Many cyber risk management professionals across the world utilize frameworks such as NIST, ISO, ITIL and COBIT as a basis to run their programs. Despite these being excellent frameworks to be utilized as a foundation for a GRC (governance, risk and compliance) program, there are still tricks of the trade that can only be learned by cyber defenders in the school of hard knocks. The industry vertical was the single most important factor in determining the risk of payout on a policy and it was the only factor that they had reliable actuarial data on.”]