Cyber Risk · Industry Outlook
Cyber Risk Outlook: five shifts reshaping insurance decisions
AI-enabled threats, cyber fraud, supplier concentration and operational-technology exposure are changing both the frequency of attacks and the way organisations should structure resilience and risk transfer.
Signals already visible in insurance discussions
Five market shifts
AI moves from productivity risk to insurable exposure
Shadow AI, sensitive-data leakage, model access controls and AI-enabled impersonation will move into underwriting questionnaires and incident-response planning.
Insurance implication: review whether privacy, network security, media liability and social-engineering triggers respond consistently to AI-enabled events.
Supplier concentration becomes a board-level accumulation risk
One cloud, identity or software provider can connect thousands of insured organisations. Expect greater scrutiny of systemic-event definitions and dependent business-interruption sub-limits.
Cyber fraud and deepfake-enabled deception converge
Fraud will increasingly combine email compromise, voice or video impersonation and compromised supplier workflows. Traditional crime and cyber policies can respond differently to the same event.
Operational technology expands the loss perimeter
For energy, mining, manufacturing, healthcare and logistics, cyber incidents can cause physical damage, safety events and prolonged production loss—not merely data recovery costs.
Claims evidence becomes a differentiator
Organisations able to demonstrate critical-path restoration, daily loss values, vendor dependencies and approved response costs should be better positioned to negotiate programme structure and claims.
Kompetenz forecast confidence
Priorities for the next renewal
For risk and finance
- Approve a cyber risk tolerance in financial terms
- Model working-capital needs during an outage
- Test limits and retentions against scenarios
- Define the evidence needed for business interruption
For security and legal
- Control AI access and sensitive-data use
- Prioritise critical vendor assurance
- Align incident response with policy notification
- Review sanctions, privacy and extortion decision paths