Cookies for anonymous analytics (Microsoft Clarity). Privacy

All articles

cyber insurance · critical infrastructure · managed security · tail risk

Cyber Insurance Tightens: Who Bears the Uninsurable Risk?

1 September 2026 7 min readBy PortLens
Cyber Insurance Tightens: Who Bears the Uninsurable Risk?

Ransomware has done something that decades of security conferences could not. It has made the insurance industry blink. Lloyd's of London syndicates quietly rewrote their cyber policy wordings in 2022 and 2023, introducing mandatory war and state-sponsored attack exclusions. Local Australian insurers followed. The headline was about exclusions. The real story is about the gap those exclusions leave, who finances that gap, and which corners of the investment ecosystem quietly grow larger because of it.

Why the Insurance Market Pulled Back

The cyber insurance market grew quickly through the 2010s on relatively thin loss experience. Then came NotPetya, Colonial Pipeline, and a sustained wave of ransomware targeting hospitals, ports, and energy operators. Aggregate losses began correlating in ways that traditional actuarial models had not priced. Unlike a flood, which hits one geography, a single piece of malware can simultaneously disable policyholders across dozens of sectors and countries. That correlation risk is precisely what makes reinsurers nervous.

Lloyd's syndicates responded by drawing a harder line around systemic events, particularly those attributed to nation-state actors. The attribution problem is the crux. When an attack is ambiguous, and most sophisticated ones are, the exclusion clause becomes a legal contest rather than a clean risk transfer. Australian critical infrastructure operators reading the fine print now face a question their boards are only beginning to wrestle with: how much of what we thought was insured is actually not?

The Residual Risk Gap and Who Finances It

When private insurance retreats, risk does not disappear. It shifts. For large Australian operators in energy, water, telecommunications, and financial services, the immediate response has been to self-insure more aggressively through captive insurance structures. A captive is essentially a company-owned insurer, domiciled in a jurisdiction like Singapore or the ACT, that holds capital against the risks its parent cannot transfer externally. The captive market has grown steadily in Australia, and cyber tail risk is one of the cleaner explanations for that growth.

Beyond captives, some of the residual risk is moving toward the capital markets through insurance-linked securities. Catastrophe bonds and collateralised reinsurance structures have historically covered natural perils. The cyber cat bond market is nascent but real. Investors willing to model aggregate cyber loss scenarios are being asked to absorb the risk that syndicates no longer want on their books. The question for any investor considering this space is whether the modelling is mature enough to price the risk honestly, or whether the market is in the early stage where sellers know more than buyers.

The Regulatory Lever: Critical Infrastructure Law as a Forcing Function

Australia's Security of Critical Infrastructure Act has progressively tightened obligations on operators across eleven asset classes. Mandatory incident reporting, risk management programs, and government assistance powers are now embedded in law. This regulatory architecture does something interesting from a financing perspective. It forces operators to demonstrate that their risk management is substantive, not cosmetic. A board that cannot show documented cyber risk financing, whether through insurance, captives, or reserves, is exposed to regulatory scrutiny as well as shareholder pressure.

That pressure flows downstream. Legal, audit, and consulting firms with critical infrastructure practices are busier. More importantly, it creates a durable demand signal for the technology and service providers that sit beneath the compliance obligation.

Managed Security Providers: the Accidental Beneficiaries

When risk cannot be transferred, it must be managed. That distinction quietly funds an entire industry.

Here is where the investment ecosystem becomes more interesting. Every cyber insurance policy sold since roughly 2020 comes with a mandatory or strongly incentivised list of security controls. Multi-factor authentication, endpoint detection and response, privileged access management, and regular penetration testing are standard conditions. Insurers did not impose these requirements out of altruism. They imposed them because they directly reduce loss frequency, which protects the insurer's book.

The side effect is that insurance underwriting has become a procurement driver for the managed security service provider sector. An operator that cannot demonstrate compliant controls cannot obtain cover at reasonable premiums, or sometimes at all. That dynamic has turned cyber insurers into indirect distributors for the managed detection and response industry. As the market hardens and coverage narrows, the spend that might have gone to premiums has to go somewhere. A portion of it flows to the managed security providers whose services become the condition of insurability.

Incident response firms occupy a similarly structural position. Most cyber policies that remain in force include a panel of approved incident response providers. When a breach occurs, the insurer often directs the response. Those panel relationships are commercially significant, and the firms that hold them have a recurring revenue dynamic that is somewhat insulated from the premium cycle.

The Hardening Premium Cycle and What Follows

Insurance pricing cycles are well understood in property and casualty markets. A soft market attracts capital, losses accumulate, the market hardens, weaker underwriters exit, disciplined ones earn better margins, and eventually new capital re-enters. Cyber is moving through a version of this cycle, but with an unusual feature: the exclusions introduced in the hard phase may not be fully removed in the next soft phase. War clauses, once embedded in policy language and tested in litigation, tend to persist.

That structural shift in what is insurable creates a permanent market for alternative risk transfer. Parametric insurance structures, which pay out based on a defined trigger rather than an assessed loss, are being explored for cyber. A policy that pays when a named ransomware variant is confirmed as active, regardless of whether the policyholder was directly affected, is one structure being discussed. These products would need capital backing, and that backing would likely come from investors rather than traditional reinsurers.

Risks Worth Sitting With

  • Cyber risk modelling is still young. Loss correlations under a major systemic attack remain poorly understood, which means any capital deployed into this space carries model risk as well as event risk.
  • Attribution ambiguity is unlikely to be resolved by technology alone. Legal and geopolitical frameworks for defining a cyber war event are underdeveloped, creating persistent uncertainty for both insurers and policyholders.
  • Managed security providers face their own concentration risk. A sector that depends on a handful of large enterprise clients and insurer panel arrangements has revenue that can reprice quickly if the market structure shifts.
  • Regulatory requirements are still evolving. The SOCI Act framework will likely expand and tighten. Operators and their investors should treat current compliance obligations as a floor, not a ceiling.
  • Government backstop risk is real. If private insurance cannot cover systemic cyber events, pressure will build for a government-backed reinsurance facility similar to Pool Re in the UK. The terms of any such facility would reshape the economics of the entire ecosystem.

PortLens Perspective

The cyber insurance story is usually told as a technology story or a security story. It is more usefully understood as a capital allocation story. When a major insurance market tightens its appetite, the risk that cannot be placed does not vanish. It redistributes across captives, capital markets, balance sheets, and the service providers whose work becomes the condition of remaining insurable. For Australian investors, the structural question is not whether ransomware losses will continue. They will. The question is which part of the risk financing chain is being systematically underpriced, and which part is quietly accumulating pricing power as the insurance market retreats. What is the second-order investment implication that most people aren't talking about: as insurers exit systemic cyber risk, could the managed security service providers and incident-response firms that replace them as the primary risk mitigants become the de facto underwriters of critical infrastructure resilience, and what does that concentration of operational leverage mean for the companies and investors exposed to them?

Share this article

Found this useful? Pass it on.

See it on your own portfolio

Find out which of these forces your ASX portfolio is most exposed to — in 60 seconds.

PortLens provides general information only — not personal financial advice. Examples are illustrative. Always do your own research or speak with a licensed adviser before making investment decisions.

New to a term used here? See the plain-English glossary.