news.mlab.sh
Back to the feed
threat-intel

Cyber Insurance Rates Are Dropping, but Exclusions Widen

Medium
Summary

Cyber insurance premiums are decreasing, driven by insurers refining their risk models and offering discounts for robust security practices. However, this positive trend is counterbalanced by a significant increase in coverage exclusions, particularly concerning social engineering attacks like ClickFix, and broader risks such as acts of war and mass cyber events. This shift necessitates careful policy review and detailed discussions with insurers to avoid unexpected gaps in coverage.

The cyber insurance market is experiencing a stabilization in pricing, with insurers adjusting their models and offering discounts based on demonstrable security improvements. This positive development is largely due to insurers finally accurately assessing risk. However, a key concern is the expanding list of exclusions within cyber insurance policies. These exclusions are becoming increasingly prevalent, impacting a wider range of potential incidents. Specifically, coverage is now frequently denied for employee actions, including sophisticated social engineering attacks like ClickFix, where an attacker manipulates individuals into performing malicious actions. The rise of ClickFix-style attacks, accounting for 52% of Huntress’s 2025 cyberattacks, highlights the vulnerability of organizations to such tactics. Beyond social engineering, exclusions now encompass broader risks such as acts of war and widespread outages of major cloud providers, potentially reducing policy payouts significantly. Furthermore, subtle changes like coverage sub-limits – restricting spending on services like breach coaching or DFIR – are adding complexity to the landscape. Organizations are being urged to meticulously examine their policies and engage in direct conversations with insurers to clarify coverage terms and avoid surprises.

Read the full article at Dark Reading