{"id":7519,"date":"2024-08-15T10:00:00","date_gmt":"2024-08-15T10:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5068\/"},"modified":"2026-05-10T19:05:31","modified_gmt":"2026-05-10T19:05:31","slug":"why-cyber-insurance-will-become-stricter-in-2024-and-what-companies-need-to-do","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2024\/08\/15\/why-cyber-insurance-will-become-stricter-in-2024-and-what-companies-need-to-do\/","title":{"rendered":"Why Cyber Insurance Will Become Stricter in 2024  &#8211;  and What Companies Need to Do"},"content":{"rendered":"<p><strong>The market for cyber insurance has changed radically: premiums have increased, exclusion clauses have grown, and the requirements for policyholders have become stricter. Those who want an affordable policy in 2024 must prove that basic security measures are in place  &#8211;  MFA, backup, incident response. No security, no insurance coverage.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>Cyber insurance premiums 2023: +11 percent on average (Marsh)<\/li>\n<li>MFA has become a mandatory prerequisite for 95 percent of insurers<\/li>\n<li>Exclusions: State-sponsored attacks, infrastructure failures, war<\/li>\n<li>Deductibles: On average 50,000-250,000 EUR for medium-sized businesses<\/li>\n<\/ul>\n<h2>Why Insurers Are Tightening the Screws<\/h2>\n<p>The ransomware wave of 2020-2022 shook the cyber insurance market. Loss ratios exceeding 100 percent forced insurers to make adjustments: higher premiums, stricter underwriting criteria, and clearer exclusions. The market is professionalizing  &#8211;  to the advantage of well-prepared companies.<\/p>\n<p>The good news: Since 2023, premiums have stabilized. Companies with demonstrably good security hygiene receive more favorable conditions. Security investments thus have a direct, measurable ROI through reduced insurance costs.<\/p>\n<h2>The New Minimum Requirements<\/h2>\n<p>Almost every insurer now requires the following before signing a contract: MFA for all remote access and privileged accounts, regular and tested backups (ideally offline\/immutable), Endpoint Detection &#038; Response (EDR) on all endpoints, patch management with defined SLAs, and security awareness training for employees.<\/p>\n<p>Those who cannot prove these basics either do not get a policy or pay significant risk surcharges. The insurers&#8217; questionnaires have become more detailed  &#8211;  blanket assurances are no longer sufficient.<\/p>\n<h2>Exclusion Clauses: What Is Not Covered<\/h2>\n<p>The most important exclusions in 2024: State-sponsored cyberattacks (\u201cWar Exclusion\u201d), systemic events (failure of a major cloud provider), known, unpatched vulnerabilities, and intentional breaches of duty. The Lloyd\u2019s Market tightened War Exclusion clauses in 2023  &#8211;  a trend that other insurers are following.<\/p>\n<p>Particularly relevant: If a company makes false statements in the questionnaire (e.g., claims to have MFA but has not implemented it), the insurer can refuse to pay. Transparency is mandatory.<\/p>\n<h2>Cyber Insurance as a Security Catalyst<\/h2>\n<p>Paradoxically, cyber insurers are driving security maturity in the medium-sized business sector more than regulation. While NIS2 fines remain abstract, the insurance premium is a concrete, annual cost item. CISOs successfully use insurance requirements as an argument for security investments with the board of directors.<\/p>\n<p>The strategic approach: Security measures that simultaneously meet insurance requirements, support NIS2 compliance, and reduce real risk have a triple ROI. MFA, EDR, and backup are the obvious candidates.<\/p>\n<h2>Key Facts<\/h2>\n<p><strong>Premium Development:<\/strong> +11 percent in 2023, stabilization in 2024 (Marsh Global Insurance Market Index)<\/p>\n<p><strong>MFA Requirement:<\/strong> 95 percent of insurers require MFA as a prerequisite<\/p>\n<p><strong>Rejection Rate:<\/strong> 28 percent of SME applications are rejected (Coalition 2024)<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Do I need cyber insurance as an SME?<\/h3>\n<p>Recommended if your business operations depend on IT  &#8211;  which is practically always the case. The question is not whether you need it, but to what extent. At a minimum, cover business interruption, forensic costs, and notification obligations (GDPR).<\/p>\n<h3>How do I lower my premium?<\/h3>\n<p>Consistently implement MFA, deploy EDR, regularly test backups, document your incident response plan, and prove security awareness training. Each of these measures measurably reduces the premium  &#8211;  typically 10-25 percent in total.<\/p>\n<h3>Does the insurance cover GDPR fines?<\/h3>\n<p>Usually no. GDPR fines are not insurable in most jurisdictions because they are considered personal sanctions. However, the costs for notification, legal advice, and crisis communication following a data protection incident are typically covered.<\/p>\n<h2>Related Articles<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2025\/05\/15\/post_id-4958\/\">Why Your Cyber Insurance May Not Pay Out in an Emergency  &#8211;  The Toxic Exclusion Clauses of the Industry<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/06\/post_id-3837\/\">Cybersecurity Trends 2026: The 7 Developments Security Decision-Makers Need to Know<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/cybersec-europe-2026-brussels-security-conference-at-the-heart-of-eu-regulation\/\">Cybersec Europe 2026: Brussels\u2019 Security Conference at the Heart of EU Regulation<\/a><\/li>\n<\/ul>\n<h2>More from the MBF Media Network<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/03\/03\/aiops-wie-ki-den-cloud-betrieb-automatisiert-und-ausfaelle-verhindert\/\" target=\"_blank\" rel=\"noopener\">Cloud Magazin<\/a>  &#8211;  Cloud, SaaS &amp; IT-Infrastructure<\/li>\n<li><a href=\"https:\/\/mybusinessfuture.com\/ki-made-in-germany-935-startups-oekosystem\/\" target=\"_blank\" rel=\"noopener\">myBusinessFuture<\/a>  &#8211;  Digitalization, AI &amp; Business<\/li>\n<li><a href=\"https:\/\/www.digital-chiefs.de\/149-000-offene-it-stellen-wie-cios-ki-copiloten-als-fachkraeftersatz-nutzen\/\" target=\"_blank\" rel=\"noopener\">Digital Chiefs<\/a>  &#8211;  C-Level Thought Leadership<\/li>\n<\/ul>\n<p><em>Header Image Source: Pexels \/ Vlad Deep<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"The market for cyber insurance has changed radically: premiums have increased, exclusion clauses have grown, and the requirements for policyholders have become stricter. Those who want an affordable policy in 2024 must prove that basic security measures are in place &#8211; MFA, backup, incident response. No security, no insurance coverage. TL;DR Cyber insurance premiums 2023: [&hellip;]","protected":false},"author":55,"featured_media":5067,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyber insurance","_yoast_wpseo_title":"Why Cyber Insurance Will Become Stricter in 2024 - and What Companies Need to","_yoast_wpseo_metadesc":"Cyber insurance in 2024 demands stronger security\u2014reduce premiums by improving defenses now. Act before policies get stricter.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5068"],"footnotes":""},"categories":[251],"tags":[245,233],"class_list":["post-7519","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-compliance","tag-ransomware"],"evm_reading_time_minutes":4,"wpml_language":"en","wpml_translation_of":5068,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7519","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7519"}],"version-history":[{"count":5,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7519\/revisions"}],"predecessor-version":[{"id":11891,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7519\/revisions\/11891"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5067"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7519"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7519"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7519"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}