Should cyber insurance require proof of patched security first?
Cyber insurance is becoming a band-aid that lets companies ignore basic security hygiene. We saw a mid-sized logistics firm pay $40k in premiums last year, then get hit with a ransomware demand for $200k — they had no multi-factor authentication on their VPN and still used 'admin' as a password. Insurers are starting to ask hard questions before writing policies, but I wonder if the whole model just shifts the cost instead of pushing real prevention. Should companies be forced to prove they've patched critical vulnerabilities before they can even buy coverage?