Cyber insurance: lack of evidence puts the policy at risk
Ticking security measures in an insurance application without reliably checking their implementation puts cyber coverage at risk when an incident occurs. The required evidence must be available at any time.
Related: NIS2 Patchwork: Four States Face EU Court · Südwestfalen IT: The Lesson of Municipal IT
What is cyber insurance?
A cyber insurance policy covers the financial consequences of cyberattacks: business interruption, data restoration, liability and crisis costs. Insurers can make access to insurance, limits and premiums conditional on demonstrated security measures. Risk assessment has previously relied mainly on annual application questions. Insurers are shifting towards ongoing, data-driven assessments of the externally visible attack surface.
Businesses renewing cyber insurance in the DACH region today need records that underwriters can understand from operational evidence without further questions.
The insurance gap grows faster than capacity
NTT DATA sees the largest uninsured gap across commercial insurance today in cyber risk. Risk is growing faster than insured capacity, widening the outstanding gap. The Insurtech Global Outlook 2026 puts uninsured cyber losses in 2023 at an equivalent of around 153 billion euros. For 2030, NTT DATA expects an equivalent of more than 620 billion euros.
The growing gap in cyber insurance is not just a capacity problem; above all, it is a speed problem. As long as premiums are calculated annually while threats and attack surfaces change from week to week, the gap between actual risk and available coverage will widen structurally. Businesses that continue to invest 70 percent of their IT budget in operating legacy architectures are, in effect, financing their own vulnerability. Those funds are then unavailable for reducing risks and building resilience. That is precisely why the shift from reactive assessment and pricing to continuous risk sensing is not a minor technical issue. It is a prerequisite for making cyber exposure insurable again.
Munich Re puts the global cyber premium market in 2024 at an equivalent of around 13.7 billion euros. The volume remains below one percent of global property and casualty premiums. Europe accounted for around 2.9 billion euros in 2024, representing 21 percent of the global market. The global market will double by 2030, with a compound annual growth rate of more than 10 percent. The vast majority of cyber risks remain uninsured, even though most could be insured.
In its report dated 31 August 2026, Swiss Re puts average annual growth in cyber premiums since 2022 at 5 percent. According to the report, premium rates are falling for the fourth consecutive year. The decline of around 5 percent in 2026 is smaller than the roughly 13 percent fall in 2025.
Bitkom reports total losses from data theft, espionage and sabotage of 289.2 billion euros. Cyberattacks accounted for 202.4 billion euros, or 70 percent of the recorded total. 87 percent of companies were affected, compared with 81 percent in the survey’s immediately preceding year. At the same time, 59 percent of surveyed companies feel their survival is threatened by this situation.
In its current situation report for 2025, Germany’s Federal Office for Information Security (BSI) continues to describe the situation as tense. 119 new vulnerabilities appear every day, an increase of 24 percent.
Germany’s Federal Criminal Police Office (BKA) recorded a total of 1,041 reported ransomware attacks in its own reporting data for 2025. Companies and public bodies were particularly affected, including many SMEs.
Specialist insurance broker Howden identifies cyber risk underinsurance in France, Germany, Italy and Spain. Between 2020 and 2025, 49 percent of the businesses examined there experienced at least one documented attack. The direct costs of these attacks totalled 307 billion euros across the four markets. More than 70 percent of businesses had no cyber insurance policy. According to Howden’s model calculation, wider use of security measures and cyber insurance could have reduced costs between 2020 and 2025 by 204 billion euros.
Uninsured cyber losses by 2030, according to NTT DATA
Global cyber premium market in 2024, according to Munich Re; less than 1 percent of property and casualty premiums
of German companies affected by data theft, espionage or sabotage in 2025, according to Bitkom
Why static questionnaires are no longer enough
NTT DATA calls the shift from annual pricing to continuous sensing Detect, Decide, Defend. According to the Insurtech Global Outlook 2026, 45 percent of insurers prioritise prevention-oriented operating models. The publicly available report page does not state a sample size for this figure. Up to 70 percent of IT budgets still go into legacy systems, tying up scarce funds.
As early as its September 2025 market report, Swiss Re described complex, jargon-heavy questionnaires as a brake on business with SMEs. It called for scalable, technology-driven underwriting with automation and risk scoring. Competition led to significant concessions on premiums, limits, coverage and required security controls.
Allianz Commercial and Coalition announced an expanded partnership on 6 May 2026: Allianz intends to transfer its standalone commercial cyber business worldwide to Coalition. After completion, Coalition is to take primary responsibility for pricing, product development, risk mitigation and claims handling. Allianz will continue to support large and multinational risks and provide insurance capacity. A phased rollout is planned; the agreement is subject to the necessary approvals.
Aon combines its CyQu platform with outside-in data from SecurityScorecard for a continuous underwriting view. The aim is to move from a point-in-time snapshot to an ongoing assessment of the visible attack surface.
Outside-in scores support the shift from an assessment on a fixed date to an ongoing view of controls and the attack surface. On 9 October 2025, Bitsight reported 30 percent growth in its insurance business in the first half of its financial year, from 1 February to 31 July 2025. According to Bitsight, a Gallagher Re study found that additional external scan data can improve identification of companies with elevated claims risk by up to 40 percent. A Marsh McLennan study published by Bitsight in 2022 also found statistically significant relationships between security ratings, 13 risk vectors and cyber incidents. These vendor statements do not demonstrate guaranteed prevention of losses in an individual case.
According to the German Insurance Association (GDV), insurers insist on effective security measures for new policies. Under this approach, cyber prevention can no longer remain an unsupported assertion in the insurance application. In the Forsa survey for the GDV published on 22 September 2025, more than two-thirds of surveyed companies failed to meet all the basic IT security criteria. The annual survey covers 300 decision-makers and IT managers in small and medium-sized businesses.
Annual questionnaires remain legally central to duties of disclosure, but are losing their role as the sole basis for underwriting.
Definition · Outside-in scan
An outside-in scan assesses a company’s externally visible attack surface, such as open ports, exposed services and patch levels, without access to internal systems. Insurers use these scores alongside the application to keep risk, premiums and limits up to date.
Which evidence determines coverage and premiums
Insurance broker and risk adviser Marsh increasingly treats twelve controls as a minimum in ongoing underwriting of cyber risks. According to Marsh, MFA, EDR or MDR help determine insurability. The same applies to tested backups and controlled privileged access. Organisations should assess the controls continuously, because an annual self-report is no longer enough as the sole basis for assessment. Underwriters increasingly also rely on technical evidence and continuously available risk data.
The following overview shows which evidence matters and which internal function provides it.
| Control | What counts as evidence | Who provides the evidence |
|---|---|---|
| MFA for remote access, email, cloud administration and privileged access | Export from the identity provider or Conditional Access with deployment coverage percentage and a list of exceptions | IT operations creates the export and security management assesses coverage |
| EDR, XDR or MDR | Deployment coverage report and evidence of alert response | Security management maintains the report and IT operations confirms coverage |
| Protected, encrypted and tested backups | Date of the last restore test and an offline or immutable copy | IT operations provides the test date and insurance management adds it to the file |
| Privileged access | PAM or MFA on all administrator accounts | Security management and IT operations produce the account export together |
1. Identity: MFA with evidence of deployment coverage
The underwriter checks MFA for remote access, email, cloud administration and privileged accounts. An export from the identity provider or Conditional Access with the deployment coverage percentage and a service-account list counts as evidence. A tick without evidence of deployment coverage does not provide a reliable indication that the control has been implemented. Phishing-resistant methods such as FIDO2 move up the underwriting agenda for higher limits. Marsh’s analytics show the effect particularly where MFA is fully implemented.
2. Endpoint: EDR, XDR or MDR with evidence of response
The underwriter checks the vendor, endpoint coverage and 24/7 response of the EDR or MDR platform in use. The deployment coverage report and evidence of alert response from ongoing operations must be submitted. A vendor name alone is not reliable evidence of actual endpoint coverage. Anyone claiming a 24/7 response must be able to demonstrate the process from alert to response reliably.
3. Recovery: tested backups with a restore date
Insurers require protected, encrypted and tested backups as reliable components of the recovery chain. The date of the last restore test and an offline or immutable copy provide verifiable evidence. A documented restore-test date gives considerably stronger evidence of backup effectiveness. IT operations provides the test date, and insurance management keeps it in the application file.
4. Privileges: PAM or MFA on every administrator account
Privileged Access Management, or at least MFA on every administrator account, forms this set of controls required by insurers. According to Marsh, it is among the central requirements of many insurers. Demonstrable use of PAM or MFA on every administrative account counts as evidence. A tick concerning administrator rights without an account export does not provide a reliable indication of this control in underwriting. Security management and IT operations produce the account export together and place it in the application file.
5. The four further controls
Scan reports, the legacy-system inventory and adherence to a patch SLA provide evidence of patch and vulnerability management. Incident response with a tabletop exercise requires named roles and a record of the last exercise performed. RDP hardening and logging belong in the same further set of technical evidence. Marsh sees the strongest correlation with lower incident probability in automated hardening. The remaining controls for email, web, awareness, legacy systems and the supply chain require participation rates, test data and follow-up training.
What courts examine in an application
In January 2025, the Schleswig-Holstein Higher Regional Court held a cyber insurance contract invalid after it was challenged (16 U 63/24). The policyholder had answered risk questions about malware protection and updates affirmatively without a factual basis and signed the application. The court treated these unsupported answers as fraudulent misrepresentation; the insurer was entitled to challenge the contract.
In 2023, the Tübingen Regional Court ruled in favour of the claimant policyholder in case 4 O 193/21. Gaps that the insurer could have asked about in the application did not automatically result in loss of coverage in that case.
DORA has applied since 17 January 2025; NIS2 applies on country-specific dates. Both obligations require documentation and testing, while the insurance policy remains a separate contract.
Information registers, resilience-test reports and incident reports produced under these obligations can also be partly useful for underwriting. Some of these records can support both the insurance application and regulatory documentation.
In Germany, the NIS2 Implementation Act has been in force since 6 December 2025. Austria has its own legal framework under NISG 2026; the law enters into force on 1 October 2026. Switzerland falls outside NIS2 and DORA and has its own reporting obligation for cyberattacks on critical infrastructure.
What ongoing evidence gives security management
Evidence of core controls helps determine access to insurance, pricing and the continuation of the policy. Missing evidence affects access, limits and pricing even before a loss occurs. The visible maturity of controls and outside-in data on the external attack surface can also play a role.
Security management maintains the evidence, with shared responsibility among IT operations, security and insurance management. The annual questionnaire and a certificate provide evidence at a particular point in time, while ongoing evidence is now visibly being added. Which records from IT operations, security and insurance management will be available in one file before the next renewal?
Frequently Asked Questions
Answers to the key questions about cyber insurance.
Is an ISO 27001 certificate enough for a cyber policy?
ISO 27001 is a positive signal, but it does not automatically provide coverage. The certificate does not replace evidence of MFA, EDR and backup deployment coverage.
What are the consequences of incorrect information in an insurance application?
The Schleswig-Holstein Higher Regional Court upheld the challenge to a contract because risk questions had been answered affirmatively without a factual basis; the contract was therefore invalid. Embellished claims about security measures thus jeopardise cyber coverage.
Do NIS2 and DORA replace cyber insurance?
NIS2 and DORA replace neither the policy nor the sum insured. Depending on their scope and national implementation, both regimes require documentation, tests and records suitable for reporting. The same documents accelerate the shift from questionnaires to evidence, but do not replace an insured limit.
Editor’s Picks
Editor’s PickWindows Vulnerabilities: Patch Priority for Critical AssetsEditor’s PickFortinet 2026: Time-to-Exploit Drops to 24-48 Hours – What DACH SOCs Must Operationalize NowEditor’s PickVault Showdown: Bitwarden Business vs 1Password
More from the MBF Media Network
cloudmagazinKubernetes Secrets: External or Sealed Secrets?MyBusinessFutureThe AI oversight in Germany now has an addressDigital ChiefsCyber Insurance 2026: Premiums Doubled, Coverage Halved – The Calculation No CFO Wants to See
Image source: AI-generated (August 2026)
Translated from the German original using artificial intelligence. The German version is authoritative.





