Time to Reassess Critical Claims Areas for Cyber

Time to Reassess Critical Claims Areas for Cyber
July 28, 2026 12 mins

Time to Reassess Critical Claims Areas for Cyber

Reassessing Critical Cyber Claims for UK Businesses

This article – part of a series which also explores key claims issues in motor, casualty and property – looks at the claims trends driving the cyber insurance market and the actions businesses should consider to help mitigate their risks and costs.

Key Takeaways
  1. Cyber insurance claims tripled in 2024 and could be even worse for 2025.
  2. Ransomware is still the top threat but evolving risks like AI are on the increase.
  3. Supplier liabilities, ‘silent cyber,’ regulatory challenges and growing insurer requirements around cyber resilience place further pressure on businesses.

Cyber Losses on the Rise

New figures from the Association of British Insurers show that a sample of UK insurers (not all the UK market) paid out at least £197 million in cyber claims in 2024 — more than three times the amount they paid out in the previous year. Recent high-profile attacks in 2025 suggest those figures could get even worse. 

It is why for every business – from SMEs to multinational corporations – it is critical to reassess cyber risk claims areas including ransomware, artificial intelligence (AI)-driven attacks, the impact of attacks on suppliers and the risks from ‘silent cyber’ (insurers excluding cyber cover from other lines of insurance).

Quote icon

Cyber claims are escalating fast, but the impact is not predetermined. With ransomware still dominant, AI‑driven attacks rising and wider third‑party and regulatory exposures, organisations that reassess controls, supply chain resilience, policy wordings and claims readiness will better withstand disruption and secure sustainable cyber cover.

Nikki McCullouh
Head of Claims, UK
  • £197m

    paid out in UK cyber claims in 2024 across a sample of insurers, reflecting a sharp escalation in loss severity.

    Source: ABI

  • 3x

    year on year increase in cyber claim payouts, signalling accelerating frequency and impact of cyber events.

    Source: ABI

Ransomware Threat Persists

Ransomware is still the top cyber threat. Specialist insurer Beazley reported that “ransomware activity remained consistently high throughout Q4 [2025]” although the number of incidents stabilised after peaking in August. Business services have overtaken healthcare as a primary industry target for ransomware, while financial services, education and government remain the sectors consistently targeted. 

Beazley further reports that most ransomware incidents begin with stolen credentials or hijacked sessions, especially via VPNs and remote desktop tools. Infostealers (malware that infiltrates computer systems to steal confidential information) and credential harvesting are key ransomware enablers. There is also a growth in double extortion where attackers demand payment to leave a firm’s computer systems and then threaten to publish stolen data. 

On the positive side, insurers report more attacks are being detected and stopped early, with 58% contained at the initial stage in the second quarter of 2025 (up from 48% in the previous three months), showing improved managed detection and response (MDR) capabilities.

What Your Business Should Consider
  • Organisations should establish distinct protocols for standard account holders and privileged account holders. Inadequate controls over privileged accounts can turn a single compromise into a catastrophic event. For this reason, it is important to strengthen identity and access controls: prioritise multifactor authentication, robust password policies and identity and access management (IAM) solutions. 
  • Organisations that rigorously test their crisis management plans consistently respond more effectively to cyber incidents. Prioritising integrated exercises that bring together all tiers of the response structure clarifies decision making authority and operational responsibilities, strengthens cross team collaboration, and reveals weaknesses in a safe environment, ahead of a real life-event.
  • Organisations that carry cyber insurance typically recover more quickly and are better able to mitigate revenue loss, which in some industries can be significant. However, any risk transfer strategy must be complemented by a strong business resilience strategy. Therefore, businesses should not be reliant on cyber insurance alone and should adopt the appropriate resilience mechanisms to prepare for, withstand, respond and recover from an attack.
  • Model and understand your largest losses ahead of any claim, so that the business is clear on how they will be potentially incurred, calculated, documented and presented to insurers. 
  • Present an accurate view of your security environment to help ensure claims are not denied. 
  • Q4

    Ransomware remained the leading cyber threat through Q4 2025, with sustained targeting of business services and other critical sectors.

    Source: Beazley

  • 58%

    of ransomware attacks were contained at the initial stage in Q2 2025, reflecting improved detection but persistent attack activity.

    Source: Beazley

AI Threats Evolve

As businesses look to invest in AI, there is a need to stay alert to best practice and evolving AI-related risks. There has, for example, been a recent increase in AI being used to create real-time deepfakes (generate videos): a Hong Kong finance employee thought he was speaking to his boss on a video call and sent HK$200 million to a threat actor. AI voice cloning can now mimic a person’s voice with near-perfect accuracy, often fooling both humans and voice authentication systems. 

Looking ahead, insurers see AI as the next main cyber threat; not only in relation to its video/voice generative capability but also in its ability to identify vulnerabilities in a business network and accelerate vulnerability exploitation and attack development. Threat actors are using computing literature posted online and running it through AI to produce new ways to infiltrate networks. What would've taken a hacker weeks of work can now be done in hours.

Other evolving threats on the increase include business email compromise (BEC), payment diversion fraud (PDF) via social engineering, distributed denial of services attack (DDOS) and loss of protected data (via an error or rogue actor).

What Your Business Should Consider
  • Review policy language. Older policies might refer to breaches committed by any “natural person” which would not cover an AI-related breach.
  • Prepare for AI-driven threats. Train staff to recognise deepfakes and fake communications. Consider additional controls for financial transactions. 
  • Increasing losses from phishing, vishing and smishing, often with limited sub-limits in policies, means your business should check the level of cover for these threats. 
  • AI should also be used as a security control, enhancing threat detection, response, and prevention through continuous monitoring and intelligent automation.

This is a chance to get ahead by establishing dedicated leadership roles responsible for managing these new risk exposures (e.g. focused on new and evolving threats) as well as continuously monitoring developments in the underlying technologies.

Supplier Liability Grows

Evolving technology is creating more supplier vulnerabilities, which is resulting in both first- and third-party liability claims. These range from cyber risk and business interruption to directors’ and officers’ claims and loss of reputation. There is an increased targeting of remote monitoring and management (RMM) tools with the aim of finding vulnerabilities to achieve widespread (one-to-many) impacts via upstream providers. 

A business can have the best information security, but if a supplier is not as robust and suffers a cyber-attack, it could compromise its clients. There is also the risk of contingent business interruption if a supplier goes down following an attack, leaving its clients unable to get the materials or services they depend on. 

What Your Business Should Consider
  • Supply chain risk often remains a key residual risk. Even with strong internal controls, your business is still exposed to weaknesses and disruptions at third-party and upstream providers.
  • Assess your reliance on critical suppliers to gain a clearer understanding of the associated operational and commercial exposure to develop a robust commercial plan.
  • Incorporate key suppliers in your overall cyber risk management approach (including business continuity processes and risk transfer strategies) to enhance vendor and supply chain security. 
  • Investigate how your critical suppliers (such as software as a service [SaaS] providers) would respond if a cyber incident shut down their services or disrupted your access, so you understand the knock on impact to your own operations.
  • $200m

    lost in a single deepfake enabled fraud incident, demonstrating the potential severity of AI driven financial crime.

    Source: Case example

  • HOURS

    now required for attackers to identify and exploit network vulnerabilities using AI, compressing attack timelines and reducing response windows.

    Source: Industry insight

Don’t Rely on Silent Cyber

Insurers are updating traditional property and casualty policies to exclude cyber risks. So-called silent cyber, where insurance policies do not specifically include or exclude cyber risk, means insurers can be unintentionally exposed to cyber risks they did not intend to cover.

This is why many carriers are updating their policy language to exclude cyber risks, driven by recent claims activity and exposure gaps. In a couple of years, it is reasonable to assume that if an organisation does not have a standalone cyber policy, a cyber event will be unlikely to be covered under any other suite of insurance policies that they may have.

What Your Business Should Consider
  • While certain lines of business may offer limited protection against cyber losses, most insurance policies either restrict coverage through sublimits or exclude cyber risks in their wording.
  • Without a dedicated cyber insurance policy, your business may face unnecessary complications and prolonged negotiations when handling claims related to cyber incidents. This can result in delays, increased costs, and uncertainty about coverage and recovery.
  • Policies with affirmative cyber coverage language often carry a significant risk of eroding overall policy limits in the event of a cyber incident. For instance, while D&O insurance may appear to offer broad protection, it typically only responds to specific losses related to D&O liabilities arising from cyber events, rather than covering the full spectrum of cyber-related losses.
  • A standalone cyber insurance policy can transfer cyber risks off balance sheet and provide services in a crisis to improve risk management and cyber resilience.

Insurer Requirements Ramp Up

Insurance carriers increasingly require controls such as multifactor authentication, firewalls, endpoint protection, regular backups and vendor risk management before confirming coverage, reflecting their experience that these measures reduce both claim frequency and severity. 

As insurers become more technical in their assessment of cyber risk, organisations should look to optimise their underwriting submission process. This can be achieved by using the feedback provided during this process to develop metrics around security controls that clearly link to risk exposure and the risk transfer strategy. 

Strong alignment between security, risk and insurance functions typically leads to a more integrated approach to managing cyber risk and, in the event of a claim, can enhance the effectiveness of the response while demonstrating that critical controls and processes have been thoughtfully implemented.

What Your Business Should Consider
  • Treat cyber insurer questionnaires and control requirements as useful external feedback to help shape and improve your organisation’s security roadmap, not just as a tick-box exercise to obtain cover.
    Pre
  • Prepare a clear and concise underwriting submission pack that sets out your key controls, processes, incident response arrangements and governance, to build underwriter confidence, support negotiations and reduce issues at claim time.
  • Put in place a simple process to record and highlight security improvements each year (for example, new controls, better monitoring, or increased resilience) so you can show progress and use it to challenge the market on terms and pricing.
  • Once a policy is placed, spend time on claims readiness: agree roles, escalation paths, documentation expectations, and how you will work with incident response providers, so the organisation is ready to act quickly and effectively if an incident occurs.

Regulatory Challenges

Across the board, intellectual property and data privacy regulations are not aligned across different national jurisdictions, which creates risks for firms operating internationally.

It’s important to also note that regulatory fines now cover both privacy and cybersecurity failures (the European Union’s Network and Information Security Directive 2 – NIS2, and Digital Operational Resilience Act – DORA).

What Your Business Should Consider
  • Review which regulations are likely to shape your clients’ and key suppliers’ requirements (e.g., risk management and security standards, reporting, audit rights), and map where your current approach may fall short.
  • Identify which internal processes (e.g., third-party onboarding, due diligence, incident reporting, contract management) will need to change to comply with new rules and assign clear ownership and timelines for those updates.

How Aon Can Help

At Aon, we work with clients to help assess, analyse, mitigate, transfer and recover from their cyber risks.

This approach helps us to understand their risk posture, engage with insurers, attract risk capital from the insurance marketplace and allow clients to make informed decisions to enhance their cyber resilience. 

We support clients with:
  • The full cyber risk journey
    Our suite of cyber risk services work together to drive efficiencies and transparency and help clients be better informed to manage risk and safeguard their balance sheets effectively.
  • Deep and broad experience
    Our global team of cyber risk specialists helps organisations make decisions with clarity and confidence in a complex digital environment. With decades of experience, Aon helps clients be better advised throughout their cyber risk journey.
  • Pioneering cyber risk solutions
    Aon stands out with advanced tools like the Cyber Risk Analyzer and CyQu. These tools provide insights into a business’s risk profile and the effectiveness of security controls, helping clients understand vulnerabilities, prioritise investments, and make better decisions. They also support a more accurate understanding of how these insights feed into a business’s loss distribution modelling, demonstrating how current security investments affect overall risk exposure.
Aon’s Thought Leaders
  • Nikki McCulloch
    Head of Claims, UK Commercial Risk

General Disclaimer

This document is not intended to address any specific situation or to provide legal, regulatory, financial, or other advice. While care has been taken in the production of this document, Aon does not warrant, represent or guarantee the accuracy, adequacy, completeness or fitness for any purpose of the document or any part of it and can accept no liability for any loss incurred in any way by any person who may rely on it. Any recipient shall be responsible for the use to which it puts this document. This document has been compiled using information available to us up to its date of publication and is subject to any qualifications made in the document.

Terms of Use

The contents herein may not be reproduced, reused, reprinted or redistributed without the expressed written consent of Aon, unless otherwise authorized by Aon. To use information contained herein, please write to our team.