A CISO identifies that a critical vendor managing customer PII has no cyber insurance. Under a shared risk model, what financial control should the CISO recommend?
-
A
Terminate the vendor contract immediately
-
B
Require the vendor to obtain adequate cyber liability insurance as a contractual obligation
-
C
Purchase additional cyber insurance to cover the vendor's risk
-
D
Classify the vendor as a low-risk third party