Article Read Time

Cyber insurance costs have risen over the past decade. Applications have tightened, and what insurers will pay has narrowed. As a result, the coverage an organization expects may differ from what it receives after an attack.
During a recent review of a large organization’s cyber insurance, our team found a policy that covered only the first round of cleanup after an attack, and only up to $25,000. The same policy required the organization to hire an information technology firm owned by the insurance company itself, instead of a vendor the organization already knew and trusted. For an organization of that size, $25,000 would barely cover the first few days of an investigation, let alone the cost of rebuilding systems, notifying the public, and making up for lost operations.
That policy is far from unusual. Over the past 10 years, cyber insurance has become harder to buy, more expensive to keep, and considerably harder to collect on when something goes wrong. Many leaders renew each year without reading past the declarations page, which is the summary sheet at the front of the policy, and they assume the coverage still matches what they were told when they first signed.
Cyber Insurance: a market that changed quickly
A decade ago, cyber coverage was fairly easy to buy for most organizations. Applications ran a page or two, premiums were modest, and underwriters, the people who decide whether to insure an organization and at what price, asked few hard questions about how its systems were protected. Insurers were still learning what cyber losses looked like, and they priced policies as though serious attacks on smaller organizations would stay rare.
Ransomware changed that math. As attacks that lock up an organization’s files and demand payment spread from 2019 through 2021, claims climbed faster than premiums could keep pace. Marsh, one of the world’s largest insurance brokers, reported that cyber insurance prices in the United States rose an average of 96 percent year over year in the third quarter of 2021. That was the steepest increase the firm had recorded since 2015.
Insurers responded by tightening the gate. Applications now commonly ask whether an organization uses multifactor authentication, which means a second login step beyond a password. They also ask about tested offline backups and endpoint detection and response, software that monitors each computer for signs of an intruder. Organizations that cannot show those controls often face higher deductibles, lower limits, or no offer at all.
Harder to collect
Getting a policy solves only half the problem, because the promise on paper is only as good as the claim that follows it. In 2022, Travelers asked a federal court to void International Control Services’ policy after a ransomware attack revealed the company had not used multifactor authentication as its application described. The two sides agreed in August 2022 to treat the policy as void from the day it began, which left the company without the coverage it had counted on for that attack.
Large companies have fought similar battles over exclusions, which are the events a policy lists as not covered. The drug maker Merck spent years in court after its insurers cited a war exclusion to deny claims from the 2017 NotPetya attack, which the company valued at $1.4 billion. A New Jersey appeals court sided with Merck in 2023, and the case settled in January 2024. By then, Lloyd’s of London had already required its insurers to exclude losses from major state-backed attacks on policies written or renewed after March 31, 2023.
Where the fine print hides
Most denials and disappointments come from ordinary contract language that nobody reviewed closely before signing. Common trouble spots include sublimits, which are smaller caps inside the overall limit for items such as ransomware, cleanup, or legal costs, and co-insurance clauses that make the policyholder pay a share of every dollar. Many policies also require using the insurer’s panel of approved vendors, as in the $25,000 case above, and some set strict deadlines for reporting an incident.
Another quiet risk is the gap between the application and daily practice. If an organization told its insurer that every account uses multifactor authentication and a single administrator account does not, that one answer can become the basis for a denial. Controls drift over time as staff change, and systems are replaced, so an answer that was accurate at signing may no longer be accurate at renewal.
What to do before the next Cyber Insurance renewal
A few steady habits close most of these gaps. None of them require hiring an outside firm, and most can be finished well before the next renewal meeting.
- Read the full policy, including the exclusions and every sublimit, with the person who runs your technology in the room.
- Compare each answer on your most recent application against how your systems actually work today, and correct anything that has drifted.
- Find out whether you must use the insurer’s vendors, what those vendors will cover, and whether the limits fit an organization of your size.
- Write down the reporting deadline and the claims phone number, and keep a printed copy somewhere an attack on your network cannot reach.
Commonwealth Sentinel regularly reviews cyber insurance policies for organizations across the Commonwealth to confirm that the coverage matches what leaders believe they bought, what they actually need, and what they have promised the insurer. When the policy and the network are read side by side, gaps like the $25,000 cleanup cap tend to surface in an afternoon instead of in the middle of a crisis. Organizations that want a second set of eyes on their policy can reach us at 502-234-5554 to talk. An insurance policy is a promise made in calm weather, and the time to test it is well before the storm arrives.
