
Huntsman Security warns that organisations face perfect storm of evolving cyber security and compliance regulations and increased threats across the globe
Huntsman Security has warned that the number of organisations that will be either unable to afford cyber insurance, be declined cover, or experience significant coverage limitations is set to double in 2023. Even for those insured, the perfect storm of ongoing attacks, tightening regulations and growing financial pressures is making it more likely that any attack on an organisation will leave it exposed.
“Factors like the supply chain crisis, inflation and skill shortages are all adding to the difficulty for organisations trying to execute on their cybersecurity strategy. At the same time, increases in insurance premiums, limits on coverage, increasing underwriting rigour, and capacity constraints are all limiting the accessibility of cyber insurance, for many,” commented Peter Woollacott, CEO Huntsman Security.
“Loss ratios will not improve until premium incomes better match the current level of pay-outs. With this reduced insurance access alongside increasing cyber threats and tightening regulations, many organisations are losing cyber insurance as an important risk management tool. Even those who can still get insurance are paying a prohibitively high cost,” Woollacott continued.
With a third of UK firms subject to cyber attacks at least once a week, cyber insurance as part of overall risk management is crucial. To bridge this accessibility gap insurers are seeking to improve the quality of risk information, so premiums better reflect the true cost of that risk. Unless organisations can demonstrate they have insurers’ specified controls in place to manage their security risks, insurers will continue to have difficulty quantifying that risk. It’s for these reasons that insurers have changed the basis upon which their products are offered to reflect the risk being underwritten more accurately.
In this environment, improving and demonstrating the effectiveness of security controls will now be essential: both for organisations looking to improve their cyber resilience and oversight while enhancing their eligibility for insurers, and for insurers who need to minimise their own exposure by ensuring the accuracy of their risk pricing process. These are likely to include:
Forrester Research, in their “Top Cybersecurity Threats for 2022” report, dated April 2022, predicts that, as risk information improves, it is likely that insurers will include new underwriting requirements and greater scrutiny of risk mitigation and security program maturity. As noted, this is already underway with insurers undertaking more rigorous underwriting processes. If other lines of insurance are any guide, as organisations start to improve their cyber risk management and oversight, insurers will improve their risk pricing models and reward those organisations that can evidence higher levels of security controls with more favourable insurance costs and terms.
Changing buyers’ and sellers’ need for cybersecurity will undoubtedly result in ongoing recalibration in the insurance market. Cyber risk introduced by third party suppliers is a case in point.
“Organisations must not just protect themselves but take responsibility to ensure their suppliers, partners and stakeholders are doing the same,” commented Peter Woollacott. “The best way of achieving this is to follow best risk management practice to ensure that your organisation employs effective security controls to quickly identify and manage any emerging cyber risk. This will give businesses the best chance of identifying potential cybersecurity weak spots and if the worst happens, still being able to benefit from a cost-effective cyber insurance policy that funds containment and recovery activities.”
“Right now, the cyber insurance sector is driving security controls world-wide. And even when legislators, regulators and the courts have caught up, it will still be insurers seeking to improve the quality of their risk pricing information that will set security terms. Organisations should ensure they are able to take advantage of any improvement in terms offered by enhancing their security controls and posture.”
Since 1999, Huntsman Security has been on the cutting edge of cyber security software development, serving some of the most sensitive and secure intelligence, defence and criminal justice environments in the world.
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543