Insurers Lag in Ransomware Recovery Testing Despite Cybersecurity Investments
Event summary
- Triple-I and Fenix24 report highlights gaps in insurers' cybersecurity preparedness, particularly in ransomware recovery testing.
- Cyber insurance market grew to $15.3B in net premiums written in 2024, with ransomware accounting for only 19% of claims in 2023.
- Key vulnerabilities identified include patching cadence, authentication practices, and comprehensive recovery testing.
- Business email compromise and funds transfer fraud represented 56% of reported cyber claims in 2023.
The big picture
Insurers face a paradoxical challenge: they underwrite cyber risk for clients while struggling with their own cybersecurity gaps. The report underscores the need for systematic preparation over perfect prevention, as ransomware and business email compromise claims continue to rise. With the cyber insurance market projected to grow to $16.3B in 2025, addressing these vulnerabilities is critical for maintaining trust and operational resilience.
What we're watching
- Recovery Testing Gaps
- How insurers will address the gap between idealized recovery tests and real-world ransomware scenarios.
- Authentication Practices
- Whether insurers can eliminate less secure MFA methods like SMS and email confirmation.
- Patching Cadence
- The pace at which insurers adopt accelerated patch cycles to counter rapidly exploited vulnerabilities.
