A cyber policy transfers part of the financial loss to the insurer. It does not transfer responsibility for system architecture, business continuity or dependence on technology suppliers. This distinction is particularly significant right now, as insurance cover is becoming cheaper, whilst the consequences of technological failures remain one of the greatest business risks.
In the second quarter of 2026, global cyber insurance premiums fell by an average of 4 per cent. This marked the twelfth consecutive quarter of declines. Marsh points to the abundant supply of capital and competition amongst insurers, which enables companies to negotiate not only lower prices but also higher limits and broader coverage. At the same time, according to the Allianz Risk Barometer, cyber incidents remain the most significant global business risk in 2026; 42 per cent of respondents cited them as such.
The market is growing despite falling prices. Munich Re estimates the value of global cyber premiums in 2025 at nearly $15 billion and forecasts around $28 billion in 2030. The problem, therefore, is not the availability of insurance. The problem arises when a company treats an insurance policy as a substitute for control over its own technology.
The most costly incidents clearly illustrate the scale of this difference.
Following the ransomware attack on Change Healthcare in 2024, UnitedHealth Group reported $2.2 billion in direct response costs and a further $867 million in business disruption costs. The company later estimated the number of people whose data was affected by the incident at around 190 million.
The source of the problem was not some exotic attack technique. During a congressional hearing, UnitedHealth CEO Andrew Witty confirmed that one of Change Healthcare’s critical systems did not have MFA implemented. The company acquired Change Healthcare in 2022; Witty also spoke of legacy technologies that were in the process of being modernised.
This is a case of technological debt that has ceased to be merely an IT problem and has become a liability running into billions of dollars. The insurance policy may help to cover the costs of the fallout. However, it does not eliminate the consequences of incomplete post-acquisition integration, a lack of access controls or reliance on a critical system.
This is even more evident following the CrowdStrike outage in July 2024. There was no cyber-attack. A faulty software update was enough to disrupt the operations of companies around the world. Delta Air Lines estimated the direct impact on revenue at around $380 million, with additional operating costs of $170 million. Over the course of five days, the airline cancelled around 7,000 flights.
For the insurance market, CrowdStrike was particularly significant precisely because the cause was not an attack. CyberCube estimated global insured losses at between $400 million and $1.5 billion, whilst also highlighting significant policy limitations. Cover for business interruption resulting from system failure is not always standard, and where it is provided, it may have a separate limit. The typical waiting period before business interruption cover takes effect is 8–12 hours, although the range typically seen is 6–24 hours.
In practice, a difference of just a few hours in the time taken to restore systems can therefore determine not only the extent of the loss, but also what proportion of it will actually be covered by insurance.
Verizon’s data shows that the pressure is shifting from individual security measures to an organisation’s ability to manage its entire technology environment. In the DBIR 2026, exploiting vulnerabilities became the most common method of initial access to systems, accounting for 31 per cent of breaches. In 2025, organisations fully remedied only 26 per cent of critical vulnerabilities listed in CISA’s catalogue of actively exploited vulnerabilities, whilst the median time taken to fully remediate them rose to 43 days. Ransomware was present in 48 per cent of the breaches analysed.
Regulations are moving in the same direction. DORA, which comes into force in January 2025, does not reduce the financial sector’s digital resilience to simply having insurance cover. It requires ICT risk management, resilience testing, incident response and control of risks associated with external technology providers.
Technology insurance remains a financial instrument: it allows part of an unpredictable loss to be converted into the predictable cost of a premium. Operational maturity determines something else entirely — whether a failure will remain a technical incident or turn into a crisis affecting liquidity, sales and reputation. The policy only comes into effect once an incident has occurred. The quality of the architecture, backups, vulnerability management and recovery procedures determines the scale of the incident.

