Shutterstock.com_2537215541/voyata
13 September 2026Reinsurance

SMEs and personal lines driving next phase of APAC cyber growth: Gallagher Re

SMEs and personal lines offer significant room for cyber growth across Asia-Pacific, but better consumer education and understanding of accumulation risk will be critical, says Gallagher Re’s APAC cyber leader.

Key points:
SMEs and personal lines offer growth
Education remains a barrier to take-up
Accumulation data key as market grows
“If we can help clients understand and quantify the risk, and see the benefits of the cover, the cyber market can grow rapidly.”

Asia-Pacific’s cyber insurance market remains much smaller than those in the US and Europe, but Gallagher Re sees significant room for growth beyond the large corporate market, particularly among SMEs and personal lines.

Carlos Grijalva, executive director and head of cyber for APAC at Gallagher Re, says greater awareness and understanding of the cover will be important to unlocking that potential.

“If we can help clients understand and quantify the risk, and see the benefits of the cover, the cyber market can grow rapidly,” Grijalva told EAIC Today.

During the Covid period, buyers struggled to secure cyber terms, limits and broad cover. Now, local and international insurers are writing corporate, SME and personal cyber business across APAC.

“Capacity is no longer the issue,” Grijalva said. “The biggest problem right now is trying to educate the end consumer.”

There is significant room for expansion in SME and personal cyber, he said, where a substantial protection gap remains. The increasing use of digital payment platforms across populous markets including China, India and Indonesia could also create opportunities to extend cover.

“Digitisation, the implementation of AI and the construction of data centres across Asia create considerable growth potential,” Grijalva said. “These are large areas of exposure that need appropriate cover.”

Closing the protection gap 

Personal cyber is beginning to gain traction, but take-up remains limited, Grijalva said. Expanding the market will require insurers and brokers to improve client engagement, broaden distribution and better explain what policies cover.

The often-hidden nature of cyber incidents can make that difficult, leaving potential buyers uncertain about their exposure and how much insurance they need.

“The problem is that many cyber incidents occur without becoming public knowledge,” Grijalva said. “Unless an event is very large, people may never hear about it.”

Insurers could do more to demonstrate the practical value of cover, he said. Cyber policies can give clients immediate access to forensic specialists, incident-response teams, ransomware negotiators, reputation-management advisers and communications specialists following an incident.

Buyers unaware of that support may instead favour cheaper options offering more limited cover.

“Earlier cyber policies contained grey areas,” Grijalva added. “Current wordings are much clearer and more straightforward about what they cover and exclude.”

AI ups the ante

“AI is definitely changing the risk landscape in several ways,” Grijalva said. Threat actors can use the technology to target victims in other countries with more convincing language, translation and punctuation than in the past, when poor translations made some fraudulent messages easier to identify.

But AI could also improve risk management, with underwriters using the technology to analyse exposures and support decisions around cover, limits and pricing.

“AI is helping in the transformation itself, but it’s also a big threat because the regulations are not 100% there in most of the countries worldwide,” he said, particularly in Asia.

Many policyholders

As insurers write more cyber business, understanding accumulation risk becomes increasingly important. A failure at a widely used cloud provider, for example, could affect multiple insureds simultaneously and generate claims across portfolios. 

“Cyber incidents remain the core concern because they can generate significant financial losses across multiple organisations simultaneously,” Grijalva said. “It would not be one standalone incident affecting one company. The effects could spread through the entire supply chain.”

To estimate the cost of such an event, insurers and reinsurers needed better data and risk modelling showing which policyholders relied on the same providers. Grijalva also called for stronger cyber hygiene and closer coordination among insurers, reinsurers and brokers. “Sometimes there is not enough discussion among insurers, reinsurers and brokers,” he said. “Success will come from balancing customers’ needs with a sustainable understanding of the underlying risks.”

Carlos Grijalva is executive director and head of cyber for APAC at Gallagher Re. He can be reached at Carlos_Grijalva@gallagherre.com.

For more news from the East Asian Insurance Congress conference (EAIC) click here.

Did you get value from this story?  Sign up to our free daily newsletters and get stories like this sent straight to your inbox.