Update on Drone Hysteria With Video

This truly appears to be primarily and perhaps completely caused by mass hysteria and not any actual drone swarm of any kind. There remains the possibility that there were unauthorized drones in sensitive areas, but that does not appear to account for most of the reports.

After spending hours looking for any videos of the supposed drones in New Jersey and elsewhere, I was surprised to find that the overwhelming majority of the sightings seem to be clear, unambiguous and completely doubtless examples of civil and commercial aircraft.


This reminds me very much of the battle of Los Angeles, which was not actually a real battle but rather just an example of similar mass hysteria. We are seeing similar hallmarks to previous flying phenomena hysteria, including a mushrooming number of reports and increasing drama as more and more people are convinced that drones have crashed, are attacking or something else.

Could Drones Over New Jersey Be a Case of Mass Hysteria?

It’s far from certain, and there are a few cases that appear to be legitimate drone sightings, but a large number also appear to be civilian aircraft or other mistakes. At least some, thought perhaps not all reports are a case of panic.

If you have not been living under a rock, you are probably aware that people around New Jersey, and now elsewhere are up in arms over reported sightings of drones. Drone sightings are not at all unusual in the year 2024, but these include reports of drones over sensitive military facilities and critical infrastructure, such as reservoirs and power plants. These reports started coming in around November 13th and have gotten more and more extreme as time has gone on.

At present, a number of elected officials, such as mayors, the governor and police chiefs have voices concern. A great deal of drama is now under way, while officials are demanding answers from the FBI, military or others. Many are calling for the drones to be shot down.

The problem is we still don’t actually have any answers as to what is happening and the reports are fragmented and inconsistent. With time, confusion has only increased and primary evidence of documentation has been lacking.

Now similar reports are being made across the Northeast. At first it was claimed that the drones were “spreading to New York.” Now they claim to have been seen across the Northeast and the US in general.

Here is what seems to have been reported:

  • It has been reported that the drones are only out at night, reportedly appearing at dusk and not being seen during the day.
  • Many of the drones have lights on them, in some cases the lights are strobes or other standard hazard and navigational lights.
  • There have been reports of bright lights and drones that are highly visible and not trying to be stealthy.
  • The drones have been reported over restricted areas, such as Trump-owned property, military installations and airports.
  • Air traffic, including a medical helicopter have had to be diverted due to concerns over drone collisions.
  • Their origin, flight paths and landing locations remains elusive.
  • There are unconfirmed reports of drones switching off lights or otherwise trying to hide when pursued.
  • Many have claimed that the drones are enormous in size, frequently described as the size of an SUV or larger.
  • Reports imply the same drones remain in the sky for hours and travel great distances.

It should be noted that such large and capable drones do exist and are available for purchase. The reports of drones “The size of an SUV” or “8 feet in diameter,” if true, do imply that these are not consumer drones, but rather larger, higher capacity drones. Such drones do exist and are used in agriculture, surveying and other professional pursuits. It’s also possible that a large experimental drone could be constructed by hobbyists, as parts and supplies to build large drones do exist.

Continue reading

Just How Bad Are We Doing With Cyber Security? Lets look at the past week…

So just how bad is ransomware and cyber security in general? To get an impression, lets look at the past week. Just over the past 7 days, there have been over a dozen major ransomware attacks, though a few have not been well reported in the news media. The fact is, we have fallen for a kind of creeping normality. It’s not normal and it should not be considered a routine thing to see this happen.

Starbucks Impacted By Cyber Attack
Stop & Shop Hit By Cyber Incident – May Result In Bare Shelves
Supply Chain Management Vendor Blue Yonder Succumbs to Ransomware
The City of Odessa, TX Experiences a Cyber Incident
Weeks Later, Problems Persist At Hannaford Supermarkets
Wirral University Teaching Hospital Experiences Major Cyber Incident
Retailers Struggle After Attack on Supply Chain Provider Blue Yonder
RRCA Accounts Management Falls Victim to Play Ransomware Attack
Aspen Healthcare Services Announces Data Breach
Zyxel Firewalls Targeted in Recent Ransomware Attacks
Fintech Giant Finastra Investigates Data Breach

Continue reading

How The Failure Of Cyber Security Cost Harris the Election

Many do not realize this, but Donald Trump largely won the election because of cyber security failings by the current administration. Don’t believe me? Cyber security losses are a huge factor in inflation and have caused a massive economic problem, which has decimated healthcare and cost billions to government agencies, all while financing Hamas and the war in Ukraine.

These macroscopic problems may not seem to be linked to cyber security losses, but they are. While politicians like to pretend it is a minor, specialized issue, the fact is that cyber losses are now decimating business and hurting the monetary supply. They are a huge factor in why American businesses are failing and why it is harder than ever to compete. The pain that Americans feel at the gas pump, when they get their pay check, pay for insurance and the problems in the world are not 100% caused by poor management of cyber risks, but that is part of it.

The biggest problem, as I have stated before, is that we simply cannot improve things until the insurance sector cleans up its act. The moral crisis we now are seeing is caused primarily by the insurance sector, which has made the decision that it is fine to lose money on cyber security and it’s fine to raise rates. They’ve created a monster, and that monster can’t be kept at bay until regulators wise up and recognize that insurance must be held accountable for the disgusting and despicable conduct of cyber security underwriters.

Continue reading

An Underwriters’ Guide to Cyber Risk: Managing 3rd Party Risk – Part 2

Understanding and Preventing Zero Day And Other Software Supply Chain Attacks

This is the second post in the series, intended to help better understand how third party risks can be managed, and addressing the problem of misinformation from high raking sources. Because of the pervasiveness of the myth that third party risks are unmanageable, primarily due to the insistence by insurance executives that “Well I don’t understand it, and therefore it can’t be done.” But because of this toxic insistence, it is necessary to break things down and provide detailed supporting information.

In this post, we will look at zero days and unpatched vulnerabilities as a type of exposure to third party risk. Zero days are similar to supply chain attacks, and many of the same methods for controlling zero days apply to supply chain attacks as well. MOVEit is an example of a zero day attack, which caused massive damage to the US and global economy. It illustrates exactly how these attacks work.

In some ways, it was the kind of systemic attack that insurers are constantly complaining about. However, it also illustrates all the ways the damage could have been prevented. MOVEit was bad, but it was also tragic, because so much of the loss could have been prevented, if we had our act together on this.

Continue reading

An Underwriters’ Guide to Cyber Risk: Managing 3rd Party Risk – Part 1

Due to the length of this detailed topic, it will be broken into multiple parts. One of the reasons this post is so long is the extreme entrenchment of incorrect views, and therefore, a need to provide detailed explanations of why they are wrong.

As written about earlier, Warren Buffet is one of the worst out there when it comes to spreading misinformation and unnecessary alarm about cyber security risks. He’s not the only one, however. There seems to be an incessant and rather insane cry of “Well, there are third party risks and they could be systemic. Lets throw our hands up in the air and say there is nothing we can do.”

Of course, this is not the case, in the finite and artificial world of cyber security, no risk is insurmountable and all can be understood. Third party risks come from the fact that so many organizations are dependent on various third parties, such as vendors and contractors. Even clients and customers can be a third party risk, because some organizations rely on a relatively limited number of clients.

In this video-accompanied post, I will do my best to provide detailed information to refute this dangerous and deeply entrenched idea.

Lets be clear on something, this is not new or unique to cyber:
There is nothing new or novel about this concept at all. Some policyholders have always been dependent on a limited number of vendors or service providers. Even in the years before cyber security, a major failing of the power grid, as happened in 2003 and 1977, can cause widespread loss across a large area. A single storm can impact a huge area, or a bad hurricane season can bring devastating storms to a large area. That’s what a systemic risk is.

However, in cyber security, all systemic risks can easily be detected ahead of time, if we care to look. They’re artificial, based on the relationships we choose to have and the artificial, man-made, engineered systems we use with the human-created, anthropogenic, artificial, man-made, ARTIFICIAL RISKS. And therefore finite and easy to understand. It’s always easy to know your risks, when they are in engineered systems you own, right?

Continue reading

Cyber Insurance Applications Revealed

The moral failing of insurance that pays ransom regularly, makes no attempt not to, affirmatively disengages leaders and funds terrorism should be obvious, but many argue with me, stating that insurers are doing the best they can, have incomplete data, or that they are improving.

Unfortunately, they’re not. There have been a few small measures taken, mostly just in terms of wording changes. Not a dime has been invested in enforcement or compliance management.

To show how negligent these insurance companies have been, it’s important to take a look at the applications they have for cyber insurance. These applications represent all that these companies have, in terms of policy controls. It’s abundantly clear that no adult with any idea how any of this works wrote these. There is never any other enforcement. Even large clients do not receive independent assessments or audits. These “requirements” are not generally enforceable, do not create a call to action and, just plain won’t ever work. Money will continue to be lost until even the most minimal efforts to do otherwise are made.

Cyber insurance is considered a loss center (for some reason) and for this reason it gets zero investment and the underwriters who end up on this line are typically the lowest achievers. That’s truly the opposite of what is needed here.

These applications seem to be current, although some have not been updated in years. I do not think it is at all unreasonable to say that those who were responsible for writing the loss controls, for an insurance that paid extortion, to foreign hostile parties, should face some kind of criminal charges. This is not normal. This is not okay. It should not be normalized to have such clueless people, when professionals are avaliable.

Check out this PDF to get an idea of just how bad this situation is.

BREAKDOWN OF CYBER INSURANCE APPLICATIONS

HSB Total Cyber Insurance Application
AIG’S CYBER UNDERWRITING APPLICATION
Travelers CyberRisk Applications and Forms
Chubb Cyber And Privacy Insurance
Beazley Cyber Application
The Hartford CyberChoice Premier Application
FailSafe Cyber / Information Risk Supplement Application

How To Underwrite Cyber Insurance Properly

Because the artificial risk of cyber-attacks Is So controllable, Cyber Insurance can be a reliable cash cow, but it we must rethink what cyber risk is and what role cyber insurance plays. Doing so unlocks the door to billions of dollars in potential profits. Currently, nobody in the entire insurance sector knows how to do this and nobody does it properly.

The term for what we are living through is moral crisis.

Last year, the world lost hundreds of billions of dollars to cyber attacks and trillions were lost to the total economic impact of these attacks.  The biggest problem is ransomware, but business email compromise, leading to fund transfer fraud and other types of account interception and social engineering fraud are also costing the economy billions.  Every week, we hear about more police forces, hospitals, schools and critical institutions being attacked.  Ransom is frequently paid.  Lives have even been lost.  It’s no longer possible to rely on your doctor, lawyer, police force or fire department to be there for you and not leak your private information.

And then we have cyber insurance, which keeps paying ransom and racking up losses, insisting that “cyber is just inherently high loss” or “cyber incidents are like earthquakes: unpredictable and unstoppable.”  We see top ranking executives, even the likes of Warren Buffet saying that it is expected that cyber insurance will lose money.  It will because cyber risks are just big risks and we don’t know how to control them.  Also, we don’t have enough data, and perhaps in a few years we will be able to figure out how to price it.

As an expert in cyber security, ransomware especially, with an education in cyber security and over 20 years of experience, I cannot stress this enough: THIS IS INSANE!

Cybercrimes are just that: crimes.  Like all crimes, they are human created and can be stopped. Cyber security is not some oddball unfigured-out kind of thing.  It’s just bad guys breaking into our systems because we do not institute strong enough controls.  The idea that cyber criminals are so much smarter than our best engineers is absurd.  It’s the year 2024 and the US has the best technology in the world.  None of this needs to happen.  We could shut this down in a day, if there were proper experts involved.

There has been a massive misunderstanding of the nature of cyber risk by the insurance sector, and in doing so we have entrenches a monster which is sapping hundreds of billions of dollars out of the legitimate economy and is funding terrorism.  The history of cyber insurance is a comedy of errors.  There’s a reason no legitimate cyber risk experts should not have been consulted from day one, but there was a belief that cyber was simply a shiny object that could be monetized to appeal to the digital age. Insurers have been trying to sell cyber insurance without investing a dime in understanding it. They’ve simply broken something they don’t understand and now consider it a lost cause. This is absurd.

The truth is simple: If not for the fact that cyber insurance has come along and decided to encourage bad behavior, while funding crime, we would not have the ransomware problem we do. Our hospitals would be safe. Our schools would be safe. Our emergency services would not be targeted. The problem cannot currently be solved, because insurance companies stubbornly insist that they don’t want to, but are fine paying out ransoms.

Continue reading

What We Lack In Cyber Security

The severe moral and ethical failure of the insurance sector, when it comes to cyber security, must be understood in the context of the greater economic issues that it has created. Insurance is a very important foundation to risk management in the private sector. It’s well known that, in the absence of loss control and underwriting standards, insurance can become a subsidy for behavior badly. This is a classic moral hazard, which is made worse by the fact that cyber insurance underwriters have standardized the payment of ransom, endangering all of society and creating massive economic problems.

But there is actually more to it than that. Because of the affirmative disconnection by insurance leaders, who are hell bent on not discussing this sore subject, we have seen a massive divesture of the safety systems we need to keep society running smoothly. Insurance, as an economic force, provides some necessary services and incentives, which it currently does not.

Unfortunately: I can say with 100% confidence, that until the insurance sector gets their act together and starts making money, rather than losing it, we simply will be unable to make substantive progress in cyber security. Effectively, insurance underwriters have broken all economic incentives toward having better cyber security. This is not a minor thing. It’s exactly why we have the problems we do.

A good example is technical approvals. Without the ability to have independent authorities to test and approve individual technologies, it’s impossible to fully enforce good standards. This is vita and it’s unresolvable to not have technical level approvals or products and processes. At present, every organization is left to its own devices to develop its own standards and nothing can truly be mandated.

So why do they do this, when it loses them money? It seems to be a stubborn refusal to spend on cyber controls, because the geriatric idiots who run these pathetic companies are convinced that it’s too new-fangled to bother with. Also, if they decided to stop losing billions, it might cost them hundreds of thousands of dollars. Yes, of course, it’s stupid. It’s a classic case of intimidation by a seemingly new risk, wanting to save face and fear of anyone finding out how bad you’ve been doing at your job.

You see a lot of that in cyber security. Cyber security professionals are pretty used to walking into a client who has just made some terrible mistakes and needs some help getting their reputation back together. We see that more than almost any other area, and we are very empathetic to it. The fact that insurance companies have made such an extraordinary effort to exclude legitimate subject matter experts should tell you something.

One thing that should be kept in mind is that the insurance sector in general, has absolutely lost its way. That goes far beyond cyber security. Insurance has been taken over by purely finical people, who have no idea at all how risk management works and are absolutely opposed to spending a time on loss control or risk analysis. It’s sad because the loss of the ethical compass of the insurance sector has caused far greater problems. It’s why car fatalities have gone up and why nobody is pushing for better fire protection for California.

In case anyone has missed this: It would be substantially cheaper to pay for loss control than to continue to pay out losses, and it would boost profits significantly to reign in these losses.

The depravity of cyber underwriters, their extreme level of greed and their cowardly refusal to ever engage with a single person who understands the risk really underlies just how immoral and truly unethical these people are. They are not only hurting their companies, but endangering the very communities they live in. They’ve thrown their country, their investors, their policyholders all under the bus.

In future posts, there will be greater deconstruction of the terrible history of cyber insurance and how it has caused all these problems for society. The history is well understood. AIG started selling cyber insurance in 1999, without any qualifications. They were warned about this, but it was cheaper not to bother. The addiction to a quick profit, even at the cost of long term losses, seems to be pervasive these days. That sent the industry down a very dangerous path. Today, not a single cyber insurance underwriter knows a thing about the actual field of cyber security. No, I’m not kidding.

There is truly no place for cowards in risk management.

Things We Need to Fix The Cyber Problem

(But do not because of the severe lack of insurance buy in)

Continue reading

The Perfect Analogy for How We Manage Cyber Risk…

It has been over a year since one of the most bizarre freak accidents to capture the world’s attention. I am, of course, speaking of the Titan submersible, operated by the company Oceangate. The company had been operating the submersible for a few years, and it had already gone through a hull replacement, with the previous carbon fiber hull being replaced due to concerns over fatigue. This should tell you something, because most submersibles use materials with a great enough factor of safety and high enough confidence that dangerous levels of material fatigue are just not an issue.

At the time this happened, I, personally, knew very little about the operation. I had heard of a new private venture, which had been taking paying customers to the titanic. To be perfectly honest, that kind of thing isn’t all that interesting to me. Of all the shipwrecks in the world, few have been more thoroughly documented or more constantly bombarded by tourists and other activity. Sure, it still holds some level of scientific and historical interest. It is, after all, one of few liners of the era that still exists in any form. The only others that are still around are also sunk, such as the Britannic and Lusitania.

It would be one thing to lay a single plaque on the Titanic as a tribute to the tragedy, but it seems every single expedition feels the need to leave their mark and explain why they are the best and most poetic at memorializing the ship. At some point, it starts to look like litter.

Continue reading