Security News

Cybersecurity news aggregator

INFO News Dark Reading

Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security

  • What: Cyber insurance is reshaping how organizations approach cybersecurity
  • Impact: Organizations are now required to quantify risk for insurance purposes
Read Full Article →

TechTarget and Informa Tech’s Digital Business Combine. Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBER RISK CYBERSECURITY OPERATIONS CYBERSECURITY ANALYTICS ENDPOINT SECURITY NEWS Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security In this latest installment of the Reporters' Notebook video series, we discuss how cyber insurance is forcing organizations to quantify risk, what's covered (and what's not), and why this could be the best thing to happen to cybersecurity. Fahmida Y. Rashid,Kristina Beek May 28, 2026 SOURCE: DARK READING Cyber insurance has evolved from a niche product into a critical component of enterprise risk management, fundamentally changing how organizations approach cybersecurity. Unlike traditional property insurance, cyber insurance faces adversaries whose tactics are constantly evolving. These attackers are becoming more sophisticated and have more tools at their disposal than ever before. The cyber insurance market has matured significantly over the past three decades and now encompasses coverage for breach remediation costs, regulatory penalties, business interruption losses and cyber extortion payments. But perhaps more importantly, cyber insurance is forcing a long-overdue conversation about the true cost of cyberattacks. By attaching actual numbers to previously abstracted risks, insurers are compelling organizations to move beyond vague concerns about "getting breached" to understanding specific financial impacts and operational disruptions. Related:How CISOs Should Prep for Agentic-Ready AI BOMs However, this safety net comes with an unexpected consequence: insured companies are more likely to pay ransomware demands. Threat actors take the time to identify which organizations carry cyber insurance and for how much, then calibrate their demands accordingly. When attackers know a company is insured for $10 million, they can make a compelling business case to pay the ransom to avoid $50 million in business losses. This creates a troubling dynamic in which insurance, designed to protect organizations, may actually incentivize the very attacks it's meant to mitigate. This risk quantification is reshaping the entire cybersecurity landscape in other ways as well. Insurance providers now require organizations to maintain minimum security standards—such as multi-factor authentication, proper data backups and documented incident response protocols—or risk having their claims denied. Three reporters—Dark Reading's Fahmida Y. Rashid, TechTarget SearchSecurity's Richard Livingston, and Cybersecurity Dive's David Jones — open up their notebooks to share insights on how cyber insurance is evolving, what the declining premiums really mean, and how this particular safety net is simultaneously making organizations more vulnerable to ransomware and improving their overall security posture. Learn more in the video transcript below, and check out other episodes in the Reporters' Notebook series for insights and coverage from across Informa TechTarget's three cybersecurity publications. Fahmida Y. Rashid, Richard Livingston & David Jones: Full Video Transcript This transcript has been edited for clarity and length by Informa TechTarget's internal AI assistant. For the full experience, please watch the video. Related:Checkbox Assessments Aren't Fit to Measure Risk Dark Reading's Fahmida Y. Rashid: Hi and welcome to our latest edition of Reporters' Notebook. I'm Fahmida Rashid, managing editor of technology and features at Dark Reading, and I'm joined here with my counterparts from Cybersecurity Dive and TechTarget SearchSecurity. I'll have everyone introduce themselves. So, Richard, why don't you take it away? TechTarget SearchSecurity's Richard Livingston: Hi, I'm Richard Livingston. I'm a writer and editor with TechTarget SearchSecurity. Cybersecurity Dive's David Jones: I'm David Jones. I'm a reporter with Cybersecurity Dive. DR's Fahmida Y. Rashid: And for this month's Reporters' Notebook, we are going to be digging into cyber insurance. I feel like that is a term that everyone is talking about. All three of us have written a lot about the topic, and there's just so much that doesn't quite surface in people's consciousness. Richard, let's just start right off. What is cyber insurance? What is it? What is it covering? What is it for? TTSS's Richard Livingston: Yeah, so I read a great quote the other day, and this is a unique thing, right? It's not like property insurance. I heard a great quote that said, for property insurance, fires are not trying to figure out better ways to burn you. And with cyber insurance, what we're trying to actually do is cover a risk that is trying to override your security protocols. And I think all of us know that this is getting worse, that hackers are getting more sophisticated. Related:Research Hub Bridges Cybersecurity Gap for Under-Resourced Organizations They have more tools at their disposal. Really over the last 30 years or so now, cyber insurance has matured to the point where we now have a market that for businesses that rely on data in the cloud, which is pretty much just about everybody. They are covering now remediation services, and that's the costs of responding to a breach, forensics, legal fees, PR, you name it. Information security and privacy liability, the claims and damages from a breach. Regulatory defense and penalties, all the fees and the penalties and the legal costs that can come from a regulatory action if you find a damaging breach. The business interruption, the lost revenue that you're going to see there. Media liability, this could be a reputational problem too. And then also the big one is cyber extortion. We have hackers asking for ransom and people are paying. DR's Fahmida Y. Rashid: I do want to know before we go on further, a couple years ago I was having a conversation with security expert Jeremiah Grossman and one of the things he said is the fact that we have cyber insurance is actually going to be the good thing for cybersecurity because we're finally attaching numbers, we're finally quantifying. Before it was like, we don't want to get breached, we don't know how much it costs or what the impact is. And now that the insurance companies are coming in and they're saying, no, we can't be loosey goosey here. We need to know what the impact is. We need to know what it's going to cost to get, you know, back up and running. What are your liabilities? And it's going to change how we talk about cybersecurity. Just now when you were running through all the things insurance covered, that's exactly what was reminding me that I don't think five years ago we would have even talked about liability in the context of an attack. TTSS's Richard Livingston: Yeah, well, you know — what's insurance? Basically claims and actuarial tables. And, you know, as long as there is a business model for them, they're going to keep putting out coverage there, you know, as long as they can keep getting those premiums and they're making more money than they're paying out. You know, there's your business model. DR's Fahmida Y. Rashid: I know, Dave, we were talking a little bit about what IT insurance covered. You had some really interesting insights there on what is covered or not covered and what those big questions are. CD's David Jones: Yeah, I mean, think what has evolved over the years is that companies are starting to really understand how cyber risk impacts the bottom line of their businesses, where it's not just, you know, a corporate CISO or an IT manager that is dealing with the fallout of a cyberattack or business disruption related to cyber. I think that what you're seeing now is that companies are now dealing with not just the potential loss of data, but they're dealing with the potential disruption of their business function. So essentially what you have is a company may, you know, have some kind of a breach or some type of a ransomware event or other type of disruption where they functionally cannot operate for a period of hours, days, or weeks at a time. And in certain cases, they can't operate kinetically. They have to shut down their factories or their connections where they have an IoT connection with various partner companies. They may not be able to sell their product. We ran into that with companies like JLR. There were other companies that had to deal with weeks long disruptions of their operations where they couldn't move their product. And one of things that cyber allows you to do is you can kind of price in the potential risk of what would happen if I basically could not move my product or operate my business for a series of weeks or days. And you have to be able to estimate, OK, let's say I'm out of business for a week. If you go back to like Colonial Pipeline, for example, you basically can't move your fuel for almost a week. What kind of bottom-line impact is that gonna have on my business? And how do I factor in the risk of being able to manage that? And the insurance companies at the same time, what they do is they force you to take a really hard look at how am I prepared to be resilient? What am I doing to protect our business in the event of where I can't get into my data, my employees can't get on their computers? I can't move my product to and from a warehouse. And cyber insurance will basically force you to look at how do you back up your data? How do you access your data in the event of a shutdown? What type of protocols you put in place? Multifactor, hiding assets from the Internet, using stronger passwords and they will force you to make some very tough decisions about, you know, do I have the resources set aside where I may be going back to a very low tech version of my business for a couple of we

Share this article