It's unclear what has changed since the last time Bruce covered this. Has there ever been any substantial payout from an insurance company over a cybersecurity incident? I just don't see any way to lock down a network, especially one that's a Windows monoculture, to the degree needed to put a dollar figure on any potential future breaches for the term of a policy. There's nothing for the insurance industry to "figure out", because they're already parting money from fools. It's the fools who need to wise up and realize that cybersecurity is not a "risk" that is best addressed by insurance. 275b896192a0747488011f203c764a3f4f8d60832d56eeb6aa5dfcaef0258604