Two-thirds of UK organizations do not have cyber insurance

Date:

Share post:

Nearly two-thirds of British organizations are not insured for cyber incidents, according to Risk: Value report from NTT Security. Even with massive uproar around cybersecurity and the Global Data Protection and Regulation coming to effect earlier this year, a vast majority of UK companies do not have a cyber insurance to cover major cyber attacks and breaches.

The report which surveyed 1,800 global senior decision makers from non-IT functions pointed out that UK organizations have spent more than $1 million to recover from cyber attacks. “With estimated annual losses from cyber crime now topping $400bn (£291bn) according to the Center for Strategic and International Studies, you would hope more organisations would be beating a path to insurers’ doors. But while the insurance sector is certainly seeing growth in the number of policies being taken out to cover such losses, it’s an issue that many senior decision makers are not on top of, ” said Kai Grunwitz, Senior VP EMEA, NTT Security.

According to the study, less than a third (29 percent) of firms have dedicated cybersecurity insurance in place. Even here six percent said their insurance covers only for information security breaches, while 11 percent covered data loss alone. This was despite the fact that 81 per cent of the respondents felt that it is important for their organizations to be cyber insured.

He added, “While cyber risk insurance should be put in place to help mitigate the potential fallout of a data security breach, a policy must not be seen as a ‘get out of jail free’ card. Cyber insurance must be complementary to an effective risk-based information security strategy, not a replacement for it. You wouldn’t expect your house insurance provider to pay out if you were burgled when the doors and windows are left unlocked. So don’t expect a payout – or indeed an insurance policy – if you haven’t put in place the right processes and policies.”

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...