Cyber insurance is facing increasing skepticism from companies, with some, like medical technology firm Stryker and Jaguar Land Rover, opting not to purchase standalone coverage and bearing the full cost of cyberattacks. This trend occurred despite rising ransomware attacks and government endorsements, leading to a decline in U.S. cyber insurance coverage in 2024 according to the National Association of Insurance Commissioners (NAIC).

While cyber insurance premiums were predicted to reach $15.6 billion last year, and prices have dropped, claims can be challenging. An NAIC report revealed that three out of four cyber insurance claims in the U.S. were closed without payment. However, the growing use of AI, including new tools like Anthropic’s Mythos, is empowering cybercriminals and prompting some hesitant buyers to reconsider coverage, according to the Financial Times.

Cyber insurance typically covers certain direct losses, such as lost profits from business interruption, crisis response costs (investigators, PR, ransom negotiators, if legal to pay), and legal defense bills from lawsuits due to data breaches. For example, Aon broker Kevin Kalinich states that privacy and security breaches insured before widespread generative AI deployment will still be covered. Importantly, as highlighted by Greg Sparacio of Aon, these policies are especially useful for businesses relying on third-party software, as vendor contracts often offer little protection against cyberattacks or data loss affecting those tools. Darren Teshima, a partner at Covington, an insurance recovery specialist law firm, notes that legal claims from data breaches can last for years.

However, critical limitations exist. Cyber insurance generally does not cover direct financial losses from crime or fraudulent fund transfers. For instance, if hackers steal $2 million directly from a company account, a cyber policy would typically cover event response services but not the stolen funds themselves; this would require a separate policy like crime or fraudulent funds transfer insurance. This gap in coverage remains despite AI making it easier for criminals to steal funds through methods like deepfake technology, as these losses are still classified under crime rather than cyber policies, according to the Financial Times. As AI changes the nature of risk, experts like Kalinich recommend re-evaluating new exposures.