Go back

GCP Short: Evolving cyber market and the role for captives

21m 43s

GCP Short: Evolving cyber market and the role for captives

This discussion between Zurich Insurance experts examines the evolving cyber insurance market and the role of captives. Nick Pritchard notes the market is currently advantageous for buyers, characterized by unprecedented capacity, innovative products with integrated risk services, and mature incident response solutions. However, he cautions that long-term challenges like rising ransomware, AI threats, and geopolitical instability persist. Recent high-profile UK cyber attacks have tangibly demonstrated the impact of such events, leading to a surge in new policy purchases and existing clients reassessing their coverage adequacy and actively using risk management services. On the captive front, Esme Gold explains that despite a softer market, interest in using captives for cyber risk remains strong. Captives provide a long-term strategic tool to navigate market cycles, secure higher coverage limits, and offer greater control. Nick adds that Zurich values captive involvement because it fosters heightened client engagement, leading to more transparent risk discussions, accurate pricing, and efficient claims handling. Ultimately, captives help create more robust, cost-effective, and tailored cyber insurance programs by aligning the interests of the insured and the insurer.

Transcription

3424 Words, 19624 Characters

English
Hello and welcome to this GCP Short produced in partnership with Zurich Insurance and taking a look at the state of the commercial cyber market and the current trends in how corporates are using their captive. Joining me for the next 20 minutes are Esme Gold, Head of Captives and ART and Nick Pritchard, senior cyber liability underwriter both at Zurich Insurance Company, UK. In our conversation, Nick explains how cyber insurance is evolving, the response of the market and buyers to recent high-profile loss events, particularly in the United Kingdom, and why a captive's involvement is often viewed favorably by the carrier. Esme explains the different ways captives take part in cyber programs and the activity she has seen from customers. So Nick, great to have you on to the global captive podcast for the first time and to talk about cyber again. The global cyber insurance market continues to evolve and I think possibly general consensus is it is a better time for buyers in the commercial market now than it was two to three years ago. Do you agree of that? Is that correct and what is driving the current market dynamic? Thanks very much for having me on the podcast. I think first and foremost, I absolutely do agree with that statement. Fundamentally, there has never been a better time to buy cyber insurance and that's due to I guess a couple of reasons. First one being there is a fantastic choice for buyers at the moment. The levels of capacity in the market are unprecedented in terms of the short history of the cyber insurance market. The next thing I would say is that actually in terms of the innovation that has gone on in terms of products from a wording perspective but also from a development of risk management services, propositions that come often tied with insurance products or through broker offerings. That is at a new level. There is new levels of creativity, everything from scanning tools, to soft consultancy services, to outreach services during policy periods and also kind of discounting of vendor tooling as well. I think the final point to highlight would just be in terms of the maturity of the products. Obviously a key and fundamental part of the cyber insurance solutions is actually at how does the policy operate in the event of an incident. In terms of those claim solutions, they are now far more tried and tested than they have ever been, whether that is for an in-house solution, an outsource solution or some form of hybrid of that. Some of the outsource vendors in the ecosystem have dealt with thousands of incidents now and so there has never been a better time to get a kind of assurance around the quality of the service that you are going to be able to get in the event of that worst case scenario. I would caution that slightly in terms of that direction of the market travel. I think it is quite right to note that actually the prevalence of kind of ransomware and ransom demand events has kind of exploded in different areas in recent years. I read a recent report from SRM that stated that actually the number of threat actor groups that they observed in 2024 was just under double the amount that were around in 2023. You also combine that with the kind of number of class action suits in relation to wrongful collection mainly in the US. On top of that, the explosion of use of artificial intelligence over the last couple of years and the uncertainty that brings, actually you have got a kind of perfect storm of different types of losses that are coming together. That is all with the backdrop of actually some really bi-friendly environments for the last couple of years. We have seen two or three years of significant rate reductions that cannot go on forever. It is a great time to buy right now. That is set to continue but there are things on the horizon that might challenge that in the long term. Obviously, we have had some pretty high profile recent cyber events, particularly here in the UK. How do you see those kind of events drive behaviour and activity both from buyers and also you guys as the underwriters? It has been a really interesting period to be involved in cyber insurance. A really busy period as well from an underwriting. I suppose a broken perspective too. I think the first thing I would highlight is this. Yes, we have seen some incredibly high profile incidents in the UK this year. But that is not to say that these kind of events haven't been around. I mean, I look at some of the data from the ICO in 2024. There was 32 different enforcement actions relating to GDPR breaches in 2024. So it suggests that the events have been going on. Our claims experience suggests that too. But I think what is different this time is actually at all levels, whether it is a general public level, an organisational level or actually a governmental level. People are starting to feel the impacts and effects in a very different way. So this is probably the first time that people have in the UK have walked into their local supermarkets with their favourite supermarkets and seen some of their shells empty. And that is not because of supply chain shortages. It has been off the back of cyber incidents. It is also one of the first times that actually people in certain instances haven't been able to go into work because there has been factory shutdowns for instance. People are seeing the kind of real tangible impact of a cyber attack that would go beyond just the breach of an email address and contact number. And that is really beginning to resonate. It is starting conversations. And it is increasing the amount of press on these kind of incidents. So I guess what that is led to and what we have observed at Zurich is firstly an increase in buying rates. I look back and compare our three months post, one of the first large high profile incidents in the UK this year and compare that to the same period for 2024. And actually the number of new policies the Zurich bound in that period is actually double year on year. Not all of that is going to be driven by first time buyers but response and reaction to two of those incidents. But it goes to show that there is some movement there. And it is not just first time buyers that are peaking their interests with. It is also existing buyers that are re-evaluating actually the adequacy of their existing program, the adequacy of their limits. And they are coming back midterm and saying can we increase that limit to a more appropriate level. I think the other two pieces on changes in buyer behaviour is actually around things like evaluation of limit adequacy. That is one piece of it. I mentioned earlier that actually insurers, brokers and vendors in this ecosystem are offering a far more broad suite of risk management services as part of the risk transfer solutions. And actually our customers are taking advantage of that. They are utilising those services to a greater extent than they have done in previous years, whether they are using them to undertake cyber risk quantification analysis to support with things like the limit adequacy. Or actually they are testing their response readiness through tabletop exercises. There is a whole broad suite of services that are being activated in a way that they probably haven't been in the in prior years. And I think the final piece is actually just an evaluation of the appropriateness of the coverage that is within some of the policy wording. Specifically in relation to things like supply chain cover. So actually some of those large UK high profile instance this year haven't just had an impact on the organisation that has been the target of the attack. Actually their suppliers and in certain instances their customers have also been impacted too. So it is actually well how fit for purposes is some of that. This isn't just a challenge for the UK, these events have always been there. They've been there at different times in intensities in different regions. But this is also picked interest from our customers abroad. They want to understand what's gone on with these incidents, how the insurance markets responding and does it have any impact for the approach to their cyber insurance programmes. And so I guess in terms of how that has led to an impact to underwriting. Firstly under item broke has to respond to that increase in demand. Which is it's been a challenge but the market has certainly stepped up in terms of service levels and ensuring that those customers that want cover now or in the next week or the next couple of weeks they're able to get those services as soon as possible. I think in terms of well actually some of the UK high profile incidents to what extent have they impacted the profitability of the market and that's led on to some I guess more aggressive underwriting action. Actually I think the message is really positive. There's been an incredibly mature response from insurers. We haven't seen this a needy at response in terms of withdrawal capacity or a major hiking rates. It's actually been more around kind of the continuity of service. And also well actually this is a often it's been a relatively new novel route of attack. So it's well actually what can we learn from these incidents. How can we talk to our customers about this and to ensure that they're in the best possible place to prevent and mitigate any potential events that might transpire off the back of it. So that's diving into things around protection of IT help desk and service desk. But it's also having a better understanding reliance on and understanding the reliance on of critical third parties as well. So yeah there's been there's been major shifts in buying activity but there's also been been I guess there's been an adequate response from underwriting and in quite a I guess a sensible and reasoned and measured way. So as may that's the kind of some of the commercial market landscape and outlook and that's really useful to have that from Nick. So thank you but on the captive side then because and it's always good to get that commercial market insight first because obviously captives don't exist in a vacuum and people tend to use their captives in tandem with the commercial market. How do you assess as made a current appetite among in short to use their captives to write cyber or or pass their program. How has a softer market led to less capitalisation or is it still very much kind of on the increase to the captive role. Thanks Richard and thanks for having me. It's great to be back on the global captive pull cost. I think where it comes to cyber and captives if we go back a couple of years we saw a lot of in shards exploring the option of adding cyber into their captive. In the current environment you might expect this to have changed but a captive is a long-term solution which is designed to navigate all stages of the cycle plus many in shards have a captive first model as well so that was demonstrated in the 2025 MX stats which in also indicated that just under 30% of their members with captives are writing cyber. So I think that coupled with in the 2025 global risk report cyber came up as risk number five on that so it's still very high on the risk management agenda so we are still seeing traction in the captive cyber area. I'd certainly echo that as many in terms of take up of captives. The pace at which I guess captives were using cyber insurance two, three years ago there was a real acceleration but we are still seeing new buys come to market and utilise their captive for cyber insurance as well and I think just to highlight one or two of the points you mentioned there I think the first one being utilisation of a captive to stem volatility in market cycles. I think it's fair to say that the expectation around market cycles in the cyber insurance market is that it's likely to be heightened for a couple of reasons things like the the product age it's still relatively in its infancy despite it's I guess the progress is made over the last five to ten years. I mentioned AI earlier we yet to see the impact of AI really bleed into the cyber insurance claims landscape today it's it's it's AI's really been used to optimize social engineering tactics but the restores in the press very recently around actually the the use of AI for more wholesale attacks on on organisations I think well actually there's a lot of unknowns as to where that's where that's heading is that going to lead to an increase in frequency increase in severity and how did it had organisations to adequately respond and and defend against that. I think the other piece neither two pieces really are just just around firstly cyber insurance and cyber activities largely influenced by geopolitics and we were in a relatively unstable period at the moment and I think the final piece is the speed of change of legislation this is a relatively new risk and so legislation is is trying to keep up with that and and so with different territories and regions changing legislation at different places that leads to a little bit more than unsettled environment and can lead to can lead to a little bit more uncertainty around around claims expectations I suppose and so utilisation of a captive to stem some of that that volatility is a really powerful and useful tool I think the second point I'd add is is actually off the back of what we mentioned early in terms of the insured's really re-evaluating limit adequacy one of the one of the really effective ways of building adequate limit is to actually utilise a large captive placement lower down the programme and so we've seen customers do that time and time again in order to kickstart that programme to get up to the to the high limits and access capacity from all areas of the market so there is certainly still a relevance around captive's even even during a softer spell in the cyber insurance market yeah I think it's definitely the case that nowadays we see captive's play a role a more varied role in in programmes and have depending on the parent company's priorities and objectives obviously the captive can fit into different parts of the programme as may one of the main considerations for companies when they are assessing whether to use their captive or not in their cyber programmes. Thanks so with my underwriting hat on have they understood and accurately quantified the risk I think Nick talked a bit about risk quantification earlier whilst fronting is our core Zurich proposition we see engagement with our resilient solution colleagues by insured and captive supporting their cyber risk quantification. Other cyber resilience measures would need to be part of the overall programme for how they're handling their risk so I'd expect to see all that due diligence sitting behind a decision on whether or not to use their captive and if we focus a bit more on the captive obviously it would depend on the advice from their captive consultant or captive manager but there would likely be a need to assess the capital requirements and diversification impact of adding any line of business to a captive. And what are the different structures a captive can be used to support a cyber programme? So as a relatively new line of business often with limited prior loss experience and low frequency expectations we've worked closely with Nick and our expert cyber underwriters to develop an innovative approach to our fronting exposure assessment and this is to ensure we can deliver for insured captives and the broker timeline expectations in this field. Structurally as with all lines of business we predominantly see captives taking the primary layer of a risk. That said cyber is often placed in towers so this gives the captive choice to participate in the layer that suits them and the overall placement best. I think where we talk about the interest in potentially buying increased limits for this field where additional limits are considered the insured can work with the captive appetite to optimise their placement in the overall programme. And so Nick actually last year in March we hosted an event in Brussels where one of your colleagues Tom Clayton was on with some of your Zurich captive colleagues from Zurich and it became very obvious on that panel that Zurich does like to see captive participation when underwriting a cyber programme. Can you explain maybe if that is still the case and why does the captives involvement often help you as underwriters get confidence in the programme or put the programme together? Yeah absolutely that is still the case. I mean Zurich is really passionate generally whether it's in cyber or other lines of business around working in tandem with our customers and brokers to solve complex risk challenges and cyber is no different to that and I think actually the kind of captive arrangements we've got in cyber and across other lines of business really epitomises that statement around being passionate around working together for a common goal. So we're absolutely still interested in increasing our involvement in this space but I guess just on the point around how does it help underwriters, how does it help Zurich get increased confidence in the solutions we're building with our customers. Generally speaking when actually there's a captive involvement we see heightened engagement from our customers and that leads to increased insight sharing and that allows underwriters generally to have a more transparent conversation with our customers around the different services that they offer their approach to risk management of those services that leads to kind of more accurate pricing and tailoring of coverage to their needs. It also helps improve efficiency in the claims handling process. Increased familiarity with the services that Zurich can offer and our outsource partners leads to improved response times and less surprises I suppose in terms of how that claims handling process works which is a better outcome for all involved. It just doesn't just help Zurich underwriters, it does help our customers too. They get increased insight sharing and there's an active feedback loop around that with the increased engagement so they're able to learn from our experiences on the trends we're seeing in our claims, Zurich but also within the wider market and I guess the final point is it actually also allows customers to buy increased limit. It also increases competition above their captive participation too because you're in almost inviting more insurers to attach at a point that perhaps they're more comfortable at so it can create a more cost-effective structure for our customers too. Thanks Nick and I think general benefits of a captive that you've covered a lot of them but the cost control by creating a single holistic platform for risk management captives can improve cash flow management and investment returns, a captive's ability to provide the additional capacity and to control the type and level of risk it retains versus risk transferring it to the commercial insurers is very valuable whatever stage of the market's in. I think better decisions and broader knowledge with a consistent overview of exposures and risk information and insured can make better informed strategic risk management decisions and we talked a bit about legislation, regulation, a captive can help with transparency on that so consolidating risks into a captive can help responding to answer regulatory demands for higher levels of transparency. Great well, Esme and Nick, pleasure to have you on to the Global County podcast. Thank you very much. Thanks very much.

Podcast Summary

Key Points:

  1. The cyber insurance market is currently favorable for buyers due to increased capacity, product innovation, and mature claims services.
  2. High-profile cyber incidents in the UK have raised public awareness, driven increased policy purchases, and led buyers to re-evaluate their coverage limits and risk management services.
  3. Captives remain a relevant and growing tool for corporates to manage cyber risk, offering benefits like stabilizing market volatility, enabling higher coverage limits, and fostering deeper engagement with insurers.
  4. Insurers like Zurich view captive participation positively as it enhances risk insight, improves underwriting accuracy, and leads to more efficient and cost-effective insurance programs.

Summary:

This discussion between Zurich Insurance experts examines the evolving cyber insurance market and the role of captives. Nick Pritchard notes the market is currently advantageous for buyers, characterized by unprecedented capacity, innovative products with integrated risk services, and mature incident response solutions. However, he cautions that long-term challenges like rising ransomware, AI threats, and geopolitical instability persist. Recent high-profile UK cyber attacks have tangibly demonstrated the impact of such events, leading to a surge in new policy purchases and existing clients reassessing their coverage adequacy and actively using risk management services.

On the captive front, Esme Gold explains that despite a softer market, interest in using captives for cyber risk remains strong. Captives provide a long-term strategic tool to navigate market cycles, secure higher coverage limits, and offer greater control. Nick adds that Zurich values captive involvement because it fosters heightened client engagement, leading to more transparent risk discussions, accurate pricing, and efficient claims handling. Ultimately, captives help create more robust, cost-effective, and tailored cyber insurance programs by aligning the interests of the insured and the insurer.

FAQs

Yes, it is currently a favorable time for buyers due to increased market capacity, product innovation, and more mature claim solutions that have been tested through numerous incidents.

These incidents have increased buying rates, prompted existing buyers to reassess their coverage limits, and led to greater utilization of risk management services like cyber risk quantification and tabletop exercises.

Captives help manage market volatility, provide additional capacity, and allow companies to optimize their coverage layers, often by taking primary positions or supporting higher limits in insurance towers.

Captive involvement fosters greater customer engagement and transparency, leading to more accurate pricing, tailored coverage, and improved efficiency in claims handling, benefiting both insurers and insureds.

Key trends include rising ransomware threats, increased use of artificial intelligence, evolving legislation, and a growing suite of integrated risk management services offered alongside insurance products.

Data shows that nearly 30% of captives are writing cyber insurance, reflecting its high priority on risk management agendas and the long-term strategic role captives play across market cycles.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.