Cybercrime continues unabated, growing in sophistication, frequency and severity. In fact, cyber risk is among the top risk concerns of companies globally. CNA CyberPrep, built on nearly two decades of cyber insurance expertise, is a proactive program of cyber risk services developed by CNA Risk Control and CNA Cyber insurance underwriters in partnership with leading cybersecurity specialists.
CNA CyberPrep is available to all CNA cyber policyholders, providing them with a network of cybersecurity professionals and services to actively identify, mitigate and respond to their cyber risks. CNA CyberPrep is modeled on industry-leading cybersecurity frameworks for standards, guidelines and best practices, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework, and is rooted in strong partnerships with highly regarded cybersecurity professionals.
IDENTIFY CURRENT CYBERSECURITY POSTURE
A select group of vendors and services help insureds identify the strengths and weaknesses of their cybersecurity posture, while also providing recommendations for further cybersecurity steps.
- CNA Risk Control Gap Analysis
- CNA Risk Control Information Security and Cyber Infrastructure Self-Assessment
- WhiteHaX – Cloud-Based Penetration Test
- CyberArk – Privileged Access Security Assessment
- External Vulnerability Assessments*
- Penetration Testing*
- Risk Assessments*
MITIGATE POTENTIAL CYBERSECURITY RISK
Cybersecurity recommendations are put into action by additional vendors and services, which help insureds enhance their cybersecurity posture by mitigating potential cyber risk.
- CNA’s eRiskHub® Web Portal
- Computer-Based Training Modules
- CNA-Approved Breach Counsel Consultation
- Incident Response Planning and Testing*
- Policy and Procedure Development and Testing*
- Tabletop Simulations*
- CyberArk Red Team Tactics, Techniques and Procedures (TTP)*
- Security Awareness Training*
- Endpoint Protection and Monitoring*
- Password Management*
- Multi-Factor Authentication*
- CyberArk Privileged Access Management Products*
- OneTrust Educational Materials*
- Data Mapping*
RESPOND TO CYBERSECURITY INCIDENT
Security incidents are often high-pressure situations. CNA’s incident response vendors have a deep understanding of critical steps to minimize an incident’s impact and provide help after one occurs.
- Breach/Privacy Counsel
- Forensic Investigation and Remediation Firms
- Notification Vendors
- Credit Monitoring Vendors
- Public Relations Firms
- Incident Management
CNA cyber insureds may choose from fee-based preferred pricing services*, and value-added options, which are included as part of their CNA cyber policy.
CYBERPREP
Learn about all of the program benefits this three-pronged approach to cybersecurity preparedness provides.
CYBER RISK SOLUTIONS
An Array of Cyber Liability Insurance Products
CNA offers a market-leading suite of cyber liability insurance products and risk control resources for businesses of all sizes, built on nearly two decades of cyber insurance expertise.
RISK CONTROL E-TALKS
Audio Series on Business ResiliencyThis business resiliency series will address how natural and manmade catastrophes, pandemics, and civil unrest create a level of uncertainty, complexity, and challenges that unfold in real-time.
SORCE®
SORCE On DemandSORCE On Demand provides instant access to CNA"s library of risk control resources 24/7, offering learning at your convenience.