From Risk to Recovery – Every Stop: The Cyber Insurance Journey with Tawana Johnson

Season 2 /
/Episode 29

From Risk to Recovery – Every Stop: The Cyber Insurance Journey with Tawana Johnson

The Safe House Initiative podcast, hosted by Jeff Edwards and co-hosted by Tawana Johnson, delves into cyber insurance for small to mid-sized businesses. This series builds on previous discussions about incident response flaws, now focusing on the lifecycle of cyber insurance from risk assessment to claims and litigation.

Tawana Johnson, a former litigator and current cyber breach coach at Lewis Brisbois, shares her expertise in handling cyber incidents like ransomware attacks, emphasizing cyber insurance’s role in mitigating damage. A key point is the alarmingly low adoption rate (around 4%) of standalone cyber insurance policies among SMBs, attributed to a lack of understanding or perceived complexity.

Tawana explains her role as a breach coach: supporting clients in crisis, ensuring attorney-client privilege during investigations, and coordinating with insurance carriers, forensic teams, and vendors to navigate legal obligations and recovery.

The upcoming series will cover risk quantification, the role of brokers, underwriting, the claims process, class-action litigation, coverage disputes, and business interruption claims. Tawana highlights the evolving nature of cyber insurance, with carriers now using threat intelligence and penetration testing. She stresses the vital importance of standalone cyber insurance, as standard property and casualty policies often fall short in cyber coverage.

Overall, the episode introduces the complexities of cyber insurance, addressing long-term risks beyond immediate incident response. The goal is to raise awareness, boost adoption, and offer practical guidance for SMBs to better protect themselves from cyber threats.

Highlights:

🔹 Low Adoption: Only ~4% of SMBs have standalone cyber insurance.

🔹Breach Coach Expertise: Tawana Johnson offers unique insights from her legal and breach coaching background.

🔹Privilege & Coordination: Breach coaches are key to maintaining attorney-client privilege and managing incident response.

🔹Risk Quantification: Essential first step before purchasing insurance.

🔹Educated Brokers: Crucial for proper cyber insurance advice.

🔹Comprehensive Series: Covers claims, litigation, and disputes.

🔹Standalone Policies: Provide critical, specialized cyber protections.

Key Insights:

🔹Awareness Gap: Low adoption indicates a lack of understanding and accessibility of cyber insurance.

🔹Breach Coach Role: Provides crucial legal and emotional support, ensuring privileged communication.

🔹Evolving Market: Requires greater due diligence due to sophisticated underwriting (e.g., pen testing).

🔹Broker’s Pivotal Role: Knowledgeable brokers are essential for appropriate policy selection.

🔹Incident Response Coordination: Multi-stakeholder collaboration, often led by a breach coach, is vital.

🔹Litigation Risk: Increasing class action lawsuits and coverage disputes necessitate preparedness.

🔹Standalone Benefits: Offer unique services (breach coaches, negotiation support) beyond financial coverage.

This episode aims to empower businesses with knowledge and strategies for managing and mitigating cyber risks in the digital world.

#CyberInsurance #SMBsecurity #Ransomware #Cybersecurity #BusinessProtection

Cyber Risk: Where Mitigation Meets Insurance With Michael Phillips

Cyber risk management is often framed as a choice between prevention and insurance. In reality, the most resilient organizations combine both.
In this episode of The SafeHouse, Jeff Edwards speaks with Michael Phillips, Global Head of Cyber at Coalition, about how insurers evaluate cyber risk and why mitigation and insurance must work together.

Building on a previous discussion about the elements of risk management, the conversation explores how underwriters think about cyber exposure, what signals insurers look for when assessing organizations, and why operational resilience is becoming central to modern cyber insurance.

The result is a practical discussion about how businesses should approach cyber risk today.

Read More »

Making Sense of Risk Management with Davis Hake

Cyber risk management is often discussed in technical language. But at its core, risk is financial.

In this episode of The SafeHouse Podcast, Jeff Edwards interviews Davis Hake of Venable to break down how cyber risk should be measured, communicated, and quantified inside organizations.

For CISOs, risk managers, brokers, underwriters, and resilience professionals, this episode provides a practical framework for thinking about cyber exposure beyond compliance checklists.

If you want to understand cyber risk in terms that boards and CFOs actually respond to, this conversation is essential listening.

Read More »

When Cybersecurity Became a State Responsibility with James Saunders

Federal cybersecurity responsibility has shifted to the states. What happens next?

In this episode of The SafeHouse Podcast, Jeff Edwards welcomes James Saunders, Chief Information Security Officer for the State of Maryland, for a deep conversation on state-level cybersecurity, resilience, and leadership.

James walks through his path from early technical support roles to federal cybersecurity leadership and now to protecting Maryland’s digital ecosystem. He explains Maryland’s IT Master Plan, the state’s five-pillar cybersecurity strategy, and how partnerships, talent, and resilience come together in practice.

This episode offers a behind-the-scenes look at how cybersecurity decisions are made at scale, how states collaborate with one another, and why taking care of people matters as much as taking care of systems.

Read More »

Why Cyber Warranties Are Not Insurance — and Why That Matters

Kirsten Bay, CEO and co-founder of Cysurance, explains why warranties are becoming a critical layer in cyber risk management. Bay explains how AI-driven cyber certification can help organizations predict where risk is most likely to surface, prevent disruption before it becomes a claim, and protect both insureds and carriers by creating clear, defensible signals of cyber maturity.

Read More »

Cybersecurity Frameworks Made Practical: From Confusion to Clarity

Ryan Ettridge, CEO of CyberCert, tackles a problem many organizations struggle with – cybersecurity frameworks that look good on paper but feel overwhelming or unusable in practice.
Ryan explains how AI-driven cyber certification can help organizations predict where risk is most likely to surface, prevent disruption before it becomes a claim, and protect both insureds and carriers by creating clear, defensible signals of cyber maturity.
Chart a clear path from path from compliance to real-world readiness with fundamentals covered in this episode.

Read More »