GENERAL

Why Cyber Insurance Claims Are More Frequently Being Rejected

Listen to the podcast on iono.fm

You can also access this podcast on iono.fm here.

JEREMY MAGGS: This is alarming. Nearly half of cyber insurance claims are either denied or only partially approved, as insurers tighten their standards regarding cybersecurity and governance.

A recent worldwide study suggests that many organizations are losing out because their policy declarations do not accurately reflect their real-life situations when a cyber event occurs.

Listen/read: SA earns top spot as target for cyber attacks [2025]

Let’s explore this topic further. Joining me is Muhammad Ali, managing director and cybersecurity and ISO expert at World Wide Industrial & Systems Engineers (WWISE).

Welcome, Muhammad. Let’s discuss that concerning statistic: 47% of claims are denied. Is this primarily due to insurers avoiding payouts, or are companies exaggerating their cybersecurity readiness?

MUHAMMAD ALI: That’s a relevant question, and it’s really a combination of both.

Many organizations believe they are well-prepared. Their IT departments provide reports that instill confidence in top management or the board about their cybersecurity posture.

However, they often make minimal investments in the necessary cybersecurity measures to protect both personal and corporate data.

Cybersecurity is frequently viewed as a cost rather than an investment. Today, the question isn’t if an attack will occur, but when.

ADVERTISEMENT

CONTINUE READING BELOW

Organizations must acknowledge that they will face cyber threats. Various factors contribute to misunderstandings about their security measures.

Some may have policies that look solid on paper but do not match their actual practices. Others might rely on outdated or poorly drafted policies.

Read: IT consultants also need business interruption insurance [2024]

From the perspective of a cyber insurance provider, if you’re paying premiums, they will conduct assessments. They will examine your real security controls, governance, and practices.

There might be an expectation of a payout just because you have cyber insurance, but that’s a misconception. Noncompliance leaves businesses at risk, as they fail to invest in and follow the protocols established in their policies. So, it’s a combination of both factors.

JEREMY MAGGS: What you’re implying is that having cyber insurance isn’t a viable cybersecurity strategy.

MUHAMMAD ALI: Precisely. Cybersecurity ranks among the top ten risks for most large companies; relying solely on cyber insurance is misguided.

While insurance companies can assist in the event of attacks like ransomware, they are not obligated to pay out, a common misunderstanding.

Read: SA businesses vulnerable to cyber attacks [2024]

Organizations often overlook the fine print and fail to fulfill their obligations regarding solid cybersecurity governance.

They are negligent and do not adhere to the fundamental standards of cybersecurity.

JEREMY MAGGS: Let’s address another striking statistic. Ransom demands have skyrocketed to approximately R17 million in South Africa. Is cyber insurance still a viable option at this rate, Muhammad?

ADVERTISEMENT:

CONTINUE READING BELOW

MUHAMMAD ALI: That depends on several factors. Consider denial-of-service attacks: they pose a significant threat. If a ransomware attack occurs, it could halt operations entirely.

If your systems are down for an extended period, the financial losses could amount to millions, not to mention the reputational damage.

If your company is publicly traded, you are legally obligated to notify regulators of an attack, which can lead to serious reputational consequences. It’s essential to weigh the costs of investment against potential returns.

If cyber insurance premiums are high, consider the ramifications of an attack or downtime on business operations, systems, applications, users, and sensitive data, alongside regulatory involvement.

It’s a tricky situation, and it’s crucial to evaluate whether the premiums are worth the coverage. However, there are ways to reduce these premiums.

JEREMY MAGGS: There’s also a trend moving from annual audits to continuous assurance. While I understand your point, do most South African companies possess the technical capability to make this transition?

MUHAMMAD ALI: Currently, there is a significant skills gap, especially in practical skills. Many individuals quickly rise to leadership or management roles.

While that is fine, the technical expertise required to interpret firewall rules, understand network security settings, and grasp default configurations is often lacking.

Listen: Insurance trends: Storm-proofing your business

Companies require technically skilled personnel to identify threats and vulnerabilities and ensure systems and applications remain up-to-date.

There is a knowledge gap in South Africa, making us precarious targets for ransomware attacks, particularly in sectors like healthcare and banking.

Listen/read: AI-powered scams targeting South African banks, insurers, and retailers

The global community perceives us as negligent or under-skilled, making us an attractive target. We need to improve our education and skill sets and be honest with ourselves about our understanding of cybersecurity.

JEREMY MAGGS: Before we conclude, for any CEOs or CIOs listening, what’s the one control they should prioritize to avoid joining that 40%?

MUHAMMAD ALI: It’s essential to align with internationally recognized best practice standards. Start with that.

Insurance providers may not stress this, but whether it’s ISO 27001 or the NIST framework, adhering to these standards and effectively applying controls can lead to a significant reduction in cyber insurance premiums, sometimes by up to 50%.

Moreover, regular external audits and strong internal controls will bolster overall organizational security and improve employee understanding, preventing them from falling prey to cyber threats.

Read: Sarb strengthens defenses against cyber attacks [2025]

This approach not only enhances the organization’s security posture but also empowers individuals with practical knowledge to evade cyber threats. I recommend this as a foundational standard for any CEO or executive.

JEREMY MAGGS: Thank you, Muhammad Ali, managing director of cybersecurity and ISO expert at WWISE. It’s been a pleasure speaking with you.

Follow Moneyweb’s in-depth finance and business news on WhatsApp here.

Leave a Reply

Your email address will not be published. Required fields are marked *