Comment by ibejoeb
3 hours ago
Well, these types of companies typically carry cyber incident insurance. If there was, say, a ransomware attack, the carrier is going to bring in a forensic team to investigate. If it is determined that there was negligence, like not patching a system, that will be used to deny a claim. This might be a little different from the lastpass situation in that it's an untrustworthy vendor, but there's still significant exposure.
If this bank were my client, I would make sure that the decision-makers were aware.
No comments yet
Contribute on Hacker News ↗