Cyber insurance remains a hot news topic with digital threats increasing on a number of fronts seemingly on a weekly basis. Insurance Edge spoke to Simon Gilbert, CEO, of tech-focussed intermediary, Elmore Insurance Brokers about the issue of cyber insurance and the path he thinks the market is taking. Simon Gilbert is CEO of Elmore Insurance Brokers, a specialist insurance broker covering digital innovation and infrastructure, cyber resilience and crime, liability and dispute risks.

Cyber insurance is connected to operational resilience. The conversation is moving on from simply whether a business can obtain cover and at what price to the need to demonstrate a wider awareness and preparedness.
“The strongest cyber insurance programmes start with how prepared business is,” said Simon Gilbert. “Insurers want evidence that businesses understand their critical systems, know where their dependencies sit and have tested how they would respond to a serious incident.”
The impact, however, differs considerably across the market.
Different businesses, different pressures
For SMEs, simplicity remains critical. Smaller businesses can depend heavily on technology and data while having limited internal cyber security resources. They need straightforward applications, rapid decisions, clear pricing and practical cyber services.
Underwriting for this segment is becoming automated. External scanning, standardised control requirements and other risk signals can quickly determine whether a business falls within an insurer’s appetite.
This makes getting the fundamentals right essential. It also reinforces the broker’s role in helping businesses understand insurer requirements and present their risk effectively.
“Automation can make cyber insurance more accessible, but it can also create harder boundaries,” continued Gilbert. “Businesses without fundamental controls may find their options restricted very quickly.”
The more complex mid market presents a different challenge. These organisations can have substantial technology estates, valuable data and significant third-party dependencies without always having the resources of a major enterprise.
And in these circumstances, underwriting discipline becomes more stringent.
“Insurers want evidence rather than assurances,” says Gilbert. “Which systems are genuinely critical? Where could an outage create the greatest financial damage? Which dependencies could cause disruption? Which controls have been implemented and how have they been tested? These are all questions a mid-market company must be prepared to answer.”
Simply completing a proposal form is no longer enough. The quality of risk information can influence pricing, coverage and insurer appetite.
“Underwriters need evidence that helps them understand where a material loss could actually occur,” Gilbert continued. “A good submission should explain the business behind the controls, rather than simply provide a list of them.”
Specialist brokers like Elmore’s play a central part in translating complex operational and regulatory risks into submissions that insurers can assess with confidence, and that work often makes the difference in securing cover on favourable terms.

From annual renewal to continuous engagement
Large corporate accounts face another set of pressures.
Complex supply chains, international operations, cloud infrastructure and reliance on critical technology providers mean cyber exposure can change considerably during a twelve-month policy period.
That means an annual underwriting snapshot is becoming less relevant. Insurers want confidence that governance and control effectiveness hold up throughout the year, not just at renewal.
Artificial intelligence, technology concentration, geopolitical instability and major service provider failures are also changing the potential scale and nature of losses.
For larger insureds, the relationship between business, broker and insurer needs to be continuous.
Preparedness is part of the proposition
One of the clearest examples of this change is the growing importance of tabletop exercises.
A well-designed exercise can reveal weaknesses that a questionnaire will miss. It can test who makes decisions, how quickly an incident is escalated, whether insurance notification requirements are understood and how technical, legal, regulatory and communications teams will work together.
“Businesses should understand how their insurance will respond before they need to use it,” says Gilbert. “An incident is the wrong time to discover uncertainty around notification, decision making or access to specialist support.”
This points to a wider change in how cyber insurance should be viewed.
Cyber cover remains an important mechanism for transferring financial risk, but its value extends into preparedness. The underwriting process can identify weaknesses and encourage stronger controls, opening up better dialogue between businesses and insurers.
Cyber exposure also rarely fits neatly within one policy. A single incident can create issues involving cyber, crime, professional indemnity and management liability. Looking at these exposures together can provide a clearer picture of how a business is protected.
The next phase will be defined by proof
Pricing and capacity will continue to change, but the more important shift is towards evidence. Businesses that can explain their exposure and demonstrate that their controls have actually been tested will be better positioned to secure effective insurance programmes.
That raises expectations for brokers too. Clients need advisers who understand technology, regulation and insurance, and who can translate complex operational risk into information insurers can use with confidence. This fits Elmore’s approach as a specialist risk partner working across complex digital and financial risks.
“Cyber insurance is becoming a resilience tool,” Gilbert says. “The policy remains essential, but preparedness, evidence and ongoing engagement are becoming just as important to achieving the right insurance outcome.”
The next phase of cyber insurance will be defined by proof of controls, preparedness and of an organisation’s ability to respond when the pressure is real.

Be the first to comment