Kannry (23:34): And here's the deal. At the end of the day, so much of this rests on solid risk management, and it's fiduciary responsibility, as simply as that. This has been a core aspect of what we set out to build from the beginning, and a core aspect of Axio's thesis. Cyber risk quantification, or whatever you want to call it, because that term has a historically challenging context, which we can talk about. But what it really points to, or is intended to enable, is informed understanding and decisioning, especially for organizational leadership and the board of directors.
Back to your point about things that are very low in probability, that doesn't give you a free pass to flat-out ignore it. If the biggest one on your event register is a $20 billion number, but it has a 0.5% chance, that doesn't give you the free pass to say, who cares, it can't happen, forget about it, don't even bother to buy insurance, whatever controls we have are perfectly sufficient, pay attention to the next thing.
Patrick Miller (25:09): Yeah, "good enough."
Scott Kannry (25:10): If that thing does happen, whether tomorrow or 10 years from now, that's a bad day for a company's management. It's a very good day for shareholders' attorneys and the plaintiffs' bar, who during discovery for the shareholder lawsuit will find out the event was just disregarded, that the team said who cares.
There can be a different narrative. The company says, yes, that's a $20 billion event, and yes, it has an extremely low probability. But let's consider it. What are we currently doing? If we want to do more, is there a technical control that's economically reasonable to invest in? What would it cost to buy $20 billion of insurance, or anything in between? If the numbers decide that the next thing is cost-prohibitive, because asking the insurance industry for $20 billion of coverage might cause them to say, sure, we'll sell it to you for $10 billion, the company might say, that's not a wise trade-off, so we're going to accept that risk.
Now fast forward. If the event happens tomorrow or a year from now, and the lawsuit gets filed and people go through discovery, they'll look back. Yes, we can always get sued and lawyers always make their money. But that decision-making process, and how the board and exec team adjudicated it, actually does pass the fiduciary responsibility and duty-of-care test. And that's okay. The former example is a bad day, a really bad day. The current example is still a bad day, but it's an okay day. The duty-of-care test was passed.
Patrick Miller (27:36): Even from a duty-of-care perspective, I look at it like this. I do a lot of work in critical infrastructure, and there are organizations I've seen there with a very large appetite for risk, and it blows my mind. Whether it's shareholder lawsuits, insurance attorneys coming in to make sure you actually did what you said on the questionnaire, or a regulator or investigation team, whatever form of external oversight comes in, you need some way to prove you actually made the decision. You didn't just gut-check it and figure it out as you go. That's where this satisfies so many things at once, when you have that level of transparency in your diligence. "We looked at these things, we made these decisions based on these numbers" is a much better position than "we didn't think it would happen, so we didn't do anything about it."
Scott Kannry (28:43): Right, and that speaks to what we think we've gotten right about our approach to this discipline of cyber risk quantification. Doing it in a way that's fast, but prudent and reasonable in how the process is carried out. Starting on the impact side first, layering in reasonable, understandable, transparent variables that point to probabilities, and keeping a consistent track record, is a means to an end. It's not just duty-of-care protection from a legal standpoint, it's also a far more effective guidepost for prioritization and decisioning. All of that value can be achieved in not too long a time, versus spending 25 hours arguing about whether the likelihood is 1.25% or 1.26% until you're burned out, put the project down, and don't touch it again for six months. You've lost so much potential and opportunity.
Patrick Miller (30:28): Right. And I like your term of security decision support. One thing I typically see is that the board wants to know, we're putting this much money into security, and it always seems like you keep coming back asking for more, and the risk just seems to continually be there. There are complaints about whether our investment is actually moving the needle. The other way they try to do this is through security metrics, and then you're trying to measure this and that, and your measurements always have to change, because something like "how many blocked firewall attempts" is a useless figure. We're still trying to find the magic set of metrics.
I look at this not as a replacement, because you should still measure some things, but it gives you another way to look at it. If you've done these things, it dropped this amount of risk, and not just because we think we dropped it, but because it shows you in dollars how much dollar-risk we just dropped. So it helps you decide which priorities to have, which technologies to spend on, maybe even which practices, in addition to whether the metrics support those same numbers, based on what your risk-quant math says and the decisions you made. Is that capturing it right?
Scott Kannry (31:51): No, that's 100% it. And there's an art-to-science scale to it. For some investments you can look at the risk-reduction impact and understand it very clearly. Take the absence of network segmentation and the ability for somebody to reach your entire customer database. If you implement segmentation and, very simplistically, parcel out customers A through M in one database and N through Z in the other, sure, there's still a "you can get to both" dynamic, but now the impact of somebody getting to half the database versus the whole thing is understood.
Similarly, improving backup and recovery so that if a scenario happens you have high confidence you'll be back online in one day versus eight lets you factor in the revenue that won't be lost during the seven days you would otherwise have been offline. And buying insurance transfers risk off your balance sheet. Whereas you were holding the bag on X amount of loss, now an insurer is. You know the delta and can factor in how much you'll pay for the policy versus how much loss is paid by somebody else. That's the science part.
The art side relates to things like enterprise-wide MFA, where a capability has an effect that covers the entirety, or the majority, of possible loss events. How do you parcel it out? That's where the art comes in. But that's the logic. How much are you going to spend on a control, capability, process, or insurance policy? What is its function? How does that function relate to the loss scenarios, reducing likelihood, precluding it, or minimizing impact? Then you compile those data points across everything, and you've got a pretty good view of what you're currently spending on, how it's impacting your risk, what you want to spend on, and how that would impact your risk. You've got a better roadmap for where to continue spending, where you need to spend, and where you want to spend more, because the thing you could do tomorrow is much better than the thing you shouldn't have been doing for the last year, because it doesn't do anything anymore.
Patrick Miller (35:12): Right. My next one. I've looked at various risk models, qualified or quantified, and there are some long, heinous equations that factor in all these things and take an enormous amount of data capture, interviews, and various methods to gather enormous amounts of data to come up with the dollar-risk situation for you. I'm assuming AI can make this a lot easier and faster. So how are you using AI to make this problem easier?
Scott Kannry (35:52): A couple of ways, and you've hit the nail on the head on the benefits of AI from an implementation and enablement standpoint. First, effectively using AI to do initial research and understand, from a risk standpoint, the profile of a company, or in our case a customer, that wants to go on this journey. Things can now be done totally AI-driven that previously would have taken a decent amount of time in back-and-forth with the company.
Patrick Miller: How much time? Like a month? Two weeks?
Scott Kannry (36:36): Personally, we've always been in the couple-of-days range. But a couple of days could easily have turned into months, when the delta relates to somebody who went on vacation and put the info request at the bottom of their priority list, and they're the long pole in the tent for providing the values on the assets that form the basis of the model.
Patrick Miller (37:11): I've run into those situations where you just can't get the data from the person or the thing.
Scott Kannry (37:14): Exactly. But now, having AI capabilities do a lot of that research and make educated inferences from our own historical database and what's out there, we feel like we can get 90 to 95% of the way there before we even engage with the customer, all behind the scenes, which is really powerful. Then on a go-forward basis, making the perspectives and insights much more real-time and dynamic, through data integrations and monitoring the threat universe, has changed the recency of the perspectives we can provide. We can arm people to make better decisions and understand where to focus this morning, and whether something's real, versus what historically would have taken days, weeks, or months depending on data refreshes.
Patrick Miller (38:26): The flip side of that question is what AI is doing to make your problem harder. By that I mean, the various Anthropic and OpenAI, and now Meta just said "me too, we had a model go out and attack a bunch of things, it escaped its sandbox." We're also using AI to find vulnerabilities at a record pace. There was the vulpocalypse doom that was the original language, and now we're finding some of these are probably not even exploitable. We're getting past the hype cycle into the reality phase, but it's still a massive problem, and a major enabler for an attacker. It's an enabler for a defender too, but we're still figuring out where those defenses work and where they don't. From a defense perspective, relying on it, because it's non-deterministic, is difficult. You can't just say we'll trust it all to AI, and AI will fight AI. So this changes the risk dynamic in ways I'm curious about. How are you dealing with that with these models?
Scott Kannry (39:42): I think one thing in particular, which also needs to be thought about, and I don't know how far ahead, but it's probably an appropriate part of the conversation to reference quantum being out there.
Patrick Miller (40:00): Of course.
Scott Kannry (40:01): What I'm getting at goes back to what we talked about a little while ago, especially in the risk quantification world, and how people have used it, or maybe better put, used it as an excuse not to pay attention to something in the past. That 0.5% likelihood event that everybody took a quick look at and said, ah, there's no way, we don't need to do anything, whatever we're doing is probably fine. Well, with the advent of AI vuln-exploit capabilities and everything else the bad guys can get their hands on, and looking a bit ahead to quantum, there's a higher likelihood that the 0.5% scenario could happen tomorrow morning. And it's happening right now.
Patrick Miller (41:00): And you're just not noticing.
Scott Kannry (41:02): Thinking about it logically, that's one easy way to answer what we're doing about it. Use all of that as further justification to actually use the capabilities we're talking about to understand the impact side of the equation, and not disregard highly improbable but highly impactful events just because they're improbable. They ought to get more than passing attention in today's day and age.
Patrick Miller (41:42): That's a fair answer, just shifting more toward that, because it really does change a lot of the probability aspect. It does scale impact a bit, but in a lot of cases, if you're already looking at loss of the plant, you can't scale that beyond.
Scott Kannry (41:59): That's exactly right. Especially in the industrial world, that's why this whole discipline, when done and delivered well, ends up being far more well received. People react along the lines of, geez, we should have done this five years ago. When you start on the impact side, the risk picture becomes very clear very quickly. Plants are plants, valued at what they're valued at, and then you work backwards, and it's okay.
Patrick Miller (42:44): That's interesting to hear. I've got maybe one or two final questions, but before we get there, here's something. I've got some friends who are CISOs, and the question I've always got is, are you on the D&O? Because if you're not on the D&O, you're basically the certified information fall guy. It's almost a guarantee that when the event happens, you're going to take the hit. We've seen Tim Brown and others. You have a D&O option for CISOs. Is that what I'm hearing?
Scott Kannry (43:27): That's correct. We rolled that out a couple of weeks ago, thanks to a unique partnership with AEGIS Insurance Services and Lloyd's of London, to offer an embedded or complementary CISO D&O policy to Axio subscribers, specifically for the benefit of the organizational CISO and his or her direct reports. So basically the core security team.
We'd been hearing this for a long time, usually when people asked about my background in insurance, and not long into it they'd say, can we talk about D&O insurance? Well, I didn't really do that, but I know enough to be dangerous. The concerns would pop up: depending on where I sit in the organization, I don't know if I'm definitively covered. Even if they show me the policy, I'm still uncertain whether I fall into the protected class of directors and officers, because I'm two layers down, I report to a CIO. Or in certain segments, like the private mid-market, a lot of organizations don't even buy D&O. So if they're not going to buy it to begin with, they're not going to buy it for a particular person.
In today's day and age, exactly to your point, when an event happens and the organization loses money, shareholders often bring on plaintiffs' attorneys to file lawsuits to recoup lost investment gains. The fingers start pointing at the CISO, and if there's no coverage and they're personally named in the suits, of which there have only been a couple of cases so far, it could leave them holding the bag. It's a very unnerving thought for security leaders. The whole premise of our offering is that the insurers we've partnered with have become very educated on Axio, our capabilities, our methodology, and the whole premise of risk quantification and decisioning. They've basically given it the notional seal of approval to say, if you use Axio, and use it consistently, and report to the board on a quarterly basis, you have met your cybersecurity leadership duty of care, therefore you've fulfilled your fiduciary responsibilities. And they're willing to back that with somewhere between a one and five million dollar D&O policy specifically for the CISO and their direct reports.
Patrick Miller (46:32): Again, it goes back to the transparency and diligence in the decision support that was used. Cool. Okay, my last question. If you had to get one point across to an infrastructure company, maybe even a critical infrastructure board, what would be the one thing you'd want to make sure you got across?
Scott Kannry (46:57): It goes back to so much of what we discussed today. Despite some challenging, to be nice, historical connotations, and of course nothing is perfect, from a board and executive-team standpoint, whether it's us or somebody else, the capability needs to align with what the company wants, desires, and has the appetite to implement. I have believed from the very beginning of this journey, I believe it today, and I'll believe it tomorrow, that an effective cyber risk quantification capability, when done well, transparent and explainable, from a security, digital, and increasingly AI-risk standpoint, absolutely ought to be part of what a board says we need to do, and keep doing, for all the benefits. It's what puts this whole discipline on the same plane as every other organizational discipline that comes under governance. It's as simple as that, and it's not going to change.
Patrick Miller (48:16): Awesome. We'll close with that. That's great advice, Scott. Thank you so much for your time. I really appreciate it.
Scott Kannry (48:22): Thank you for having me, Patrick. Had a ton of fun. Looking forward to getting this out, and happy to continue to be in the trenches with you out there.
Patrick Miller (48:31): Much appreciated. Thanks for listening to the Ampyx Cyber Critical Assets Podcast. You can find us on all your favorite podcast sources, so please like, subscribe, and share with your colleagues. Check out our other content, such as blogs and news, at ampyxcyber.com. That's a-m-p-y-x-c-y-b-e-r dot com. Ampyx Cyber, securing your world.