Apropos of Bruce Schneier's ETCON talk on why security is a business problem, not a tech problem, WashPo is reporting that the Feds are pressuring tech companies to work with the insurance industry to establish liability (and relief therefrom) for security vulnerabilities.
The administration has been talking to insurance firms about the idea of writing cybersecurity insurance for companies, Clarke said, offering an example of one carrot-and-stick approach.
The catch, however, is that the coverage would only be available to companies that meet certain criteria developed by the insurance industry and the private sector.
(Thanks, John!)