banner-why-daymark.jpg

Information Technology Navigator

Tips, Advice & Insights from Technology Pros

David Anderson, VP of Cyber, Woodruff Sawyer

David Anderson is a dedicated and fierce advocate for his clients focusing on complex cyber, privacy, technology, and professional liability issues. With extensive experience in risk assessment, pre-breach network security risk discovery and risk management, as well as hands-on post-incident client support and claims advocacy, David is committed to helping his clients navigate a complex and ever-changing cyber and professional liability insurance marketplace to ensure they achieve market-leading coverage terms and conditions at the best possible premium.
Find me on:

Recent Posts

Public Company CISOs Beware: The SEC Is No Longer Playing Nice

 

On October 30, 2023, the US Securities and Exchange Commission (SEC) announced fraud charges against SolarWinds and its former chief information security officer (CISO), alleging that “SolarWinds’ public statements about its cybersecurity practices and risks were at odds with its internal assessments.” This comes on the heels of the SEC’s newly implemented rules for disclosures relating to cyber risk. Publicly traded companies (along with pre-IPO and foreign private issuers) must now adhere to new and prescriptive rules requiring the disclosure of “material cybersecurity incidents” as well as annual disclosures relating to “cybersecurity risk management, strategy, and governance.”

There is a lot going on with all the recent SEC and cyber headlines, so let’s break it down piece by piece. This blog outlines several high-level calls to action that CISOs and their stakeholders should consider as they work through their cyber risk strategy and their cyber and/or directors and officers (D&O) insurance renewals.

Read More
Tue, Dec 05, 2023
Share:   

Demystifying Cyber Insurance

A CISO Primer on Navigating Cyber Insurance

After 10+ years of working with clients to negotiate and place cyber insurance, I’ve noticed that one of the most frequent challenges has always been getting the underwriters and my client’s information security stakeholder (like a CISO or CIO) to understand each other. It’s no surprise that insurance is *gasp* slow to evolve – but in their defense, underwriters have come a long way over the last three years. It’s also no secret that being a CISO is one of the most important leadership roles within a company these days. So why are there massive communications disconnects? Why are CISO’s often ill equipped (through no fault of their own) to navigate the cyber insurance ecosystem? How are brokers and their underwriting partners not ensuring that their clients understand the coverages within cyber policies and how the insurance contracts work? How can we bring all the stakeholders in the process together to make our clients more resilient and create a sustainable cyber insurance marketplace? This blog aspires to demystify cyber insurance for all the information security stakeholders in the room so that they are best equipped to dovetail their strategy with what the insurance marketplace is looking for.

Read More
Tue, Aug 15, 2023
Share: