cyber insurance · ransomware · private credit · systemic risk
Cyber Insurance at Its Limits: Who Bears the Risk Now?

When Lloyd's of London quietly updated its market bulletin on systemic cyber-event exclusions in 2023, most headlines treated it as an insurer tidying up policy language. It was considerably more than that. It was the moment the insurance market signalled it could no longer act as the silent underwriter of civilisation's digital risk. What follows from that admission touches corporate balance sheets, the private credit market, Australian government policy and the next generation of IT procurement. None of those connections made the front page.
The Exclusion Clause That Changes Everything
Lloyd's syndicates and a growing number of domestic Australian carriers have begun inserting or tightening exclusions for losses that stem from state-backed cyberattacks or events with systemic, correlated impact across many policyholders at once. The logic is straightforward. A single ransomware attack on one hospital is an insurable event. A coordinated attack that simultaneously cripples hospitals, energy grids and financial clearing systems is not, because the losses are not independent. Insurers price risk on the assumption that not everything fails at once. Cyber does not always honour that assumption.
The practical effect is that policies are narrowing precisely as the threat is widening. Premiums have risen sharply, sub-limits on ransomware payments have appeared, and the burden of proof for attribution, whether an attack is state-sponsored and therefore excluded, has become a genuinely contested legal question. Australian corporates renewing cover in 2024 and 2025 are discovering that the policy they held last year is not the policy they hold today.
The IT Procurement Cascade
Here is where the first-order consequence becomes a second-order investment signal. When insurance no longer fully backstops a risk, rational boards do one of two things. They self-insure by building larger reserves, or they reduce the underlying risk through capital expenditure. The latter is already happening. Conversations that used to end with a CFO signing a cyber policy are now continuing into the IT architecture itself.
Insurers are increasingly requiring, or offering premium discounts for, specific technical controls: multi-factor authentication across all privileged accounts, endpoint detection and response platforms, immutable offsite backups, and network segmentation that limits lateral movement. These are not soft recommendations. They are underwriting criteria. That shifts the conversation from the risk management team to the CIO and then to the vendor selection process.
The firms that supply those controls, and the managed security service providers who implement and monitor them, are seeing demand that is no longer purely driven by internal security budgets. It is being driven by insurance renewal deadlines. That is a meaningfully different, and arguably more durable, demand signal. It also concentrates purchasing power among a smaller set of vendors whose products explicitly appear on insurer-approved control frameworks.
Private Credit Finds a New Corner of the Market
Cyber incidents do not wait for a company's annual credit facility review. When a ransomware attack locks systems, the immediate need is liquidity: to pay response firms, to fund business interruption costs, to manage legal exposure and, in some cases, to negotiate with threat actors. Insurance used to be the primary funding mechanism for that response. With coverage gaps widening, something else has to fill the space.
When insurance retreats from a risk it cannot price, capital markets eventually step in. The question is always: on whose terms.
A small but growing segment of the private credit market is beginning to finance cyber-response and recovery. This takes several forms. Some specialist lenders are offering pre-arranged incident response credit facilities, essentially a standby line that a company can draw on the moment it declares a cyber event. Others are providing acquisition finance for the incident response and digital forensics firms that are themselves being bought up by private equity as recurring-revenue professional services businesses.
For investors already exploring private credit as a portfolio diversifier, this is worth watching. The underlying cash flows in cyber-response are counter-cyclical in an unusual way. Demand for forensics, recovery and legal services does not fall during economic downturns. It often rises. That makes the credit profile of these businesses somewhat distinct from most corporate lending. Whether it justifies a specific allocation is a question of each investor's mandate and risk tolerance, but the asset class is no longer hypothetical.
Canberra's Quiet Backstop Debate
In the background, a more consequential question is forming in Australian policy circles. If private insurance cannot cover a truly systemic cyber event, and if critical infrastructure sectors cannot self-insure at the required scale, who bears the residual risk? The answer, by default, is the sovereign.
Australia is not alone in confronting this. The United States Treasury has been studying a federal cyber insurance backstop modelled loosely on the Terrorism Risk Insurance Act, which was introduced after September 11 when private terrorism cover evaporated. The UK, Singapore and the European Union are at various stages of similar conversations. In Australia, the Treasury and the Department of Home Affairs have been consulting on critical infrastructure resilience frameworks that edge toward, without yet committing to, a government reinsurance mechanism for catastrophic cyber events.
A sovereign backstop would be significant for markets in several ways. It would define, for the first time in Australian law, what constitutes a systemic cyber event and what does not. It would almost certainly come with mandatory reporting and security standards for covered entities. And it would implicitly place a floor under the liability exposure of critical infrastructure operators, which is relevant to how those assets are valued and financed.
The Concentration Risk Inside the Solution
There is an irony embedded in the market's response to cyber risk. The drive toward insurer-approved security platforms is consolidating enterprise spending around a small number of dominant vendors. That creates a different kind of systemic concentration. A critical vulnerability in a widely mandated security product becomes, by definition, an event affecting a large proportion of insured entities simultaneously. This is not a theoretical concern. Several major incidents in recent years have originated in security or IT management software that was itself near-ubiquitous.
Investors looking at the infrastructure layer beneath cybersecurity should hold this tension in mind. Concentration in the solution stack is not the same as resilience. It may, in some scenarios, amplify the very systemic risk that insurers are trying to price away.
- Attribution risk: courts and arbitration panels have not yet settled how to determine state-sponsorship for exclusion purposes, and that uncertainty hangs over every large claim.
- Policy basis risk: companies may discover that their understanding of coverage and the insurer's interpretation diverge only at the worst possible moment.
- Sovereign backstop timing: any government scheme is likely years away, leaving a coverage gap that neither private nor public capital is fully addressing today.
- Regulatory drag: mandatory cyber standards tied to insurance or a government scheme could raise compliance costs for smaller listed companies disproportionately.
PortLens Perspective
The tightening of cyber insurance coverage is not primarily a story about insurers. It is a story about where risk goes when it cannot be priced. Right now it is migrating simultaneously into corporate capital expenditure budgets, into a nascent corner of the private credit market, and onto the contingent liability of the Australian sovereign. Each of those destinations creates an investment ecosystem worth understanding: the IT vendors whose products are becoming infrastructure by regulatory fiat, the private lenders building new credit structures around incident response, and the critical infrastructure operators whose valuation may one day hinge on whether Canberra decides to formalise a backstop. The general information here does not constitute financial advice, and every investor should consider their own circumstances and consult a qualified adviser before making decisions. What is the second-order investment implication that most people aren't talking about: if Australia introduces a sovereign cyber backstop modelled on terrorism reinsurance, which critical infrastructure asset classes get re-rated first, and who captures that repricing?
See it on your own portfolio
Find out which of these forces your ASX portfolio is most exposed to — in 60 seconds.
PortLens provides general information only — not personal financial advice. Examples are illustrative. Always do your own research or speak with a licensed adviser before making investment decisions.
New to a term used here? See the plain-English glossary.