USENIX Security2023Top-tier venue
Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach Attorneys
Daniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel Schwarcz
Abstract
Incident Response (IR) allows victim firms to detect, contain, and recover from security incidents. It should also help the wider community avoid similar attacks in the future. In pursuit of these goals, technical practitioners are increasingly influenced by stakeholders like cyber insurers and lawyers. This paper explores these impacts via a multi-stage, mixed methods research design that involved 69 expert interviews, data on commercial relationships, and an online validation workshop. The first stage of our study established 11 stylized facts that describe how cyber insurance sends work to a small numbers of IR firms, drives down the fee paid, and appoints lawyers to direct technical investigators. The second stage showed that lawyers when directing incident response often: introduce legalistic contractual and communication steps that slow-down incident response; advise IR practitioners not to write down remediation steps or to produce formal reports; and restrict access to any documents produced.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- Incident Response Planning Using a Lightweight Large Language Model with Reduced HallucinationKim Hammar, Tansu Alpcan, Emil C. LupuNDSS 2026 · 16 citations
- Understanding Legal Professionals' Practices and Expectations in Data Breach Incident ReportingEce Gumusel, Yue Xiao, Yue Qin, Jiaxin Qin et al.CCS 2024
Builds on6
- Reading the Tea leaves: A Comparative Analysis of Threat IntelligenceVector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy et al.USENIX Security 2019 · 123 citations
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson et al.USENIX Security 2017 · 94 citations
- SoK: Cyber Insurance - Technical Challenges and a System Security RoadmapSavino Dambra, Leyla Bilge, Davide BalzarottiS&P 2020 · 47 citations
- A different cup of TI? The added value of commercial threat intelligenceXander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr et al.USENIX Security 2020
- Helping hands: Measuring the impact of a large threat intelligence sharing communityXander Bouwman, Victor Le Pochat, Pawel Foremski, Tom van Goethem et al.USENIX Security 2022
Related papers
- "Tell Them They Are a Responsible Entity, Not a Customer": Understanding Practitioner Challenges in Sector CSIRTsAksel Ethembabaoglu, Natalia I. Kadenko, Yana Angelova, Yury Zhauniarovich et al.CHI 2026 · 1 citation
- Do You Play It by the Books? A Study on Incident Response Playbooks and Influencing FactorsDaniel Schlette, Philip Empl, Marco Caselli, Thomas Schreck et al.S&P 2024 · 13 citations
- SoK: Quantifying Cyber RiskDaniel W. Woods, Rainer BöhmeS&P 2021 · 54 citations
- "We can't Allow IoT Vendors to Pass off all Such Liability to the Consumer": Investigating the U.S. Legal Perspectives on Liability for IoT Product SecurityPrianka Mandal, Amit Seal Ami, Iria Giuffrida, Daniel Shin et al.S&P 2025
- "Where Are We On Cyber?" - A Qualitative Study On Boards' Cybersecurity Risk Decision MakingJens Opdenbusch, Jonas Hielscher, M. Angela SasseNDSS 2025
