12 August 2026FeaturesInsurance

Insurance is not enough: cyber resilience requires more than a policy, panel says

Buying cyber insurance increasingly means buying resilience. Panellists explore how carriers are helping clients prevent, respond to and recover from attacks.

Key Points:
Cyber resilience starts long before any breach
Preparation, response matter as much as financial cover
SME demand pushing cyber beyond the traditional policy

Cyber insurers are increasingly selling far more than a policy. As cyber threats grow more complex and insurance reaches less sophisticated buyers, carriers are evolving into long-term resilience partners, providing prevention, incident response and recovery services alongside financial protection.

For many small and medium-sized businesses, buying cyber insurance increasingly means buying security capabilities. Modern policies come packaged with vetted incident responders, continuous monitoring and expert support available within minutes of an incident.

That shift reflects how the market itself has evolved, says Raphael Da Costa, product line leader, cyber and tech E&O at Markel. “Cyber insurance in the early days was heavily consumed by bigger, larger, more sophisticated organisations,” he explained.

“As the penetration in the marketplace broadens to less sophisticated clients, they  are coming in with much less experience on how to handle these type of things and, really, that’s where we can step up and find a solution where we can help them and hold their hand a little bit in the beginning.”

Da Costa was speaking during ‘Insurance is not enough: how carriers are evolving to cover cyber from all angles’, a panel discussion hosted by Intelligent Insurer in partnership with Markel, moderated by editor Aditi Mathur (Watch the full panel discussion here).

Joining him were Jonas Schwade, chief executive of Cysmo; Jeffrey Wheatman, senior vice president, cyber risk strategist at Black Kite and Josh Riley, co-founder of Upfort.

"You don’t want to find your fire extinguisher when the building’s already burning.”

Closing the cyber security gap

For smaller organisations without dedicated cyber teams, insurers are becoming one of the few accessible sources of expertise. “They are really left alone,” said Schwade. “They don’t have the service provider at hand. They don’t have the budget to spend on cyber security.”

Insurance carriers are uniquely positioned to bridge that gap, argued Riley. “Where would I find 10,000 or 100,000 businesses, and have a credible conversation with them about improving cybersecurity? I don’t think anybody’s in a better position to do that than an insurance company right now.”

Wheatman cautioned, however, that expectations must remain proportionate. “The standard of due care for a $5 million mom-and-pop shop is going to be very, very different than the standard of due care for a $50 billion company,” he said.

Reaching those businesses is only part of the challenge, the guidance insurers provide also has to be meaningful. Schwade warned that when carriers bombard clients with cyber alerts, they are crying wolf “over and over again”, and a client who checks 10 warnings and finds nothing behind them will have little confidence left for the 11th alert.

Riley agreed: “I don’t want to erode my trust with you by talking about things that don’t matter.”

For Wheatman, the real opportunity lies in helping boards understand cyber risk in commercial, rather than technical, terms. Executives, he argued, care about “money coming in, money going out, and if something goes bad, who’s in trouble?” Cyber teams rarely tie the technical details back to those numbers. “That’s what insurance companies do, and maybe that’s an opportunity for collaboration.”

"Money coming in, money going out, and if something goes bad, who’s in trouble?”

Resilience starts before the breach

Preparation long before an attack remains one of the biggest contributors to a successful outcome, panel agreed.

Da Costa believes response must be locked in long before crisis strikes. He said Markel keeps vetted incident responders on retainer, while clients who use their own providers must identify when the policy is arranged rather than during a crisis. “You don’t want to find your fire extinguisher when the building’s already burning,” he said.

Schwade agreed that the an active cyber incident is not time to be reading policy wording for the first time. That preparation allows carrier to move quickly once an incident occurs. Da Costa said policyholders receive a response within 10 minutes. “It might be the worst day of that CISO’s year, but for us it’s routine. It’s not an emotional reaction. We can handle it calmly and efficiently.”

"When carriers bombard clients with cyber alerts, they are crying wolf over and over again.”


An evolving threat landscape

While insurers are broadening the services they offer, the threat landscape continues to evolve.

Markel has yet to see a measurable impact from AI in its claims figures, Da Costa noted, but it has registered a significant increase in social engineering, fuelled by deepfakes and AI-generated personal information.

Schwade believes AI is also changing attacker economics, making it commercially viable to target far greater numbers of smaller businesses for lower ransom demands. “I think the attackers will always have the advantage because they just need to be right once and attack a company successfully once, and the defenders have to be right 100% of the time,” he said.

"Cyber insurance will continue evolving into a subscription-style resilience service that combines prevention, protection and recovery into a single offering.”

Watch the full panel discussion below.

Beyond the policy

Ultimately, panellists agreed that resilience is measured not simply by whether an attack occurs but by how quickly an organisation can recover.

Wheatman pointed to organisations such as KNP Logistics, which collapsed following a ransomware attack, as examples of the business consequences of prolonged disruption. For smaller businesses, Riley said the priorities remain: understand critical vulnerabilities, secure email systems and know exactly whom to call when an incident occurs. Da Costa reiterated that knowing whom to call should be the priority. Having a clear recovery plan in place is essential “to minimise the long-term disruption and get everyone back up and running”.

Looking ahead, Riley believes cyber insurance will continue evolving into a subscription-style resilience service that combines prevention, protection and recovery into a single offering. “If I could say, because I sign up with Markel as my provider, that I know I’m not negligent from the point of this purchase on… they’ve sold me this nice subscription for pre-breach, for insurance, for post-breach.”

Markel is already building that broader risk management ecosystem through partnerships with companies including Black Kite and Upfort to give clients “a different view on your security posture”, Da Costa said.

It all comes down to communication, he added. “The more we can talk and be proactive and know what’s available before the policy binds is, from my point of view, the key to have a successful and a long-term relationship.”

Click here to watch the full panel discussion.

Did you get value from this story? Sign up to our free daily newsletters and get stories like this sent straight to your inbox.