It’s Official: Cyber Insurance is No Longer Seen as a 'Safety Net'

Stu Sjouwerman | Mar 26, 2024

Cyber Insurance No Longer Safety NetA new report on the state of email security sheds some light on how organizations are viewing and approaching cyber insurance as they shift strategy toward being cyber resilient.

The topic of cyber insurance has been covered quite a bit here on this blog. From when cyber insurance first began as a concept, to the challenges it poses for organizations looking as their last resort after an attack, to changes in insurance policy and law.

Now it seems organizations are largely realizing what cyber insurance can and can’t do for them.

According to new data in Mimecast’s State of Email and Collaboration Security 2024 report:

  • 65% of organizations no longer see “cyber insurance as a comprehensive safety net for coping with cyber threats” — this is up from 50% last year
  • 66% are less likely to rely on cyber insurance “due to the restrictions insurers are placing on these policies” — up from 52% last year

However, this doesn't mean everyone is running away from cyber insurance. According to the report, 99% still have a policy and 45% have two or more. Cyber insurance still has a meaningful place for organizations, but for very specific coverages of very specific attack events.

In other words, its intended use is heading toward coverage of catastrophic cyber events.

This means that organizations are compensating with stronger security controls that align with attacks that include protecting email, protection from AI-based attacks, and security awareness training to get the user to play a role in protecting the organization.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.