ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Keeping cyber insurance premiums down

keeping cyber insurance affordable
keeping cyber insurance affordable

Five years after NotPetya, Mark Coates at Gigamon explains how zero trust and deep observability could be the keys to ensuring that cyber insurance premiums remain affordable

 

Given the current events in Ukraine, it’s fitting to acknowledge the fifth anniversary of the NotPetya ‘ransomware’. It was a landmark cyber threat for many reasons. But perhaps most importantly, it signalled the beginning of the end for affordable cyber insurance premiums.

 

Pricing in the UK rose by 102% from Q4 2021 to the first three months of 2022. But peer behind the headlines and things aren’t so black and white. Organisations with the right security posture can still reduce their premiums and increase coverage.

 

The key is to embrace a Zero Trust architecture to improve proactive protection. And prioritise “deep observability” – the addition of real-time, network-level intelligence that will amplify the power of metric, event, log and trace-based monitoring and observability tools.

 

This holistic visibility mitigates risk across the organisation by allowing rapid detection of, and response to, potential threats.  

 

A multibillion-dollar problem

NotPetya was a 2017 Russian state-sponsored campaign to destroy IT infrastructure in neighbouring Ukraine. Researchers suspect the disk-wiping malware was spread via infected SaaS accountancy software popular among public sector bodies there.

 

The bad news is that it escaped, infecting multi-nationals using the same software, and then travelling via their VPNs to other parts of the world. It cost the global economy billions, including hundreds of millions for big-name firms like Danish shipper Maersk, FedEx, global law firm DLA Piper and pharma giant Merck.

 

The repercussions of NotPetya will be felt for many more years to come. In the first instance, it led insurers to tighten scrutiny of cyber policies to broaden the definition of what kind of cyber attack constitutes an “act of war”. But the ransomware epidemic that followed in the succeeding years has had another, far more powerful and immediate impact. With insurers in the red after paying out to ransomware victims countless times on under-priced policies, things are changing.

 

Over recent months prices have soared, while coverage limits have been lowered in many of the hardest hit sectors. Some organisations in healthcare and government are struggling to find suitable coverage at all—forced to turn to multiple providers to reach the required liability limit.

 

Building better security

That’s bad news on the face of it, but not catastrophic. In fact, this period of adjustment and pain could actually be good for the industry if it forces organisations across verticals to enhance their security posture.

 

Take ransomware. Threat actors typically compromise organisations via vulnerability exploitation, phishing emails or RDP compromise. Or they’ll buy this access from specialised cyber criminals known as initial access brokers (IABs). Once inside a target network, they’ll use legitimate tools to move laterally, looking for sensitive data to steal. Finally, they’ll deploy the ransomware payload. If the bad guys have used corporate credentials to get in, and legitimate tooling to move laterally, most legacy security tools will be unable to spot them until it’s too late.

 

In this context, cyber insurance should never be seen as a “get-out-of-jail free” card to use as a substitute for effective threat prevention, detection and response. While it’s certainly a useful option to help mitigate financial risk, enterprises should be more proactive.

 

A Zero Trust architecture, for instance, that requires authentication of every user, account or device regardless of their point of access, puts security front of mind. Considering the rise in BYOD (bring your own device) policies, as well as the prominence of IABs, trust across IT infrastructure should be earned, never freely given.

 

All users should be considered threats until they can prove otherwise, and lateral movement opportunities kept to a minimum to reduce risk.

 

But organisations can and should go further still. With hundreds of ransomware affiliates operating with impunity from Russia and other hostile jurisdictions, there’s always another breach around the corner. That makes deep observability critical to reduce the impact of attacks.

 

Starting from the network

Organisations should prioritise deep observability from the network up, to help them reduce risk. Why? Because while threat actors can bypass SIEMs and endpoint detection and response (EDR) tools, they will always leave behind a behavioural trace at a network level. By analysing this metadata, intelligent algorithms can spot suspicious activity that may otherwise fly under the radar.

 

Harnessing this network visibility and control, deep observability can plug critical visibility gaps, support proactive threat hunting and enhance granular forensics work. It means security operations (SecOps) teams can cut through the noise of threat alerts and take rapid action to resolve and remediate any breach before it has turned into a serious incident.

 

Increased visibility will also be a key pillar in enabling a Zero Trust architecture and therefore a more security-focused mindset across an organisation.

 

It’s all about delivering defence in depth wherever business-critical data is stored. In this way, organisations can amplify previous investments in metric, event, log and trace-based monitoring to offer the 360-degree view of threat activity that those traditional tools alone cannot.

 

NotPetya was one of the first destructive worm events to have a global impact. Since the start of the year, we’ve seen many more similar threats used against Ukrainian targets. It wouldn’t take much for this cyber conflict to spill over again.

 

That’s why organisations need strong cyber security founded on Zero Trust, deep observability and network insight. It won’t just help to keep insurance premiums down. It could make all the difference in the broader fight to mitigate cyber risk.

 


 

Mark Coates is VP EMEA at Gigamon

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543