TrollEye Security

Cybersecurity Leadership

Cyber Insurance Rates Are Falling, But the Fine Print Could Leave You Exposed

Falling cyber insurance premiums sound like good news, but Gartner analysts say carriers are quietly stripping coverage for social engineering, war exclusions, and mass events, exclusions many policyholders won't notice

Why Lower Cyber Insurance Rates Are a Warning Sign, Not a Win

Cyber insurance premiums have been declining, and that’s exactly the headline that should concern your security team. According to a presentation at the Gartner Security & Risk Management Summit, the real story is what’s being removed from your policy coverage while you’re celebrating lower renewal rates.

Paul Furtado, distinguished vice president analyst at Gartner, outlined the market shifts at a recent summit session: prices are stabilizing and even dropping as carriers have refined their risk models, but the list of exclusions continues to grow in ways that many policyholders are not prepared for.

The Coverage Gap - Social Engineering, War Exclusions, Mass Events, and Sub-limits

The expanding exclusion list is the most significant shift in the cyber insurance landscape right now. Employee actions, outdated software, failure to maintain security controls, and activity related to mergers and acquisitions are among the exclusions that commonly prevent policies from paying out. The nuance matters: “employee actions” exclusions in some policies extend to social engineering attacks, which has major implications given how threat actors are currently operating.

An example that Furtado offered at the summit is an attacker social engineering someone in your finance department into wiring a million dollars, but never directly accessing or controlling your systems. In that case, many carriers will classify that as a failure of internal controls, not a cybercrime covered by your policy. 

Beyond social engineering, two other exclusion categories deserve attention. First, cyber war clauses: Lloyd’s of London has published definitions adopted widely across the market that can exclude certain nation-state attacks. If your organization is hit by a state-sponsored intrusion, the answer to whether you’re covered may depend heavily on how the carrier interprets attribution. Furtado’s advice is to push your broker or underwriter for specifics before an incident, not after.

Second, mass cyber event clauses can reduce payouts by as much as half in the case of a widespread outage affecting a major cloud provider or other critical infrastructure. As enterprises concentrate more workloads with fewer cloud vendors, this exclusion is becoming increasingly material.

Sub-limits are a quieter, but no less significant concern. A $10 million policy doesn’t mean you have $10 million to spend freely. Policies increasingly cap what can be spent on specific services, breach coaches, digital forensics and incident response (DFIR) providers, and legal fees, at amounts far below the total policy value. Organizations that haven’t stress-tested those caps against their actual incident response costs may find themselves short.

The "Tail" Coverage Problem When Switching Providers

One of the more under-appreciated risks surfaces at renewal time. If an organization discovers it was breached last month but has since switched to a new insurance provider, it may find itself in a gap: the new policy won’t cover a previously undiscovered incident, and the old policy has expired. Tail coverage, which provides a window of overlap during transitions, is designed to address this, but organizations often fail to request it when switching carriers.

It’s also worth noting that high-limit coverage has fundamentally changed. Carriers that once would have underwritten a $100 million policy individually now syndicate that risk across a panel of insurers, meaning organizations seeking large limits have to actively sell themselves to multiple underwriters, not just a single carrier relationship.

What About AI?

Before getting to what your team should do, it’s worth noting one area that hasn’t shifted yet. Furtado noted that AI has not yet had a substantial impact on how policies are written or how coverage is structured. Carriers are watching the space closely, particularly as concerns grow around autonomous AI agents and their potential to introduce new categories of risk, but those concerns have not yet translated into meaningful policy changes.

Organizations should not assume that stability will last. As AI-driven threats evolve and insurers develop better models for assessing AI-related risk, exclusions and underwriting criteria in this area are likely to follow.

What This Means for Your Organization

Lower premiums can create a false sense of security. The cyber insurance market is functioning, but its mechanics have shifted in ways that require active attention from security and risk leadership. A few immediate actions worth taking:

  • Pull your current policy and audit the exclusions section – specifically around employee actions, social engineering, acts of war, and mass cyber events. Map those exclusions against your actual threat environment.
  • Ask your broker or underwriter direct questions – don’t rely on general policy language. If your organization were hit by a campaign that triggered a fraudulent wire transfer, would you be covered? Get a written answer.
  • Review sub-limits against incident response costs – if your DFIR retainer or breach coach fees exceed the cap in your policy, you need to know that now, not when you’re filing a claim.
  • Request tail coverage when switching providers – the discovery-to-breach timeline for many intrusions stretches months. Don’t create a gap at the moment of your highest vulnerability.

Cyber insurance is a component of risk transfer, not a substitute for a measurable security posture. Organizations that treat it as a backstop without reading the fine print may find out too late that they weren’t as covered as they thought.

Sources: Dark Reading

Your Policy Has Exclusions. Your Attack Surface Doesn’t.

TrollEye Security’s CTEM services give mid-market security teams ongoing visibility into real-world risk, continuously identifying and remediating exposures before they become the incident your insurer won’t cover.

Learn More About Our CTEM Solution

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated