What I don’t understand is why you are proposing a model (insurance) that doesn’t work in practice, and is susceptible to high levels of corruption. Why this would work differently in the case of open source.
The legal/regulation problems here are valid concerns, but the model is a bit different.
The primary corruption of insurance has a lot to do with their ability to deny paying for what they ought to cover. That's a problem. The incentives at play pretty much guarantee it will always be a problem, for which strong regulations are necessary. We don't have strong regulations in the USA for e.g., health insurance, so I can understand why the word "insurance" is unattractive.
Why this would work differently in the case of open source.
Great question.
The very incentive that makes insurance highly corrupt is what I'm proposing be leveraged to benefit open source developers.
A hypothetical insurance company would want to minimize their downside (paying money out), in order to maximize profits, because that's the economical system we live in today. The model I'm proposing is that investing in "the supply chain" would provide resources to offset risk.
On the other side, companies will want to minimize their spend on insurance. An insurance provider may offer reduced rates for companies that demonstrate some measurable commitment to security and responsible data handling practices (a.k.a. not collecting data they don't need in the first place, in case a breach does occur).
This insurance provides a currently absent mechanism for security assessors to affect positive change that protects the rest of us even if the company doesn't want to actually put in the effort.
Comments
The legal/regulation problems here are valid concerns, but the model is a bit different.
The primary corruption of insurance has a lot to do with their ability to deny paying for what they ought to cover. That's a problem. The incentives at play pretty much guarantee it will always be a problem, for which strong regulations are necessary. We don't have strong regulations in the USA for e.g., health insurance, so I can understand why the word "insurance" is unattractive.
Great question.
The very incentive that makes insurance highly corrupt is what I'm proposing be leveraged to benefit open source developers.
A hypothetical insurance company would want to minimize their downside (paying money out), in order to maximize profits, because that's the economical system we live in today. The model I'm proposing is that investing in "the supply chain" would provide resources to offset risk.
On the other side, companies will want to minimize their spend on insurance. An insurance provider may offer reduced rates for companies that demonstrate some measurable commitment to security and responsible data handling practices (a.k.a. not collecting data they don't need in the first place, in case a breach does occur).
This insurance provides a currently absent mechanism for security assessors to affect positive change that protects the rest of us even if the company doesn't want to actually put in the effort.
That's why I proposed it as a contender.
It sounds unlikely that the insurance companies would fund anything. Someone will pay for this but not the insurance company.
This why I postulated "a new kind of cyber insurance" rather than what the industry has already cooked up.
The implication is: This new insurance would be legally obligated to actually fund stuff.