why aren't all 10 resolved? a statement only gets an assessment when the public
record can support or contradict it. opinions and what-ifs never can, and 0 checkable
ones are still open, waiting for their date. predictions held up or didn't;
assertions are supported or contradicted. on every card:
▮▮▮▮▮ certainty ·
▮▮▮▮▮ debate potential. speakers are clickable
Opinion
Experian's outdated browser usage signals poor security hygiene, says Bob Sohval
“Northwestern Mutual on the left is, is doing a pretty reasonable job of keeping their browser browser use up to date. Experian, not so much. And this is a signal that they're not paying enough attention to security hygiene in, in their company.”
Insight
Cyber breach prediction is more accurate on portfolios than individual companies
“And I would say that, ah, in general, breach prediction on portfolios is somewhat easier than for individual entities. The law of large numbers does apply here, and it's easier to make statements at a portfolio level.”
Assertion Not checkable as stated
Companies with poor security scores are five times more likely to breach
“Of the probability of a breach given a poor score versus a good score, and we look at our data, and that is a ratio of five, something like that. So poor scores are predictive of breach.”
Disclosure
SecurityScorecard operates proprietary honeypots and sinkholes to detect corporate malware
“We are able, we operate our own bank of sinkholes and honeypots to detect malware on, on systems that are at the, on the companies that we monitor.”
Assertion Supported
Sohval: Corporate digital footprints by IP count span over eight orders of magnitude
“In terms of digital footprint, number of IPs, that spans more than eight orders of magnitude.”
Disclosure
SecurityScorecard observes a 1,000-to-1 ratio of non-breached to breached companies
“The number of non-breached companies, the ratio of non-breached to breached is something like, in our system or our platform, something like a thousand to one.”
Assertion Partly supported
Industry-wide cyber breach detection takes an average of five months
“Industry average is five months.”
Assertion Not checkable as stated
SecurityScorecard monitored around 200,000 entities as of October 2017
“Currently we monitor in the vicinity of some 200,000 entities, mostly companies, but also government organizations, government agencies, hospitals, different organizations.”
Prediction Not checkable as stated
SecurityScorecard aimed to monitor one million entities by the end of 2018
“We plan on growing that to about one million by the end of next year.”
Prediction Not checkable as stated
SecurityScorecard predicted data ingestion would reach petabyte scale by late 2018
“That will grow a factor of six at least next year. And by the end of next year we'll be at the petabyte. Level.”