惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
F
Fortinet All Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
S
Secure Thoughts
SecWiki News
SecWiki News
Hacker News: Ask HN
Hacker News: Ask HN
Google DeepMind News
Google DeepMind News
N
Netflix TechBlog - Medium
Recorded Future
Recorded Future
Hacker News - Newest:
Hacker News - Newest: "LLM"
Webroot Blog
Webroot Blog
Cloudbric
Cloudbric
博客园 - 司徒正美
The Cloudflare Blog
W
WeLiveSecurity
T
Tailwind CSS Blog
V2EX - 技术
V2EX - 技术
H
Heimdal Security Blog
Jina AI
Jina AI
MyScale Blog
MyScale Blog
S
SegmentFault 最新的问题
Apple Machine Learning Research
Apple Machine Learning Research
雷峰网
雷峰网
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Project Zero
Project Zero
C
CXSECURITY Database RSS Feed - CXSecurity.com
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
博客园 - 【当耐特】
Forbes - Security
Forbes - Security
Last Week in AI
Last Week in AI
G
GRAHAM CLULEY
C
Check Point Blog
P
Proofpoint News Feed
L
LINUX DO - 最新话题
博客园 - Franky
P
Proofpoint News Feed
T
Tor Project blog
S
Security @ Cisco Blogs
Hugging Face - Blog
Hugging Face - Blog
阮一峰的网络日志
阮一峰的网络日志
J
Java Code Geeks
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
宝玉的分享
宝玉的分享
C
Cyber Attacks, Cyber Crime and Cyber Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
O
OpenAI News
小众软件
小众软件
云风的 BLOG
云风的 BLOG
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO Overconfidence is the new zero-day as teams stumble through cyber simulations UK's Cyber Security and Resilience Bill makes Parliamentary debut Cyberpunks mess with Canada's water, energy, and farm systems Trump's workforce cuts blamed as America's cyber edge dulls Feds flag active exploitation of patched Windows SMB vuln How malware vaccines could stop ransomware's rampage Salesforce refuses to pay ransomware crims' extortion demand Germany slams brakes on EU's Chat Control snoopfest Germany slams brakes on EU's Chat Control snoopfest Employees regularly paste company secrets into ChatGPT Oracle tells Clop-targeted EBS users to apply July patch Red Hat repos raided, claims cybercrew, files stolen Suspected Chinese spies broke into 'numerous' enterprises UK gov acknowledges 'strong case' for JLR financial support JLR extends shutdown – again – as toll on workers laid bare UK chancellor blames cyberattacks on Russia despite evidence Fortra discloses 10/10 severity bug in GoAnywhere MFT Entra ID bug could have granted access to every tenant UEFI Secure Boot for Linux Arm64 – where do we stand? JLR says cyber cleanup to take additional week Insider blamed for FinWise data breach affecting nearly 700K Nork snoops whip up fake military ID with help from ChatGPT UK government dragged for incomplete security reforms Church of England abuse victims exposed by lawyer's email US spy chief claims UK backdown on Apple backdoor demand Workday confirms CRM breach via social engineering Black Hat/DEF CON: AI more useful for defense than hacking Ex-White House cyber guru talks Microsoft security fails CISA releases malware analysis for Sharepoint Server attack China: US spies used Microsoft Exchange 0-day to steal info Security pros drowning in threat-intel data Identity attacks surge 156% as phishermen get craftier Organizations can’t keep up with supply chain security musts Amazon CISO: Iranian hacking crews ‘on high alert’ UK data watchdog fines 23andMe £2.3M over 2023 breach Employers are demanding too much from junior cyber recruits FCA warned four staffers who pocketed regulator data Ransomware just wrecked your network – now what? Ivanti RCE attacks 'ongoing,' exploitation hits clouds Ex-NSA listened to Scattered Spider's calls: 'They're good' Snowflake CISO talks lessons learned from breaches, improv Why CVSS is failing us and what we can do about it Infosec pros still aren't nailing the basics of AI security Ransomware crims targeting systems between IT and operations Why aggregating asset inventory leads to better security NCSC and industry at odds over how to tackle shoddy software Powerschool extortionists may not have deleted stolen data CrowdStrike trims workforce by 5 percent, aims to rely on AI NSO Group must pay Meta $168M in WhatsApp spy case Ghost in the shell script: Boffins seek code correctness How Intruder finds what others miss in cloud security Linux malware can avoid syscall-based endpoint protection Infosec pro blabs about alleged malware mishap on LinkedIn The future of AI in cybersecurity in a word – optimistic CVE board 'kept in the dark' on funding, members say Security snafus caused by third parties up from 15% to 30% Blue Shield shared 4.7M people's health info with Google Ads Who needs phishing when your login's already in the wild? US cyber defenses are being dismantled from the inside Bug hunter obtains an SSL cert for Alibaba Cloud in 5 steps
Cyber insurers paid out over twice as much for UK ransomware attacks last year
2025-11-11 · via The Register - Security: CSO

The number of successful cyber insurance claims made by UK organizations shot up last year, according to the latest figures from the industry's trade association.

The Association of British Insurers (ABI) said £197 million ($259 million) in cyber insurance payouts were made to victimized organizations in 2024, up from £59 million ($77 million) in 2023.

ransomware

UK to ban ransomware payments by public sector organizations

READ MORE

Cyber insurance companies are a controversial part of the security market. Some argue the minimum standards they enforce on policyholders drive up security standards, while others have accused them of encouraging criminals to extort by making payments to ransomware crews.

ABI data showed that ransomware and malware infections contributed to 51 percent of the claims made by UK organizations in 2024. This percentage increased markedly year-over-year, with ransomware and malware making up 32 percent of all claims in 2023.

The ABI said the surge in attacks leading to policy payouts illustrates an increase in sophistication and the damage cyberattacks are having on businesses.

"Cyber insurance is more than just a financial safety net," said Jonathan Fong, head of general insurance policy at the ABI. "The right policy not only supports businesses in the aftermath of an incident but can also help prevent attacks through access to expert advice, threat monitoring, and incident response planning. 

"With cyber threats continuing to grow in scale and sophistication, it needs to be a critical component of every organisation's modern risk management strategy."

The ABI's most recent data pertains to the period before the wave of digital heists on major British businesses began this year.

These included retailer Marks & Spencer, which last week reconfirmed to investors that it made a maximum £100 million ($131 million) claim on its cyber insurance policy, suggesting that 2025's data could lead to further increases in total payouts.

Officials at fellow besieged retailer Co-op confirmed in September the company did not hold comprehensive cyber insurance in place at the time of its April attack, and it would not make a claim on the limited-scope policy.

CFO Rachel Izzard told Reuters: "We had the front-end elements of cyber insurance in place in terms of the immediate response capabilities in the technology space for third parties, but we don't believe we will be claiming on insurance for back-end losses."

Jaguar Land Rover reportedly did not have a cyber insurance policy in place at the time of its hugely costly cyberattack this year. When The Reg asked the org about this, a JLR spokesperson told us: "We do not comment on commercial matters such as these." Ultimately, the UK government had to step in with a landmark support package to help the automaker, and the smaller businesses across its supply chain, financially recover.

Even if JLR did have a cyber insurance policy in place at the time - however comprehensive it might have been - it is unclear whether the massive costs associated with its downtime would have been materially eased by an insurance payout.

The circa £2 billion ($2.6 billion) costs of its attack could be compared to those of Change Healthcare in the US, whose ALPHV ransomware attack in 2024 also led to costs exceeding $2 billion.

Industry figures have debated the role and efficacy of cyber insurance for years. 

At the UK National Cyber Security Centre's (NCSC) annual conference earlier this year, the matter of cyber insurance was one of the few topics all the top expert panellists agreed on, offering support for its role in improving security standards.

The prevailing takeaways from the CYBERUK session were that insurers hold decades of expertise in assessing risk, and they have access to the most pertinent threat intelligence affecting modern organizations, which informs their policy requirements.

If organizations can't meet them – i.e. they don't implement the baseline standards required to defend against the most successful modern attacks – they don't get a policy.

On the other side of the debate sit those who believe insurers are encouraging ransom payments.

Anne Neuberger, chief of cyber under the Biden administration, argued last year for a ban on insurers from covering extortion payments, claiming current policies incentivize payments, which in turn fuel cybercriminal operations.

Others who spoke to The Register at the time disagreed. 

Monica Shokrai, Google Cloud's head of business risk and insurance, said: "I'm not convinced that banning the ransom from being paid by cyber insurance policies will remediate the issue."

"In the case of large companies, cyber insurance will still cover the cost of the incident and the ransom itself often isn't material, particularly compared to the cost of business interruption that a large corporation may face. 

"So, if larger companies continue to pay the ransom despite insurance not covering it, the impact of a ban on the insurance coverage becomes less meaningful."

Others argued that a payment ban was too reductive a countermeasure, saying the root cause of rising payments was due to "widespread digital insecurity." ®