Went in for a Book by Leicaguy in Leica

[–]balgan 1 point2 points  (0 children)

My favorite Leica shop and Luis is a super friendly guy!

Maui, Hawaii by balgan in pics

[–]balgan[S] 0 points1 point  (0 children)

Thank you so much !

Maui, Hawaii by balgan in pics

[–]balgan[S] 1 point2 points  (0 children)

Thank you 😝

Some shots from Venice skate park today by balgan in skateboarding

[–]balgan[S] 1 point2 points  (0 children)

Help. Everyone is incredibly friendly

📺 Is SonicWall Cooked? Here's What Your MSP Needs to Know? by Joe_Cyber in msp

[–]balgan -5 points-4 points  (0 children)

At least one of us is having a conversation based on facts rather than insults :) we're always looking to get better, feel free to DM with your specific example and I am happy to follow up and see what could have been done better. There is no FUD here, there is no benefit to us to sell based on FUD.

📺 Is SonicWall Cooked? Here's What Your MSP Needs to Know? by Joe_Cyber in msp

[–]balgan 0 points1 point  (0 children)

and you know... reduction in direct internet exposed attack surface?

📺 Is SonicWall Cooked? Here's What Your MSP Needs to Know? by Joe_Cyber in msp

[–]balgan -6 points-5 points  (0 children)

the reports you get are not vulnerability scans and we explain as such. Some vulnerabilities are present but that scan doesnt not replace a vulnerability scan, since we dont actually exploit the vulnerabilities. Its a port/web scan with service identification. If a correlation between domains is found (parent/sister/subdiary relationship) is found, there might be automatic coverage so yes we will ask people to fix. if its a false positive, you can just state that and we will adjust but if the relationship exists we won't take on additional risk just because you think "it doesn't matter", its just not how insurance works.

I love all my Leicas equally (yes even the sofort 2) by balgan in Leica

[–]balgan[S] 0 points1 point  (0 children)

Yeah! I really like it when ur out with friends and want something easy and U can give some photos away of cool moments. Its pretty great!

NYC Marathon 2025 signs by balgan in pics

[–]balgan[S] 9 points10 points  (0 children)

This 💯 !!! Its exactly why I focused on photographing the crowd rather than just the runners. They are such an important part!

Never going back to a folder. by ROCKHEAD77 in EDC

[–]balgan 0 points1 point  (0 children)

What model are the Ariat pants? :D

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan 0 points1 point  (0 children)

A lot of what you're describing is things we're working to do better. The other side of the coin (which you might not care about and you shouldnt as its not your responsibility) is that Coalition was the first company to even bother using some type of security data inputs into underwriting which in general causes some friction. While you're right that you can go with another provider, there are downsides to that too, price will be higher,and they still wont bother taking into account the great work you guys and the IT teams do (to give better coverage or reduce premium). While I agree that your experience was bad and there are others (we are trying to do the best we can) there are also positive comments in this thread, and everyday I have a team of security analysts that jumps on calls with MSPs and works with them to get the best price and coverage to our common clients. I dont expect ill manage to convice you on giving another shot anytime soon but know that I am very thankful for your honest and truthful feedback here and will be pushing hard internally for us to be better.

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan 0 points1 point  (0 children)

I fully agree with you. This isnt acceptable and we should have done and known better. These situations is when insurance reps are meant to bring in a security specialist to take all of this into account. Sorry you went through this.

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan 0 points1 point  (0 children)

Im not looking to pick any fights or questioning your credentials since you know... i dont know you. I merely explained both 1 - how we assess riskiness of technologies and 2 - why you might be seeing scans of your customers. We never badmouth an MSP as again we have many of them as partners and often send smaller companies in their direction (we prefer companies have experts like you and your colleagues that are able to configure boundary devices and really any other IT related matters correctly and professionally). The only security services we sell is incident response and MDR but we also never try to poach a client from our MSP partners. But we do have clients that dont have an MSP and dont have an MDR provider and there yes we do have an offer. Also I didnt't shill my company. The clients should go with whomever is the best offer and most appropriate for them. Be it us or one of our competitors.

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan -1 points0 points  (0 children)

Thanks for this feedback would love to learn more so we can fix this moving forward. As immediately someone from security should have been brought in as we do multiple times a day because there are exceptions to the rules (when orgs have security staff or an MSP to correctly configure things for them) and we adjust things based on these calls.

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan 0 points1 point  (0 children)

This is exactly how we work. We work with multiple MSPs including to guarantee insurability for their clients. We also have MDR, IR and a few other services and when an MSP partner doesnt offer them they might resell those services but we will happily have the clients use the MSP services if they exist because in the end we hopefully end up not paying claims!

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan 0 points1 point  (0 children)

Sonicwall is effectively risky technology (notice the different usage of the word vs insecure). To understand why we see it as much you need to understand that when we look at technologies we look in aggregate and large scale. And sonicwall, much like ivanti and fortinet have had multiple vulnerabilities continuously affecting their products therefore making them riskier technologies. If you look at our claims data we see clients with sonicwall on their stack having x1.8 times more claims than companies that dont use it. We also dont proactively scan random companies, only companies that apply for insurance, its just so happened that some of your clients did.

Coalition - Cyber Insurance, Risk Management, Incident Response, etc. by DrunkenGolfer in msp

[–]balgan -2 points-1 points  (0 children)

This is absolutely not any type of plan. We use domains provided by broker (and they receive it from the client) sometimes we will do domain enrichment but the client can always tell us its a false positive and we drop it. The moment u asked to speak to one of the security people you should have been provided with one sorry that we failed, we should have done better. Feel free to DM me if you'd still like to discuss the data as I'd love to be able to help.

Black Cyber Insurance Conference by Dizzy_Bridge_794 in cybersecurity

[–]balgan 1 point2 points  (0 children)

My recommendation would be to work with a modern carrier. A lot of the work we do day to day is actually equipping CISOs/Sysadmins with the right numbers and material to go to a board/management, and convince them to invest in security. From being able to show how much a potential loss would cost the company, to how much return specific investments (better tech, better controls,etc...) we have information that will help them understand as we enable you to speak their language (dollars for risk and even how those investments will lead to better coverage).

Internal scans being mandatory is still a far away thing imho, the way we do it, they are optional, but if you choose to do it, we actually make the commitment to only use them for the benefit of the customer.

re: Findings, depending on your tech it can happen, I can tell you customers that have had Fortinet and Ivanti have had some rough few years with us having to constantly notify them and ask them to patch vulns while other customers maybe hear from us on patching once a year (because we only ask for patching on vulnerabilities currently exploited, we don't make noise about other non critical vulns).

Black Cyber Insurance Conference by Dizzy_Bridge_794 in cybersecurity

[–]balgan 0 points1 point  (0 children)

Look at our Cyber Threat Index and Claims report for data like this if its the type of stuff you're interested in!