Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News

      Insurer Considers Microsoft NT High-Risk

      Written by

      eWEEK EDITORS
      Published May 28, 2001
      Share
      Facebook
      Twitter
      Linkedin

        eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

        Microsofts server software is easy to install, loaded with features and fairly reliable. It may also be more costly to insure against hack attacks.

        J.S. Wurzler Underwriting Managers, one of the first companies to offer hacker insurance, has begun charging its clients 5 percent to 15 percent more if they use Microsofts Windows NT software in their Internet operations. Although several larger insurers said they wont increase their NT-related premiums, Wurzlers announcement indicates growing frustration with the ongoing discoveries of vulnerabilities in Microsofts products.

        Some industry observers believe other insurers may follow Wurzlers lead, which could affect the overall hacker insurance market, a sector that the Insurance Information Institute estimates may generate $2.5 billion in annual premiums by 2005.

        “We saw that our NT-based clients were having more downtime” due to hacking, says John Wurzler, founder and CEO of the Michigan company, which has been selling hacker insurance since 1998.

        Wurzler said the decision to charge higher premiums was not mandated by the syndicates affiliated with Lloyds of London that underwrite the insurance he sells. Instead, the move was based on findings from 400 security assessments that his firm has done on small and midsize businesses over the past three years.

        Wurzler found that system administrators working on open source systems tend to be better trained and stay with their employers longer than those at firms using Windows software, where turnover can exceed 33 percent per year. That turnover contributes to another problem: System administrators are not implementing all the patches that have been issued for Windows NT, Wurzler said.

        According to Microsofts Web site, more than 50 vulnerabilities — and the patches to fix them — have been issued for Windows NT server software since June 1998.

        Microsoft spokesman Jim Desler said the hacker insurance market is still too young to declare Wurzlers move a trend. “Theres not enough history or business to draw conclusions about rate-setting practices,” Desler said. As the market matures, rates are likely to be based on best practices, rather than on platforms or products, he predicted. “We provide unparalleled support in the area of security.”

        American International Group, the countrys largest insurance underwriter, said it will not raise its rates for Windows NT-based systems. Nor will Aon, the worlds second largest insurance broker. The use of NT is “just one factor in the overall assessment of risks. It can be an indicator of other vulnerabilities, but you may also have other things in place to counter that, like firewalls and intrusion-detection systems,” said Kevin Kalinich, a director in Aons technology and telecommunications group.

        However, Harry Croydon, CEO of Safeonline, a London risk analysis firm that works with underwriters at Lloyds, predicted that Wurzlers decision to charge more for Windows NT machines is “a trend we will see increasing.” Just as drivers who own rare cars pay more to insure them, Croydon said, “certain types of software expose you to different risks.”

        Although Wurzlers company is small — eight employees — digital security firms are watching it closely. Bruce Schneier, Counterpane Internet Securitys co-founder and chief technical officer, said it makes sense for underwriters to differentiate premiums based on the type of software and hardware thats used. “Insurance companies are looking to manage their risk effectively. If theres a technology that reduces risk, theyll charge lower premiums,” Schneier said.

        Indeed, several insurers offer discounts to clients that use managed security service providers or put certain security devices on their networks. For example, last week, AIG said it will cut premiums up to 10 percent for clients that use a new security device made by Invicta Networks, a Virginia company headed by Victor Sheymov, a former KGB agent. Invicta claims its device, which uses an Internet Protocol address-shifting technology, is impossible to hack.

        Windows-based servers are frequently victimized by hackers. From August 1999 to November 2000, 56 percent of all the successful, documented hack attacks occurred on systems using Microsoft server software, according to statistics posted at Attrition.org, a Web site that records hackers exploits.

        Given Windows NTs record, Gene Spafford, the director of Purdue Universitys Center for Education and Research in Information Assurance and Security, believes higher insurance premiums may be justified. “NT is more difficult to install correctly and keep up to date than Linux,” Spafford said.

        Right now, it appears that Wurzler is going it alone among insurers by charging higher premiums to Windows NT users. But Wurzler said the higher prices are not costing his company customers.

        A policy covering revenue lost due to hacking costs about $4,000 per year for each $1 million in coverage, he said.

        About half of his clients use Windows NT, Wurzler said; the rest use Linux or Unix. Given that breakdown, he said its easy to justify higher rates for NT machines. “Why should a Unix player with fewer vulnerabilities subsidize NT users?” Wurzler asked.

        And Wurzlers not through with Microsoft. He said his firm is looking at vulnerabilities in Microsofts Internet Information Server software, and that it may soon begin charging higher premiums for that product, too.

        eWEEK EDITORS
        eWEEK EDITORS
        eWeek editors publish top thought leaders and leading experts in emerging technology across a wide variety of Enterprise B2B sectors. Our focus is providing actionable information for today’s technology decision makers.

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        MOST POPULAR ARTICLES

        Artificial Intelligence

        9 Best AI 3D Generators You Need...

        Sam Rinko - June 25, 2024 0
        AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
        Read more
        Cloud

        RingCentral Expands Its Collaboration Platform

        Zeus Kerravala - November 22, 2023 0
        RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
        Read more
        Artificial Intelligence

        8 Best AI Data Analytics Software &...

        Aminu Abdullahi - January 18, 2024 0
        Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
        Read more
        Latest News

        Zeus Kerravala on Networking: Multicloud, 5G, and...

        James Maguire - December 16, 2022 0
        I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
        Read more
        Video

        Datadog President Amit Agarwal on Trends in...

        James Maguire - November 11, 2022 0
        I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
        Read more
        Logo

        eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

        Facebook
        Linkedin
        RSS
        Twitter
        Youtube

        Advertisers

        Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

        Advertise with Us

        Menu

        • About eWeek
        • Subscribe to our Newsletter
        • Latest News

        Our Brands

        • Privacy Policy
        • Terms
        • About
        • Contact
        • Advertise
        • Sitemap
        • California – Do Not Sell My Information

        Property of TechnologyAdvice.
        © 2024 TechnologyAdvice. All Rights Reserved

        Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

        ×