Two cyber insurance providers disclosed in a recent whitepaper the critical need for greater public sector involvement to strengthen societal resilience in the event a catastrophic cyber event occurs. The Marsh McLennan-Zurich document emphasizes the urgent need for ‘innovative’ solutions to close the gap between risk and insurance – particularly for small and medium-sized businesses that are often uninsured or underinsured, as rapidly evolving cyber threats are outpacing the capacity of traditional insurance and risk management solutions to fully mitigate them. 

In a whitepaper titled ‘Closing the cyber risk protection gap,’ Marsh McLennan and Zurich Insurance Group noted that the global cost of cybercrime is projected to increase to nearly US$24 trillion by 2027, up from close to #8.5 trillion in 2022. However, this estimate does not include the cost of non-malicious events, such as those witnessed in the recent CrowdStrike outage. It also highlights mass malware and mass cloud outages as examples of cyber incidents that are currently considered insurable up to a certain level of financial loss, and events such as critical infrastructure failure, which are generally considered uninsurable.

“Cyber threats are outpacing the ability of traditional insurance and risk management approaches to fully mitigate them. The resulting cyber risk protection gap is a societal challenge that urgently needs collective action from both the insurance industry and the public sector,” John Q. Doyle, president and chief executive officer at Marsh McLennan, and Mario Greco, group chief executive officer at Zurich Insurance Group, wrote in the foreword. “In this report, Zurich, the global multi-line insurer, and Marsh McLennan, a global professional services firm in the areas of risk, strategy, and people, have joined forces to suggest ways of addressing the cyber risk protection gap. We consider strategies to enhance the functionality and risk–bearing capacity of the private cyber insurance market, identify areas of limited insurability and non-insurability, and suggest principles for public-private partnerships to address these critical issues.” 

They noted that from strengthening resilience to managing catastrophic risk, re/insurers, governments, and technology providers should strive to establish the right partnerships so that the industry is better placed to offer more cyber risk protection, and to ensure that there are viable solutions in place should an extreme cyber incident occur. 

The Marsh McLennan-Zurich whitepaper added that better risk models and knowledge-sharing partnerships will help insurers expand the scale and scope of cyber protection. “However, given the potential impact of connected cyber risk and the high claims cost related to extreme cyberattacks on, for instance, critical infrastructure, there are limits to the amount of financial loss the re/insurance industry can absorb.”

Catastrophic cyber incident scenarios can be classified into incidents that are considered insurable up to a certain level and incidents that are generally considered non-insurable, due either to lack of insurer risk appetite or being against conventional public policy. The categorization is based on criteria including the nature of the cyberattack, its spread, the nature of the damages caused, and the economic loss at stake. 

“Simultaneously, there is a commonly held view of non-insurability. If a cyber incident results in a critical infrastructure failure — related to areas including power outage, financial market infrastructure, utility supply, telecommunications, internet access, or satellite systems — the risks have a significant accumulation potential,” the Marsh McLennan-Zurich whitepaper identified. “Potentially accumulating risks are currently regarded as unmanageable due to a lack of visibility regarding the resilience of connected entities to manage the dependencies on these critical infrastructures. With widespread use of digital technologies, single points of failure could have far-reaching implications.” 

As evidenced by the recent CrowdStrike incident, major IT outages — including those caused by a simple, yet apparently defective, ‘content update’ — could potentially cascade into catastrophic cyber incidents when there is a lack of public-private coordination. 

The Marsh McLennan-Zurich whitepaper also observes that it is also possible that some organizations might have experienced less damage had they built in measures including quicker patching of systems, information sharing, and stronger defenses of downstream entities. With the accumulation of catastrophic vulnerabilities, the ways to execute future attacks multiply, and the number of threat actors grows, raising the need for alternative mitigation measures that include some sort of public sector involvement.

It also pointed out that developing a better understanding of how to include more prominent public sector involvement in addressing potentially catastrophic cyber risks will help bring much-needed clarity to businesses, brokers, and insurers alike. 

The insurance industry and the public sector must continue to work together to educate and incentivize insurance buyers by fostering cybersecurity maturity and ensuring its affordability — if necessary, through the use of measures such as governmental subsidies. Many governments around the world have developed education and information–sharing resources. 

The Marsh McLennan-Zurich whitepaper further details that cyber risk is now akin to these other risks. “The need for a public-private approach for cyber risk has emerged from the continuing transformation of the digital economy, the blending of physical processes with virtual control, and the growing role and expanding capabilities of new technologies, most recently, generative AI.” 

The insurance industry has turned its attention to risks affecting critical infrastructure or nation-state attacks that result in a ‘major detrimental impact’ on essential services, reflecting the potential magnitude of losses from an unquantifiable cyber incident. This has led to the development of evolved infrastructure exclusions and a new style of war exclusions in cyber policies. These, in turn, shine a spotlight on the ensuing coverage gap stemming from those risks that are considered unquantifiable, and therefore call out for some sort of public-private partnership.

The Marsh McLennan-Zurich whitepaper mentioned that properly designed, a government framework can create a mechanism that enhances efficiency, thus reducing the economic impact of a catastrophic cyber incident. Any solution, regardless of its precise design and to be effective and efficient, should follow a set of principles that addresses the connected and/or catastrophic nature of these risks; recognizes the different needs and behaviors between SMBs and large firms; and reflects the need for widespread accessibility and affordability. 

It must also enhance the cyber resilience of the global economy; use efficient delivery mechanisms by leveraging insurers’ actuarial, financial, administrative, and distribution expertise; and respect the fundamental need for risk-oriented pricing to avoid misaligned incentives. 

The Marsh McLennan-Zurich whitepaper also noted that the government plays multiple essential roles in addressing catastrophic cyber risks. For example, the government can marshal resources at a scale beyond any private sector organization. In addition, governments can establish policies and regulations to bring a ‘whole-of-government’ approach to develop preparedness and build resilience. Such initiatives should derive from a collaborative effort between government and industry. The majority of US critical infrastructure remains owned or controlled by the private sector. In addition, industry may bring expertise and innovation that lift the effort to success. 

Furthermore, collaboration with industry also brings the opportunity to share data, so that both may close vulnerabilities and combat threats. Doing so will require overcoming various obstacles to creating a common framework for data sharing, including current legal constraints regarding privacy, the lack of a common language regarding incidents, conflicting data guidelines, and limited incentives. 

In its conclusion, the Marsh McLennan-Zurich whitepaper called for strengthening society’s cyber resilience is inextricably linked to the evolution of the cyber insurance market. Creating a virtuous cycle — via incentivizing cyber hygiene best practices, fostering public-private collaboration and recovery mechanisms, and establishing a common framework for structured data collection/sharing — positions the market to protect businesses against their most pressing cyber risks, fulfilling its ultimate purpose. 

The insurance industry and the public sector are urged to collaborate, share, and innovate to confront the growing cyber risk protection gap, foster resilience, and safeguard society and economy from the escalating cyber threat landscape.

In May this year, S&P Global reported that growth in the US cyber insurance market has stalled due to increasing threats. Premiums in the market dipped slightly in 2023 after several years of rapid growth, amidst falling prices and emerging new threats. Direct written premiums for stand-alone and package cyber business combined fell 0.7 percent to $7.18 billion in 2023 from $7.24 billion in 2022, according to S&P Global Market Intelligence data. Although a small drop, it ends a prolonged period of rapid growth in cyber premium volume.

The fall was driven by stand-alone business, where direct written premiums fell 3.2 percent to $4.93 billion. This was partly offset by a 5.1 percent growth in the package business. By contrast, direct premiums for stand-alone businesses grew by 62 percent year on year in 2022 and 91 percent in 2021.


Anna Ribeiro


Industrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.