{"id":80727,"date":"2026-06-10T12:01:28","date_gmt":"2026-06-10T12:01:28","guid":{"rendered":"https:\/\/www.europesays.com\/ch\/80727\/"},"modified":"2026-06-10T12:01:28","modified_gmt":"2026-06-10T12:01:28","slug":"marsh-mclennan-zurich-whitepaper-flags-growing-cyber-risk-protection-gaps-issues-call-to-action","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ch\/80727\/","title":{"rendered":"Marsh McLennan-Zurich whitepaper flags growing cyber risk protection gaps, issues call to action"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Two cyber insurance providers disclosed in a recent whitepaper the critical need for greater <a href=\"https:\/\/industrialcyber.co\/industrial-cyber-attacks\/cisa-issues-ics-advisories-highlighting-vulnerabilities-in-critical-infrastructure-systems-medical-devices\/\" rel=\"nofollow noopener\" target=\"_blank\">public sector involvement<\/a> to strengthen societal resilience in the event a catastrophic cyber event occurs. The Marsh McLennan-Zurich document emphasizes the urgent need for \u2018innovative\u2019 solutions to close the gap between risk and insurance \u2013 particularly for small and medium-sized businesses that are often uninsured or underinsured, as <a href=\"https:\/\/industrialcyber.co\/reports\/sp-global-reports-profitability-return-in-global-cyber-insurance-market-as-reinsurers-emerge-crucial-for-growth\/\" rel=\"nofollow noopener\" target=\"_blank\">rapidly evolving<\/a> cyber threats are outpacing the capacity of traditional insurance and risk management solutions to fully mitigate them.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In a whitepaper <a href=\"https:\/\/industrialcyber.co\/download\/closing-the-cyber-risk-protection-gap-marshmclennan-zurich\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">titled<\/a> \u2018Closing the cyber risk protection gap,\u2019 Marsh McLennan and Zurich Insurance Group noted that the global cost of cybercrime is projected to increase to nearly US$24 trillion by 2027, up from close to #8.5 trillion in 2022. However, this estimate does not include the cost of non-malicious events, such as those witnessed in the recent <a href=\"https:\/\/industrialcyber.co\/it-ot-collaboration\/crowdstrike-update-leads-to-disruption-across-critical-infrastructure-environments\/\" rel=\"nofollow noopener\" target=\"_blank\">CrowdStrike outage<\/a>. It also highlights mass malware and mass cloud outages as examples of cyber incidents that are currently considered insurable up to a certain level of financial loss, and events such as <a href=\"https:\/\/industrialcyber.co\/cisa\/critical-infrastructure-under-attack-as-us-agencies-sound-alarm-on-cyber-threat-from-iranian-linked-groups\/\" rel=\"nofollow noopener\" target=\"_blank\">critical infrastructure<\/a> failure, which are generally considered uninsurable.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCyber threats are outpacing the ability of traditional insurance and risk management approaches to fully mitigate them. The resulting cyber risk protection gap is a societal challenge that urgently needs collective action from both the insurance industry and the public sector,\u201d John Q. Doyle, president and chief executive officer at Marsh McLennan, and Mario Greco, group chief executive officer at Zurich Insurance Group, wrote in the foreword. \u201cIn this report, Zurich, the global multi-line insurer, and Marsh McLennan, a global professional services firm in the areas of risk, strategy, and people, have joined forces to suggest ways of addressing the cyber risk protection gap. We consider strategies to enhance the functionality and risk\u2013bearing capacity of the private cyber insurance market, identify areas of limited insurability and non-insurability, and suggest principles for public-private partnerships to address these critical issues.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">They noted that from strengthening resilience to managing catastrophic risk, re\/insurers, governments, and technology providers should strive to establish the right partnerships so that the industry is better placed to offer more cyber risk protection, and to ensure that there are viable solutions in place should an extreme cyber incident occur.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Marsh McLennan-Zurich whitepaper added that better risk models and knowledge-sharing partnerships will help insurers expand the scale and scope of cyber protection. \u201cHowever, given the potential impact of connected cyber risk and the high claims cost related to extreme cyberattacks on, for instance, <a href=\"https:\/\/industrialcyber.co\/critical-infrastructure\/critical-infrastructure-faces-30-percent-surge-in-cyber-attacks-knowbe4-report-highlights\/\" rel=\"nofollow noopener\" target=\"_blank\">critical infrastructure<\/a>, there are limits to the amount of financial loss the re\/insurance industry can absorb.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Catastrophic cyber incident scenarios <a href=\"https:\/\/www.marsh.com\/en\/about\/media\/public-private-action-to-bridge-cyber-protection-gap-and-boost-resilience.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">can be classified<\/a> into incidents that are considered insurable up to a certain level and incidents that are generally considered non-insurable, due either to lack of insurer risk appetite or being against conventional public policy. The categorization is based on criteria including the nature of the cyberattack, its spread, the nature of the damages caused, and the economic loss at stake.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cSimultaneously, there is a commonly held view of non-insurability. If a cyber incident results in a <a href=\"https:\/\/industrialcyber.co\/threat-landscape\/critical-infrastructure-continues-under-threat-as-hackers-strike-at-port-of-seattle-and-halliburton-oilfield\/\" rel=\"nofollow noopener\" target=\"_blank\">critical infrastructure failure<\/a> \u2014 related to areas including power outage, financial market infrastructure, utility supply, telecommunications, internet access, or satellite systems \u2014 the risks have a significant accumulation potential,\u201d the Marsh McLennan-Zurich whitepaper identified. \u201cPotentially accumulating risks are currently regarded as unmanageable due to a<a href=\"https:\/\/industrialcyber.co\/threats-attacks\/cyber-attacks-give-boost-to-cyber-insurance-market-but-challenges-are-many\/\" rel=\"nofollow noopener\" target=\"_blank\"> lack of visibility<\/a> regarding the resilience of connected entities to manage the dependencies on these critical infrastructures. With widespread use of digital technologies, single points of failure could have far-reaching implications.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">As evidenced by the recent CrowdStrike incident, major IT outages \u2014 including those caused by a simple, yet apparently defective, \u2018content update\u2019 \u2014 could potentially cascade into catastrophic cyber incidents when there is a lack of public-private coordination.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Marsh McLennan-Zurich whitepaper also observes that it is also possible that some organizations might have experienced less damage had they built in measures including quicker patching of systems, information sharing, and stronger defenses of downstream entities. With the accumulation of catastrophic vulnerabilities, the ways to execute future attacks multiply, and the number of threat actors grows, raising the need for alternative mitigation measures that include some sort of public sector involvement.<\/p>\n<p class=\"wp-block-paragraph\">It also pointed out that developing a better understanding of how to include more prominent public sector involvement in addressing potentially catastrophic cyber risks will help bring much-needed clarity to businesses, brokers, and insurers alike.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The insurance industry and the public sector <a href=\"https:\/\/industrialcyber.co\/news\/cisa-and-fbi-issue-updated-alert-on-blacksuit-ransomware-targeting-critical-infrastructure-sectors\/\" rel=\"nofollow noopener\" target=\"_blank\">must continue to work<\/a> together to educate and incentivize insurance buyers by fostering cybersecurity maturity and ensuring its affordability \u2014 if necessary, through the use of measures such as governmental subsidies. Many governments around the world have developed education and information\u2013sharing resources.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Marsh McLennan-Zurich whitepaper further details that cyber risk is now akin to these other risks. \u201cThe need for a public-private approach for cyber risk has emerged from the continuing transformation of the digital economy, the blending of physical processes with virtual control, and the growing role and expanding capabilities of new technologies, most recently, <a href=\"https:\/\/industrialcyber.co\/features\/managing-cyber-risk-challenges-from-emerging-technologies-including-generative-ai-across-ot-sector\/\" rel=\"nofollow noopener\" target=\"_blank\">generative AI<\/a>.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The insurance industry has turned its attention to risks affecting critical infrastructure or nation-state attacks that result in a \u2018major detrimental impact\u2019 on essential services, reflecting the potential magnitude of losses from an unquantifiable cyber incident. This has led to the development of evolved infrastructure exclusions and a new style of war exclusions in cyber policies. These, in turn, shine a spotlight on the ensuing coverage gap stemming from those risks that are considered unquantifiable, and therefore call out for some sort of public-private partnership.<\/p>\n<p class=\"wp-block-paragraph\">The Marsh McLennan-Zurich whitepaper mentioned that properly designed, a government framework can create a mechanism that enhances efficiency, thus reducing the economic impact of a catastrophic cyber incident. Any solution, regardless of its precise design and to be effective and efficient, should follow a set of principles that addresses the connected and\/or catastrophic nature of these risks; recognizes the different needs and behaviors between SMBs and large firms; and reflects the need for widespread accessibility and affordability.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">It must also enhance the cyber resilience of the global economy; use efficient delivery mechanisms by leveraging insurers\u2019 actuarial, financial, administrative, and distribution expertise; and respect the fundamental need for risk-oriented pricing to avoid misaligned incentives.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The Marsh McLennan-Zurich whitepaper also noted that the government plays multiple essential roles in addressing catastrophic cyber risks. For example, the government can marshal resources at a scale beyond any private sector organization. In addition, governments can establish policies and regulations to bring a \u2018whole-of-government\u2019 approach to develop preparedness and build resilience. Such initiatives should derive from a collaborative effort between government and industry. The majority of US critical infrastructure remains owned or controlled by the private sector. In addition, industry may bring expertise and innovation that lift the effort to success.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Furthermore, collaboration with industry also <a href=\"https:\/\/industrialcyber.co\/features\/rising-cybersecurity-demands-reshape-ics-procurement-strategies-across-critical-infrastructure\/\" rel=\"nofollow noopener\" target=\"_blank\">brings the opportunity<\/a> to share data, so that both may close vulnerabilities and combat threats. Doing so will require overcoming various obstacles to creating a common framework for data sharing, including current legal constraints regarding privacy, the lack of a common language regarding incidents, conflicting data guidelines, and limited incentives.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In its conclusion, the Marsh McLennan-Zurich whitepaper called for strengthening society\u2019s cyber resilience is inextricably linked to the evolution of the cyber insurance market. Creating a virtuous cycle \u2014 via incentivizing cyber hygiene best practices, fostering public-private collaboration and recovery mechanisms, and establishing a common framework for structured data collection\/sharing \u2014 positions the market to protect businesses against their most pressing cyber risks, fulfilling its ultimate purpose.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The insurance industry and the public sector are urged to collaborate, share, and innovate to confront the growing cyber risk protection gap, foster resilience, and safeguard society and economy from the escalating cyber threat landscape.<\/p>\n<p class=\"wp-block-paragraph\">In May this year, S&amp;P Global <a href=\"https:\/\/www.spglobal.com\/marketintelligence\/en\/news-insights\/latest-news-headlines\/us-cyber-insurance-growth-stalls-as-threats-ramp-up-81664841\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reported that<\/a> growth in the US cyber insurance market has stalled due to increasing threats. Premiums in the market dipped slightly in 2023 after several years of rapid growth, amidst falling prices and emerging new threats. Direct written premiums for stand-alone and package cyber business combined fell 0.7 percent to $7.18 billion in 2023 from $7.24 billion in 2022, according to S&amp;P Global Market Intelligence data. Although a small drop, it ends a prolonged period of rapid growth in cyber premium volume.<\/p>\n<p class=\"wp-block-paragraph\">The fall was driven by stand-alone business, where direct written premiums fell 3.2 percent to $4.93 billion. This was partly offset by a 5.1 percent growth in the package business. By contrast, direct premiums for stand-alone businesses grew by 62 percent year on year in 2022 and 91 percent in 2021.<\/p>\n<p>\t\t<img loading=\"lazy\" decoding=\"async\" width=\"96\" height=\"96\" src=\"data:image\/svg+xml,%3Csvg%20xmlns=\" https:=\"\" alt=\"\" data-lazy-src=\"https:\/\/www.europesays.com\/ch\/wp-content\/uploads\/2026\/06\/Anna-Ribeiro-min-96x96.jpg\"\/><img loading=\"lazy\" decoding=\"async\" width=\"96\" height=\"96\" src=\"https:\/\/www.europesays.com\/ch\/wp-content\/uploads\/2026\/06\/Anna-Ribeiro-min-96x96.jpg\" alt=\"\"\/><\/p>\n<p>&#13;<br \/>\n\t\t\t\t\tAnna Ribeiro\t\t\t\t<\/p>\n<p>&#13;<br \/>\n\t\t\t\t\tIndustrial Cyber News Editor. Anna Ribeiro is a freelance journalist with over 14 years of experience in the areas of security, data storage, virtualization and IoT.\t\t\t\t<\/p>\n<p>\t<a class=\"post-author-link\" href=\"https:\/\/industrialcyber.co\/author\/annaribeiro\/\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n","protected":false},"excerpt":{"rendered":"Two cyber insurance providers disclosed in a recent whitepaper the critical need for greater public sector involvement to&hellip;\n","protected":false},"author":2,"featured_media":80728,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[128],"tags":[2588,1995,2084,2080,41837,10282,41838,41839,219],"class_list":["post-80727","post","type-post","status-publish","format-standard","has-post-thumbnail","category-zurich-insurance","tag-critical-infrastructure","tag-cyber-insurance","tag-cyber-resilience","tag-cyber-risk","tag-cyber-threats","tag-marsh-mclennan","tag-risk-protection","tag-sp-global","tag-zurich-insurance"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ch\/116725710074219038","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/posts\/80727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/comments?post=80727"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/posts\/80727\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/media\/80728"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/media?parent=80727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/categories?post=80727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ch\/wp-json\/wp\/v2\/tags?post=80727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}