Skip to main content

Why cyber must move from policy purchase to proof of resilience

Glyn Thomas

View from the top: Glyn Thoms, global FINEX cyber strategy leader at Willis, argues that cyber insurance must be treated as a core part of organisational resilience rather than be bolted on after the fact.

“If we are already investing heavily in cyber controls, do we really need cyber insurance as well?”

It’s a question I was asked recently, and I suspect it’s one that many cyber insurance professionals hear more often than they would like.

It is a fair challenge, but it reveals a central issue facing our industry. Too often, cyber insurance is treated as separate from resilience: a purchase made after technology decisions are taken, response plans are written and the board has been reassured that the organisation is “prepared”. 

Cyber insurance should be one of the clearest proof points of resilience, not a document that sits apart from it. Used well, underwriting imposes discipline. It forces organisations to evidence controls, test assumptions and bring together risk, finance, legal, technology, communications and the board.
Glyn Thomas, Willis

In my view, that separation is no longer sustainable.

The insurance industry has spent years proving that cyber insurance is not an alternative to controls. Firewalls, endpoint detection, multi-factor authentication and employee training reduce the likelihood of an incident. 

But controls do not eliminate impact. Increasingly, the question is not whether an organisation has invested in security, but whether it can respond, recover and absorb the financial consequences when security is tested.

Transactional

That is where the insurance industry has both a challenge and an opportunity. Many organisations still see insurance through a transactional lens. They ask about limits, premiums and exclusions, but not always whether the policy is embedded in their incident response plan, if vendors are ready to act, or business interruption assumptions and third-party dependencies are understood.

Cyber insurance should be one of the clearest proof points of resilience, not a document that sits apart from it. Used well, underwriting imposes discipline. It forces organisations to evidence controls, test assumptions and bring together risk, finance, legal, technology, communications and the board. 

In many organisations, renewal may be one of the few moments when cyber risk is assessed across operational, financial and governance dimensions all at once.

Before the claim

But if we want organisations to treat cyber insurance as strategic, we need to make its value clearer before a claim happens. The strongest policies do more than reimburse loss. 

They provide access to incident response specialists, forensic experts, legal advisers and crisis communications support that can materially affect recovery. Yet those benefits are often underused because they are poorly understood, introduced too late or not built into response planning.

For me, the most important shift is moving from assumption to evidence. Boards may feel confident when they see cyber security investment, but confidence is not preparedness. The real test is whether plans have been rehearsed, decision rights are clear, suppliers can support recovery and the insurance programme responds as expected under pressure.

This matters because cyber risk is now a boardroom issue as much as a technology issue. It can affect revenue, reputation, regulation and directors’ accountability. It also moves across insurance lines. A cyber incident may trigger cyber cover, but it can also raise questions for directors’ and officers’ liability, crime, professional indemnity and business interruption. 

As artificial intelligence, deepfakes and vendor concentration grow, the industry must think more holistically about how losses emerge and where gaps may sit.

Beyond price

The future of cyber insurance won’t be defined only by capacity, wording innovation or price. Those will remain important, but they are not enough. The market must also connect insurance decisions to operational reality.

 Which systems would cause the most financial damage if they failed? Which vendors could create the longest disruption? Does the policy limit reflect those exposures? These are the strategic questions for leadership.

This is a key issue facing the insurance industry now: not whether cyber insurance has a role, but whether we can help organisations use it properly. The answer should not be a sales message that organisations

need more cover. It should be a more demanding conversation about alignment between risk, controls, response planning, governance and risk transfer.

When a CFO asks me whether they need both controls and insurance, my answer is yes – but not because insurance compensates for weak security. They need both because prevention and recovery are different disciplines. Controls reduce the chance of disruption. Insurance helps determine whether disruption becomes manageable or financially damaging.

For the insurance industry, the task is to make that distinction clearer, more practical and measurable. If we can do that, cyber insurance will no longer be seen as an afterthought or a reluctant cost. 

It will be recognised as a strategic lever for resilience, a driver of better governance and a critical part of preparing for incidents that cannot be fully prevented.

Only users who have a paid subscription or are part of a corporate subscription are able to print or copy content.

To access these options, along with all other subscription benefits, please contact info@postonline.co.uk or view our subscription options here: https://subscriptions.postonline.co.uk/subscribe

You are currently unable to copy this content. Please contact info@postonline.co.uk to find out more.

Most read articles loading...

You need to sign in to use this feature. If you don’t have an Insurance Post account, please register for a trial.

Sign in
You are currently on corporate access.

To use this feature you will need an individual account. If you have one already please sign in.

Sign in.

Alternatively you can request an individual account here