A recent study reveals that just 22% of UK CEOs believe their cyber insurance policies will fully cover both the additional costs and lost revenue resulting from cyberattacks, exposing many businesses to greater financial risks than anticipated.
- Only 22% of UK CEOs expect full cyber insurance coverage for costs and lost revenue.
- One in five UK enterprises has not modeled the business impact of cyberattacks.
- Data breaches and reputational damage remain top CEO concerns amid insufficient cover.
What happened
New research conducted by Cohesity surveyed 100 CEOs from large UK enterprises to gauge their confidence in cyber insurance policies amidst escalating cyber threat incidents. The study found that only around one in five CEOs believe their insurance would cover both the additional expenses and revenue losses following a cyberattack. A further third expect coverage only for additional costs, another third for lost revenue alone, and about 10% anticipate little to no coverage for either.
The report highlights a critical gap between the expectations and the actual protection provided by cyber insurance. Many businesses overestimate their coverage and have limited insight into the financial consequences of cyber incidents, with approximately 21% of CEOs having not performed any detailed business impact modeling on cyber risk scenarios.
Why it matters
The findings underscore the financial vulnerability UK companies face if they rely solely on cyber insurance without a full understanding of policy limitations. Cyberattacks are expected to reduce company revenues by an average of 15%, but some CEOs underestimate the complexity and costs associated with recovery beyond what insurance payouts might cover.
CEOs identified data breaches, reputational damage, high remediation costs, and operational downtime as their main fears, yet many policies currently available may not comprehensively address these risks. This disconnect could leave businesses exposed to significant financial and operational disruptions that insurance alone cannot mitigate.
What to watch next
Businesses should prioritize calculating their actual financial exposure from cyber risks and gaining clarity on what their insurance policies truly cover. Developing detailed recovery plans and regularly testing system resilience will be vital to ensuring critical services can be restored after an attack, something insurance funds alone may not guarantee.
Industry experts recommend that UK companies move beyond risk transfer and focus on risk reduction strategies, including robust cyber defenses, incident response planning, and transparent communication with insurers. Future developments in cyber insurance offerings and regulatory guidance may also impact how companies approach coverage adequacy and business continuity.