Cyber’s biggest problem is the one the market still refuses to confront

Daniel Johnson, Class Underwriter, Cyber, AEGIS London

Over the last two years since AEGIS London launched its cyber offering, news headlines, panel discussions and market chatter have been dominated by the rise of artificial intelligence, growing geopolitical tensions, increasingly sophisticated cyber attacks and high-profile technology outages. Yet despite all the attention on these issues, the biggest threat facing the cyber insurance market today is the same one it has faced for a number of years – systemic risk.

History repeating itself?

The conversations around AI are likely to continue for a considerable period of time. AIwill undoubtedly shape businesses, economies and risk landscapes for years to come. However, from a cyber insurance perspective, much of the debate feels familiar. Five or six years ago, the market was having similar conversations about the Internet of Things (IoT). Today, IoT remains important, but it is no longer as much of a significant talking point, and this may come to be true of AI. It will influence cyber risk, but it is only one part of a much broader challenge.

The same can be said for cyber war and geopolitical tensions. These issues rightly attract attention, particularly against a backdrop of heightened global instability and concern about attacks on critical infrastructure. From an insurance perspective, considerable effort has gone into addressing these exposures through war exclusions and policy wordings. Whether those clauses ultimately perform as intended when tested remains to be seen, but there are mechanisms in place that help to manage the risk.

The challenge from systemic cyber risk

The challenge with systemic cyber risk is different. It is far harder to define, harder to quantify and, perhaps most importantly, harder to manage. It encompasses many of the industry’s biggest concerns. AI can contribute to systemic risk. Geopolitical events can create systemic risk. Technology supply chains represent systemic risk. The common thread is interconnectivity.

Modern businesses increasingly rely on a relatively small number of technology providers, cloud platforms and critical digital infrastructure. When one of those things fails, the consequences can spread very quickly across industries, countries and insurance portfolios. The CrowdStrike outage in 2024 showed how a single technology failure could disrupt businesses worldwide. Similar concerns have arisen following major cloud outages and cyber incidents that have affected significant numbers of organisations simultaneously, such as Canvas, the US education provider that experienced a cyber incident impacting schools and colleges across the US during final year exams. These events should be viewed as warnings.

These recent events are often shown as proof that the market is holding up well. However, this is not always the case. On several occasions, the cyber market has benefitted from specific coverage triggers, timing issues or other factors that limited insured losses. That is not the same as proving the product is robust. It may simply mean the market has not yet faced the full test.

This matters because cyber remains relatively small compared with more established insurance classes. A more severe outage, a longer disruption or a maliciously motivated event that falls more clearly within cover could produce a very different outcome. This could force a much more important discussion around whether the market can sustainably absorb the very risk it was created to insure.

Managing cyber risk in an interconnected world

What concerns me is that, despite years of discussion, insurers, regulators and governments still have no credible answer to the central question: how do we manage this risk? When it comes to war, the market has developed exclusions. When it comes to AI, insurers can choose to cover exposures, price for them or potentially exclude certain elements. Systemic cyber risk does not lend itself to such straightforward solutions.

There is no obvious mechanism that allows insurers to simply exclude the interconnected technology ecosystem upon which modern businesses depend. If they attempted to do so, they would significantly reduce the value proposition of cyber insurance itself. If broad categories of supplier-related exposure were removed from policies, many policyholders would ask what remains covered.

The market now faces a difficult balance on how to provide meaningful protection while managing the accumulation risk created by a highly interconnected digital economy. In some respects, the situation resembles accumulation risk in the property market. Insurers can assess exposure to hurricanes or floods within defined geographic areas and manage concentration accordingly, but cyber risk operates differently.

A technology failure affecting a provider headquartered in one country can create losses for organisations around the globe. A business in the US, supported by infrastructure in Europe and serving customers worldwide, can generate exposures that cross multiple jurisdictions simultaneously. Traditional approaches to risk management become much harder to apply in that environment.

Look beyond the headlines

This is why the conversation needs to move beyond the latest headlines. AI will continue to evolve, geopolitical tensions will continue to shift and new technologies will be

created. However, systemic risk remains the underlying issue that connects many of these challenges. If the market cannot develop a sustainable approach to managing large-scale, interconnected cyber events, it must ask difficult questions about the long-term resilience of the product itself.

That does not mean the outlook is pessimistic. This should be seen as an opportunity for the market to address these challenges through greater collaboration between insurers, governments, regulators and technology providers. The discussion is already happening, but not yet at the scale required. The industry needs to be willing to move beyond the easier conversations and tackle the issues for which there may not be obvious answers.

The market needs to consider that in a class where tail risk remains deeply uncertain, measured growth is not timidity, it is discipline.

Cyber remains an attractive and necessary product, but its long-term success depends on ensuring the market can withstand the shocks that inevitably lie ahead.

This article was published in Insurance Day on 04 August 2026.

 

Contact