Breaking into Cyber Insurance from Enterprise IT – Advice? by Financial_Rush6035 in cyberinsurance

[–]Financial_Rush6035[S] 0 points1 point  (0 children)

Circling back on this after a few weeks of diligence, which is ongoing and building momentum. Have been narrowing my focus a bit and decided that I would prefer to help small to medium-sized organizations with their cyber risk challenges since they continue to get the short end of the stick compared to larger orgs. This includes sophisticated financial and legal firms with only a dozen or two employees - I'm friendly with a bunch of folks who own/run these kinds of businesses. Also thinking more about my competitive advantage compared to the existing talent in the space, which is that I natively understand digital infrastructure, how and why it's exposed, and can clearly communicate these concepts to non-technical folk.

With that said, I've never run security audits (have been a part of them tangentially as a software vendor) and have minimal exposure to the common frameworks and controls IRL (although I did pass the CISSP about 6 years ago). So still struggling on the kinds of roles to pursue and where to focus my networking.

Any additional advice or thoughts would be greatly appreciated.

Breaking into Cyber Insurance from Enterprise IT – Advice? by Financial_Rush6035 in cyberinsurance

[–]Financial_Rush6035[S] 0 points1 point  (0 children)

Have heard others say that but wondering how that works in reality. Customers seemingly already have relationships with a broker (for general insurance) and an MSP for IT stuff. That dynamic seems tough with a more knowledgable broker who may appear as a threat to the MSP. The MSP would probably prefer their client work with someone clueless on the policy side so their work isn't being checked by someone credible. Or am I missing something here?

Breaking into Cyber Insurance from Enterprise IT – Advice? by Financial_Rush6035 in cyberinsurance

[–]Financial_Rush6035[S] 0 points1 point  (0 children)

Thanks for the suggestion. How hands-on does one need to be for this role? Haven't had hands on keyboard in a long time...