BIP America

collapse
Home / Daily News Analysis / Reading between the lines of a cyber insurance policy

Reading between the lines of a cyber insurance policy

Jul 18, 2026  Twila Rosenbaum  8 views
Reading between the lines of a cyber insurance policy

Enterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024, signaling widespread adoption. Yet as coverage has become common, payouts have grown less predictable, leaving many organizations to discover that what they thought was covered may not be. Understanding the nuances of a cyber insurance policy is critical for any organization that relies on this risk transfer mechanism.

The gap between exposure and coverage

The Global Federation of Insurance Associations, which represents insurers accounting for close to 90 percent of premiums worldwide, quantified the cyber protection gap at about $900 billion in a 2023 report. Annual economic losses from cyber incidents exceed that figure, meaning insurance only covers a small fraction of global losses. A 2024 white paper from Marsh McLennan and Zurich Insurance Group amplified these findings and called for public-private action to close the gap. The Federation reached similar conclusions independently, confirming that insured losses remain far below total damage.

The US cyber market contracted in premium volume for the first time on record, driven by eleven consecutive quarters of rate decreases. Excess capacity has pulled prices down even as reported losses have climbed. This apparent paradox—falling premiums despite rising losses—raises questions about the sustainability of the current market and the accuracy of risk pricing. Historical data from the early 2020s shows that after a period of rapid rate increases following high-profile ransomware attacks, the market corrected as new carriers entered and competition intensified. However, the gap between total cyber losses and insured losses persists, leaving many organizations underprotected.

The underwriting bargain

Applications for cyber coverage run long. Some questionnaires now include more than fifty items covering multifactor authentication, backup practices, endpoint detection, patching cadence, and incident response testing. Answers become legal representations. A control that lapses after binding, or a partial deployment described as universal, can shift a later claim into dispute. Insurers rely on these representations to assess risk, and any inaccuracy can be grounds for denial.

“Cyber insurance has a legitimate role, but it is not a control plane, a trust model, or a resilience strategy. It is a residual-risk financing tool,” Dr. Chase Cunningham, a former NSA analyst who publishes analysis under the DrZeroTrust name, told Help Net Security. Cunningham stresses that insurance should complement security, not replace it. The application process itself can reveal weaknesses, but only if applicants take it seriously. Many companies assign the task to staff without deep technical understanding, leading to omissions or overstatements that later surface during claim adjudication.

Denials cluster around recurring themes. Independent analyses place the denial rate for cyber claims between 40 and 44 percent. Cases hinge on misrepresentation, lapses in required controls, and application answers signed off by staff without deep technical understanding of the attestations. For instance, a company that claims universal MFA but has an exception for legacy systems may find a ransomware claim denied if attackers exploited that gap. The underwriting bargain demands honesty and ongoing compliance, yet many organizations treat the application as a one-time exercise.

Exclusions carved out of catastrophe

Merck’s litigation over NotPetya damages, which the company put at roughly $1.4 billion, tested the war exclusion in “all risks” property policies and produced a New Jersey appellate ruling favoring the pharmaceutical company in May 2023. The case settled confidentially in January 2024. This landmark decision highlighted the ambiguity of exclusion clauses in the context of cyber attacks. NotPetya, attributed to Russian military actors, caused billions in damage globally, and insurers argued it was a hostile act. The court disagreed, ruling that the policy language did not clearly exclude such events.

Lloyd’s of London had already moved in the same direction, issuing a market bulletin in August 2022 that required standalone cyber policies to explicitly exclude state-backed attacks from March 31, 2023 onward, with four model clauses offering different levels of restriction. This proactive step was intended to clarify coverage and limit exposure to systemic risks from nation-state actors. However, it also means that many policies now contain broad exclusions that may catch incidents where attribution is disputed. Organizations must carefully review the specific language of their policies to understand what state-backed activities are excluded, as definitions vary.

Social engineering sits in a similar zone. Standard policies often exclude these events entirely or cap payouts at $250,000, a figure that sits well under the average loss for this attack type. Social engineering attacks, such as CEO fraud or invoice manipulation, rely on human manipulation rather than technical vulnerabilities. Despite their frequency and cost, they remain underinsured. Some carriers offer separate social engineering coverage or endorsements, but these often come with higher premiums and stricter conditions. The popularity of these attacks has grown, yet the insurance response has been conservative.

Systemic risk and public policy

Lloyd’s scenario modeling has estimated that a major attack on global financial services payment systems could cost the world economy roughly $3.5 trillion. That figure sits far above the total premiums the entire cyber insurance market collects each year. Such a scenario could bankrupt multiple carriers and destabilize the industry. The potential for cascading failures across sectors underscores the need for public-private cooperation, similar to terrorism risk pools.

Cunningham sees room for a federal cyber backstop along the lines of the Terrorism Risk Insurance Act, with conditions attached. “I think a federal cyber backstop is worth exploring for truly catastrophic systemic cyber events, but only if it is designed as a last-resort resilience mechanism, not as a subsidy for weak security,” he said. He argues that eligibility should require minimum controls tied to NIST CSF and CISA’s Cybersecurity Performance Goals, with evidence-based proof, and that both insurers and policyholders should retain meaningful exposure so taxpayers avoid underwriting preventable negligence. This approach would incentivize better security hygiene while providing a safety net for tail risks.

Discussions about a federal backstop have been ongoing since the early 2020s, but no legislation has passed. The challenge lies in defining “catastrophic” and ensuring that the backstop does not lead to moral hazard. If insurers know the government will cover extreme losses, they may relax underwriting standards. Conversely, without a backstop, the market may fail to provide coverage for systemic risks, leaving critical infrastructure unprotected. The balancing act continues.

Guidance for mid-market buyers

Mid-market companies without a dedicated CISO or in-house counsel often lean on brokers to interpret cyber risk. Cunningham recommends a wider circle. “I would tell them to build a small advisory triangle around the insurance process: a cyber-specialist broker, an independent technical advisor or fractional CISO, and outside counsel who understands cyber coverage and breach response,” he said. This ensures that application answers are technically accurate and legally sound, reducing the risk of future claims denials.

He points to CISA’s Cybersecurity Performance Goals and NIST’s small business cybersecurity materials as starting baselines. On broker credentials, he lists PLUS cyber-liability training, RPLU, CPLP, The Institutes’ Associate in Cyber Risk Management, CPCU, ARM, CRM, and CIC as useful screening signals. Claims experience matters as much as any credential. A broker who has handled only a handful of claims may lack the depth to navigate complex disputes.

One question, he says, tends to reveal the difference. “How many cyber claims have you helped manage?” A surface advisor asks about limits, revenue, and MFA. A serious advisor probes where MFA is enforced, who holds privileged access, how backups are protected, when the last restore occurred, and what sub-limits apply to social engineering and business interruption. These details matter because they directly influence coverage outcomes. For example, business interruption coverage often has waiting periods and may not cover reputational harm or regulatory fines. Understanding these nuances requires a specialist.

Coverage decisions carry legal weight the day a questionnaire is signed. Application answers become the record insurers reference when a claim arrives, and the gap between advertised limits and payable amounts often traces to sublimits, waiting periods, exclusions, and control representations written before an incident. Resilience work sits upstream of any policy. Insurance follows the security program that produced it. Organizations that invest in robust security controls, continuous monitoring, and incident response planning will not only reduce their risk but also obtain more favorable insurance terms.


Source: Help Net Security News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy