When the European Union General Data Protection Regulation (GDPR) came into effect in May 2018, we in the cyber insurance industry all wondered how zealously each national enforcement agency would levy fines for the inevitable infringements.
Bug bounty programs are growing at an incredible rate. According to the 2018 Hacker Power Security Report, almost every statistic about bug bounties has increased: from a 54% increase in new programs launched to a 49% increase in the number of reports submitted and vulnerabilities disclosed publicly. This is a positive sign for the future of the disclosure industry, in contrast to a troubled beginning when companies and governments pursued legal action against those who reported vulnerabilities (such actions, however, are still happening).
At the time of the announcement, the Cyence Cyber Risk model was predicting that Marriott had a probability of 83% of having any incident and a probability of 43% of having a data breach specifically. Perhaps more relevant, our model estimated a 12% probability of having an insurance relevant incident.