Cyber Insurance Carriers Tighten Coverage Conditions Amid Rising Risks
Cyber insurers now require stronger security controls and updated AI risk policies for coverage.
Why it matters: Rising cyber risks make it crucial for legal and compliance teams to understand stricter insurance conditions to manage exposures and claims effectively.
- Insurers now demand Multi-Factor Authentication, Endpoint Detection and Response, and tested backups for coverage eligibility.
- Policies are updated with AI-specific exclusions and new language addressing deepfakes and supply chain vulnerabilities.
- BOXX Insurance added affirmative AI and deepfake coverage to address gaps in traditional policies.
- Despite premium softening, coverage gaps persist, with only 22% of UK leaders confident their insurance covers cyberattack costs.
The cyber insurance landscape is evolving as carriers respond to increasing cyber threats by tightening underwriting standards and refining policy language. Insurers now require robust security controls including Multi-Factor Authentication (MFA), Endpoint Detection and Response (EDR), and regular, tested backups as conditions for coverage, according to a client alert.
Emerging risks pertaining to artificial intelligence (AI), deepfakes, and supply chain vulnerabilities have prompted insurers to update policies with AI-specific exclusions to clarify coverage. Fenwick analysis highlights this trend toward coverage fragmentation in response to AI-related risks.
Recognizing ambiguity in existing cyber policy language on AI-driven incidents, BOXX Insurance introduced affirmative coverage for AI and deepfake-related events within its Cyberboxx Business policy, addressing a critical gap, as reported.
While the cyber insurance market has witnessed some softening in pricing with premium reductions and stable rates, substantial coverage gaps remain. According to surveys, only 22% of UK business leaders believe their cyber insurance would fully cover the costs of a cyberattack, underscoring concerns about underinsurance and complexity of cyber threats.
Experts emphasize that organizations must view insurance as part of a broader resilience strategy rather than a fail-safe. Fraser Hutchison, VP UKI at Cohesity, says, "Organizations cannot treat an insurance policy as a substitute for resilience. They need to understand exactly what their policies will and will not cover, model potential impacts of different attack scenarios, and prepare for losses beyond their policies." Joseph Cook of The Arizona Group notes the market benefits from sufficient reinsurance capacity and stable or reduced premiums but stresses it's not a license to lower security standards.
By the numbers:
- $15 billion — projected global cyber insurance premiums in 2025
- 47% — year-over-year increase in initial ransom demands in 2025
- 70% — dual-extortion attacks among all ransomware claims in 2025
- 22% — UK business leaders confident their cyber insurance adequately covers cyberattack costs
Yes, but: Despite premium reductions and growing product innovation, significant coverage gaps and exclusions, especially regarding AI risks, mean organizations must still prioritize robust cybersecurity measures.
What's next: Expect further policy refinements as insurers adapt to evolving threats, including more detailed AI risk provisions and increased scrutiny of insureds' security controls.