Two things landed on finance directors' desks over the same weekend. The first was news that a ransomware crew had used a widely deployed IT management product to encrypt hundreds of downstream businesses in a single coordinated push over a public holiday. The second, for anyone renewing cyber cover this month, was a quotation with the premium up by half or more, the limit cut, and a new schedule of ransomware sub-limits and coinsurance that was not in last year's policy. Those two facts are the same fact. Cyber insurance is repricing because the loss model it was built on no longer describes reality, and the practical consequence for buyers is that the policy has stopped being a financial product you purchase and become a control audit you pass.
What actually broke
Cyber was underwritten for years as a low-frequency, high-severity line: occasional large breaches, mostly independent of one another, spread across a diverse book. That is how fire is priced, and it works because two warehouses in different cities do not burn on the same afternoon for the same reason. Ransomware destroyed the independence assumption. A single vulnerability in a single widely used product now produces hundreds or thousands of simultaneous claims from unrelated insureds — which is precisely the correlated, aggregated loss that insurance cannot absorb. The weekend's events are a live demonstration: one management tool, one weekend, a very large number of small and mid-sized businesses, many of whom will have the same three insurers. Layered on top are rising claim severity, business interruption losses that dwarf the ransom itself, and the uncomfortable public argument that insurers reimbursing extortion payments helped fund the growth of the criminal market. A major European insurer said in May it would stop writing new policies in its home market that reimburse ransom payments — a small change in practice and a very large signal. Reinsurers have drawn their conclusions, and capacity has followed them out of the room.
Read the renewal, not the premium
The premium increase gets the attention. The wording changes matter more. Expect some or all of the following: a ransomware sub-limit well below the policy limit; coinsurance requiring you to carry a percentage of any extortion loss; longer waiting periods before business interruption cover begins; a narrower definition of contingent business interruption, which is the cover that responds when your supplier is attacked rather than you; tighter dependent system definitions; and warranties or conditions precedent requiring specified security controls to be in place and maintained. Unresolved above all of it is the war and state-actor question. The litigation arising from the 2017 destructive malware incidents, where insurers declined on the basis of hostile act exclusions, has still not produced settled law, and every large policy now contains wording that a sufficiently determined insurer could point to after a state-attributed attack. Ask your broker directly how the policy responds if an incident is publicly attributed to a government, and get the answer in writing.
The application is now the audit
The most useful document in cyber security this year is not a framework. It is the supplemental ransomware application that underwriters have standardised on, because it states plainly what the market now considers the minimum: multi-factor authentication on remote access, email and privileged accounts; endpoint detection and response deployed across the estate; backups that are offline or immutable, with tested restoration; email filtering; privileged access management; network segmentation; a patch policy with timeframes; removal of end-of-life systems; awareness training; and a tested incident response plan. That list is close to right, it is free, and it arrives with a deadline attached, which is more than most security programmes manage. It also carries a trap that very few buyers have internalised. Those answers are representations. If you certify that multi-factor authentication is enforced everywhere and the eventual intrusion arrives through the one legacy service where it was not, you have handed the insurer a coverage argument at the precise moment you need the money. The discipline is unglamorous: every answer should be verifiable by a named person, evidence should be retained with the application, and known exceptions should be disclosed explicitly rather than rounded up to a yes. A disclosed gap costs premium. An undisclosed one can cost the claim.
| Answer area | Evidence to retain | Exception to describe |
|---|---|---|
| Multi-factor authentication | Account and remote-access coverage review | Legacy services or accounts without enforcement |
| Backups | Restoration-test record and custody design | Untested systems or uncovered data |
| Endpoint controls | Deployment inventory and review owner | Unsupported or excluded devices |
| Incident response | Exercise record and contact arrangements | Unresolved actions and deployment constraints |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Decide what you are actually buying
Cyber policies bundle several distinct things: incident response and forensics, breach counsel, notification and credit monitoring, extortion cover, first-party business interruption, third-party liability, and regulatory defence costs. For large organisations, the balance-sheet protection is the point. For mid-sized ones, the most valuable component is often the panel: immediate access to a competent incident response firm and experienced breach counsel at three in the morning, at pre-negotiated rates, without a procurement process. Buyers who evaluate policies purely on limit and price routinely overlook the panel quality, which is the part they are most likely to use. Work out which losses you genuinely cannot absorb, and buy for those. A thirty-day outage and the legal aftermath is a different question from a forty-thousand-dollar extortion demand.
Practical Guidance for Insurance Readiness Review
- Start the renewal four months out, not four weeks. Obtain the questionnaire early and treat the gaps as a delivery plan.
- Verify every application answer and retain the evidence, with one accountable signatory who has actually checked rather than asked around.
- Disclose exceptions explicitly. Precision in the application is cheaper than a coverage dispute after an incident.
- Read the sub-limits, coinsurance and waiting periods first, then the premium. That is where the cover actually changed.
- Ask in writing how the policy responds to a state-attributed attack, and record the answer alongside the policy.
- Present a risk narrative, not a form — control trend data, remediation roadmap with dates, tabletop results. Underwriters price uncertainty, and evidence reduces it.
- Evaluate the incident response panel as seriously as the limit, including whether those firms can actually deploy where you operate.
- Model the declined scenario — higher retention, a group captive, or a funded self-insurance reserve — before you need it.
The Regional Angle
Three features shape how this market hardening reaches Gulf buyers. The first is that regional capacity is not regional. Cyber cover written by local insurers here is largely fronted, with the risk reinsured into London and continental European markets. When those markets contract, Gulf buyers experience the full force of a repricing driven by loss experience in North America and Europe — regardless of their own claims history, and regardless of whether the regional book has performed well. There is no local pool to retreat to. The practical implication is that negotiating leverage does not come from loyalty or from a clean record; it comes from presenting a risk that an underwriter in another hemisphere can distinguish from the average submission in front of them. The second follows from that, and it is an advantage if you use it. Underwriters have very little regional loss data, because breach disclosure has historically been limited here and much of what happens is never published. Faced with an information vacuum, underwriters default to global assumptions and conservative pricing. That means evidence has unusually high leverage in this market: a submission that includes control attestations, a dated remediation plan, results from a tabletop exercise, penetration test summaries and a clear statement of what is not yet in place will materially outperform a competitor's blank questionnaire, because it is the only signal in the file. Regional buyers consistently underinvest in the submission and then wonder why the terms look punitive. The third is structural, and it affects groups more than single entities. Insurance in this region is frequently bought entity by entity: the mainland trading company through one broker, the free zone entity through another, the Saudi subsidiary locally because it must be, each with different wordings, different limits and different renewal dates. The result is duplicated premium, inconsistent definitions, and gaps that only appear when an incident crosses entities — which it always does, because the systems are shared even when the policies are not. A group master policy with local fronting where regulation requires it is the standard fix, and the hard market is the moment to do it, because consolidating spend is one of the few genuine levers a buyer still has. For larger groups, this is also the year the captive conversation becomes serious: with capacity scarce and pricing volatile, a captive in one of the region's financial centres starts to look less like a treasury curiosity and more like the only way to retain risk deliberately rather than by accident. Groups that place cover through takaful structures for policy reasons should begin that conversation earlier still, since the panel of markets willing and able to write cyber on those terms is narrower and moves more slowly.
The objection worth taking seriously
The honest objection is that cyber insurance is becoming a poor product. You pay significantly more for a lower limit, with a sub-limit on the only peril you actually fear, a coinsurance share, a waiting period longer than most outages, a warranty that could void the cover, and an unresolved exclusion that might apply to any sophisticated attack. Add the cost of the controls underwriters now demand, and a mid-sized company can easily spend more on insurance and compliance than its realistic expected annual loss. Several thoughtful risk managers are openly arguing for self-insurance plus a control budget instead. For small organisations with modest exposure, that argument frequently wins on the numbers, and it should not be dismissed as cynicism. Two things keep it from being the general answer. First, insurance is not bought against the average year; it is bought against the year that ends the company. A firm that can absorb a forty-thousand-dollar extortion demand may not survive thirty days of interrupted operations, the legal aftermath, and the customer claims that follow, and that is the scenario the policy exists for. Second, the control demands are not really a cost of insurance. Multi-factor authentication, tested offline backups and endpoint detection are the cost of operating a business that depends on computers in 2021; the insurance market has simply put a date on work that was already overdue. What the buyer should reject is not the discipline but the passivity — accepting whatever terms arrive, without a submission that earns better ones.
Common Questions
Will insurers stop covering ransom payments altogether?
Some already have in specific markets, and political pressure is building. Assume that extortion reimbursement becomes harder, more conditional and more expensive, and plan your response capability on the basis that the payment may be yours to fund and yours to justify.
Does a certification help at renewal?
Less than evidence of specific controls. Underwriters ask about multi-factor authentication coverage, backup immutability and endpoint detection deployment because those correlate with loss. A certificate without those answers moves nothing.
What if we are declined?
Treat it as diagnostic rather than final. Most declinations trace to two or three missing controls; fix them, document the fix, and re-approach the market with a dated narrative. In the meantime, raise the retention and fund it deliberately.
What should we expect over the next twelve months?
Expect further capacity withdrawal, with ransomware coinsurance and sub-limits becoming standard rather than negotiable. Expect explicit state-backed attack exclusions to be drafted and adopted across the market within the next year or so, which will make the attribution question a commercial one rather than a legal curiosity. Expect underwriters to move from asking about controls to verifying them, using external scanning and evidence requirements at renewal. Expect regulatory and political intervention on ransom payments in more jurisdictions. And expect the weekend's mass incident to produce a correlated claims event that tests every aggregation assumption in the market — with terms at the following renewal reflecting the answer.
Insurance Readiness Review — we prepare your submission the way an underwriter reads it: verified control evidence, disclosed exceptions, a dated remediation plan, and a wording review that tells you what you are actually covered for.
