Skip to main content

Article

Why now is a good time to review your cyber cover

Despite ongoing claims activity, the cost of cyber insurance has fallen from its recent peak. Discover why now is a good time to review your cover.

Businesses can strengthen their cyber defences and still face significant financial exposure if a serious cyber event disrupts operations.

The quiet crisis in cyber insurance

Marsh’s latest report, ‘The quiet crisis in cyber insurance: Many companies carry more risk than they realise’, shows that 67% of UK clients purchase cyber limits that would be insufficient for a 1-in-100-year loss scenario. That matters because a 1-in-100 event is no longer an unrealistic scenario. Today, this scale of event is considered a realistic stress test for businesses that operate in an interconnected environment, and failure to purchase adequate protection may leave firms more exposed to catastrophic balance sheet impacts, even when their security defences appear robust.

Businesses often grapple with a choice between investing in cybersecurity or purchasing cyber insurance. Some believe that they have sufficient controls in place and therefore do not need insurance. The reality is, and as events in recent years have shown, cybersecurity and cyber insurance shouldn’t be seen as mutually exclusive - they’re complementary.

When choosing what limit to purchase, companies can leave themselves more exposed owing to default and potentially regrettable choices.

Reviewing your cyber limit

To ensure your company’s cyber limit is accurate, it is advisable to take a comprehensive view of the financial consequences of a severe cyber event. When planning with your broker, the following points may need to be reviewed:

  • Lost revenue during outage periods, modelled across multiple time horizons (hours, days, and weeks).
  • The speed and resources needed to restore core systems under operational pressure - not in theory, but in practice.
  • Contingent exposure: what happens if a key technology provider, outsourcer, or logistics partner suffers an outage first?
  • The cost to rebuild confidence, retain customers, and stabilise operations after a public incident.
  • Additional staffing and manual workarounds required to maintain critical functions.
  • Incident response and investigation costs, including forensic investigation, crisis consultants, and breach counsel.
  • System rebuild and restoration - in particular, identification of critical systems and assets and prioritisation of restoration of these.
  • The potential impact of regulatory fines and penalties or claims arising following a cyber event.
  • Contractual liabilities and the company’s position on customer compensation and goodwill gestures.
  • Reputational recovery and retention spend.

In many cases, the insured limit is exhausted long before the total economic damage is established. The insurer does not absorb that shortfall - it falls to your balance sheet. Ensure your risk transfer strategy reflects the true cost of operational disruption, not just headline breach expenses.

Market conditions remain favourable for buyers

Despite ongoing claims activity, the cost of cyber insurance has fallen materially from its recent peak. Primary cyber pricing is down approximately 42% from 2022 levels, driven by stronger insurer competition, broader capacity, and coverage for well-managed risks.

That decline creates a welcome opportunity for companies to capitalise on market dynamics. Organisations that reduced cover in the past to manage costs may now be able to secure higher limits today for a similar - or, in some cases, lower - premium than in recent renewal cycles. However, the market cycle may not stay favourable for insureds forever: as severe claims continue to develop, pricing and underwriting discipline can tighten again.

Expert cyber risk advice and insurance

Given that cyber risk is constantly evolving, many businesses are now turning to cyber insurance, which helps them recover losses and associated costs, for instance, resulting from large–scale breaches, business interruption, ransomware, and other types of cyberattack. We recommend working with your insurance broker or risk management experts to review your cyber risk preparedness, security controls, any insurance gaps, and your cyber insurability.

Related insights