
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

Insurers selling cyber cover in Asia are being asked to do a lot more than pay claims .
Summary
Brokers now want policies to come with services such as tabletop exercises, said Ruiwen Wan, cyber risk team lead at Zurich Resilience Solutions (ZRS), Zurich Insurance’s risk advisory arm. Wan, who covers Hong Kong, mainland China, Singapore and Southeast Asia, said those requests began to pile up in 2025 and have risen sharply this year. “It has become a trend in the market that when clients go for insurance, they can also get some cyber services from insurers,” she told Computer Weekly on a recent trip to Singapore.
“It’s also helpful to them because it may lower their premium and give them better coverage.” Vivien Bilquez, head of cyber resilience at ZRS, who has a global remit and is based in Switzerland, said the cover itself has become a commodity. “The problem is that cyber insurance is becoming commoditised, which means people take it to check the box,” he said. “To be honest, it’s a soft market today, so we also need to provide more than just the insurance.” According to insurance broker Marsh’s Global insurance market index , cyber insurance rates in Asia fell 8% in the second quarter of 2026, compared with a 6% decline in the previous quarter, as insurers deployed more capacity and competition increased.
Organisations that shore up their defences are rewarded with lower premiums, and that makes them a better risk for Zurich, Bilquez said. Things were different in the market’s early days , when Zurich built up its team of cyber risk engineers after applications for coverage started to outstrip its ability to vet them. “Initially, we received too many requests for cyber insurance, and we needed a group of professional people to evaluate if this is a good or bad risk, and if we can write the policy for the organisation,” Wan said.
When those cyber risk engineers assessed organisations against the US National Institute of Standards and Technology (NIST) framework about 10 years ago, more than half were at such a low level of maturity that Zurich had doubts about covering them, she added. The vetting work has since grown into a consulting business. Bilquez said ZRS has about 80 cyber specialists worldwide and expects that to reach around 300 as it brings in staff from Beazley , the UK specialist insurer and major cyber underwriter that Zurich recently acquired for £8.1bn.
Zurich also owns SpearTip , a US firm that offers managed security services. When asked if Zurich works with security companies, Bilquez said: “We are the cyber security consulting firm. Everything is done by us.” Wan said the team has also hired penetration testers from other companies to conduct red-teaming and penetration testing for clients.
Blind to suppliers Wan said that despite all the money large organisations have spent on cyber defences, most have little oversight of the cloud providers, software-as-a-service (SaaS) platforms, payment processors and other partners they rely on. That leaves them vulnerable to supply chain attacks . “We go on site and assess our clients, and what they do for third-party risk management is they just throw the compliance questionnaire to their suppliers,” she said.
“There’s not even a cyber-related question in this questionnaire. If I ask them, ‘Do you know if your critical supplier allows remote access?’ they have no idea.” Many contracts also give customers no right to audit their suppliers, Bilquez said. “When a supplier has a breach, it’s not the supplier that suffers – it’s the customer, because the customer cannot go after the supplier.” To assess a client’s supply chain risks, ZRS scans the client’s environment to map where its data goes and which suppliers handle it.
It then ranks those suppliers against key risk indicators and helps the client rewrite contracts to include cyber security and data protection checks. Zurich’s claims data lets it put a figure on what a breach at each supplier would cost. One outage, many claims A different kind of risk is outages at large technology suppliers.
Wan cited the Amazon Web Services (AWS) outage in October 2025 and the botched CrowdStrike update in July 2024, which crashed about 8.5 million Windows devices within hours. “In most of the claims we have seen, the cost of the business interruption is much larger than the cost of restoring digital assets,” she said. Such outages have led to claims from Zurich’s customers, with business interruption being a major loss covered by its cyber policies.
Insurers are also exposed to aggregation risk, where a single failure affects many policyholders across industries and geographies at the same time. “Imagine if there is an outage in a cloud or an outage in AI,” Bilquez said. “Because everyone is using the same provider, it triggers all the policies and we could go bankrupt,” he said.
“So, it’s very important for us to model the accumulation and make sure that the customers we are insuring are resilient. Otherwise, our business goes down.” Putting a number on risk ZRS does not rely solely on the security questionnaire that companies complete when applying for cyber insurance. Its consultants interview clients’ infrastructure and IT teams to determine, for example, how often they scan for vulnerabilities and how they track patching.
The findings are then compared with those of a client’s peers, which Wan said is important given how ransomware gangs select their victims. “Ransomware is becoming a business. They go for the money, they want the ransom, so they go for the easy targets,” she said.
“If you are better than half of your peers, you may not be the target for the ransomware group.” ZRS also estimates the financial impact of cyber incidents such as a ransomware attack or, for manufacturers, a disruption to operational technology (OT) systems , using Zurich’s data on business interruption losses, ransom demands and recovery costs. It is now working out the return on investment of individual security controls, so that companies with limited budgets can prioritise their security spending. Zurich also has cyber policies to cover attacks using AI, but so far, it has not received a claim for one, Bilquez said, adding that AI is increasing the number of attacks rather than creating new cyber threats.
“Instead of receiving 20 attacks a day, with AI, a customer today can be receiving 10,000 attacks a day.” He also said defenders should use AI to monitor, detect and block attacks just as quickly, but that people, not AI tools, should run penetration tests. “Human oversight is very important today, and it will become more and more important.” Read more about cyber security in APAC Proofpoint is hiring over 200 engineers in Hyderabad to develop models that can interpret the intent behind the actions of AI agents, its latest investment in a market where its business has tripled in a year. The Australian government has set up a taskforce to review how it responds to AI-related cyber incidents , after an OpenAI agent gained unauthorised access to a Medicare website run by Services Australia.
Kaspersky researcher Sojun Ryu says ransomware crews have joined nation-state groups in going after South Korean organisations, as traces of LLM output start turning up inside malware. Unauthorised access to a development and testing environment managed by IBM has exposed the names, NRIC numbers and property addresses of about 70,000 people held by the Singapore Land Authority.
KazaSec's take
Incidents like this rarely start with the headline event itself, they usually trace back to an exposed remote-access endpoint, an unpatched perimeter system, or a credential phished weeks earlier. The organizations that recover fastest are the ones that tested their defenses and their incident response plan before they needed them.
Coverage details
Related security advisories
Relevant from KazaSec
More security news
We help organizations find and fix the gaps before they make headlines.