Why Understanding Cyber Risk Insurance is Essential to Protect Your Business

The French cyber insurance market presents a rarely discussed paradox: premiums are decreasing while claims are skyrocketing. The LUCY 2025 study by AMRAE, based on over 20,000 policies, reveals that indemnified claims have risen from 54.5 million euros to 83.2 million euros in one year, an increase of 53%.

At the same time, premiums for large companies have dropped by an average of 32%. This discrepancy between the actual cost of attacks and the price of coverage raises a direct question for any business: what is your cyber insurance contract really worth today?

Recommended read : The keys to effective sports nutrition to boost your performance

Falling premiums and rising claims: what the soft market changes for SMEs

The term “soft market” refers to a phase where competition among insurers drives prices down and expands the coverage offered. Liberty Specialty Markets confirms this trend at the European level, despite high losses and risks amplified by artificial intelligence.

For an SME, this situation seems favorable: accessing cyber coverage is cheaper than it was two years ago. However, this drop in premiums does not reflect a decrease in risk. It indicates a commercial appetite from insurers that could abruptly turn if claims continue to rise.

Related reading : The best solutions to easily optimize your personal finances

The concrete danger for companies that subscribe now is facing sudden price increases or additional exclusions of coverage at renewal. A contract signed in a soft market does not obligate the insurer to maintain its terms. Before signing, it is essential to examine the renewal clauses and pricing revision mechanisms, not just the amount of the initial premium.

To understand cyber risk insurance in its fundamental mechanisms, one must first grasp that the price of a policy says nothing about the quality of the protection offered.

Business leader and insurance broker examining a cyber risk insurance contract during a professional meeting

Underinsurance in cyber: the real problem for French companies

The 2025 survey by the Swiss Insurance Association reveals a striking figure: only 10.8% of companies have cyber insurance, despite a 22% increase in premiums collected in 2024. Available French data suggests a comparable situation, even more pronounced for micro and small businesses.

Underinsurance is not limited to the complete absence of a contract. It also concerns companies that hold a policy with coverage limits disconnected from their actual exposure. A company that stores personal data for thousands of clients but has coverage capped at a few tens of thousands of euros for notification costs finds itself in trouble at the first serious incident.

Three warning signs of inadequate coverage

  • The contract does not explicitly mention coverage for crisis management costs (communication, forensic expertise, legal assistance), which often represent the heaviest part of a cyber claim.
  • Data hosted by a cloud provider is not covered, or is only covered if the provider is specifically named in the policy, which excludes any change of provider during the contract.
  • The claims notification clause imposes a very short deadline (sometimes 48 hours) while detecting an intrusion typically takes several weeks.

IT outsourcing exacerbates underinsurance: when part of the information system is managed by a third party, the boundary between what is covered and what is not becomes blurred. Checking this articulation in the contract is a prerequisite, not an option.

NIS 2 Directive and cyber insurance: a regulatory convergence underway

The transposition of the European NIS 2 directive modifies the liability framework for executives regarding cybersecurity. The companies concerned (and there are many more than under NIS 1, as the scope expands to include mid-sized enterprises and certain critical suppliers) must demonstrate that they have implemented proportionate cyber risk management measures.

In this context, cyber insurance is gradually transitioning from optional coverage to a commercial requirement. Some clients are beginning to condition their calls for tenders on the presentation of a cyber coverage certificate. Not being insured can become a commercial hindrance even before it is a financial risk.

Field feedback varies on this point: not all sectors have yet integrated this requirement, and maturity varies greatly by industry. The Chambers of Commerce and Industry of Hauts-de-France, for example, are already urging companies to anticipate these obligations. Other regions remain behind.

Executive liability and liability insurance

NIS 2 introduces the possibility of personal sanctions for executives in case of failure to meet cybersecurity obligations. This liability is not systematically covered by a standard cyber insurance policy. It falls under directors’ liability insurance (D&O), a separate contract whose interactions with the cyber policy need to be verified.

The interplay between cyber insurance and directors’ liability insurance is a frequent blind spot in the protection of mid-sized companies.

Company director consulting a cyber insurance interface on a tablet in a server room

Reading a cyber policy: the clauses that determine true coverage

Beyond the premium amount and overall limit, three contractual elements condition the real utility of cyber insurance in the event of an incident.

  • The scope of covered data: some policies exclude unencrypted data or data stored on personal devices (BYOD), significantly reducing the scope of coverage.
  • The definition of the triggering event: does a detected but inactive ransomware constitute a claim? The answer varies from one insurer to another and conditions the initiation of coverage.
  • The prevention obligations imposed on the insured: some policies stipulate a loss of coverage if the company has not kept its security patches up to date or has not conducted an audit in the last twelve months.

These technical clauses are not always included in the commercial documentation. They can be found in the special conditions, sometimes in annexes. A cyber contract is read backwards, starting from the exclusions.

The cyber insurance market is evolving rapidly, driven by contradictory dynamics: falling prices, rising claims, tightening regulations. A company that subscribes without analyzing these three dimensions (pricing, actual coverage scope, regulatory obligations) risks paying for protection that will not trigger at the critical moment.

Why Understanding Cyber Risk Insurance is Essential to Protect Your Business