Unlock the Editor’s Digest for free
Roula Khalaf, Editor of the FT, selects her favourite stories in this weekly newsletter.
Days after Stryker faced a devastating cyber attack in March, the medical technology company disclosed that it had not purchased cyber insurance.
The attack forced the company to delay scheduled surgeries and had a “big impact” on first-quarter earnings, its chief executive said on an analyst call.
But Stryker is one of a growing number of companies that are opting not to buy standalone cyber insurance coverage, even as some governments endorse the product and as businesses face a rise in ransomware attacks.
Jaguar Land Rover also declined cyber insurance coverage prior to a cyber attack last year that forced the carmaker to shut down its systems, which meant it had to bear the full cost of the incident.
Cyber insurance faces increasing scepticism from companies that doubt it will pay when they need it, or cover their biggest losses. In the US, cyber insurance coverage actually declined in 2024, the most recent year studied by the National Association of Insurance Commissioners (NAIC).
But growing use of AI, including the release of new tools such as Anthropic’s Mythos, could empower cybercriminals, fuelling a further rise in advanced hackings and cyber crime. This has prompted some potential buyers to take a second look.
Swiss Re predicted that premiums paid for cyber insurance would reach $15.6bn last year, and prices for the product have dropped in recent years.
So what does cyber insurance protect against — and does it actually pay out?
What is covered and what isn’t
Cyber insurance typically covers businesses against some direct losses from a cyber attack, such as lost profits from business interruption, as well as the cost of crisis response, which may include investigators, public relations specialists and ransom negotiators.
It can also cover businesses against lawsuits brought by customers or suppliers due to a data breach or another privacy violation — claims that can rack up big legal defence bills.
“The insurance is both for the data breach itself and the lawsuits that come up later . . . those claims can last for years,” says Darren Teshima, a partner at Covington, an insurance recovery specialist law firm.
Cyber insurance can even cover the ransom demanded by cybercriminals, if the ransom is legal to pay and is not being made to a sanctioned entity.
Coverage can be particularly useful, says Greg Sparacio, a cyber specialist at insurance broker Aon, for businesses relying on third-party software: “You may think, I’m primarily relying on these tools, I don’t need cyber insurance. But the contracts that you have in place with those software vendors don’t usually offer much protection if there is a cyber attack against them, or they lose your data.”
Crucially, however, policies generally do not cover against crime or fraudulent funds transfer — the funds actually stolen through hacking.
Say you run a small business, for example, and hackers gain access to your company’s account credentials to steal $2mn.
If you have a cyber insurance policy, you could pick up the phone and call event response services that would quickly kick into gear. Insurers emphasise that proactive security measures and rapid event response are some of the product’s benefits.
Your insurance could also cover the cost of containing the fallout — including security costs and reputation management — and could even compensate you for lost profits during the period when you are offline. It could then help you manage the costs of litigation stemming from this breach. But it will not cover the $2mn you lost. For that, you would generally need a separate policy, such as crime or fraudulent funds transfer insurance.
And when you go to make a claim for the items your policy does cover, data shows, getting a payout can be tricky. In the US, according to an NAIC report last year, three in four cyber insurance claims were closed without any payment.
How does AI change things?
In addition to ordinary cyber attacks, companies face a growing threat from AI, which can empower would-be cybercriminals to design new and more sophisticated hacking and ransomware tools.
There are also risks for companies from their internal use of AI, including the possibility that enterprise AI software hallucinates or goes rogue, potentially leading to business losses.
Cyber insurance policies will cover some but not all of these risks, brokers say.
Importantly, says Aon broker Kevin Kalinich, privacy and security breaches that were insured prior to the widescale deployment of generative AI will still be covered, even as AI potentially makes these losses bigger or more severe.
And while AI has made it easier to hack into a business and steal funds — for example, through deepfake technology that can convincingly imitate a CEO instructing an employee to transfer money — these losses would still not be covered under a cyber policy. They would require insurance against crime.
But if AI has changed the nature of the risk, Kalinich says, “you need to take a look at new exposures”.
