惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Palo Alto Networks Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
C
CERT Recently Published Vulnerability Notes
C
Cybersecurity and Infrastructure Security Agency CISA
S
Schneier on Security
S
Securelist
酷 壳 – CoolShell
酷 壳 – CoolShell
C
CXSECURITY Database RSS Feed - CXSecurity.com
Cyberwarzone
Cyberwarzone
Apple Machine Learning Research
Apple Machine Learning Research
S
SegmentFault 最新的问题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
GbyAI
GbyAI
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Microsoft Security Blog
Microsoft Security Blog
云风的 BLOG
云风的 BLOG
Recorded Future
Recorded Future
Webroot Blog
Webroot Blog
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
TaoSecurity Blog
TaoSecurity Blog
C
Cisco Blogs
博客园 - 【当耐特】
Blog — PlanetScale
Blog — PlanetScale
Hugging Face - Blog
Hugging Face - Blog
B
Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Attack and Defense Labs
Attack and Defense Labs
The Last Watchdog
The Last Watchdog
U
Unit 42
阮一峰的网络日志
阮一峰的网络日志
Project Zero
Project Zero
WordPress大学
WordPress大学
L
LINUX DO - 最新话题
F
Fortinet All Blogs
L
LINUX DO - 热门话题
PCI Perspectives
PCI Perspectives
Simon Willison's Weblog
Simon Willison's Weblog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
MongoDB | Blog
MongoDB | Blog
Latest news
Latest news
P
Proofpoint News Feed
T
Threat Research - Cisco Blogs
The Hacker News
The Hacker News
爱范儿
爱范儿
O
OpenAI News
J
Java Code Geeks
T
The Exploit Database - CXSecurity.com
H
Hackread – Cybersecurity News, Data Breaches, AI and More

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements Introducing the Anomaly Framework Stopping Identity Threats with ITDR through MXDR Security Operations Over Tools Beyond Tools: A Strategic Approach to Data Security Cyber Threat Response Strategies for MSPs Threat Advisory: Email Account Compromise BECs In the Wild: When Millions of People Are Expecting the Same Email Michigan and Wisconsin Proposed Age Verification Bills and the Impact on VPNs and SASE: What You Need to Know Cyber Threat Detection Strategies for MSPs Cyber Threat Prevention Strategies for MSPs Simplifying CMMC Level 1 with Todyl GRC How to Complete Your CMMC Level 1 Self-Assessment: A Step-by-Step Walkthrough Cyber Threats Don't Take Time Off How MSPs Build Lasting Client Relationships Through Proactive Operations Risk Management for MSPs: Why Business Context Changes Everything 5 Pillars for Security Program Growth in 2025 One Action MSPs can take to Address Risk and Secure Clients Building Resilience in a Perimeter-less World with Defense-in-Depth Aligning Technology Implementation to Business Outcomes Top 5 Myths about Cybersecurity How Conditional Access Transforms Your Cybersecurity Program Why MSPs need to embrace a prescriptive model How Texas SB 2610 Positions MSPs as Strategic Risk Advisors Simplifying cybersecurity maturity with managed cloud SIEM Addressing firewall vulnerabilities Understanding the Pitfalls of RDP MSP Zero-Day Response Plan: When Security Tools Can't Help You Old is Gold: Tackling Persistent Vulnerabilities How MXDR drives operational efficiencies Using SASE for secure remote access How to find the best endpoint security solution What to ask of a prospective endpoint security vendor Thinking Red, Acting Blue: Turning Attack Tactics in Your Favor Zero-Day Attacks and False Alarms: Lessons for MSPs Dissecting the Recent Rise in 2025 Zero Days MSP Security Monitoring Strategy: Identity and Cloud Blind Spots Introducing the Todyl Community: A Collaborative Platform for MSPs Threat Advisory: PDFast Freeware Compromise Navigating Today’s Cybersecurity Threat Landscape: Where MSPs Should Start Threat Advisory: Understanding the Recent SonicWall SSL VPN Vulnerability and How to Protect Your Clients Partner Spotlight: GoTech IT Solutions Threat Advisory: SQL Injection in FortiClient CVE-2023-48788 The Importance of SSL Inspection Navigating Compliance Frameworks: Common Challenges and Effective Solutions Making the most of SASE Web Filtering Iran & Middle-East Geopolitical Shifts: Emerging Cyber Risks for SMBs MSP Security KPIs That Matter: Beyond Vanity Metrics to Business Outcomes MSP Challenges Looking into 2025 Combining EDR and NGAV for Defense-in-Depth Starting Your Security Framework Journey: A Practical Implementation Guide Cyber Insurance vs. Warranties: Key Risk Management Elements Akira Ransomware: A Persistent Threat to MSP Operations Transforming Cyber Insurance for MSPs and Their Clients Two Truths, Double Whammy: Why Vulnerability Remediation Needs a Rethink Using LAN ZeroTrust for segmentation The role of SIEM in incident response Partner Spotlight: 917 Solutions Threat Advisory: Business Email Compromise Campaign using OVPN for Obfuscation Beyond Implementation: Creating an Ongoing Security Framework Program ClickFix: Fake Captcha Leads to Real Damage Streamlining Security and Compliance Information Gathering with Assessments EpiBrowser: A Sophisticated PUP Masquerading as Chromium Partner Spotlight: AnchorSix Tips to Help MSPs Set Goals for the New Year How SIEM helps detect insider threats Massive Wave of Network Security Vulnerabilities Demands Immediate Action FortiJump: The FortiManager Zero-Day Vulnerability Explained Use cases of SASE: Software-defined perimeter Threat Advisory: LightPerlGirl Malware Why MSPs Must Prioritize CIS Critical Security Controls v8.1 for Client Success
The Cyber Insurance Crisis: Why MSPs and Their Clients Are Struggling
Zach Dressander · 2026-01-09 · via Todyl Blog

In the past few years, the cyber insurance landscape has transformed dramatically. Once, policies began with a relatively straightforward process of filling out a questionnaire and receiving affordable coverage. Now the process is complex, costly, and often frustrating for businesses of all sizes.

At the heart of this transformation lies a fundamental problem: the challenge of accurately quantifying cyber risk. This challenge affects everyone in the ecosystem and has created a perfect storm in the cyber insurance market.

The Cyber Risk Appraisal Dilemma

The cyber insurance industry faces a significant challenge: how to accurately measure the risk they're insuring. Unlike other insurance types where decades or centuries of actuary data exist, cyber risk remains notably difficult to quantify.

The Questionnaire Problem

Traditional approaches to cyber risk assessment rely heavily on questionnaires, creating challenges across the insurance ecosystem:

  • Insurers struggle to accurately assess risk without visibility into actual security implementations
  • MSPs face challenges aligning client security programs with complex policy requirements
  • Businesses encounter substantial gaps between their expectations and policy realities when incidents occur

The Data Gap

The fundamental issue is a data gap—insurers have limited information about what they're actually insuring. This results in:

  1. Limited visibility into how organizations manage their security.
  2. Self-reported data that may not accurately reflect reality.
  3. No standardized validation of security claims made in questionnaires.
  4. Difficulty correlating specific security controls with actual risk reduction.

For MSPs and their clients, this cyber risk appraisal challenge has created a cascade of problems.

Several factors have converged to create today's challenging cyber insurance environment:

1. Surging Cyberattacks

The frequency and severity of cyberattacks have increased tremendously. Ransomware and business email compromise attacks continue to rise, targeting organizations of all sizes across every industry. This surge in attacks has led to record-breaking insurance payouts. As a result, carriers reassessed their risk models and tightened their application criteria.

2. Rising Premiums and Declining Coverage

As insurers struggle to turn profits, premiums have skyrocketed while coverage options have often diminished. Even organizations with strong security practices are facing significant premium increases during renewal cycles.

3. Tighter Underwriting Standards

Insurance carriers have dramatically tightened their underwriting requirements. Questionnaires that once took minutes to complete now stretch to dozens of pages. They come with detailed technical questions that many organizations struggle to answer correctly.

4. Coverage Limitations

Even as premiums rise, coverage is often becoming more limited. Insurers are introducing more exclusions, lower coverage limits, and higher deductibles to manage their risk exposure.

5. Coverage Denials

Perhaps most concerning, many businesses are being denied coverage altogether. If an organization can't demonstrate robust security controls, insurers increasingly decline to offer any coverage. These businesses then become exposed to potentially devastating financial losses if attacked.

The MSP Challenge: Caught in the Middle

For MSPs, the cyber risk appraisal problem creates significant challenges:

The Translation Problem: MSPs must translate their security implementations into the language of insurance questionnaires. For their clients, the process often fails to express the true value of the MSP's security services.

Validation Difficulties: There's no standardized way to validate that security implementations actually reduce risk in the eyes of insurers.

Client Expectations Gap: Clients expect their MSP to solve the problem of increasing premiums and coverage denials. despite security investments, they often expect their MSP to help solve the problem—creating potential relationship strain.

Security-Insurance Disconnect: Security best practices and insurance requirements often seem disconnected, making it difficult to align security implementations with insurance objectives.

The Path Forward: Solving the Cyber Risk Appraisal Challenge

Forward-thinking MSPs can use insurance to set their offering apart and provide greater value to clients. It requires a fundamental shift in how we measure cyber risk. Instead of relying on subjective questionnaire responses, MSPs must pull objective, validated data about security implementations.

Creating a standardized validation framework bridges the gap between security implementation and measuring risk. Doing so lets MSPs help clients overcome the insurance challenges while demonstrating the true value of their security services.

Of course, managing risk through security controls only covers half the picture. Read on to learn how cyber insurance and warranties work together in risk management, covering the residual risk that remains after security controls.

About Zach Dressander

Zach Dressander is the Senior Director of Marketing for Todyl, leading a team of innovative marketers focused on delivering insights and experiences to help IT professionals successfully navigate the cybersecurity landscape using the Todyl Platform. Prior to joining Todyl, he was helping drive marketing efforts for Deloitte Cyber & Strategic Risk, where he supported the launch of Deloitte's Cloud Cybersecurity Managed Services with AWS and the MXDR by Deloitte offerings. Previously, he was the lead marketer for Deloitte's Center for Regulatory Strategy, working with regulatory and compliance subject matter experts across industries to help enterprises successfully navigate evolving regulations.