From ATT&CK to CL&IM: Cyber Insurance Data Modeling using MITRE ATT&CK and beyond
Matt Berninger,
Marsh McLennan
Before ATT&CK, defenders and intelligence analysts couldn't meaningfully compare notes, since different terms were used for different things, and there was no central repository of definitions to rely on. By providing a common taxonomy of TTPs, MITRE ATT&CK has allowed for the type of coordination, comparison, and collaboration that over the last decade has made defenders meaningfully better at tracking and stopping adversaries. In the world of cyber insurance, we face a similar problem. We lack common definitions and frameworks. When insurers wish to share data analysis or trends, the signals get confused. What is the difference between a ransomware claim, a phishing claim, and a malware claim? When does BEC involve a compromise versus simple impersonation fraud? These definitions matter when we use this data to inform risk profiles, control investments, insurance pricing, and business decisions. Property insurance doesn't confuse hurricanes and tornadoes, and neither should cyber insurance. In this talk we will outline the framework we've developed at Marsh McLennan to tackle this issue, and how we connect to and integrate MITRE ATT&CK. We hope to illuminate some issues, and provide a path forward to clarify the confusion.