Cyber insurers and cyber providers don’t need to be rivals.
Insurance provider Coalition, which gained managed detection and response capabilities last fall with its acquisition of Wirespeed, has sought to build a bridge between policy and tools — and to make sure managed service providers know. Critics have lumped the firm in with insurance carriers who actively prey on MSPs’ customers, according to Coalition executives.
“I happen to think that almost all of them are bad, except for Coalition,” Tim MalcomVetter, general manager of Coalition Security and co-founder of Wirespeed, told Channel Dive.
Dozens of insurance companies have combined cyber platforms and services with policy, but MalcomVetter said those bundles are often an afterthought and typically use a third-party MDR provider.
“Was it built just for cybersecurity?” MalcomVetter said. “Or is it just another line in a dozen or more lines of insurance in a 100-year old company that's just a big bank?”
Coalition is up against cybersecurity vendors that actively market against insurance providers while offering breach warranties to MSP clients, according to MalcomVetter. Breach warranties are unregulated, require a long list of requirements to be met, and are rarely paid out, according to MalcomVetter.
Legal firewalls and contractual policy have helped Coalition maintain friendly terms with MSPs, MalcomVetter added.
It hadn’t always been that way. Prior to the Wirespeed acquisition, Coalition sometimes positioned its security tools directly to policyholders.
“They didn't stop for a second to think, was there an MSP in play, and what would the MSP reaction be?” MalcomVetter said. “We got acquired in November, and I immediately put a halt to that. Anytime there's a deal going and you smell an MSP involved, you contact the MSP and you say, 'Your client wants Wirespeed. Would you like 20 points? We'd like to do this deal on your paper.’”
MalcomVetter said it was clear to him that MSPs were the logical way for the company to cross-sell its cyber platform.
“There's 4,000 MSPs in North America, and we have 100,000 policyholders,” he said. “We would be stupid to think that we can serve 100,000 policyholders without building the equivalent of an MSP that's the size of 4,000 MSPs. Why would we do that? Why would we make them all enemies?”
Coalition established its incident response business as a legally separate entity from its insurance business. As a result, when an insurance customer files a claim for a breach and the insurance unit needs information from the incident response unit, an attorney functions as a third-party breach counselor between the two groups.
“A lot of times the breach counselor will say, ‘No, don't share anything back,’” MalcomVetter said. If the security side wants to send information to underwriters, it must be in aggregate and anonymized.
Coalition execs call the legal firewall evidence against the notion that it is using cybersecurity data from clients as a way to respond to insurance claims. It’s not a method to deny claims, but rather to reduce the risk of them happening in the first place, according to Josh Hobein, manager of cybersecurity and automation at MSP CentrexIT.
“[With this tool], the possibility of them submitting a claim is lower. They have actual numbers that can back that up,” Hobein said.
A conversion story
Hobein is a skeptic turned believer on insurance-provider hybrids.
Hobein once complained about the entities to his insurance broker friend, who had actively partnered with Coalition. Hobein’s friend encouraged him to speak to Coalition, but Hobein was miffed that insurers weren’t staying in their lane.
“‘They're not a security company,’” Hobein recalled saying. “‘I do security. I know what the hell I'm doing. I don't want insurance to be doing it.’ I was a little bit more colorful than that.”
Eventually, Hobein met with MalcomVetter. He came away impressed. A small handful of CentrexIT clients already held policies with Coalition, but Hobein decided to build Wirespeed into his organization’s stack.
The integrated stack moved faster than its predecessor. It caught a compromise in an email before it appeared on Microsoft logs. MalcomVetter said the two-year-old Wirespeed platform was built to quickly adjust to the needs of SMB clients, while freeing up cybersecurity professionals from remedial work.
“It's a lot of deterministic automation that we've built, and it's because we know the problem space,” MalcomVetter said. “ We built very good abstract solutions for it, so that we can reuse it.”
Coalition puts Wirespeed customers on month-to-month contracts rather than locking them into multi-year agreements. MalcomVetter said this model keeps friction out of the relationship.
“If you lose a customer, we lose it with you,” MalcomVetter said. “We're not sticking it to you, going, ‘No, you get six more months on this contract.’”
A tiered policy expands the MSP’s per-seat discount as they add customers.
“We love that because our customer acquisition costs are very small,” MalcomVetter said. “We just take care of you. You take care of them.”