惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
I
InfoQ
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
云风的 BLOG
云风的 BLOG
有赞技术团队
有赞技术团队
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
The GitHub Blog
The GitHub Blog
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
G
Google Developers Blog
WordPress大学
WordPress大学
B
Blog
人人都是产品经理
人人都是产品经理
小众软件
小众软件
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
Apple Machine Learning Research
Apple Machine Learning Research
N
Netflix TechBlog - Medium
Last Week in AI
Last Week in AI
博客园 - 聂微东
Jina AI
Jina AI

The Register - Security: CSO

Anthropic's Mythos has The Kettle crew curious, skeptical 'People's Panel' to check if UK wants controversial Digital ID will cost £630K Top npm package backdoored to drop dirty RAT on dev machines Lightning-fast exploits mean patch fast, says Cisco Talos Lightning-fast exploits mean patch fast, says Cisco Talos Smooth criminals talking their way into cloud environments, Google says Cybercrime up 245% since the start of the Iran war Scattered Lapsus$ Hunters seeks women to defraud helpdesks Every day in every way, passwords are getting worse CISA quietly updated ransomware flags on 59 flaws last year Deepfake job seeker applied to work for an AI security firm Deepfake job seeker applied to work for an AI security firm AI-powered cyberattack kits are 'just a matter of time' AI-powered cyberattack kits are 'just a matter of time' FortiGate SSO bug still exploitable despite December patch FortiGate SSO bug still exploitable despite December patch Judge tosses CrowdStrike shareholder suit over 2024 outage DRAM shortage may drive firewall prices higher: analysts Ransomware attacks kept climbing in 2025 as gangs refused to stay dead Around 1,000 systems compromised in ransomware attack on Romanian water agency 1,000 systems pwned in Romanian Waters ransomware attack Half of exposed React servers remain unpatched amid attacks CISA warns spyware crews are breaking into Signal and WhatsApp accounts FCC guts Salt Typhoon telco rules despite espionage risk CISA orders feds to patch Oracle Identity Manager zero-day SEC drops SolarWinds lawsuit that painted a target on CISOs everywhere SEC bails on SolarWinds lawsuit Palo Alto kit sees massive surge in malicious activity amid mystery traffic flood Palo Alto kit sees massive surge in malicious activity Countries use cyber targeting to plan strikes: Amazon CSO
Cyber insurers paid out over twice as much for UK ransomw...
2025-11-11 · via The Register - Security: CSO

The number of successful cyber insurance claims made by UK organizations shot up last year, according to the latest figures from the industry's trade association.

The Association of British Insurers (ABI) said £197 million ($259 million) in cyber insurance payouts were made to victimized organizations in 2024, up from £59 million ($77 million) in 2023.

ransomware

UK to ban ransomware payments by public sector organizations

READ MORE

Cyber insurance companies are a controversial part of the security market. Some argue the minimum standards they enforce on policyholders drive up security standards, while others have accused them of encouraging criminals to extort by making payments to ransomware crews.

ABI data showed that ransomware and malware infections contributed to 51 percent of the claims made by UK organizations in 2024. This percentage increased markedly year-over-year, with ransomware and malware making up 32 percent of all claims in 2023.

The ABI said the surge in attacks leading to policy payouts illustrates an increase in sophistication and the damage cyberattacks are having on businesses.

"Cyber insurance is more than just a financial safety net," said Jonathan Fong, head of general insurance policy at the ABI. "The right policy not only supports businesses in the aftermath of an incident but can also help prevent attacks through access to expert advice, threat monitoring, and incident response planning. 

"With cyber threats continuing to grow in scale and sophistication, it needs to be a critical component of every organisation's modern risk management strategy."

The ABI's most recent data pertains to the period before the wave of digital heists on major British businesses began this year.

These included retailer Marks & Spencer, which last week reconfirmed to investors that it made a maximum £100 million ($131 million) claim on its cyber insurance policy, suggesting that 2025's data could lead to further increases in total payouts.

Officials at fellow besieged retailer Co-op confirmed in September the company did not hold comprehensive cyber insurance in place at the time of its April attack, and it would not make a claim on the limited-scope policy.

CFO Rachel Izzard told Reuters: "We had the front-end elements of cyber insurance in place in terms of the immediate response capabilities in the technology space for third parties, but we don't believe we will be claiming on insurance for back-end losses."

Jaguar Land Rover reportedly did not have a cyber insurance policy in place at the time of its hugely costly cyberattack this year. When The Reg asked the org about this, a JLR spokesperson told us: "We do not comment on commercial matters such as these." Ultimately, the UK government had to step in with a landmark support package to help the automaker, and the smaller businesses across its supply chain, financially recover.

Even if JLR did have a cyber insurance policy in place at the time - however comprehensive it might have been - it is unclear whether the massive costs associated with its downtime would have been materially eased by an insurance payout.

The circa £2 billion ($2.6 billion) costs of its attack could be compared to those of Change Healthcare in the US, whose ALPHV ransomware attack in 2024 also led to costs exceeding $2 billion.

Industry figures have debated the role and efficacy of cyber insurance for years. 

At the UK National Cyber Security Centre's (NCSC) annual conference earlier this year, the matter of cyber insurance was one of the few topics all the top expert panellists agreed on, offering support for its role in improving security standards.

The prevailing takeaways from the CYBERUK session were that insurers hold decades of expertise in assessing risk, and they have access to the most pertinent threat intelligence affecting modern organizations, which informs their policy requirements.

If organizations can't meet them – i.e. they don't implement the baseline standards required to defend against the most successful modern attacks – they don't get a policy.

On the other side of the debate sit those who believe insurers are encouraging ransom payments.

Anne Neuberger, chief of cyber under the Biden administration, argued last year for a ban on insurers from covering extortion payments, claiming current policies incentivize payments, which in turn fuel cybercriminal operations.

Others who spoke to The Register at the time disagreed. 

Monica Shokrai, Google Cloud's head of business risk and insurance, said: "I'm not convinced that banning the ransom from being paid by cyber insurance policies will remediate the issue."

"In the case of large companies, cyber insurance will still cover the cost of the incident and the ransom itself often isn't material, particularly compared to the cost of business interruption that a large corporation may face. 

"So, if larger companies continue to pay the ransom despite insurance not covering it, the impact of a ban on the insurance coverage becomes less meaningful."

Others argued that a payment ban was too reductive a countermeasure, saying the root cause of rising payments was due to "widespread digital insecurity." ®