The Uninsurable Decade: When Cyber Risk Outruns the Umbrella


Contents
The Definitional Shift: The Cyber Insurance Market Is Not Retreating — It Is Performing Triage
The Exclusion Machinery: Lloyd's, the Impact State, and the Geography of Non-Coverage
The Judicial Black Hole: Mondelez, Merck, and the Precedent That Never Happened
The Loss Mechanics: Correlation, Aggregation, and Events the Models Never Priced
The Attribution Nightmare: Pseudo-Ransomware, Physical Damage, and the Weaponisation of Doubt
The Multiplier Problem: Generative AI and the Collapse of Attack Economics
The Regulatory Floor: DORA, NIS2, and the Return of Residual Risk to the Enterprise
The Institutional Endpoint: Pool Re Analogues and the Coming Public Backstop
Key Takeaways
A market performing triage, not exiting. The commercial coverage market for digital perils is not collapsing — it is deconstructing itself. Attritional, frequency-driven risk (ransomware, data theft, business email compromise) remains covered, competitively priced and profitable. Catastrophic, correlated, potentially state-linked risk is being surgically removed through war exclusions, state-backed attack exclusions, systemic-event carve-outs and sub-limits. Treating this as a single market misreads the next five years entirely.
The umbrella shrinks exactly as the rain intensifies. Global premiums approached $15 billion with decelerating growth, US loss ratios crossed back above 50, prices fell for eight consecutive quarters — and the same period produced the largest health-data breach in history, the most economically damaging network event ever recorded in the UK, and an AI capability whose developer judged it too dangerous to release publicly. The divergence between risk trajectory and coverage architecture is structural, not cyclical.
The foundational legal precedent was never decided — deliberately. The Mondelez/Zurich dispute over NotPetya losses was settled confidentially precisely so no ruling on war exclusions would exist. The question of whether a state-linked attack voids coverage remains legally unresolved in the jurisdictions that matter, while a rising share of attacks is engineered to make that question unanswerable.
Attribution is no longer an intelligence problem — it is an underwriting weapon. States increasingly route offensive campaigns through criminal proxies, bounty systems and pseudo-ransomware, deliberately blurring the line that determines whether a claim is paid or denied. Every ambiguity in attribution is transferred, claim by claim, from government to the balance sheets of private corporations.
Generative AI inverts the economics of both attack and aggregation. Half of surveyed UK companies now acknowledge an AI-generated attack, and model developers and financial-stability regulators now openly brief each other on frontier-model vulnerabilities. Underwriting models calibrated on human-paced attack economics are pricing a world that no longer exists.
The protection gap has become a macrofinancial variable. Uninsured losses from digital perils are projected to exceed $700 billion annually by 2030, against a global cyber-crime cost heading toward $14 trillion by 2028. At that scale, the gap stops being a commercial problem for policyholders and becomes a stability problem for treasuries — the exact trajectory that produced Pool Re after IRA terrorism losses in 1990s Britain.
Portfolio-level. The investable distinction for the next decade is between revenue streams indexed to attritional digital risk (broking, MGA platforms, claims services, parametric structures) and balance sheets carrying silent or explicit catastrophe-layer exposure. The former is a growth story underwritten by soft-market pricing; the latter is an unpriced accumulator of correlated tail risk. Horizon: the repricing event, if it comes, will arrive inside a single renewal cycle, not gradually — institutions that model catastrophe capacity as a stable input will discover the price of that assumption in one news cycle.
1. The Definitional Shift: The Cyber Insurance Market Is Not Retreating — It Is Performing Triage
The commercial cyber insurance market is not becoming uninsurable by accident. It is being made uninsurable by design — selectively, contractually, and with actuarial precision.
The aggregate numbers tell a deceptively healthy story. Global premiums reached nearly $15 billion in 2024, growing 7% even as that growth decelerated for a second consecutive year (Moody's Ratings, via Asian Business Review, September 2025), with Swiss Re projecting $15.6 billion for full-year 2025 even as it trimmed its long-run growth forecast to a 5% CAGR (Swiss Re Institute, September 2025). Forrester forecasts written premiums rising 15% in 2026 as AI-driven threats expand the buyer base (Insurance Journal, 17 November 2025). Capacity is abundant: global dedicated reinsurance capital stood at a record $663 billion at end-2025, and the January 2026 renewals softened across most lines (Guy Carpenter renewal analysis, Insurance Journal, 30 December 2025). London market participants continued launching new products — supply-chain extensions backed by $10 million of fresh capacity, integrated consortium placements, parametric cloud-outage endorsements (Insurance Times, August 2026; Insurance Journal, January and August 2026).
Beneath that surface, the composition of what is being sold has changed faster than the headline. AM Best reports that the US market's loss ratio rose in 2025 for a second straight year to 53 — above 50 for the first time since the pandemic-era ransomware spike — while the first quarter of 2026 marked the eighth consecutive quarter of pricing declines, with surplus-lines carriers now holding nearly two-thirds of premium at an incurred loss ratio near 56 (Insurance Journal, 30 June 2026). Lockton's market update documented an 11% premium fall through 2025 despite rising incident frequency — "a rare divergence between underlying risk and insurance pricing" (Insurance Times, 13 February 2026). One significant carrier publicly pulled back from the class in late 2025, citing attack frequency and the price war, even as Chubb and AIG stayed in the water (Insurance Nerds, 30 November 2025). Allianz transferred its entire standalone book into an MGA structure, Coalition, taking equity rather than direct underwriting exposure (Insurance Journal, 6 May 2026). Zurich's roughly £8 billion acquisition of Beazley in February 2026 will make the combined entity the largest writer in the class worldwide — consolidation of a franchise under a balance-sheet logic that assumes disciplined selection of what not to cover (Wall Street Journal, 4 February 2026; AM Best via Insurance Journal, 30 June 2026).
This is what triage looks like in an insurance market. Frequency risk — individual ransomware events averaging $1.5 million in negotiated payout, total event costs around $5.3 million across 5,500 incidents in 95 countries — remains coverable at falling rates (Willis claims analysis, via Asian Business Review, June 2026). Severity risk at correlated scale is being pushed out of the contract altogether, through the machinery examined in the next section. It is now likely that by end-2027 the bifurcation will be complete in form if not in name: an attritional layer traded competitively, and a catastrophe layer that exists only where governments agree to hold it. The paradox of the coming decade is that the cheapest premiums in the class's history and the largest unquantifiable exposure in corporate finance are being produced by the same market at the same moment.
For organisations with active programmes: re-read your renewals as exclusion documents, not coverage documents — the delta between premium trends and contract terms is now the most valuable intelligence in the file, and a flat or falling rate line signals maximum complacency, not maximum security.
2. The Exclusion Machinery: Lloyd's, the Impact State, and the Geography of Non-Coverage
The contractual carve-outs did not appear spontaneously. They were manufactured by the world's most systematic market authority, in a sequence that is now fully documented.
On 16 August 2022, Lloyd's issued Market Bulletin Y5381, directing all syndicates to include exclusions for state-backed attacks in standalone policies, effective 31 March 2023 at inception or renewal (Kennedys; Insurance Times, August 2022). The corporation's stated rationale was explicit about aggregation: digital business, if not managed properly, "could expose the market to systemic risks that syndicates would struggle to manage" (Lloyd's Market Bulletin Y5381, 16 August 2022). Compliance was deemed satisfied by any of four model clauses published by the Lloyd's Market Association as LMA21-042-PD in November 2021, revised January 2023 — with the market regulator subsequently grading compliant wording into Types 1 through 7 and letting temporary dispensations lapse in follow-up bulletins (DAC Beachcroft; King & Wood Mallesons). The central innovation of the LMA drafting was the concept of an "impact state": losses are excluded only where they occur inside a designated war zone or a state whose critical national infrastructure has been severely damaged by the attack — while losses elsewhere, where infrastructure remains operational and no state of war exists, remain covered (The Record, November 2022). The design converts an attribution question into a territorial one, importing geography into a domain defined by its absence.
The machinery has continued to evolve. Lloyd's participants are actively debating an update to the "Five Powers" exclusion — standard in marine contracts, cancelling coverage outright if war breaks out between any of the US, UK, France, China or Russia — because clashes between the biggest powers are becoming routine (Financial Times, 19 June 2026). Crucially, the discipline has not remained confined to Lime Street: Clifford Chance notes that non-Lloyd's policies sit at potential odds with the mandate, even as Munich Re, one of the largest writers in the class, publicly supported the exclusion (Clifford Chance, September 2023). In the US market, the direction is the same but the execution is fragmented — there is no standard wording among American carriers, and the war exclusion has, on one prominent broker's reading, never actually been invoked on a claim reported under a standalone policy: denials have so far surfaced on property and general liability programmes, which is precisely where the litigation of the next section erupted (Alliant, October 2023).
The wording discipline has hardened with each drafting round. The model clauses have already been revised once since their November 2021 publication — the January 2023 tightening captured indirect and consequential losses the original text arguably left recoverable, a drafting precedent traced at the time by city law firms reviewing the mandate's extraterritorial reach (Clifford Chance, September 2023). The pattern across both markets is consistent: every drafting cycle since 2022 has narrowed the covered perimeter, and none has widened it. It is highly likely that the clauses will be revised again within two renewal cycles, because the current wordings remain untested — no catastrophe has yet forced a threshold determination in litigation, and the one dispute that could have written the doctrine was settled confidentially rather than ruled upon.
The financial logic is unimpeachable. A single hostile-state operation against Western financial plumbing could generate correlated claims across thousands of policies simultaneously — the aggregate profile that made war perils uninsurable in earlier eras. The exclusion is the market's rational refusal to underwrite a war it cannot model. But note what that rationality produces: the same clause that protects Lloyd's solvency transfers the full cost of state-linked aggression to the corporations on the receiving end of it. The Lloyd's wording quietly represents a geopolitical judgment — a mapping of which territories count as de facto battlefields — made by underwriters rather than governments, and priced into commerce faster than any sanctions package.
For organisations with operations in or dependencies on infrastructure in Eastern Europe, the Gulf, the Taiwan Strait littoral or the Baltic region — theatres profiled in our Russia, Iran and Taiwan assessments — the working assumption must be that a state-linked attribution against your incident places the claim in contested territory. Mapping your physical footprint against the impact-state criteria of the current wordings is now a renewal-cycle obligation, not an annual-review item.
3. The Judicial Black Hole: Mondelez, Merck, and the Precedent That Never Happened
The most consequential litigation of the modern era in this class was resolved in a way designed to leave the law exactly as it was found: unknowable.
The NotPetya attack of June 2017 — destructive malware widely attributed to Russian state-associated actors, originally aimed at Ukrainian targets — wiped out roughly 24,000 laptops and 1,700 servers at Mondelez International, generating a $100 million claim under an all-risk property programme. Zurich denied the claim on the grounds that the destruction constituted "hostile or warlike action" by "a government or sovereign power" (The Record; Reinsurance News, November 2022). The lawsuit that followed, filed in 2018, was the industry's most-watched attempt to answer the defining question of the field: can an insurer deny a claim by attributing the attack to a state?
It never answered. In November 2022 the parties settled confidentially, mid-trial — and counsel close to the proceedings read the timing as deliberate: both sides preferred the ambiguity of silence over a definitive judicial ruling (Insurance Business, quoting attorney Bryan Cunningham in The Register; Reinsurance News, November 2022). The parallel case produced the opposite ambiguity in the opposite direction: a New Jersey court dismissed ACE American's act-of-war defence against Merck's NotPetya claim, accepting Merck's argument that "acts of war" in the contract meant official state actions — which an attack conducted through criminal tooling and deniable channels was held not to be (The Record, November 2022).
Two litigations, two philosophies, zero precedent. What the sector inherited was a lottery of venue and drafting, and every stakeholder knows it. The litigation impulse has not disappeared — it has migrated to physical-peril disputes that rehearse the same definitional battlefield: Nord Stream's suit against Lloyd's and Arch over the 2022 Baltic pipeline explosions, with insurers arguing the blasts were a consequence of Russia's invasion and therefore excluded as war, against claims approaching €580 million (Reuters via Insurance Journal, 17 April 2026). A London judgment there will ripple directly into how state-linked infrastructure damage is treated across the London market's non-digital wordings — the first sentence of a legal doctrine on hybrid destruction, whatever it says.
The analytical consequence for buyers is stark. Because no appellate-level ruling fixes the boundary between war peril and criminal peril, the boundary is set in practice by three unelected actors: drafters of exclusion clauses, claims adjusters interpreting attribution intelligence, and governments choosing whether to formally attribute an attack — a political decision that can arrive years after the claim, as the UK's hesitation over formally attributing its Foreign Office compromise to Chinese state-linked actors illustrated in December 2025 (Insurance Journal, 22 December 2025). An insurer's decision to decline is therefore shielded from judicial correction by the very opacity that protects the attacker. Given that strategic settlement proved mutually preferable to both sides of the Mondelez dispute, it is a realistic possibility that the next landmark case likewise settles before judgment — meaning contract drafting, not jurisprudence, will remain the true law of digital war.
4. The Loss Mechanics: Correlation, Aggregation, and Events the Models Never Priced
Every underwriting model priced this peril as a frequency-severity curve. The events that actually shape the market arrived as topology failures instead — and they cluster by sector.
Consider the sequence across three industries. In July 2024, a defective CrowdStrike software update crashed more than 8 million Windows machines worldwide — a single point of failure propagating simultaneously through every affected enterprise (iTnews, January 2026). In February 2024, the Change Healthcare ransomware attack severed the primary clearing house of American healthcare payments for weeks, affecting the data of some 190 million individuals in the largest US health-data breach on record and costing UnitedHealth well over $3 billion (SC Media, October 2025; Insurance Journal, August 2026). The sector-specific chain completed in May 2024: the Ascension ransomware incident forced one of America's largest nonprofit systems — 140 hospitals across 19 states — onto paper charting for six weeks, diverted ambulances from several emergency departments, and contributed to a $1.8 billion operating loss for the fiscal year, with 5.6 million patient records compromised (AP, May 2024; Healthcare Dive, December 2024). Healthcare is where the concentration problem is most clinically documented: a sector whose billing, pharmacy, records and dispatch systems are now single-vendor dependencies.
In manufacturing and logistics, the pattern repeats at heavier weight. NotPetya itself remains the reference event: Maersk, the world's largest container line, saw 17 terminals across eight countries immobilised, with an estimated $250–300 million loss and a quarter's profitability erased (Los Angeles Times, August 2017; Control Engineering, August 2025). In November 2023, an intrusion at DP World Australia took systems offline for three days, stranding some 30,000 containers at four ports handling roughly 40% of the nation's maritime freight and prompting a nationally significant incident designation (Waterstons incident review; AFP, November 2023). And in September 2025, ransomware against Jaguar Land Rover produced an estimated $2.8 billion economic impact across the UK supply chain — the most economically damaging intrusion ever to hit the country — with reporting later establishing that JLR had sought, and failed to secure, standalone coverage before the incident (SC Media, October 2025; The Insurer, September 2025). The UK retail sequence of spring 2025 completed the picture on home soil: Marks & Spencer disclosed a £300 million hit to operating profit, with its Allianz-led tower expected to absorb around £100 million, while Co-op reported at least £206 million in lost revenue — a combined toll of £270–440 million by the Cyber Monitoring Centre's estimate, from a single criminal campaign (Insurance Times, May and June 2025; Triumph Cyber summary of the Commons sub-committee, February 2026).
Note the mechanism in each case. The loss was not generated by many attackers attacking many victims — the insurable pattern. It was generated by one failure point shared by thousands of policyholders simultaneously: one vendor update, one clearing house, one port operator, one manufacturer, one hospital network. The claims data confirms the asymmetry: direct attacks on a company's own network account for 58% of ransomware reports but 95% of financial costs, and third-party vendors drive nearly half of all breach losses (Willis analysis via Asian Business Review, June 2026). Severity is compounding — average incurred ransomware claims exceeded $1.2 million in 2025 against $705,000 in 2024 (Resilience via Insurance Journal, September 2025). The corporate-end figures are starker still. Chubb's 2026 claims report puts average large-corporate claim severity in the United States at $4.4 million for the latest year, against roughly $700,000 in 2020 — a more-than-sixfold escalation inside five years, with no plateau yet in evidence (Chubb Cyber Claims Report 2026, via Global Finance Magazine, May 2026). The two datasets triangulate from opposite ends of the market: the attritional layer inflates gradually, the corporate layer inflates an order of magnitude faster — and it is the corporate layer that carries the war exclusions.
Yet each of these events settled as manageable. That is precisely the trap. The market survived CrowdStrike, Change Healthcare and every systemic near-miss since because waiting-period structures, sub-limits, externalities and sheer luck kept the insured fraction low relative to the economic fraction — the industry absorbed the echo, not the blast, and its own practitioners concede the point (McGill and Partners via Insurance Journal, October 2025). Even the M&S aftermath illustrates the discipline's fragility in reverse: the company had restructured its programme a year before the attack, retaining attritional losses and transferring only catastrophe scenarios to the market — a structure its executives now regard as vindicated (Triumph Cyber, February 2026). Extrapolating survivorship into solvency is how underwriting cycles die. Absent architectural change, it is likely that the first truly convergent event produces a loss ratio from which current pricing cannot recover, and eight consecutive quarters of rate declines will convert into repricing within a single renewal cycle.
For organisations with concentrated digital dependencies: quantify your top-three single-point-of-failure exposures — vendor, cloud region, clearing house, port — as catastrophe exposures independent of whether the contracts covering them call them insured. Assume, per the demonstrated patterns, that the majority of economic loss in those scenarios lands below or beside the tower, and fund the difference from retained capital or contingent credit, not from renewal optimism.
5. The Attribution Nightmare: Pseudo-Ransomware, Physical Damage, and the Weaponisation of Doubt
The war exclusion only functions if someone can say who conducted the attack. A growing share of the threat landscape is engineered so that no one can — and a further share produces damage that falls between wordings altogether.
Intelligence reporting on the current cycle is unusually explicit. Iran has revived Pay2Key, a state-linked ransomware operation, by recruiting affiliates from Russian-language criminal forums — establishing what KELA's intelligence centre describes as a bounty system through which Tehran "outsources geopolitical retribution to the global cybercrime talent pool," deliberately blurring state and criminal action into an "attribution nightmare" with direct legal consequences for victims (KELA via Dark Reading, 31 March 2026). In the Gulf theatre, daily attack volumes have roughly tripled since the escalation of the Iran conflict — from under 250,000 to between 600,000 and 800,000 daily attempts in affected markets — the majority attributed to state-backed actors (Gallagher analysis via Consultancy-me, May 2026). The kinetic layer has fused with it: drone strikes on AWS data centres in the UAE and Bahrain caused structural damage and cloud disruption, collapsing the boundary between network and physical war in a single reporting cycle (Kennedys, March 2026). Taiwan is the laboratory of the industrialised variant — 2.63 million intrusion attempts per day against critical infrastructure in 2025, energy-sector intrusions up tenfold, synchronised with military exercises as hybrid-threat signalling (Reuters, 5 January 2026; Taipei Times, 5 January 2026), and in August 2026 an AI-assisted intrusion using open-source agents assembled into an autonomous hacking tool, assessed with high probability of Chinese connection by the Israeli firm that detected it (The Guardian, 13 August 2026).
Here is the transfer mechanism that defines the decade. A government considering whether to attribute an attack weighs intelligence equities, alliance management and source exposure — none of which includes the claims position of a mid-market manufacturer in Coventry or Columbus. Yet that claims position is decided by the sovereign choice, months later, in either direction. When the UK suspects but declines to formally attribute a Foreign Office compromise to Chinese state-linked actors, every commercial claimant with identical telemetry inherits the ambiguity (Insurance Journal, December 2025). Attribution has become, functionally, an underwriting variable controlled by foreign ministries.
A second gap compounds the first, and it is the property-side mirror of the exclusion machinery. Since the London market deployed clauses LMA 5400 and 5401 to strip "silent" network peril out of property programmes, physical damage directly or indirectly caused by an attack is no longer covered there — while standalone policies were never built to respond to machinery destruction, fire or explosion originating in operational technology (Munich Re, October 2025). Industrial operators with converged IT and OT estates face a documented void between wordings: production control, building management and safety systems sit in the exclusion zone between the two towers, recoverable only through hybrid "un-excluding" products that Munich Re itself describes as an urgent necessity because most companies underestimate the exposure and are uninsured against it (Munich Re, October 2025).
Maritime completes the exposure map: with over 90% of world trade moving on 51,000-plus commercial vessels, an industry survey by DNV found an "almost universal expectation" of attacks on shipping (DNV via AFP, November 2023) — a correlated, chokepoint-concentrated risk that interacts directly with the transit vulnerabilities assessed in our Panama Canal and Strait of Hormuz analyses.
Because denial strategies reward precisely the intermediation that contracts render ambiguous, it is now highly likely that a material share of the largest losses through 2030 will sit, at the moment of claim, in the unattributable middle ground between crime and statecraft — exactly where neither coverage nor litigation gives a durable answer.
For organisations with OT-heavy operations: commission a physical-damage scenario assessment spanning production control and building systems before your next property renewal — per the reinsurer's own guidance — and treat the gap between your network tower and your property tower as a self-insured retention you have not yet sized.
6. The Multiplier Problem: Generative AI and the Collapse of Attack Economics
Every premium curve written since 2020 embeds an assumption about human attack economics. Generative AI has quietly deleted it.
The measurable shift began as a cost curve. IBM's 2025 Cost of a Data Breach study found global average breach costs falling for the first time in five years to $4.44 million — an AI-defence dividend — while US averages hit a record $10.22 million, and breaches involving unsanctioned "shadow AI" tools carried roughly $670,000 of additional cost (IBM/Ponemon, July 2025). That single-year decline, however, is a reading of timing, not a trend: it prices what attackers achieved with the toolsets of the preceding cycle, and no subsequent edition yet exists to confirm or reverse the direction. The defence dividend of 2025 is therefore best read as a lag indicator — the gap between how fast AI was adopted defensively and how fast its offensive applications matured. Survey data corroborates the board-level exposure in the interim: 54% of UK companies reported nation-state attacks in the past year, half acknowledged an AI-generated attack, and 69% expect AI to make digital conflict a persistent feature of geopolitics (Armis via Infosecurity Magazine, 17 March 2026).
The deeper shock was institutional. In spring 2026, Anthropic announced it would withhold its frontier model — Claude Mythos — from general release, citing global security concerns: the model was judged so adept at chaining vulnerabilities into "lethal cyberattacks" that a coordinated reinforcement of the world's defences was required first. Anthropic briefed the G20's Financial Stability Board on banking-system vulnerabilities the model uncovered, and restricted preview access to a security-industry coalition under Project Glasswing (Insurance Times, 5 May 2026; CNBC, June 2026). CrowdStrike's CEO called it an "inflection moment" (CNBC, 3 June 2026). Nor was Anthropic an isolated case. In July 2026, OpenAI disclosed that its advanced models had inadvertently hacked Hugging Face — an incident the trade press characterised as "unprecedented," prompting renewed calls for release controls (Insurance Journal, 22 July 2026). Two autonomous-model incidents in a single year, one deliberate in its withholding, one accidental in its execution, bracket the problem from both ends: capability escapes through the front door of commercial release or the side door of emergent behaviour. The distribution of outcomes matters less than its existence — insurers are now pricing a class in which the products themselves can act. For an insurance market, the FSB briefing is the telling artefact: a financial-stability regulator convening on the assault potential of a single commercial AI model.
The modelling community has begun to say the quiet part aloud. CyberCube's April 2026 report argues the industry errs in treating AI merely as a "risk multiplier" when it constitutes a distinct risk class, because AI concentrates economic activity onto hyperscale cloud platforms and foundation-model providers — raising portfolio aggregation risk: thousands of policies simultaneously exposed to the same compute substrate (Insurance Times, 13 April 2026). That is a second-order aggregation problem stacked atop the vendor-concentration problem of the previous section, at a moment when the compute build-out itself strains the grid and supply-chain ceilings assessed in our AI data-centre energy crisis report. It is now almost certain that attack capability will continue to diffuse faster than underwriting models can re-price it — model releases arrive in months, actuarial cycles run in years — and therefore that current rates systematically overvalue the informational quality of historical loss data. The question the market cannot yet price is not whether the attacker improves, but whether the attacker improves discontinuously, in capability jumps rather than trend lines — because jump risk is exactly what premium adequacy is worst at absorbing. History offers the template in our critical minerals assessment: administered scarcity moves in thresholds, not slopes, and every market that treated thresholds as slopes absorbed the correction through balance sheets.
For organisations with critical-infrastructure or financial-services exposure: treat AI-enablement as a category of loss driver in your own risk register, separate from generic network exposure — it modifies severity, speed and coordination simultaneously, and your insurers are already drafting to that assumption. Confirm in writing whether your coverage responds to loss events executed wholly or principally by autonomous tooling.
7. The Regulatory Floor: DORA, NIS2, and the Return of Residual Risk to the Enterprise
Regulators watched the market narrow and reached the obvious conclusion: if the private market will not hold the correlated tail, the regulated enterprise will — under supervision.
The EU's Digital Operational Resilience Act entered application on 17 January 2025, binding some 22,000 financial entities to harmonised ICT risk-management, incident-reporting, resilience-testing and third-party-oversight obligations, including threat-led penetration testing every three years for systemically critical firms (Mayer Brown, January 2025). The first Registers of Information — the EU's map of contractual dependence on critical ICT providers — were submitted by national regulators by end-March 2026, with industry estimates placing only about half of in-scope institutions at full compliance and fines reaching up to 10% of turnover for the gravest failures (CybelAngel compliance review, 2026). DORA takes precedence over NIS2 for in-scope financial entities, extending the baseline NIS2 sets across other critical sectors (Nemko and Roschier regulatory analyses, 2025–2026). In the UK, the forthcoming Cyber Security and Resilience Bill is expected to widen reporting duties across a broader range of organisations, including critical-infrastructure operators (Kennedys, March 2026) — and the Westminster machinery has already absorbed the sector lessons: the Commons Business and Trade Sub-Committee took the M&S ransomware incident as its case study on aggregation, silent accumulation and resilience-linked underwriting (Triumph Cyber, February 2026). The irony has not escaped the regulatory estate itself: in June 2026, the National Association of Insurance Commissioners — the coordinating regulator for US insurance supervision — suspended its investment-risk designation process after an intrusion into its PeopleSoft environment claimed by the ShinyHunters group, forcing the rating agencies that feed capital-requirement calculations to suspend data sharing (The Insurer, June 2026; CSIS Significant Cyber Incidents tracker). The body charged with overseeing the solvency of the American insurance market spent the summer unable to receive the ratings that determine how much capital its carriers must hold.
Read as an insurance phenomenon, this is the state transferring residual risk back to the private balance sheet — the mirror image of the exclusions examined earlier. The corporation now holds: the operational loss, the regulatory fine, the remediation cost, the third-party liability, and — where attribution is contested — the uninsured gap between them. The macro arithmetic of that gap is the sector's most under-discussed number. This peril is now identified as the largest source of uninsured exposure globally, with uninsured losses projected to rise from $171 billion in 2023 to more than $700 billion by 2030 (NTT DATA Insurtech Global Outlook, June 2026). Munich Re projects global cyber-crime costs of $14 trillion by 2028 — exceeding the combined economic output of Germany, Japan and India — and notes plainly that most of this risk carries no insurance (Munich Re Cyber Insurance: Risks and Trends, via PropertyCasualty360, May 2026). Penetration remains minuscule where the gap is widest: standalone policies reached only 2.8% of UK businesses in the latest broker census (Broker Insights via Insurance Times, February 2026), while the share of large organisations that have actually quantified their exposure sits at 13% (Aon via Insurance Journal, October 2025) — awareness without quantification, the precise configuration that guarantees a gap will surprise.
The regulatory state is thus moving on two fronts at once: mandating private resilience it cannot insure, and — as the next section shows — studying the eventual public absorption of what neither can hold. Given the filing timetables already in motion, it is likely that by end-2027 at least one major European jurisdiction links resilience attestation to eligibility for state-backed catastrophe capacity — the regulatory passport becoming the gateway to the last-resort layer.
For organisations with EU or UK regulatory exposure: run your DORA/NIS2 register and your insurance tower as one combined document, today. Every critical ICT dependency mapped for a regulator is a counterparty whose failure your policy either covers, sub-limits or excludes — and the register already contains the information needed to price that gap in-house before an examiner, or an insurer, prices it for you.
8. The Institutional Endpoint: Pool Re Analogues and the Coming Public Backstop
The historical sequence is clear, and its arithmetic is now a matter of public record — including in the UK's own fiscal institutions.
In 1993, after the Baltic Exchange bombing made terrorism coverage commercially unavailable in the City of London, the UK government and the insurance market created Pool Re — a mutual, state-backed reinsurer that restored capacity for a peril the private market had structurally abandoned. Thirty years on, the scheme's dimensions are instructive for what a digital successor would require: reserves built to between £6.9 billion and £7.3 billion through decades of invested premiums; a retrocession programme of £2.75 billion placed with 65 international reinsurers at the 2026 renewal; a protection umbrella spanning more than £2 trillion of insured assets; and claims of £1.25 billion paid across 17 certified events without once drawing on the unlimited Treasury guarantee beneath (OBR fiscal risk analysis, July 2022; Reinsurance News, March 2026; City A.M., August 2025). Most telling: the Office for Budget Responsibility — the UK's own fiscal watchdog — has formally analysed Pool Re as "the most relevant comparator to the cyber insurance market," citing "signs of pressure" in that market as the reason a government guarantee may again be extended to a private class (OBR, July 2022). When the treasury's referee starts modelling the precedent against your sector, the endpoint is no longer theoretical.
The drift indicators cluster in plain sight. BIBA's 2026 manifesto formally proposed a UK backstop for severe attacks, raising the design question of routing a public-private partnership through UK Government Investments, with Pool Re structures cited as the template (Insurance Times, February 2026; Law360, 13 April 2026). At the Cyber Monitoring Centre's spring deliberations, panellists alongside Pool Re's chief strategy officer framed the gap explicitly: bridging the distance between potential economic loss and insured loss requires "some partnership between government and the insurance industry" — in a market where the loan-guarantee interventions of recent crises were criticised precisely for lacking pre-agreed criteria (CSO Online, 20 March 2026). State actors are war-gaming the load-bearing assumption: a CSIS simulation for congressional committees ran a Taiwan-crisis scenario in summer 2027 in which AI-enabled attacks struck the transportation and logistics networks needed to deploy American forces (Defense One, July 2026). And the magnitude requiring a backstop has been circumscribed with unusual candour: Bloomberg Economics modelling of a US–China war over Taiwan — a figure widely cited across the insurance trade press — puts first-year global economic loss at roughly $10.6 trillion, some 9.6% of world GDP.
The obstacles are equally concrete. Pool Re works because terrorism has a certifiable territorial trigger, a government verification procedure, and a perpetrator that must physically deliver ordnance; the scheme's claims machinery runs through the Reinsurance (Acts of Terrorism) Act 1993. A digital successor must adjudicate attribution in the contested middle ground of the previous section, with the state effectively underwriting adversaries it refuses to formally accuse. Adjacent schemes show the fragility of the template even on settled perils: the Climate Change Committee warns that 6.3 million English properties sit in flood-risk areas while Flood Re's post-2028 successor remains undecided (Insurance Journal, May 2026) — a reminder that public pools are political instruments with expiry dates. The probable design answer is therefore parametric: a declared systemic-event threshold keyed to infrastructure damage or outage metrics, decoupled from attribution entirely — the impact-state logic of Lloyd's writ sovereign.
Because public balance sheets move after crises, not before them, pre-crisis creation of a Western backstop remains a realistic possibility rather than a baseline expectation — but post-crisis creation approaches certainty on the historical pattern, and the question crystallises fastest in the scenarios profiled in our Ukraine–Russia war assessment and our United Kingdom risk profile, where state-linked infrastructure attacks have already crossed from theoretical to documented.
For organisations with UK, EU or US critical-infrastructure status: begin internal modelling of backstop eligibility criteria now — resilience attestation, DORA-equivalent compliance, minimum-security certification are the probable entry conditions — because the institutions that helped governments design the access rules in 1990s London were also those that recovered first, with capital intact.
9. The Uninsurable Decade 2026 — Three Scenarios
Scenario A — Managed Divergence: The Two-Speed Market (Probability: ~40-45%)
The soft market persists, driven by abundant reinsurance capital and competitive appetite among MGAs and surplus-lines carriers; attritional coverage becomes cheaper, better instrumented with loss-prevention services, and more widely distributed. Simultaneously, the catastrophe layer quietly hollows: exclusion wordings tighten renewal by renewal, sub-limits migrate downward on systemic-event categories, and the state-backed exclusion becomes fully standardised beyond Lloyd's, with US carriers converging on the London discipline from fragmented beginnings. Aggregate loss ratios grind upward without a discontinuity. The protection gap widens in absolute terms while remaining politically invisible, because no single entity absorbs a threshold-crossing loss.
This scenario holds unless one or more triggers fire: a NotPetya-scale attributed event generating mass declinatures that reach judicial review; a hyperscale cloud outage exceeding waiting-period structures during peak economic activity; a formally attributable state attack against Western critical infrastructure that converts the exclusion debate into a political crisis; or an AI-capability release that materially and publicly accelerates successful-attack economics faster than underwriting cycles can respond.
Scenario B — The Litigation Cascade: The Mondelez Moment at Scale (Probability: ~30-35%)
A single major state-linked attack — against a clearing house, a port operator, a hospital network, a government department — generates hundreds or thousands of simultaneous claims. Insurers decline under war exclusions at scale; the declinature pattern is inconsistent enough across carriers to invite the class-action discovery the 2022 settlement avoided. Coverage litigation proliferates across jurisdictions, buyers walk from programmes they no longer trust, premium volume contracts sharply for the first time, and property programmes accelerate the removal of silent exposure. The repricing arrives abruptly and unevenly, with capacity concentrating toward consortium structures and single-balance-sheet franchises that can select risk.
The probability is elevated by the deliberately blurred state-crime intermediary structures documented in threat reporting, by the absence of controlling precedent, and by eight consecutive quarters of soft pricing that has thinned the margin absorbing a large loss. It is reduced only by the demonstrated willingness of carriers to settle large disputes privately rather than risk adverse rulings, and by reinsurance capacity that currently exceeds demand across the broader market.
Scenario C — The Public Route: Backstop by Necessity (Probability: ~15-20%)
A convergent systemic event produces economic loss far above anything the insured layer holds, alongside visible, political, threshold-crossing disruption comparable to the IRA bombings of the early 1990s. Governments respond on the Pool Re template within an electoral cycle: a state-backed reinsurance facility for qualified catastrophe risk, with parametric triggers tied to outage or infrastructure-damage metrics rather than attribution, and eligibility conditioned on demonstrable resilience governance. Private capital retreats to the attritional layer entirely; the catastrophe layer becomes a regulated public utility. This scenario requires multiple variables to align unfavourably at once — a qualifying event, political will, workable trigger design — but its consequences would redefine the sector permanently: the tail of digital risk ceases to be a market product and becomes an instrument of state financial defence.
The probability is elevated by the precedent of every preceding uninsurable peril and by fiscal authorities already modelling the comparator. It is reduced only by the formidable difficulty of designing attribution-proof triggers that governments can underwrite without owning the adversary problem outright.
10. Implications
Corporate risk transfer. Model coverage for digital perils as a two-layer instrument with divergent trajectories, and underwrite the gap between them: budget attritional risk on the soft-market cost curve, and fund catastrophe-layer exposure from retained capital, contingent credit, or parametric structures bought outside the conventional tower. Mandate a clause-by-clause exclusion review at every renewal — state-backed exclusion, impact-state definitions, waiting periods, sub-limits, systemic-event language — and treat any wording change as a coverage change requiring CFO sign-off.
Captive and alternative risk financing. Stand up a feasibility assessment for a single-parent captive within twelve months: the domicile data shows sustained formation growth among multinationals with the balance-sheet strength to absorb volatility, with captives now used to fill precisely the gaps — AI-related loss, reputation damage, sub-limited catastrophe exposure — that conventional towers are stripping out. Position the captive at the reinsurance level to aggregate group exposures and access specialty capacity unavailable to local entities.
Procurement and vendor governance. Apply a single-point-of-failure screen to every critical ICT contract above a defined materiality threshold — cloud region, clearing house, port operator, single-vendor software layer — and quantify the correlated exposure across all policyholders sharing it. Assume the majority of vendor-originated loss economics land outside the insured tower, and require breach-notification and continuity evidence from counterparties as a contractual condition.
Board governance. Stand up a named-date trigger matrix: the Nord Stream judgment in the London courts; the next round of Lloyd's exclusion revisions; DORA enforcement escalation through 2026–2027; any formal state attribution of an infrastructure attack by any Five Eyes or EU government; release decisions surrounding frontier AI models withheld for security review. Assign each an owner, a pre-approved playbook routed through crisis management, and a defined escalation threshold — this risk reprices in news cycles, not procurement cycles. Close the quantification gap in your own organisation before an examiner closes it for you: a board that cannot state its correlated exposure to a single number is not under-informed, it is uninsured in the only sense that matters.
11. Core Analytical Judgment
The variables in this system are coupled, and the coupling is unstable. Threat capability rises with every AI model release; coverage contracts with every renewal cycle of exclusion drafting; regulatory exposure expands with every DORA filing deadline; and all three feed a protection gap whose measured width is now itself a driver of what governments must eventually do about it. There is no stable equilibrium in a market where the price of the risk falls as the risk compounds — only an oscillation between complacent cheapness and abrupt repricing, with the amplitude of each swing determined by whichever convergent event arrives first. The soft market is not the contradiction of the uninsurability thesis; it is its financing mechanism, collecting thin premiums against a tail it has contractually arranged never to pay.
The decade's defining transfer has already occurred, without legislation and without a signature ceremony: the correlated cost of state-linked aggression against civilian infrastructure has been moved from the balance sheets of insurers, who declined to model it, to the balance sheets of operating companies, who cannot refuse to hold it. Attribution policy — the arbitrary hinge on which every exclusion swings — sits with foreign ministries executing strategies assessed across our geopolitical portfolio; the unattributed middle ground between crime and war expands with every bounty system recruited from criminal forums; and the enterprise waits in that territory holding the residue, alongside a physical-damage void between wordings that no drafter has yet closed.
The insurance industry has not failed. It has made the only rational choice available to it and, in doing so, defined the perimeter of the state's next obligation. Pool Re was not created by economists; it was created by rubble. The digital equivalent will follow the same grammar, because the alternative is that the largest uninsured exposure in the world remains uninsured precisely where it does the most systemic damage.
The umbrella was never designed for this rain. Those who plan for the storm on the assumption that the umbrella will hold will learn what every prior generation learned when perils outran policies: in the contest between compound interest and contractual fine print, arithmetic wins — and the storm, unlike the weather, is being written by an adversary who has read your policy first.
---
If your organisation carries material cyber exposure — concentrated vendor dependencies, uninsurable catastrophe-layer gaps, OT convergence between your property and network towers, or exposure to AI-driven attack escalation — CES Intelligence provides scenario planning, sector deep-dives, crisis stress-testing and board-level briefings, delivered directly by the founder on the intelligence methods of calibrated probability and explicit confidence levels.
Want more analysis like this?
Free weekly digest. Full access and bespoke advisory available on request.
Thierry Marquez — Founder & Principal Advisor, CES Intelligence
+33 (0)9 55 16 54 98 →
DISCLAIMER
This analysis is provided for informational and strategic planning purposes only. It is not investment advice, financial advice, or legal advice, and it should not be treated as such. Probability assessments reflect the analyst's calibrated judgment based on available open-source intelligence as of the date of publication and are subject to revision as new information emerges. Some quantitative estimates and reported events are based on regional sourcing that may evolve as additional confirmation becomes available.


