{"id":24570,"date":"2026-10-06T18:47:30","date_gmt":"2026-10-06T18:47:30","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=24570"},"modified":"2026-10-06T21:47:01","modified_gmt":"2026-10-06T21:47:01","slug":"cyber-insurance-evidence-policy-at-risk","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/10\/06\/cyber-insurance-evidence-policy-at-risk\/","title":{"rendered":"Cyber insurance: lack of evidence puts the policy at risk"},"content":{"rendered":"<style id=\"premium3-layout\">.evm-premium-table table{width:100%;border-collapse:collapse;table-layout:fixed;}.evm-premium-table th,.evm-premium-table td{padding:16px;text-align:left;vertical-align:top;overflow-wrap:anywhere;border:1px solid #43524d;color:#e6e3da;font-size:.95em;line-height:1.6;}.evm-premium-table th{background:#003340;font-weight:700;color:#69d8ed;}.evm-premium-table td{background:#23261f;}[data-element=\"premium_reading\"] a{border:1px solid #e2dcd2!important;}@media(max-width:600px){.evm-premium-table table,.evm-premium-table tbody,.evm-premium-table tr,.evm-premium-table td{display:block;width:100%;box-sizing:border-box;}.evm-premium-table thead{display:none;}.evm-premium-table tr{margin-bottom:14px;}.evm-premium-table td::before{content:attr(data-label);display:block;color:#69d8ed;font-size:.78em;font-weight:700;text-transform:uppercase;letter-spacing:.04em;margin-bottom:6px;}[data-element=\"premium_tldr\"]{padding:24px!important;}.evm-premium-reading{gap:12px!important;}.evm-premium-reading img{width:86px!important;height:58px!important;}}<\/style>\n<p><strong>Ticking security measures in an insurance application without reliably checking their implementation puts cyber coverage at risk when an incident occurs. The required evidence must be available at any time.<\/strong><\/p>\n<aside data-element=\"premium_tldr\" style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"font-family:ui-monospace,monospace;font-size:0.76em;font-weight:700;letter-spacing:0.08em;text-transform:uppercase;margin:0 0 14px;color:#69d8ed;\">Key takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin:0 0 12px;color:#fff;\"><strong style=\"color:#69d8ed;\">The questionnaire alone is no longer enough.<\/strong> Twelve key controls have become an important benchmark in underwriting. Underwriters increasingly use outside-in scans to assess risk, premiums and limits.<\/li>\n<li style=\"margin:0 0 12px;color:#fff;\"><strong style=\"color:#69d8ed;\">Security measures need reliable evidence.<\/strong> Deployment coverage reports, restore-test data and account exports make implementation verifiable. NIS2 and DORA produce useful records. Some of these documents can support underwriting; they do not replace an insurance policy.<\/li>\n<li style=\"margin:0;color:#fff;\"><strong style=\"color:#69d8ed;\">Incorrect information can jeopardise coverage.<\/strong> In January 2025, the Schleswig-Holstein Higher Regional Court held a cyber insurance contract invalid after it was challenged because risk questions had been answered affirmatively without a factual basis.<\/li>\n<\/ul>\n<\/aside>\n<p style=\"border-top: 1px solid rgba(230,227,218,0.14); border-bottom: 1px solid rgba(230,227,218,0.14); padding: 14px 0; margin: 28px 0; font-size: 0.92em; color: #b8c5ce;\"><strong style=\"color: #69d8ed;\">Related:<\/strong> <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/17\/nis2-patchwork-four-states-face-eu-court\/\">NIS2 Patchwork: Four States Face EU Court<\/a>  \u00b7  <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/05\/south-westphalia-it-the-lesson-of-municipal-it\/\">S\u00fcdwestfalen IT: The Lesson of Municipal IT<\/a><\/p>\n<h2 style=\"margin-top: 48px; margin-bottom: 18px;\">What is cyber insurance?<\/h2>\n<p>A cyber insurance policy covers the financial consequences of cyberattacks: business interruption, data restoration, liability and crisis costs. Insurers can make access to insurance, limits and premiums conditional on demonstrated security measures. Risk assessment has previously relied mainly on annual application questions. Insurers are shifting towards ongoing, data-driven assessments of the externally visible attack surface.<\/p>\n<p>Businesses renewing cyber insurance in the DACH region today need records that underwriters can understand from operational evidence without further questions.<\/p>\n<h2 style=\"margin-top: 48px; margin-bottom: 18px;\">The insurance gap grows faster than capacity<\/h2>\n<p>NTT DATA sees the largest uninsured gap across commercial insurance today in cyber risk. Risk is growing faster than insured capacity, widening the outstanding gap. The Insurtech Global Outlook 2026 puts uninsured cyber losses in 2023 at an equivalent of around 153 billion euros. For 2030, NTT DATA expects an equivalent of more than 620 billion euros.<\/p>\n<figure data-element=\"pull_quote\" style=\"margin:32px 0;padding:22px 0;border-top:1px solid rgba(217,200,145,0.4);border-bottom:1px solid rgba(217,200,145,0.4);\">\n<blockquote style=\"margin:0;padding:0;border:0!important;background:transparent;font-size:1.06em;line-height:1.7;color:#e6e3da;font-style:italic;\"><p>The growing gap in cyber insurance is not just a capacity problem; above all, it is a speed problem. As long as premiums are calculated annually while threats and attack surfaces change from week to week, the gap between actual risk and available coverage will widen structurally. Businesses that continue to invest 70 percent of their IT budget in operating legacy architectures are, in effect, financing their own vulnerability. Those funds are then unavailable for reducing risks and building resilience. That is precisely why the shift from reactive assessment and pricing to continuous risk sensing is not a minor technical issue. It is a prerequisite for making cyber exposure insurable again.<\/blockquote><figcaption style=\"margin-top:14px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.74em;letter-spacing:0.08em;text-transform:uppercase;color:#69d8ed;\">Claudia Jandl, Managing Director and Head of BFSI DACH at NTT DATA<\/figcaption><\/figure>\n<p>Munich Re puts the global cyber premium market in 2024 at an equivalent of around 13.7 billion euros. The volume remains below one percent of global property and casualty premiums. Europe accounted for around 2.9 billion euros in 2024, representing 21 percent of the global market. The global market will double by 2030, with a compound annual growth rate of more than 10 percent. The vast majority of cyber risks remain uninsured, even though most could be insured.<\/p>\n<p>In its report dated 31 August 2026, Swiss Re puts average annual growth in cyber premiums since 2022 at 5 percent. According to the report, premium rates are falling for the fourth consecutive year. The decline of around 5 percent in 2026 is smaller than the roughly 13 percent fall in 2025.<\/p>\n<p>Bitkom reports total losses from data theft, espionage and sabotage of 289.2 billion euros. Cyberattacks accounted for 202.4 billion euros, or 70 percent of the recorded total. 87 percent of companies were affected, compared with 81 percent in the survey&#8217;s immediately preceding year. At the same time, 59 percent of surveyed companies feel their survival is threatened by this situation.<\/p>\n<p>In its current situation report for 2025, Germany&#8217;s Federal Office for Information Security (BSI) continues to describe the situation as tense. 119 new vulnerabilities appear every day, an increase of 24 percent.<\/p>\n<p>Germany&#8217;s Federal Criminal Police Office (BKA) recorded a total of 1,041 reported ransomware attacks in its own reporting data for 2025. Companies and public bodies were particularly affected, including many SMEs.<\/p>\n<p>Specialist insurance broker Howden identifies cyber risk underinsurance in France, Germany, Italy and Spain. Between 2020 and 2025, 49 percent of the businesses examined there experienced at least one documented attack. The direct costs of these attacks totalled 307 billion euros across the four markets. More than 70 percent of businesses had no cyber insurance policy. According to Howden&#8217;s model calculation, wider use of security measures and cyber insurance could have reduced costs between 2020 and 2025 by 204 billion euros.<\/p>\n<div data-element=\"stat_row\" style=\"display: flex; flex-wrap: wrap; gap: 16px; margin: 32px 0;\">\n<div style=\"flex: 1 1 200px; min-width: 0; background: #003340; border: 1px solid rgba(105,216,237,0.28); border-radius: 10px; padding: 22px 20px; box-sizing: border-box;\">\n<div style=\"font-size: 1.4em; font-weight: 800; color: #69d8ed; line-height: 1.1; word-break: keep-all;\">more than 620 billion euros<\/div>\n<p style=\"margin: 10px 0 0; font-size: 0.88em; color: #e6e3da; line-height: 1.5;\">Uninsured cyber losses by 2030, according to NTT DATA<\/p>\n<\/div>\n<div style=\"flex: 1 1 200px; min-width: 0; background: #003340; border: 1px solid rgba(105,216,237,0.28); border-radius: 10px; padding: 22px 20px; box-sizing: border-box;\">\n<div style=\"font-size: 1.4em; font-weight: 800; color: #69d8ed; line-height: 1.1; word-break: keep-all;\">13.7 billion euros<\/div>\n<p style=\"margin: 10px 0 0; font-size: 0.88em; color: #e6e3da; line-height: 1.5;\">Global cyber premium market in 2024, according to Munich Re; less than 1 percent of property and casualty premiums<\/p>\n<\/div>\n<div style=\"flex: 1 1 200px; min-width: 0; background: #003340; border: 1px solid rgba(105,216,237,0.28); border-radius: 10px; padding: 22px 20px; box-sizing: border-box;\">\n<div style=\"font-size: 1.4em; font-weight: 800; color: #69d8ed; line-height: 1.1; word-break: keep-all;\">87 percent<\/div>\n<p style=\"margin: 10px 0 0; font-size: 0.88em; color: #e6e3da; line-height: 1.5;\">of German companies affected by data theft, espionage or sabotage in 2025, according to Bitkom<\/p>\n<\/div>\n<\/div>\n<h2 style=\"margin-top: 48px; margin-bottom: 18px;\">Why static questionnaires are no longer enough<\/h2>\n<p>NTT DATA calls the shift from annual pricing to continuous sensing Detect, Decide, Defend. According to the Insurtech Global Outlook 2026, 45 percent of insurers prioritise prevention-oriented operating models. The publicly available report page does not state a sample size for this figure. Up to 70 percent of IT budgets still go into legacy systems, tying up scarce funds.<\/p>\n<p>As early as its September 2025 market report, Swiss Re described complex, jargon-heavy questionnaires as a brake on business with SMEs. It called for scalable, technology-driven underwriting with automation and risk scoring. Competition led to significant concessions on premiums, limits, coverage and required security controls.<\/p>\n<p>Allianz Commercial and Coalition announced an expanded partnership on 6 May 2026: Allianz intends to transfer its standalone commercial cyber business worldwide to Coalition. After completion, Coalition is to take primary responsibility for pricing, product development, risk mitigation and claims handling. Allianz will continue to support large and multinational risks and provide insurance capacity. A phased rollout is planned; the agreement is subject to the necessary approvals.<\/p>\n<p>Aon combines its CyQu platform with outside-in data from SecurityScorecard for a continuous underwriting view. The aim is to move from a point-in-time snapshot to an ongoing assessment of the visible attack surface.<\/p>\n<p>Outside-in scores support the shift from an assessment on a fixed date to an ongoing view of controls and the attack surface. On 9 October 2025, Bitsight reported 30 percent growth in its insurance business in the first half of its financial year, from 1 February to 31 July 2025. According to Bitsight, a Gallagher Re study found that additional external scan data can improve identification of companies with elevated claims risk by up to 40 percent. A Marsh McLennan study published by Bitsight in 2022 also found statistically significant relationships between security ratings, 13 risk vectors and cyber incidents. These vendor statements do not demonstrate guaranteed prevention of losses in an individual case.<\/p>\n<p>According to the German Insurance Association (GDV), insurers insist on effective security measures for new policies. Under this approach, cyber prevention can no longer remain an unsupported assertion in the insurance application. In the Forsa survey for the GDV published on 22 September 2025, more than two-thirds of surveyed companies failed to meet all the basic IT security criteria. The annual survey covers 300 decision-makers and IT managers in small and medium-sized businesses.<\/p>\n<p>Annual questionnaires remain legally central to duties of disclosure, but are losing their role as the sole basis for underwriting.<\/p>\n<div data-element=\"definition_box\" style=\"background: #23261f; border: 1px solid rgba(105,216,237,0.22); border-radius: 10px; padding: 20px 24px; margin: 32px 0; box-shadow: inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin: 0 0 8px; font-family: 'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace; font-size: 0.72em; letter-spacing: 0.12em; text-transform: uppercase; color: #69d8ed;\">Definition \u00b7 Outside-in scan<\/p>\n<p style=\"margin: 0; color: #e6e3da; line-height: 1.6;\">An outside-in scan assesses a company&#8217;s externally visible attack surface, such as open ports, exposed services and patch levels, without access to internal systems. Insurers use these scores alongside the application to keep risk, premiums and limits up to date.<\/p>\n<\/div>\n<h2 style=\"margin-top: 48px; margin-bottom: 18px;\">Which evidence determines coverage and premiums<\/h2>\n<p>Insurance broker and risk adviser Marsh increasingly treats twelve controls as a minimum in ongoing underwriting of cyber risks. According to Marsh, MFA, EDR or MDR help determine insurability. The same applies to tested backups and controlled privileged access. Organisations should assess the controls continuously, because an annual self-report is no longer enough as the sole basis for assessment. Underwriters increasingly also rely on technical evidence and continuously available risk data.<\/p>\n<p>The following overview shows which evidence matters and which internal function provides it.<\/p>\n<div class=\"evm-premium-table\" style=\"margin:28px 0;overflow-x:auto;\">\n<table>\n<thead>\n<tr>\n<th>Control<\/th>\n<th>What counts as evidence<\/th>\n<th>Who provides the evidence<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td data-label=\"Control\">MFA for remote access, email, cloud administration and privileged access<\/td>\n<td data-label=\"What counts as evidence\">Export from the identity provider or Conditional Access with deployment coverage percentage and a list of exceptions<\/td>\n<td data-label=\"Who provides the evidence\">IT operations creates the export and security management assesses coverage<\/td>\n<\/tr>\n<tr>\n<td data-label=\"Control\">EDR, XDR or MDR<\/td>\n<td data-label=\"What counts as evidence\">Deployment coverage report and evidence of alert response<\/td>\n<td data-label=\"Who provides the evidence\">Security management maintains the report and IT operations confirms coverage<\/td>\n<\/tr>\n<tr>\n<td data-label=\"Control\">Protected, encrypted and tested backups<\/td>\n<td data-label=\"What counts as evidence\">Date of the last restore test and an offline or immutable copy<\/td>\n<td data-label=\"Who provides the evidence\">IT operations provides the test date and insurance management adds it to the file<\/td>\n<\/tr>\n<tr>\n<td data-label=\"Control\">Privileged access<\/td>\n<td data-label=\"What counts as evidence\">PAM or MFA on all administrator accounts<\/td>\n<td data-label=\"Who provides the evidence\">Security management and IT operations produce the account export together<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h3>1. Identity: MFA with evidence of deployment coverage<\/h3>\n<p>The underwriter checks MFA for remote access, email, cloud administration and privileged accounts. An export from the identity provider or Conditional Access with the deployment coverage percentage and a service-account list counts as evidence. A tick without evidence of deployment coverage does not provide a reliable indication that the control has been implemented. Phishing-resistant methods such as FIDO2 move up the underwriting agenda for higher limits. Marsh&#8217;s analytics show the effect particularly where MFA is fully implemented.<\/p>\n<h3>2. Endpoint: EDR, XDR or MDR with evidence of response<\/h3>\n<p>The underwriter checks the vendor, endpoint coverage and 24\/7 response of the EDR or MDR platform in use. The deployment coverage report and evidence of alert response from ongoing operations must be submitted. A vendor name alone is not reliable evidence of actual endpoint coverage. Anyone claiming a 24\/7 response must be able to demonstrate the process from alert to response reliably.<\/p>\n<h3>3. Recovery: tested backups with a restore date<\/h3>\n<p>Insurers require protected, encrypted and tested backups as reliable components of the recovery chain. The date of the last restore test and an offline or immutable copy provide verifiable evidence. A documented restore-test date gives considerably stronger evidence of backup effectiveness. IT operations provides the test date, and insurance management keeps it in the application file.<\/p>\n<h3>4. Privileges: PAM or MFA on every administrator account<\/h3>\n<p>Privileged Access Management, or at least MFA on every administrator account, forms this set of controls required by insurers. According to Marsh, it is among the central requirements of many insurers. Demonstrable use of PAM or MFA on every administrative account counts as evidence. A tick concerning administrator rights without an account export does not provide a reliable indication of this control in underwriting. Security management and IT operations produce the account export together and place it in the application file.<\/p>\n<h3>5. The four further controls<\/h3>\n<p>Scan reports, the legacy-system inventory and adherence to a patch SLA provide evidence of patch and vulnerability management. Incident response with a tabletop exercise requires named roles and a record of the last exercise performed. RDP hardening and logging belong in the same further set of technical evidence. Marsh sees the strongest correlation with lower incident probability in automated hardening. The remaining controls for email, web, awareness, legacy systems and the supply chain require participation rates, test data and follow-up training.<\/p>\n<h2 style=\"margin-top: 48px; margin-bottom: 18px;\">What courts examine in an application<\/h2>\n<p>In January 2025, the Schleswig-Holstein Higher Regional Court held a cyber insurance contract invalid after it was challenged (<a href=\"https:\/\/www.heuking.de\/de\/news-events\/newsletter-fachbeitraege\/artikel\/cyberversicherung-olg-urteil-zur-arglistanfechtung.html\" style=\"color: #69d8ed;\">16 U 63\/24<\/a>). The policyholder had answered risk questions about malware protection and updates affirmatively without a factual basis and signed the application. The court treated these unsupported answers as fraudulent misrepresentation; the insurer was entitled to challenge the contract.<\/p>\n<p>In 2023, the T\u00fcbingen Regional Court ruled in favour of the claimant policyholder in case 4 O 193\/21. Gaps that the insurer could have asked about in the application did not automatically result in loss of coverage in that case.<\/p>\n<p>DORA has applied since 17 January 2025; NIS2 applies on country-specific dates. Both obligations require documentation and testing, while the insurance policy remains a separate contract.<\/p>\n<p>Information registers, resilience-test reports and incident reports produced under these obligations can also be partly useful for underwriting. Some of these records can support both the insurance application and regulatory documentation.<\/p>\n<p>In Germany, the <a href=\"https:\/\/www.recht.bund.de\/bgbl\/1\/2025\/301\/VO.html\" style=\"color: #69d8ed;\">NIS2 Implementation Act<\/a> has been in force since 6 December 2025. Austria has its own legal framework under <a href=\"https:\/\/www.ris.bka.gv.at\/eli\/bgbl\/i\/2025\/94\" style=\"color: #69d8ed;\">NISG 2026<\/a>; the law enters into force on 1 October 2026. Switzerland falls outside NIS2 and DORA and has its <a href=\"https:\/\/www.bacs.admin.ch\/de\/informationen-zur-meldepflicht\" style=\"color: #69d8ed;\">own reporting obligation for cyberattacks on critical infrastructure<\/a>.<\/p>\n<h2 style=\"margin-top: 48px; margin-bottom: 18px;\">What ongoing evidence gives security management<\/h2>\n<p>Evidence of core controls helps determine access to insurance, pricing and the continuation of the policy. Missing evidence affects access, limits and pricing even before a loss occurs. The visible maturity of controls and outside-in data on the external attack surface can also play a role.<\/p>\n<p>Security management maintains the evidence, with shared responsibility among IT operations, security and insurance management. The annual questionnaire and a certificate provide evidence at a particular point in time, while ongoing evidence is now visibly being added. Which records from IT operations, security and insurance management will be available in one file before the next renewal?<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Answers to the key questions about cyber insurance.<\/p>\n<details style=\"background:#003340;color:#e6e3da;padding:18px 22px;margin:12px 0;border:1px solid rgba(105,216,237,.25);border-radius:8px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#69d8ed;line-height:1.5;\"><strong>Is an ISO 27001 certificate enough for a cyber policy?<\/strong><\/summary>\n<p style=\"margin:14px 0 0;color:#e6e3da;line-height:1.7;\">ISO 27001 is a positive signal, but it does not automatically provide coverage. The certificate does not replace evidence of MFA, EDR and backup deployment coverage.<\/p>\n<\/details>\n<details style=\"background:#003340;color:#e6e3da;padding:18px 22px;margin:12px 0;border:1px solid rgba(105,216,237,.25);border-radius:8px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#69d8ed;line-height:1.5;\"><strong>What are the consequences of incorrect information in an insurance application?<\/strong><\/summary>\n<p style=\"margin:14px 0 0;color:#e6e3da;line-height:1.7;\">The Schleswig-Holstein Higher Regional Court upheld the challenge to a contract because risk questions had been answered affirmatively without a factual basis; the contract was therefore invalid. Embellished claims about security measures thus jeopardise cyber coverage.<\/p>\n<\/details>\n<details style=\"background:#003340;color:#e6e3da;padding:18px 22px;margin:12px 0;border:1px solid rgba(105,216,237,.25);border-radius:8px;\">\n<summary style=\"font-weight:700;cursor:pointer;color:#69d8ed;line-height:1.5;\"><strong>Do NIS2 and DORA replace cyber insurance?<\/strong><\/summary>\n<p style=\"margin:14px 0 0;color:#e6e3da;line-height:1.7;\">NIS2 and DORA replace neither the policy nor the sum insured. Depending on their scope and national implementation, both regimes require documentation, tests and records suitable for reporting. The same documents accelerate the shift from questionnaires to evidence, but do not replace an insured limit.<\/p>\n<\/details>\n<aside data-element=\"sources\" style=\"margin:32px 0;padding:22px 24px;border:1px solid rgba(105,216,237,.3);border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;font-weight:700;font-size:.76em;letter-spacing:.08em;margin:0 0 14px;\">Sources and reporting dates<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;display:grid;grid-template-columns:repeat(auto-fit,minmax(min(100%,260px),1fr));gap:8px 24px;\">\n<li style=\"margin:0 0 8px;\"><a href=\"https:\/\/uk.nttdata.com\/news\/2026\/insurtech-global-outlook-2026\" style=\"color:#69d8ed;text-decoration:underline;\">NTT DATA: Insurtech Global Outlook 2026<\/a><\/li>\n<li style=\"margin:0 0 8px;\"><a href=\"https:\/\/www.munichre.com\/us-non-life\/en\/insights\/cyber\/cyber-insurance-risks-and-trends-2025.html\" style=\"color:#69d8ed;text-decoration:underline;\">Munich Re: Cyber Insurance Risks and Trends 2025<\/a><\/li>\n<li style=\"margin:0 0 8px;\"><a href=\"https:\/\/bitkom-research.de\/studien\/wirtschaftsschutz-2025\" style=\"color:#69d8ed;text-decoration:underline;\">Bitkom Research: Business Protection 2025<\/a><\/li>\n<li style=\"margin:0 0 8px;\"><a href=\"https:\/\/medien.bsi.bund.de\/lagebericht\/de\/index.html\" style=\"color:#69d8ed;text-decoration:underline;\">BSI: Situation Report 2025<\/a><\/li>\n<li style=\"margin:0 0 8px;\"><a href=\"https:\/\/www.bka.de\/SharedDocs\/Downloads\/DE\/Publikationen\/JahresberichteUndLagebilder\/Cybercrime\/cybercrimeBundeslagebild2025.html\" style=\"color:#69d8ed;text-decoration:underline;\">BKA: Federal Cybercrime Situation Report 2025<\/a><\/li>\n<li style=\"margin:0 0 8px;\"><a href=\"https:\/\/ris.bka.gv.at\/eli\/bgbl\/i\/2025\/94\/P51\/NOR40273912\" style=\"color:#69d8ed;text-decoration:underline;\">Austria: NISG 2026 entry into force, Section 51<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/uk.nttdata.com\/insights\/reports\/insurtech-global-outlook-2026\" style=\"color:#69d8ed;text-decoration:underline;\">NTT DATA: 2026 report, prevention indicators<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.swissre.com\/risk-knowledge\/advancing-societal-benefits-digitalisation\/building-a-sustainable-cyber-market-in-the-AI-era.html\" style=\"color:#69d8ed;text-decoration:underline;\">Swiss Re: Cyber market, August 2026<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.swissre.com\/risk-knowledge\/advancing-societal-benefits-digitalisation\/cyber-insurance-growth-shift.html\" style=\"color:#69d8ed;text-decoration:underline;\">Swiss Re: SMEs and underwriting, September 2025<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.howdengroupholdings.com\/news\/cyber-attacks-cost-europes-four-largest-economies-300bn-in-the-last-five-years-according-to-howden\" style=\"color:#69d8ed;text-decoration:underline;\">Howden: Cyber costs in four EU markets, September 2025<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.coalitioninc.com\/en-ca\/announcements\/coalition-and-allianz-commercial-expand-strategic-global-cyber-insurance-partnership\" style=\"color:#69d8ed;text-decoration:underline;\">Allianz and Coalition: Partnership, May 2026<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/aon.mediaroom.com\/2026-02-04-Aon-Advances-Cyber-Risk-Capabilities-With-SecurityScorecard\" style=\"color:#69d8ed;text-decoration:underline;\">Aon: Cooperation with SecurityScorecard<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.bitsight.com\/press-releases\/bitsight-insurance-business-grows-30-h1-extending-market-leadership\" style=\"color:#69d8ed;text-decoration:underline;\">Bitsight: Insurance business, October 2025<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.bitsight.com\/press-releases\/study-finds-significant-correlation-between-bitsight-analytics-and-cybersecurity\" style=\"color:#69d8ed;text-decoration:underline;\">Bitsight: Marsh McLennan analysis, October 2022<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.gdv.de\/gdv\/medien\/medieninformationen\/forsa-umfrage-zu-cyberrisiken-it-sicherheit-vieler-deutscher-unternehmen-ist-mangelhaft-192844\" style=\"color:#69d8ed;text-decoration:underline;\">GDV and Forsa: IT security in SMEs, September 2025<\/a><\/li>\n<li style=\"margin:0;\"><a href=\"https:\/\/www.marsh.com\/ca\/services\/cyber-risk\/insights\/cyber-resilience-twelve-key-controls-to-strengthen-your-security.html\" style=\"color:#69d8ed;text-decoration:underline;\">Marsh: Twelve key security controls<\/a><\/li>\n<\/ul>\n<p style=\"margin:12px 0 0;font-size:.85em;color:#9aa5a0;\">The euro amounts have been converted from the sources&#8217; original figures using the ECB reference rate of 5 October 2026 and rounded.<\/p>\n<\/aside>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/26\/windows-vulnerabilities-patch-priority-critical-assets\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/windows-luecken-patch-reihenfolge-fuer-kritische-assets-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Windows Vulnerabilities: Patch Priority for Critical Assets<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/05\/27\/fortinet-2026-time-to-exploit-24-48-stunden-dach-soc\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/fortinet-2026-time-to-exploit-24-48-stunden-dach-soc-ransomware-389-prozent-2026-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Fortinet 2026: Time-to-Exploit Drops to 24-48 Hours \u2013 What DACH SOCs Must Operationalize Now<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/19\/vault-showdown-bitwarden-business-vs-1password\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/vault-duell-bitwarden-business-gegen-1password-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Vault Showdown: Bitwarden Business vs 1Password<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/05\/02\/kubernetes-secrets-external-or-sealed-secrets\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-kubernetes-secrets-external-secrets-seal-63683972.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Kubernetes Secrets: External or Sealed Secrets?<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/the-ai-oversight-in-germany-now-has-an-address\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-die-ki-aufsicht-in-deutschland-hat-jetzt-91048899-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">The AI oversight in Germany now has an address<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/cyber-insurance-premiums-coverage-cfo-calculation-2026\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-cyber-versicherung-praemien-deckung-cfo-58555824-250x147.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Cyber Insurance 2026: Premiums Doubled, Coverage Halved &#8211; The Calculation No CFO Wants to See<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;margin-top:8px;\">Image source: AI-generated (August 2026)<\/p>\n","protected":false},"excerpt":{"rendered":"Underwriters require reliable evidence of security controls. False statements about MFA, endpoint protection or backups can jeopardise coverage.","protected":false},"author":50,"featured_media":23296,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyber insurance evidence","_yoast_wpseo_title":"Cyber insurance: lack of evidence puts the policy at risk","_yoast_wpseo_metadesc":"Underwriters require reliable evidence of security controls. False statements about MFA, endpoint protection or backups can jeopardise coverage.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-24570","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":14,"wpml_language":"en","wpml_translation_of":23292,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=24570"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24570\/revisions"}],"predecessor-version":[{"id":24571,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24570\/revisions\/24571"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/23296"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=24570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=24570"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=24570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}