Cyber Insurance Risks Are Moving Too Fast For Underwriters

Today with the growing number of inter-connected systems, devices and machines there is no business without Cyber risk and these emerging perils can provide exciting opportunities for insurance firms to pursue organic growth but they also require a continual and growing understanding of the changing market and some underwriters are falling behind.

The prospect of deploying capital into a new product like cyber insurance, and potentially becoming a market leader in that space, is something nearly all insurers strive towards. However, the speed of change is making it difficult for underwriters to stay ahead of the game.

Cyber is by far one of the hottest new perils to grasp the attention of insurance markets worldwide. Market capacity has grown considerably in the past decade, spurred on by developing social and regulatory frameworks around privacy and personal data protection, as well as a sharp uptick in malicious cyberattacks.

Cyber insurance was born as a business interruption coverage for non-malicious cyber-triggered loss events. Since then, the product has evolved to protect firms against privacy breaches, malicious cyberattacks, systems failure coverage, contingent business interruption and contingent business failure.

As a net new peril, some of those coverage aspects are still very difficult to underwrite, particularly when assessing contingent risks, according to Josh Ladeau, global head of tech E&O and cyber at Aspen Insurance.

“We’ve reached a situation where the cyber insurance market has so much capacity and there’s so much focus on cyber as an area for growth in insurance, that the market’s almost moving a bit faster than we can genuinely underwrite to,” Ladeau told Insurance Business.

“If we look at contingent business interruption risk, for example, the quality of a given risk is reflective of its scrutiny of the third-parties it does business with.

“Typically, a cybersecurity-driven organisation will tend to choose third-party vendors that also demonstrate good levels of cybersecurity and resilience. Underwriters have some capability to write around that, but contingent risk remains an exponential threat which is difficult for underwriters to wrap their arms around.

“Furthermore, the limits and the nature of that contingent coverage has changed in the past year. Whereas a year ago, underwriters could get away with naming vendors they would consider for third-party business interruption risk, now they’re under pressure to offer blanket coverage at full limits for all of the vendors in a particular insured’s third-party relationship tree.”  

The ardent market enthusiasm for an emerging peril is not a new phenomenon, but if capacity grows out of control, that’s when cracks can start to appear.

Ladeau pointed out that capacity in the cyber insurance marketplace is currently outpacing appetite for the risk, a dynamic which has created a depression on pricing and rates.   

“It’s very interesting to watch what happens as losses develop in the cyber space,” Ladeau commented. “So far, a loss for a given risk has typically only had a temporary and narrow impact on that industry class. For example, a large loss like the Marriot breach, might cause a small shift in pricing around hospitality as an industry segment, but only for a short amount of time. The industry currently has a short memory around some of these losses.

“Even massive losses, like a potential limit loss on a $350 million tower, aren’t necessarily slowing the risk selection appetite of most cyber markets. You might see a few players backing away, but there are always markets ready to take their place.”

Some of the most significant cyber losses to date occurred in 2017. The NotPetya and WannaCry attacks shook the entire world, causing large aggregated losses with wide-reaching implications.

In the same year, US credit agency Equifax suffered a data breach that affected 143 million consumers and JPMorgan suffered one of the biggest bank breaches in history.

As the industry experiences more aggregated cyberattacks, the portfolio strength of insurers will likely be tested and the pack might thin out, according to Ladeau.

“Lots of markets have entered the cyber space and are playing it in the same way they would any other professional services product. With something like lawyers’ professional liability, offering $10 million in excess of $100 million for relatively thin rate is often considered a safe way to build a portfolio.

“We’re seeing markets take similar capacity plays for cyber insurance, but in reality, the cybersecurity landscape is completely different. There’s a different trajectory for typical loss in cyber,” Ladeau commented.    

“I think that’s being learned by the market, but again, the amount of capacity available is almost overshadowing that for now. What I think you’ll see in the future is a greater frequency of these mass-level attacks, more acknowledgement of that threat by insurance companies, and greater understanding that cyber events are more often tower-implicating losses rather than small-level losses on accounts.

“That will thin out the crowd in terms of the amount of high-excess capacity players there are in the market, which I think will start to drive a change in pricing as well as hopefully some constriction around coverage grants.”   

Insurance Business

You Might Also Read:

Insurance: Common Cyber Security Myths:

« Meeting The Cyber Talent Challenge Head-On
NASA's Daily Shutdown Threat »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

CSI Consulting Services

CSI Consulting Services

Get Advice From The Experts: * Training * Penetration Testing * Data Governance * GDPR Compliance. Connecting you to the best in the business.

Infosecurity Europe, 3-5 June 2025, ExCel London

Infosecurity Europe, 3-5 June 2025, ExCel London

This year, Infosecurity Europe marks 30 years of bringing the global cybersecurity community together to further our joint mission of Building a Safer Cyber World.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

The Data Privacy Group

The Data Privacy Group

The Data Privacy Group provide expert professional services underpinned by world leading automation tools and a consulting team specialized in privacy and data protection.

Bounga Informatics

Bounga Informatics

Bounga Informatics provides Digital Forensics, E-Discovery, and Endpoint Security software, hardware, and training in Singapore and other countries in Asia Pacific.

Penacity

Penacity

Penacity, LLC provides strategic consulting technology services and Information Security Services to commercial and government organizations.

Beazley

Beazley

Beazley are a specialist insurer with three decades of experience in providing clients with the highest standards of underwriting and claims service worldwide.

Innovasec

Innovasec

Innovasec provide information security consulting and training services.

DivvyCloud

DivvyCloud

DivvyCloud protects your cloud and container environments from misconfigurations, policy violations, threats, and IAM challenges.

C2SEC

C2SEC

C2Sec provides an innovative analytics platform that assesses and quantifies cyber risks in financial terms based on combining patented big data, AI, and cybersecurity technologies.

Crypto International

Crypto International

Crypto International offers comprehensive services for the operation of our customers’ IT and communication infrastructure, with a focus on cybersecurity and encryption solutions.

e-Careers

e-Careers

e-Careers is an edtech institution that provides industry recognised courses and up-skilling solutions to individuals and organisations.

QGroup

QGroup

QGroup has been re-designing the consultancy industry since 2012. We're a rapidly expanding group of consulting companies that deliver bespoke IT services including cybersecurity.

Fifosys

Fifosys

Fifosys is a professional technology infrastructure specialist, delivering a broad portfolio of high quality technical and strategic managed services.

SandboxAQ

SandboxAQ

SandboxAQ is an enterprise SaaS company combining AI + Quantum tech to solve hard problems impacting society.

Althammer & Kill

Althammer & Kill

Althammer & Kill offers pragmatic solution concepts for data protection and digitization. We advise in the field of data protection, information security and compliance.

Atlas VPN

Atlas VPN

Atlas VPN is a highly secure freemium VPN service with a goal to make safe and open internet accessible for everyone.

Alethea

Alethea

Alethea is a technology company helping companies, nonprofits, and democracies protect themselves from harms stemming from disinformation and social media manipulation.

Permiso Security

Permiso Security

Permiso combines industry leading Identity Security Posture Management with Identity Threat Detection and Response, leaving no place to hide for identity threats lurking in your environment.