SlideShare a Scribd company logo
CDCAT®
Insurance Services
Kyngswoode Services Limited
Bringing innovation to the insurance industry
The Cyber Defence Capability Assessment Tool (CDCAT®
) is an effective, comprehensive way for
organisations to assess their existing cyber defences, identify any vulnerability(s) in their defences
and what mitigations can be applied. Considering the frequency of attacks on organisations’
sensitive cyber assets – CDCAT® is an essential tool in combatting the threats posed by any
number of cyber-criminals and criminal organisations.
CDCAT® was developed by the Defence Science and Technology Laboratory (Dstl), a trading fund
of the MOD. Dstl provides impartial scientific and technological advice to the UK Armed Forces and
British Government.
Kyngswoode Services Limited was awarded, by APMG International, the rights to provide
a CDCAT® derived service to the London insurance sector and associated international
organisations.
Kyngswoode Services use the data from CDCAT®
assessments to create a view of the insurable
risk an underwriter should consider before accepting the cover. This report allows the underwriter
to consider the cyber risk fully without seeing all the underlying evidence that a client may prefer to
keep confidential due to the sensitive nature of the data.
A military grade cyber
defence assessment
Why was CDCAT® Introduced?
Cyber-criminals continuously evolve and adapt their methods
of bypassing the traditionally rigid cyber-security controls
organisations have in place. For organisations to stay safe they
need to be similarly adaptive – this is where CDCAT®
comes in.
While it is highly advantageous for organisations to implement
standards such as ISO/IEC 27001, or employ tools like
penetration testing – these only constitute one part of an effective
cyber security strategy.
CDCAT® is designed so that full sets of best practice controls are
incorporated, 145 controls in total - including ISO/IEC 27001:2013,
the US’ NIST Cyber Security Framework, UK’s 10 steps to Cyber
Security and Cyber Essentials. The result is a truly comprehensive
cyber-security assessment tool, enveloping the standard lifecycle of
assess, deter, protect, detect and respond – mapped against the ITIL
lifecycle of Service Strategy, Service Design, Service Transition and
Service Operation.
What is CDCAT®
Insurance Services?
CDCAT®
Insurance Services utilises CDCAT®
to support insurance
underwriters and brokers using fact based certified assessments
to confirm their client’s cyber defence capabilities. This will enable
brokers to seek better premiums and underwritten conditions
for their clients as well as allow underwriters to use fact based
evidence to assess cyber risks.
The resulting output includes:
■	 Overall rating of cyber risk management capability as measured
	 against agreed risk appetite
■	 Maturity scores between zero to five for each control assessed
■	 Vulnerability status for each control assessed
■	 Red, Amber, Green (RAG) status relative to risk appetite
■	 RAG status relative to best practice
■	 Benchmark rating against an organisation’s own sector / cross-
	 industry sectors, as well as geographic comparisons
■	 Estimated average annual risk cost
What benefits can CDCAT®
offer the
insurance industry?
Brokers
To give the best service to their clients, brokers need to
understand the risks they are working with. Cyber Security is no
different to any other risk yet the industry continues to cautiously
write specific cyber risk cover and Directors and Officers cover
on little known fact based assessments and without a truly
independent and impartial certification of the cyber defence
capability of their client. CDCAT®
Insurance Services will allow
a broker to achieve better underwriting and exclusions for
their clients by demonstrating their clients’ true cyber defence
capability.
Underwriters
Complex and or commercial risks are always supported by
some type of certification to validate the status of the risk such
as aviation, marine and heavy lifting. Yet the most unknown risk,
which is cyber and data breach, is assessed without any truly
independent, objective and certified status of a moment in time
assessment. CDCAT®
can provide a quick review of any clients’
defences, at any time.
Third Party Services
As an organisations cyber defence capability is measurable using
CDCAT®
it is easy to reassess capability at any point in time.
Therefore CDCAT®
can be used to support Claims Management,
Legal and Cyber Consulting Services who are engaged to provide
remedial services for clients. In each case, a current point in time
assessment could assist the outcome of each service being offered.
■	 Unique decision support system which allows a company to
	 proactively tackle its cyber security needs through business
	 risk appetite analysis.
■	 Provides simple steps to improve cyber defence capabilities.
■	 Supports continuous security improvements for organisations
	 and supply chains - as threats, consequences and risk
	 appetites change.
■	 Provides cyber professionals with the tools to build effective
	 business cases for vital updates. Worst case scenario modelling
	 outlines the potential cost to an organisation of not implementing
	 the recommended change and suffering a breach. This is
	 measured against the costs of enacting the change.
■	 Provides organisations with a way to report back to key
	 stakeholders that they are addressing sector based
	vulnerabilities.
■	 Calculates overall business preparedness scores.
■	 Cost savings can be driven through adopting an efficient risk
	 management approach utilising the recommendations.
CDCAT®
benefits:
Contact: Andrew McQuade
E: Andrew.mcquade@kyngswoode.com
T: +44 (0) 7956 640322
www.apmg-cyber.com/cdcat-insurance
www.kyngswoode.com
CDCAT® is the registered trademark of The Secretary of State for Defence and is subject to Crown Copyright and Crown Database Rights. APMG International is the principal licensee of CDCAT®, ap-
pointed to further develop and commercially exploit the tool.
Contact APMG
SOUTH AFRICA OFFICE
Tel:	 +27 21 0033623
Email:	Nigel.Mercer@apmg-international.com
SPAIN OFFICE
Tel:	 +34 911 829 933
Email:	info@apmg-espania.com
UK OFFICE
Tel:	 +44 (0)1494 452450
Email:	servicedesk@apmg-uk.com
ASIA
INDIA OFFICE
Tel:	 +91 (0)80 6583 6280
Email:	info@apmg-india.com
MALAYSIA OFFICE
Tel:	 +6.03.6211 0281
Email:	exams@apmg-malaysia.com
CHINA OFFICE
Tel:	 +86 (0)532 85 78 95 91
Email:	admin@apmg-china.com
AUSTRALASIA
AUSTRALIA OFFICE
Tel:	 +61 (0)2 6249 6008
Email:	admin@apmg-australasia.com
Global Headquarters
UNITED KINGDOM
Tel:	 +44 (0)1494 452450
Email:	servicedesk@apmg-international.com
Web:	 www.apmg-cyber.com, www.apmg-international.com
AMERICAS
Canada OFFICE
Tel:	+1.647.980.5234
Email:	info-Canada@apmg-international.com
US OFFICE
Tel:	+1.781.275.8604
Email:	US-Operations@apmg-international.com
Brazil OFFICE
Tel:	 +55 (11) 3042 4939
Email:	Info-brasil@apmg-international.com
EMEA
BENELUX OFFICE
Tel:	 +31 (0)35 52 31 845
Email:	exams@apmg-benelux.com
GERMANY OFFICE
Tel:	 +49 2133.53.1667
Email:	admin@apmg-deutschland.com
ITALY OFFICE
Tel:	 +39 333 326 6294
Email:	info@apmg-italia.com
Nordics Office
Tel:	 +46 8 587 434 00
Email:	Svante.Lundqvist@apmg-international.com
FOLLOW US ONLINE
@Cyber _APMG
www.linkedin.com/company/apmg-international
blog.apmg-international.com
www.apmg-cyber.com

More Related Content

PDF
EXIGIS RiskWorks rm.Exposures Case Study - Public Entity Risk Pool
Exigis
 
PDF
Insurance_Brochure_NextGen-Underwriting-Solution_06_2011
Arun Rama Krishna
 
PDF
What to Do Before a Cyber Incident Occurs
Colleen Beck-Domanico
 
PDF
Technical Security and Penetration Testing
IT Governance Ltd
 
PDF
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
Happiest Minds Technologies
 
PPTX
Corp Overview 11510
jduhaime
 
PPTX
Security assessment isaca sv presentation jan 2016
EnterpriseGRC Solutions, Inc.
 
PDF
Simplify Your Approach To_Assess The Risks Of Moving Into The Cloud
Happiest Minds Technologies
 
EXIGIS RiskWorks rm.Exposures Case Study - Public Entity Risk Pool
Exigis
 
Insurance_Brochure_NextGen-Underwriting-Solution_06_2011
Arun Rama Krishna
 
What to Do Before a Cyber Incident Occurs
Colleen Beck-Domanico
 
Technical Security and Penetration Testing
IT Governance Ltd
 
Whitepaper: Moving to Clouds? Simplify your approach to understand the risks ...
Happiest Minds Technologies
 
Corp Overview 11510
jduhaime
 
Security assessment isaca sv presentation jan 2016
EnterpriseGRC Solutions, Inc.
 
Simplify Your Approach To_Assess The Risks Of Moving Into The Cloud
Happiest Minds Technologies
 

What's hot (19)

PDF
Third Party Network Webinar Slide Deck 110718 FINAL
DVV Solutions Third Party Risk Management
 
PDF
FFIEC and NIST: What You Need to Know About Two Prevalent New IT Security Com...
West Monroe Partners
 
PDF
Third Party Risk Assessment Due Diligence - Managed Service as Best Practice
DVV Solutions Third Party Risk Management
 
PDF
bsi-cyber-resilience-presentation
Ajai Srivastava
 
PDF
Case study financial_services
G. Subramanian
 
PDF
PCI Certification and remediation services
Tariq Juneja
 
PDF
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
DevOps.com
 
PDF
PCI-DSS Compliant Cloud - Design & Architecture Best Practices
HyTrust
 
PDF
Weakest links of an organization's Cybersecurity chain
Sanjay Chadha, CPA, CA
 
PDF
The impact of a security breach on MSP's and their clients
Jose Lopez
 
PDF
Why does-your-company-need-a-third-party-risk-management-program
Charles Steve
 
PDF
Comodo SOC service provider
paulharry03
 
PPTX
BDQCRM Cyber Risk Management Intelligence Top 12 Final 080216
Mitchell Grooms
 
PPTX
Information Security Assessment Offering
eeaches
 
PPTX
Cytegic presentation 02 12
Cytegic
 
PDF
Debunking Myths for Cyber-Insurance
Priyanka Aash
 
PDF
MT88 - Assess your business risks by understanding your technology’s supply c...
Dell EMC World
 
PDF
Preview novarica1905 mn-pas-pc
~Eric Principe
 
PDF
SFScon21 - Christian Notdurfter - Data Protection by Design and by Default fo...
South Tyrol Free Software Conference
 
Third Party Network Webinar Slide Deck 110718 FINAL
DVV Solutions Third Party Risk Management
 
FFIEC and NIST: What You Need to Know About Two Prevalent New IT Security Com...
West Monroe Partners
 
Third Party Risk Assessment Due Diligence - Managed Service as Best Practice
DVV Solutions Third Party Risk Management
 
bsi-cyber-resilience-presentation
Ajai Srivastava
 
Case study financial_services
G. Subramanian
 
PCI Certification and remediation services
Tariq Juneja
 
Protect Yourself from Cyber Attacks Through Proper Third-Party Risk Management
DevOps.com
 
PCI-DSS Compliant Cloud - Design & Architecture Best Practices
HyTrust
 
Weakest links of an organization's Cybersecurity chain
Sanjay Chadha, CPA, CA
 
The impact of a security breach on MSP's and their clients
Jose Lopez
 
Why does-your-company-need-a-third-party-risk-management-program
Charles Steve
 
Comodo SOC service provider
paulharry03
 
BDQCRM Cyber Risk Management Intelligence Top 12 Final 080216
Mitchell Grooms
 
Information Security Assessment Offering
eeaches
 
Cytegic presentation 02 12
Cytegic
 
Debunking Myths for Cyber-Insurance
Priyanka Aash
 
MT88 - Assess your business risks by understanding your technology’s supply c...
Dell EMC World
 
Preview novarica1905 mn-pas-pc
~Eric Principe
 
SFScon21 - Christian Notdurfter - Data Protection by Design and by Default fo...
South Tyrol Free Software Conference
 
Ad

Viewers also liked (16)

PPT
Javafeature
trupti Deshmukh
 
PPT
Exception Handling.
trupti Deshmukh
 
PDF
SE2016 BigData Volodymyr Getmanskyi "How to build a dynamic pricing model usi...
Inhacking
 
PDF
SE2016 Management Aleksey Solntsev "Management of the projects in the conditi...
Inhacking
 
PPTX
πασχαλινα εθιμα
70athinon
 
PPTX
Ppt sahasfoundation
Sahas Foundation
 
PDF
Outdoor Living In Nocatee
Nocatee
 
PPT
Overridingin java
trupti Deshmukh
 
PPT
Usain Bolt
70athinon
 
PPTX
Estructuras de un Algoritmo
Yanina González
 
PPT
Javar expression
trupti Deshmukh
 
PDF
SE2016 JS Gregory Shehet "Undefined on prod, or how to test a react application"
Inhacking
 
PPTX
Swiss gold
robert martin
 
PPT
To flamingo
70athinon
 
PPTX
УЗИ при послеоперационных перитонитах
Соломаха Анна
 
Javafeature
trupti Deshmukh
 
Exception Handling.
trupti Deshmukh
 
SE2016 BigData Volodymyr Getmanskyi "How to build a dynamic pricing model usi...
Inhacking
 
SE2016 Management Aleksey Solntsev "Management of the projects in the conditi...
Inhacking
 
πασχαλινα εθιμα
70athinon
 
Ppt sahasfoundation
Sahas Foundation
 
Outdoor Living In Nocatee
Nocatee
 
Overridingin java
trupti Deshmukh
 
Usain Bolt
70athinon
 
Estructuras de un Algoritmo
Yanina González
 
Javar expression
trupti Deshmukh
 
SE2016 JS Gregory Shehet "Undefined on prod, or how to test a react application"
Inhacking
 
Swiss gold
robert martin
 
To flamingo
70athinon
 
УЗИ при послеоперационных перитонитах
Соломаха Анна
 
Ad

Similar to CDCATInsurance 2016 (20)

PPTX
Martin Huddleston: No Service Management, No Security
itSMF UK
 
PDF
Xavier Marguinaud in Corporate Livewire Cyber Security Expert Guide 2017 Dec
Laura Tibbo
 
PDF
Complacency in the Face of Evolving Cybersecurity Norms is Hazardous
Ethan S. Burger
 
PPTX
Carm presentation new logo may 14
Elsa Cariello
 
PPTX
Cybersecurity - Sam Maccherola
TechBiz Forense Digital
 
PDF
Cyber Security
NC Military Business Center
 
PDF
Cybersecurity Services Companies.pptx.pdf
Rosy G
 
PPTX
Challenges in the Business and Law of Cybersecurity, CLEAR Cyber Conference, ...
Jay Kesan
 
PPTX
Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
FERMA
 
PDF
2010 State Of Enterprise Security
Symantec
 
PDF
Protecting Your Business From Cyber Risks
This account is closed
 
PDF
Global Cyber Market Overview June 2017
Graeme Cross
 
PDF
Cover and CyberSecurity Essay
Michael Solomon
 
PPTX
CRI Retail Cyber Threats
OCTF Industry Engagement
 
PPT
Meeting the cyber risk challenge
FERMA
 
PDF
FORUM 2013 Cyber Risks - not just a domain for IT
FERMA
 
PDF
BIZGrowth Strategies — Cybersecurity Special Edition 2023
CBIZ, Inc.
 
PDF
Cybersecurity Roadmap Development for Executives
Krist Davood - Principal - CIO
 
PDF
Cyber Insurance Mathematical Model & Pricing
BaraDaniel1
 
PPTX
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
Andris Soroka
 
Martin Huddleston: No Service Management, No Security
itSMF UK
 
Xavier Marguinaud in Corporate Livewire Cyber Security Expert Guide 2017 Dec
Laura Tibbo
 
Complacency in the Face of Evolving Cybersecurity Norms is Hazardous
Ethan S. Burger
 
Carm presentation new logo may 14
Elsa Cariello
 
Cybersecurity - Sam Maccherola
TechBiz Forense Digital
 
Cybersecurity Services Companies.pptx.pdf
Rosy G
 
Challenges in the Business and Law of Cybersecurity, CLEAR Cyber Conference, ...
Jay Kesan
 
Cybersecurity mitigation strategies webinar AIG ecoDa FERMA 24 March 2016
FERMA
 
2010 State Of Enterprise Security
Symantec
 
Protecting Your Business From Cyber Risks
This account is closed
 
Global Cyber Market Overview June 2017
Graeme Cross
 
Cover and CyberSecurity Essay
Michael Solomon
 
CRI Retail Cyber Threats
OCTF Industry Engagement
 
Meeting the cyber risk challenge
FERMA
 
FORUM 2013 Cyber Risks - not just a domain for IT
FERMA
 
BIZGrowth Strategies — Cybersecurity Special Edition 2023
CBIZ, Inc.
 
Cybersecurity Roadmap Development for Executives
Krist Davood - Principal - CIO
 
Cyber Insurance Mathematical Model & Pricing
BaraDaniel1
 
2015 Cyber security solutions vs cyber criminals @WOHIT2015 (EU eHealth week)
Andris Soroka
 

CDCATInsurance 2016

  • 1. CDCAT® Insurance Services Kyngswoode Services Limited Bringing innovation to the insurance industry
  • 2. The Cyber Defence Capability Assessment Tool (CDCAT® ) is an effective, comprehensive way for organisations to assess their existing cyber defences, identify any vulnerability(s) in their defences and what mitigations can be applied. Considering the frequency of attacks on organisations’ sensitive cyber assets – CDCAT® is an essential tool in combatting the threats posed by any number of cyber-criminals and criminal organisations. CDCAT® was developed by the Defence Science and Technology Laboratory (Dstl), a trading fund of the MOD. Dstl provides impartial scientific and technological advice to the UK Armed Forces and British Government. Kyngswoode Services Limited was awarded, by APMG International, the rights to provide a CDCAT® derived service to the London insurance sector and associated international organisations. Kyngswoode Services use the data from CDCAT® assessments to create a view of the insurable risk an underwriter should consider before accepting the cover. This report allows the underwriter to consider the cyber risk fully without seeing all the underlying evidence that a client may prefer to keep confidential due to the sensitive nature of the data. A military grade cyber defence assessment
  • 3. Why was CDCAT® Introduced? Cyber-criminals continuously evolve and adapt their methods of bypassing the traditionally rigid cyber-security controls organisations have in place. For organisations to stay safe they need to be similarly adaptive – this is where CDCAT® comes in. While it is highly advantageous for organisations to implement standards such as ISO/IEC 27001, or employ tools like penetration testing – these only constitute one part of an effective cyber security strategy. CDCAT® is designed so that full sets of best practice controls are incorporated, 145 controls in total - including ISO/IEC 27001:2013, the US’ NIST Cyber Security Framework, UK’s 10 steps to Cyber Security and Cyber Essentials. The result is a truly comprehensive cyber-security assessment tool, enveloping the standard lifecycle of assess, deter, protect, detect and respond – mapped against the ITIL lifecycle of Service Strategy, Service Design, Service Transition and Service Operation. What is CDCAT® Insurance Services? CDCAT® Insurance Services utilises CDCAT® to support insurance underwriters and brokers using fact based certified assessments to confirm their client’s cyber defence capabilities. This will enable brokers to seek better premiums and underwritten conditions for their clients as well as allow underwriters to use fact based evidence to assess cyber risks. The resulting output includes: ■ Overall rating of cyber risk management capability as measured against agreed risk appetite ■ Maturity scores between zero to five for each control assessed ■ Vulnerability status for each control assessed ■ Red, Amber, Green (RAG) status relative to risk appetite ■ RAG status relative to best practice ■ Benchmark rating against an organisation’s own sector / cross- industry sectors, as well as geographic comparisons ■ Estimated average annual risk cost What benefits can CDCAT® offer the insurance industry? Brokers To give the best service to their clients, brokers need to understand the risks they are working with. Cyber Security is no different to any other risk yet the industry continues to cautiously write specific cyber risk cover and Directors and Officers cover on little known fact based assessments and without a truly independent and impartial certification of the cyber defence capability of their client. CDCAT® Insurance Services will allow a broker to achieve better underwriting and exclusions for their clients by demonstrating their clients’ true cyber defence capability. Underwriters Complex and or commercial risks are always supported by some type of certification to validate the status of the risk such as aviation, marine and heavy lifting. Yet the most unknown risk, which is cyber and data breach, is assessed without any truly independent, objective and certified status of a moment in time assessment. CDCAT® can provide a quick review of any clients’ defences, at any time. Third Party Services As an organisations cyber defence capability is measurable using CDCAT® it is easy to reassess capability at any point in time. Therefore CDCAT® can be used to support Claims Management, Legal and Cyber Consulting Services who are engaged to provide remedial services for clients. In each case, a current point in time assessment could assist the outcome of each service being offered. ■ Unique decision support system which allows a company to proactively tackle its cyber security needs through business risk appetite analysis. ■ Provides simple steps to improve cyber defence capabilities. ■ Supports continuous security improvements for organisations and supply chains - as threats, consequences and risk appetites change. ■ Provides cyber professionals with the tools to build effective business cases for vital updates. Worst case scenario modelling outlines the potential cost to an organisation of not implementing the recommended change and suffering a breach. This is measured against the costs of enacting the change. ■ Provides organisations with a way to report back to key stakeholders that they are addressing sector based vulnerabilities. ■ Calculates overall business preparedness scores. ■ Cost savings can be driven through adopting an efficient risk management approach utilising the recommendations. CDCAT® benefits: Contact: Andrew McQuade E: [email protected] T: +44 (0) 7956 640322 www.apmg-cyber.com/cdcat-insurance www.kyngswoode.com CDCAT® is the registered trademark of The Secretary of State for Defence and is subject to Crown Copyright and Crown Database Rights. APMG International is the principal licensee of CDCAT®, ap- pointed to further develop and commercially exploit the tool.
  • 4. Contact APMG SOUTH AFRICA OFFICE Tel: +27 21 0033623 Email: [email protected] SPAIN OFFICE Tel: +34 911 829 933 Email: [email protected] UK OFFICE Tel: +44 (0)1494 452450 Email: [email protected] ASIA INDIA OFFICE Tel: +91 (0)80 6583 6280 Email: [email protected] MALAYSIA OFFICE Tel: +6.03.6211 0281 Email: [email protected] CHINA OFFICE Tel: +86 (0)532 85 78 95 91 Email: [email protected] AUSTRALASIA AUSTRALIA OFFICE Tel: +61 (0)2 6249 6008 Email: [email protected] Global Headquarters UNITED KINGDOM Tel: +44 (0)1494 452450 Email: [email protected] Web: www.apmg-cyber.com, www.apmg-international.com AMERICAS Canada OFFICE Tel: +1.647.980.5234 Email: [email protected] US OFFICE Tel: +1.781.275.8604 Email: [email protected] Brazil OFFICE Tel: +55 (11) 3042 4939 Email: [email protected] EMEA BENELUX OFFICE Tel: +31 (0)35 52 31 845 Email: [email protected] GERMANY OFFICE Tel: +49 2133.53.1667 Email: [email protected] ITALY OFFICE Tel: +39 333 326 6294 Email: [email protected] Nordics Office Tel: +46 8 587 434 00 Email: [email protected] FOLLOW US ONLINE @Cyber _APMG www.linkedin.com/company/apmg-international blog.apmg-international.com www.apmg-cyber.com