The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Ops/Simplifying Cyber
Simplifying Cyber artwork

Cyber Insurance, Unfiltered

Simplifying Cyber · 2026-04-28 · 29 min

0:00--:--

Key moments - from our scoring

Substance score

60 / 100

Five dimensions, 20 points each

Insight Density13 / 20
Originality10 / 20
Guest Caliber15 / 20
Specificity & Evidence11 / 20
Conversational Craft11 / 20

Violet Sullivan brings a rare tri-partite perspective to cyber incidents - having worked as a breach counsel, forensics expert, and now insurance leader. The episode digs into why incident response often fails operationally, not technically. A core theme: miscommunication across legal, technical, and operational teams stems from overlapping terminology (like "breach coach" used by both technical and legal vendors), undefined escalation pathways, and executives unclear on who holds decision authority. Sullivan argues that cyber incidents are team sports requiring clear ball-holding and functional clarity - not acronym salad. She also addresses how crisis communications professionals bring audience-segmented strategies that security teams often overlook, and emphasizes the dangers of AI tools stripping attorney-client privilege when legal advice is fed into systems like Gemini. Throughout, she advocates for translating cyber concepts into plain language (using her diary-and-safe analogy for children as proof of concept) and treating insurance policies as legitimate risk contracts rather than symbols of failure.

Key takeaways

  • →Define role clarity before incidents occur - establish who owns legal decisions, technical decisions, and operations, because the first call of a real breach reveals all playbook gaps immediately.
  • →Avoid jargon overlaps: "breach coach," "DFIR," and "recovery vendor" mean nothing to school superintendents or board members on incident calls; use function-based language (legal help, technical help, operational help) instead.
  • →Attorney-client privilege is now at risk if you feed any part of your legal counsel into AI systems like ChatGPT or Gemini, even for "cleaning up commas," and this applies to auto-transcription of confidential meetings.
  • →Cyber insurance is a contract and risk transfer mechanism, not an admission of failure - it's as essential to a security program as vendor contracts and should be part of pre-breach planning, not panic-driven afterward.
  • →Communications strategy should segment audiences (board, customers, internal teams, security researchers like Brian Krebs) using templates from existing crisis plans for hurricanes or active shooters, not treated as an afterthought once legal arrives.

Guests

Violet Sullivan

Topics in this episode

Escalation pathwaysCrisis communicationsCompliance FrameworksAttorney-client privilege and AICrum and Forstercyber insurance policybreach notificationdigital forensics and incident response (DFIR)attorney-client privilegeInternational Women's Cyber Risk Alliance (IWCRA)

Questions this episode answers

What happens to attorney-client privilege if you use AI tools like ChatGPT on confidential legal advice from your cyber counsel?

Putting legal advice into AI systems like Gemini or ChatGPT removes attorney-client privilege, and this is a very recent legal shift. This applies even to seemingly innocent uses like asking AI to clean up commas in legal communications.

Who should make the decision to call law enforcement during a cyber incident?

The decision should be made by breach counsel (legal lead) in coordination with your incident response plan, not rogue actors. Breach counsel's first question should always be "Have you already communicated anything?" to assess what cleanup is needed.

Why is cyber insurance important in a security program?

Cyber insurance is a contract and risk transfer mechanism - like vendor agreements - that balances the reality that no security program is 100% effective. It should be part of pre-breach planning, not treated as admitting failure or used only after an incident occurs.

What's the most critical thing missing from most incident response tabletops?

Internal escalation pathways - showing how a help desk employee connects dots with someone in networking so early warning signals don't create two separate alert systems that never meet.

How should you explain cyber incidents to non-technical audiences like school boards or executives?

Use analogy and function-based language instead of jargon. For example, frame breaches as someone taking your diary, publishing your secrets, and locking you out of it - then explain prevention and recovery in those same terms.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

13 / 20

The episode contains solid practical insights about incident response coordination, role clarity, and communication strategy that would benefit a security practitioner or operator. However, it's diluted by extended personal anecdotes, casual banter, and some rambling sections that don't advance substantive learning. The most valuable segments (escalation pathways, breach determination process, communications to different audiences) are present but not densely packed.

the biggest question is just who like what makes it a breach... before you make a decision on notification, you have to decide whether or not your company needs to escalate the incident
escalation pathways because you've got to show how someone in help desk connects the dots with someone in networking. Because if you can't show that those dots are connecting, these things could be happening and two different bells going off that you're not seeing in real life

Originality

10 / 20

The core frameworks presented - escalation pathways, role clarity in incident response, separating legal from technical communications - are sensible but not particularly novel. The framing around insurance as a risk transfer mechanism is standard. The conversation relies heavily on conventional wisdom about communication and team coordination without offering contrarian views or first-principles rethinking of how incident response should actually work.

it's really just another, just like you have contracts in place with all of your security vendors, an insurance policy is just another contract. It's another risk transfer mechanism
we have legal help you and technical help you... Then we'll go operational

Guest Caliber

15 / 20

Violet Sullivan is genuinely credentialed - she holds bar certification in two states, has worked across breach notification, forensics, risk management, and now leads cyber solutions at Crum and Forster (a real insurance carrier under Fairfax). She's an adjunct professor and CEO of a global industry alliance. She's a practitioner who has actually managed incidents and built frameworks, not a career podcast guest. However, the conversation doesn't push her to demonstrate depth in the most technical or strategic areas where her expertise should shine.

I did start on the breach notification side... I went from breach notification, I did pre post-breach, and then I went to pre-breach and learned all of that risk management stuff, pen testing, vulnerability scanning
leading risk solutions for Chrome Enforcer, an insurance company that's part of a bigger brand of uh insurance companies called Fairfax

Specificity & Evidence

11 / 20

The episode lacks concrete data, metrics, specific case studies, and dollar figures. When Violet references 'some of the largest breaches of 2014 and 2015,' there are no examples given. The discussion of AI and attorney-client privilege mentions 'within the past month' but provides no citations, case names, or specific incidents. The conversation stays largely at the framework/principle level rather than grounding advice in named examples or quantified outcomes.

I went through some of the largest breaches of 2014 and 2015
I think the biggest thing legally recently within the past month has been that big change in the fact that you divulging things to AI, if it's legal advice, putting it in there is gonna basically remove attorney-client privilege

Conversational Craft

11 / 20

The hosts ask decent questions and occasionally push back ('but what if it's horribly ugly, Violet?'), but much of the conversation drifts into tangential territory without sharp follow-ups on critical claims. The hosts miss opportunities to drill into her insurance expertise or the AI/privilege issue she raises (she even admits 'I'm gonna have to ask, I don't know'). Some segments feel like friendly chatting rather than substantive interrogation. The rodeo sweetheart and nonprofit questions, while humanizing, consume time without advancing learning.

But what if it's horribly ugly, Violet? How what do we do there?
I don't know. Can I say cloud instead? Because it's like that that myth of cloud security. I put everything in the cloud. No, I don't need MFA.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

cyber28breach19insurance17back16side15different14call12technical11point11legal10security10violet9incident9already9question9risk8

Episode notes

Send us Fan Mail The fastest way to turn a cyber incident into a business disaster isn’t ransomware, it’s confusion. We sit down with Violet Sullivan, AVP and Cyber Solutions Team Lead at Crum & Forster, who has worked across cyber law, breach notification, digital forensics and incident response, and now cyber insurance. That vantage point lets her translate what each group needs when pressure is high and everyone is speaking a different language. We get practical about the moments that create real-world chaos: overlapping roles like “breach coach,” acronyms that make leaders freeze, and the dangerous assumption that someone else already handled comms or law enforcement outreach. Violet breaks down a cleaner way to run the response by focusing on function: legal help, technical help, and operational help. We also talk about why crisis communications deserves a seat at the table early, how PR teams organize messaging by audience, and how to avoid the cleanup phase that happens when people speak too soon. Then we zoom out to the contract that quietly shapes the whole response: cyber insurance.

Full transcript

29 min

Transcribed and scored by The B2B Podcast Index.

All right. Thanks for tuning into Simplify and Cyber. I'm Erin Pritz. Cody Rivers.

And today we're joined by Violet Sullivan, AVP and Cyber Solutions team lead at Crum and Forster. And we wanted to have her on the show. Juan Bronwin, who's our fearless uh coordinator and director, is joining us for this talk as well. And you'll see her more in the future.

But Violet has some really interesting experiences and perspectives because she really works at the intersection of cyber law as an attorney and cyber insurance, which we all have questions about, and then incident response, which probably means she didn't sleep through many nights at a period in her career. So without further ado, Violet, I'll let you introduce yourself, give a little bit of background on how you worked your way into cyber. And then we want to go deep on a topic or two, probably around cyber insurance and incident, where we really want to try to get into some meaty topics or learnings that you've had that our listeners can learn from and maybe do something different preventatively or in the midst of an incident.

Well, thank you for having me. I feel like you already introduced me well with that kind of triangle of cyber law, cyber insurance, and incident response. I did start on the breach notification side. So when I came into cyber, I really saw that there was a bigger picture operationally than just the legal side.

So that's when I thought I don't want to just go into privacy and be a breach coach. I want to understand the technical. So I went from breach notification, I did pre post-breach, and then I went to pre-breach and learned all of that risk management stuff, pen testing, vulnerability scanning, all of the uh all of the compliance frameworks that you have to think about and weigh and compare. Remember back when they did all this, we had all the spreadsheets that would compare because you didn't have any compliance frameworks.

Um, and now, and then I decided to go to the forensic side because I really wanted to be on the front line. I wanted to understand what happened on the scoping call and the big decisions that happened and all of that collective experience operationally, technically, legally, helped me to get where I am at, which is leading risk solutions for Chrome Enforcer, an insurance company that's part of a bigger brand of uh insurance companies called Fairfax. And I love working with a team in cyber insurance, and I get to work with not only uh the people on the insurance side, but I actually get to work with all the vendors that I used to be a part of, right?

So from Breach Council, forensics, notification, all of those colleagues that I've been friends with over the years are now the people that I get to work with every day. You must have really developed some good relationships through all those incidents because I've never heard anybody say, I love hanging out with lawyers, vendors, and for cyber people. Yeah, yeah, exactly. You know, it's funny because in group chats at one point I was like calling them my cyber friends.

And they're like, Violet, you can call us your real friends now. You've gone past that point. We do truly get to that level of of connection and nerdiness. Yeah.

Who's so who's who's easier to work with, or who's more difficult to work with? Lawyers or security people? Or insurers. Well, let's just put the full hat trick in there.

Neither one, neither one can hold back the um the face that they get, the know-it-all face that they get whenever there's an MSP on the phone. Neither one can hold back. And I've had to coach so many technical people and I say that is like telling their baby their the baby's ugly. Do not tell them their baby's ugly.

Take a step back. Don't roll your eyes. Um, so I think But what if it's horribly if it's horribly ugly, Violet? How what do we do there?

Why would you do that? Oh, this is on the intro. It's like the science. You're not part of the friends' circle.

Got it, got it. I would say I get along with the technical probably more just because there's so much um it it there's so much neurodiversity, and I'm really attracted to a lot of the neurodiversity in our field. Uh, and I think some I love a lot of the attorneys, but sometimes you get those attorneys that give us a bad name. So, okay, so you so you've been in a lot of rooms.

I'm talking about the earlier in the little prep. I heard a lot of great, cool names and you know, security firms, insurance folks, um, all speaking different languages. What's give us a story without names? What's like the most chaotic miscommunication you've witnessed where everyone thought someone else was handling it?

Cody did not prep any of us for this question, but I love it. It just came to me. I was I was like thinking, like, man, this is this is a this is a wild, wild west here. So I just want to hear from the So this is so I think some of the terminology on what the different players are called, and I think I take for take this for granted that I know these things because we speak in this language, but internally, the playbook might only have a word for okay, there's a breach council, and then there's privacy council, and they might call all things the same, the same name.

But what I usually like to say like when we're on a call is we have we're gonna have legal help you and technical help you. And there might be people under those two, but those are like the two top ones first. Then we'll go operational, right? Like, how do you print out one million letters?

Well, we can't do that in our print trap over here. So you have to sit there and I think bring it back to like function and workflow and not just using terminology that you think is like it. I was actually just on a call today, and someone's like, oh yeah, we're the recovery vendor, we're gonna help the deefer vendor do this. Why are you saying deefer?

Nobody else knows that. And internally, you may have the one security person that knows what DFER stands for, right? Digital forensics incident response for everyone. It's it's something that we use all the time, but if it's the if it's their first time, and think about who you have on the call, you might have the superintendent of a school, you might have the head of the board, you might have people that don't understand the language.

So I think that the biggest misconception that creates problems is not knowing who has the ball and not knowing what we're calling the different players because this is a big team sport. It's a marathon, not a spread. So all of all of the idioms at once, it is important to know who you're tossing the ball to. And I think that that also comes a lot with the difference between when you have a different technical vendor doing forensics and looking back at what happened versus the recovery, which is of course getting things back online.

And you can do so much simultaneously that I think people kind of forget that we got to get up and running it too. We can't just technically, it's so interesting to do forensics and look back, but you're not going to make money until you start getting things back online. Yeah. I want to double-click on who's got the ball because that that would be my chaos item that I've seen on all sides of the table, really.

And sometimes it's a little bit of, especially in tabletops where life and death and outages are not on the line. And, you know, I've seen everything from like legal, privacy, cyber, and the CIO all thinking that they're the person making the decisions. One, probably because it's not that well worked out in the playbook and there's not a racy that clearly defines it. But how how often are you see it seeing that when live fire is happening?

Or calling who's who is taking the what would you call it, like the forefront, like taking the forefront and calling law enforcement, right? Is like there's always someone rogue that's called law enforcement and you're you're or you're walking back from from communicating to employees or like, oh, we already did this. So that's when I hear when I'm on an initial call, I really like when I hear the breach counsel, um, the the attorney that's leading say, How have you already communicated?

Almost like assuming, like, can you just tell me have you done anything yet before we jump into the basics? What have you already said so we can clean up whatever whatever was already laid down? Um, I think another mistake that I've seen is just confusing, you know, okay. So uh news for today, the breach the breach coach term is trademark.

I know because I got a cease and desist. When I made it when I made a sticker one time, but that word breach coach has been used to reference the technical and the legal. And when you say it from the technical side and you give someone a decision, you're and you're not being clear and your your plan isn't clear. And I've seen plans that basically define it, and then people jump in and think another thing.

You can't have the word breach coach and not say this is counsel or this is legal, this is technical. You can't have these same words overlap. Attorneys that are gonna be super busy because I just Googled breach coach and I'm seeing trademarked uh services by three different vendors that are in the recommended uh hit results. No, I definitely gotta, I definitely gotta do not use so that's why I just write beach coach every time instead intentionally.

No, yeah, I like I spell it wrong because I'm I'm trying not to just loophole. That's a good loophole. Cooking fun at the trademark. Yeah, awesome.

Yeah, you know, you mentioned some great things there, and and I do we we do a lot of instant response, and I think another thing I see a lot is to your point, comms. Like you've always got legal, you've always got the cyber folks, you've got the um overaggressive executive that wants to be in all the different rooms and make all the decisions, and you're like, in reality, this happened. But comms, to your point, rarely gets brought in if not late, and you're like, you've got internal communications, you've got external.

And the point you write about really like is by the time the council gets there, what has already been said? Because oftentimes, to your point, and that's a that's a I I didn't think about that. It's like they're trying to do some cleanup because it's kind of pulling back and saying, okay, well, I gotta work from here. I don't get to start fresh with the new template.

I gotta say what's been said, then how do I come over top of that, or how do I come around? So that's that's a really good point and think about. Well, and I got it from breach council. That's that's where I heard it first.

And I also like from I I've learned a lot from crisis communications firms that specialize in cyber are so good at this and they're so on top of it that I think sometimes we downplay, usually we only see that money spent when there's a big, huge scale event. But I learned so much from the PR side of the house because we don't technical people don't think about you know, we're facts, facts, facts, logic. Um, so when I've sat in on sessions and learned from the PR side, they will organize the communication in audiences.

So they'll have a communication, it'll all be similar in case it gets copied for the wrong place, but it won't be like, okay, you have the way you communicate to the board, way you communicate to these customers, way you communicate to uh your internal teams, your sales teams. All of that is something that can also be in that crisis communications plan. And what I find too is that there's already probably a crisis comms plan for hurricanes, active shooters, some other type of disaster, that can usually be linked into cyber and you can push marketing to go ahead and look at the plan and see do we have any new audiences?

And then I always usually tell them about security researchers. I'm like, hey, there's a whole different media that asks different questions. And if you get a call from, you know, Brian Krebs, then you have a different response than you do. Tell them everything.

Don't hold back. No, just do it. Uh so a lot of people in cyber um end up staying in one lane, and you've had the chance to, you know, kind of branch across law and cyber and insurance, um, which probably helps with some of that friction of kind of who's got the ball and language miscommunication or translation issues. What drove you across the three and how has that helped you be a better communicator or bridge that communication divide across those functions?

That's a that's a great question. I think that it was always about learning new skill sets. When I went to from when I started, I was on the operational side. And then I knew that I had just gone through some of the largest breaches of 2014 and 2015.

Um, and I knew that I could take that learning and learn how to give effective tabletops from the operational side. We felt like, you know, we could the company I worked for, we had the first operational retainer, whereas you have these technical retainers. Well, we had operational retainers for retailers that needed call centers stood up, that needed, you know, the notifications within three days. We could guarantee, right?

Those those pieces were very formative for me. But then I needed to go learn risk management. So I learned the front end pre-breach. And then post-breach, I wanted to go back and learn technical.

So that's where I went. And I think insurance was like that final piece where I was like, wait a second, the entire economic structure of this entire crisis response very much depends on a bunch of paragraphs. And those paragraphs are in the insurance policy. And I really wanted to learn how it all worked together.

And I feel like that's kind of the central hub because it is the place where you can try to be right as a security professional 100% of the time. And you can't be right 100% of the time, or else we wouldn't see these headlines. And so having this, it's really just another, just like you have contracts in place with all of your security vendors, an insurance policy is just another contract. It's another risk transfer mechanism to balance out and be part of your total cybersecurity view.

And I I just like to debunk any myth that it's like admitting defeat or any any kind of like, oh, we'll never use that because it's another part of the way that they that a CISO or CIO or anyone in that security leadership, they balance risk. I have to jump in with my question because you're I think I I wanna I'm gonna double-click on this too, because and I think this is an opinion question. Like you're at the intersection of all of these fields, which means that you speak all languages simultaneously.

What's your opinion on how we communicate in an accessible way to all of those audiences? Like, do we have a responsibility to be defining our acronyms and our terms all the time? How are you doing that? Well, one, simplifying cyber, right?

This whole podcast is focused on simplifying. I think that this is the way you should we should have terms and ways that we can break this down where we don't have to sound important or special and we don't have to also do so much repetition. How many times do people repeat the same phrases over and over again? I think that there's a lot that you can also do.

Um, I went to, I actually got this from RSA last year. It's a kid's book. Chief Information Security Officer. I can't remember what company this was for, but uh, which should be marketing.

I go to career day for my kids' school and I talk about and I realize the best way that I've been able to explain it is I tell these kids, I said, think about your diary and think about you put all your secrets in the diary. And someone took your diary, they put all your secrets out everywhere, and they locked you out of your diary so you can't have it anymore. And then I kind of explain, hey, when you have data and you let go of that data, it could be really personal to you and you could be really frustrated about it.

And then I talk through, you know, how we prevent that and how we can lock the diary up and put it in a safe and put it, you know, all of those things. So I think that there's ways that you can make it accessible, and I think you could start thinking about this, not just for the board level and exact because everyone's focused so much on translate to board, translate to board. Yeah, but board people are also fathers and mothers. So just translate to friends, and grandfathers.

Yeah. Um, are you do you still still um adjunct profess, teach professor at Bailey University? Yes, I love it. I kind of thought about this.

You know, and your point is like asking questions is a big thing. Sometimes people are too proud of the ego's there and they don't ask the right questions, but students typically usually ask more questions. And I kind of think of like, what uh what's the question your students ask that you secretly think more executives should be asking? Oh, um the the biggest question is is just who like what makes it a breach?

The simple question, right? And the thing that I come down to, which you might miss you might think I'm going one way, switch the other way. You might think I'm going to the whole breach has a definition in different states, blah, blah, blah, blah, blah. Instead, I'm just gonna say every company would have a plan.

And you would look at the plan first because before you make a decision on notification, you have to decide whether or not your company needs to escalate the incident. So I try to go back to, I like that question because it kind of says, okay, it's not just a lead, it while it is a legal determination and we don't want you to say the B word before you, you know, need to, you need to also think about how it's escalated within your internal company and how it gets to you as like once the council is brought in, there's already been a bunch of kerfuffle that's happened at the incident, you know, level.

And think about all of that time that there is an escalation pathway internally that we don't really explain again to the board or to the executive team what that escalation pathway looks like. So, like when I do tabletops, I usually say that to me that's the most important part is the escalation pathways because you've got to show how someone in help desk connects the dots with someone in networking. Because if you can't show that those dots are connecting, these things could be happening and two different bells going off that you're not you're not seeing in real life.

100% agree. So let's talk a little bit about AI and you know, kind of in we can stay in the incident-related topic, or we can talk about more in the prevention side of it. How is AI reshaping what you're doing from a legal standpoint as well as risks that you're seeing with clients as they're trying to either get in front of or catch up with what's going on in their organizations? Well, I think the biggest thing legally recently within the past month has been that big change in the fact that you divulging things to AI, if it's legal advice, putting it in there is gonna basically remove attorney-client privilege.

That's the biggest huge bomb that's hit the legal side from AI because it really, it really jeopardizes that that defense that you use with your, you know, with your client and your lawyer when that thing gets exposed, when the content that you have created with your attorney gets exposed to AI, which you think you might be cleaning up commas and it's exposing it to losing privilege. How does that play out on like AI recorded meetings? Like if you're recording a meeting with a council in Teams and it's doing a uh transcription, is that the same risk as putting it into Gemini and asking it to some, you know, to friends that have written all these articles for LinkedIn on this that I have all saved.

Yeah. So I'm gonna have to ask, I don't know. Nice. I I mean, this is within the last month that this stuff is developed.

Yeah, yeah. I think from uh cyber side though, this is just the social engineering effect for us has been we've seen so many more believable social engineering attempts. Yeah. There's obviously a lot going on with AI that we're not even gonna get into on this conversation.

But what's kind of like your biggest eye roll moment right now when people are like, well, I have AI, I'm good to go, don't worry about this. And you're like, uh, it's just like it's like it's like you know, knives to your ears is when you're like, that's not a solution, but you know, they leverage AI, so they're they're in a good spot. Oh um, I don't know. Can I say cloud instead?

Because it's like that that myth of cloud security. I put everything in the cloud. No, I don't need MFA. Aaron, Aaron just put one, I had a good article of the day about you know the entire um you know Dell thing right now online, the compliance and a lot of that.

But I think to your point, you see a lot of fallacy and like there's marketing and AI, and people kind of say, Oh, I'm good to go. But in your area where you're solely on the incident and like the post side of things, and and the you see, hey, like that was a false sense of security, or here's here's the reality of it. So a lot of times I hear the stories. Like, I will stop meetings sometimes and say, you know, you you mentioned AI, but really we're talking about process automation, and they'll be like, Yes.

And like, just we don't have to make it shiny. We can just talk about what you've what it what the outcome is. Yeah, I totally agree. One thing to kind of pivot here, too.

I always and this was not prepped at all. So Violet, I don't want to surprise you, but every time on every episode, I kind of say, give the audience the first time they're meeting Violet Sullivan, give them like a fun fact. What is someone who may even who may even know you currently for a couple years doesn't know? What's like a fun fact, could be a good, cool hobby, a fun experience you had?

That's a good story that we can share with the audience. Well, I in high school I was a heart of Texas Rodeo Sweetheart. That's phenomenal. Please share more elaborate.

What what what does that entail? How do you how do you get to the bull or no? Okay. All right.

That's awesome. Very nice. Um, all right. So let's uh while we're on the personal topic, what do you do from a from a nonprofit give back?

Like where do you spend your time kind of adjacent to profession that you're passionate about? Well, I am a very big contributor and and love of all things that empower women in cybersecurity. And I know there's so many amazing groups like YC's and WISP, but in the insurance world, about three years ago, we realized that there wasn't really a business risk-focused cyber organization that we could all connect with. We as a kind of cohesive group, the insurance market, along with the vendors and the law firms that we work with, we created International Women's Cyber Risk Alliance.

And so that's IWCRA.org. Um, I serve as CEO of IWCA or IWCRA. And uh we have a great group of, I think we're we have over like 1,700 members in 18 different countries because this is a insurance is a very global business market, right?

It it funds a lot of the cyber events and responses that you see. And there's a lot of women that really want to connect, and I think two want to be mentored and menteeed. And I think that it's a great way for women to connect, right? Cyber is already something that there's so heavy male population in cyber technology, but in cyber, when it comes to the interns world, it's also very much what a traditional voice club.

And I think that having that connection with women in the insurance market, we've asked each other questions like, how do you ask for a raise? Or how do you get on these speaking panels? How do you get podcasts, right? How do you, how do you learn from each other?

And that's really what we're trying to do is network and learn from each other in the industry. Awesome. How do members or prospective members um get involved? And it sounds like it's you got to be in the industry.

Uh, it's international, so probably geography doesn't matter. But if we have listeners that are playing in this space, how do they reach out and get um get plugged in? You just go to iwca.org and there's a become get involved tab.

You click it and you put your name in the become a member. So you'll get newsletters, there's events um all around. There's actually an event in London in a couple weeks, and from then, oh, Toronto actually tonight, but it's it's gonna be past them for taping. So we have events all over the place um and a lot of virtual events that you can join from anywhere.

Awesome. Well that's really cool. Shifting back to the work side, maybe one last question, Cody, if you want to T one up as well, that's cool as well. Um, but if you if you were able to call yourself, let's say 10, 15 years ago and give yourself some advice specific to career and cyber, what would you what would you say on that call?

Easily, easily I would say just because you went to law school doesn't mean you have to go to a big law firm. That the ego of being a lawyer is something that you as soon as you drop it, as soon as you put it at the wayside, you can follow your skills and passions. I think being a lawyer and getting practice in law is so helpful. But I think that law school actually feeds that ego of, well, I just spent a lot of money on my degree, I need to go work for this law school and kind of lose my, I mean, big law firm and lose my soul.

And I think dropping the ego, and I think that's probably for any, any, any know-it-all type profession, when you can drop that know-it-all ego, I think you're you're gonna be happier. And I feel like that the moment that I realized I didn't have to apologize for not being at a law firm and realize how I could be used in different ways, it was so freeing. And so I would have just told myself sooner. I think you're right.

That is applicable elsewhere and probably in almost every profession. If somebody feels entitled to that they should be at the next level or that they're, you know, out outperforming everyone else. So why not me? Why not me?

And I think that gets in the way of learning and progress. Well, and that's this for maybe lawyers out there, it's like you you get this mindset of going, you're not a real lawyer unless you're at a law firm. That's almost like a thing you would tell yourself, or you you kind of like I don't know if people say it out there, but that's like the the internal monologue that I've heard a lot of other lawyers say, Oh, oh, well, you don't really practice. I'm like, but you hold the bar in two states, right?

Or you, you know, you you have these experiences, and it's like you don't you gotta throw that away that whole idea of you're not a real lawyer unless you do it this way. Yeah. On the uh on the last thing, TS, like some most of us at some point in life or in work are involved in a breach or or hear about something, but for those who have been blessed not to have, you know, and if if I think if cyber insurance existed for like everyday life and you could file a claim for you got fished into a bad relationship.

Yeah, well, you could, you know, you got fished into a bad relationship, you hit a sketchy Amazon deal, or whatever, whatever it could be. What would be the most common claim that you think would be if it's on the personal side? Um, account takeovers. Yeah.

I guess that would be more the most scary claim to me. Maybe not most common, but to me, that's where I think privacy is heading is instead of worrying about, you know, I think the financial institutions have really good compliance frameworks. But I think that account takeovers with, you know, airline miles and rewards, you know, all of these things that we have logins for and social media. I think identity is more important than just what we define PII as right now.

I think that the privacy is going to change. Yep. And not even talking yet about deep fakes and audio deep fakes and all of that. We've seen quite a bit of the last year.

It is, it is for sure. Well, Violet, thanks for coming on the show today. Good to get to know you in the virtual world, and maybe perhaps at some point we'll all get to meet in the real world. Well, thank you for having me.

Have a great day. You too. Thanks, Violet.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • Everything Is Being Recordedmnemonic security podcast · on Attorney-client privilege and AI88 / 100
  • Ransomware Sanctions, OFAC, and the Lazarus Group: A Real Case StudyThe Backup Wrap-Up · on attorney-client privilege88 / 100
  • The Power of Authentic Storytelling: Co-Founder & CEO of ICR, Tom RyanThe Safari · on Crisis communications70 / 100
  • Culture, Compliance and Humanizing Fraud Risk - Dr. Ursula Schmidt - Episode 168Fraud Talk · on Compliance Frameworks69 / 100
  • Risk Culture, Governance and Operational Resilience in Crisis ManagementRiskMasters · on Escalation pathways62 / 100
  • Office Hours #889 | The Hidden Future of Business: AI Search, Workplace Burnout & the Rise of US LacrosseOffice Hours with David Meltzer · on Crisis communications62 / 100

More from Simplifying Cyber

All episodes →
  • Part 2: Swords, Subpoenas, & Software56 / 100
  • Part 1: Saberage and Cyber31 / 100
  • The Vulnerability Playbook76 / 100
  • Spot That Vish!90 / 100
  • The Evolution of Human Risk83 / 100
Explore the best B2B Ops podcasts →
All Simplifying Cyber episodes →