I said I was done. I ended that run of blogs in the same "garage" I started it in, having argued that cars got safe because every link in a chain held, and that our broken link in cybersecurity is enforcement. Then someone I respect told me I had it wrong.
Cars didn't get safer because of enforcement or the law, they said. They got safer because of insurance. And then they didn't elaborate.
That's the kind of remark that keeps me awake at night. Partly because it came from someone whose judgement I don't dismiss, and partly because if they were right, I'd just spent a post pointing at the wrong link. So I went back to the "garage" to find out.
What I found was more interesting than either of us had said. They were partly right. So was I. And the sentence I'd written about insurance - the one I tossed off in a list without thinking hard about it, turned out to be the lazy version of a much better story.
What I Actually Got Wrong
Here is what I wrote last time, when I listed the links in the chain:
"Insurance that priced in risk."
Five words, written in passing inside a piece I'd otherwise sourced carefully, which is exactly how this sort of thing survives. Not in the claims you check, but in the ones travelling alongside them.
They aren't false. Insurers do price risk, and always have. But I wasn't writing a definition. I was naming what insurance contributed to cars getting safer. And on that question, those five words smuggle in an assumption I'd never examined.
The assumption runs like this. Insurers price risk, so safer cars become cheaper to insure, so buyers and manufacturers follow the money, so cars get safer.
It's the version almost everyone reaches for, including me. But it's also not how it happened.
In the United States, insurers' most consequential act wasn't pricing. It was funding a laboratory. The Insurance Institute for Highway Safety is a non-profit funded entirely by auto insurers, and what it did was crash cars into walls in public and publish the score. Vehicle improvements driven by those tests are estimated to have saved around 48,000 lives between 1999 and 2024, and $538 billion in societal cost, against a testing budget of roughly $600 million - close to a 900-fold return, though I'd note that's the IIHS marking its own homework, so hold the precision lightly. The direction of travel isn't seriously disputed.
Notice what did the work there. Not the actuarial table. The rating. Safety in a car was a thing no buyer could see or verify, so the market rewarded what it could see i.e., chrome, horsepower, styling etc. The IIHS made safety visible, and the market reorganised around the thing it could finally judge.
But that's the American story, and I'm writing from Europe, so I kept going, and this is the part that changed my mind properly.
Euro NCAP, the star rating most of my readers actually recognise, didn't come from insurers at all. It was founded in 1997 by the Transport Research Laboratory for the UK Department for Transport, and it's backed by the governments of the UK, France, Germany, Sweden, the Netherlands, Luxembourg and Spain, alongside motoring clubs, consumer organisations and insurance bodies. Insurers are one voice in that consortium. Thatcham speaks for the UK's, German insurers contribute through their accident research unit, but they are contributors, not the authors.
So, same function, different coalition. In America, insurers built the visibility instrument. In Europe, government built it and insurers helped pay for it. Two continents, two completely different sets of hands, one identical mechanism. Put a number on the thing buyers can't see, and watch the market reorganise around it.
Which is the real answer to my correspondent, and it's better than either of the things we'd each said. They were right that visibility was the mechanism, and right that I'd underweighted insurance. They were wrong to make insurance the author of it everywhere. And I was wrong to write "priced in risk" without checking what the link had actually done.
It also happens to be the strongest evidence yet for the argument I've been making all along. If the same instrument gets built by insurers in one jurisdiction and by transport ministries in another, then the safety never lived in who built it. It lived in the function. Take the crash-test lab away and you'd lose visibility, but you'd keep the standards, the liability, the driving test and the enforcement. Insurance was a powerful link. It was never the chain.
Which raises the question I should have asked before I moved on: in cyber, is that link working?
The Number I Couldn't Prove
I started where I thought the answer was. For a while I've been repeating a statistic - that around 40% of cyber insurance claims get denied, and not because cover didn't exist, but because organisations couldn't evidence what they believed was in place.
So I went to find the source.
I couldn't.
The 40% is everywhere: managed-service-provider blogs, broker sites, vendor explainers, LinkedIn carousels. Follow any of them back and the trail dissolves. Each cites another post citing unnamed "industry reporting," with no carrier disclosure, claims study or filing underneath. The figures that travel with it behave identically. That 44% of denials come down to inadequate evidence. That 82% of denied claims involved organisations without full MFA. Confidently attributed to major carriers, and absent from those carriers' published reports.
Twice in one investigation, then. And both failed the same way, not through carelessness, but by travelling in good company. My five words rode along inside a piece I'd researched properly. The 40% rides along inside articles full of real citations, none of which happen to attach to it.
Which is the part that stopped me, because the pattern is the argument. A claim that feels true. Repeated by people with an incentive to repeat it. Never verified, because verifying is nobody's job and it sounds about right. And then someone finally looks, and there's nothing underneath.
That is exactly what happens to a control register between renewal and breach.
What the Evidence Actually Shows
Here's what survives scrutiny.
There is a real recovery gap, it just isn't a denial rate. NetDiligence's 2025 Cyber Claims Study analysed 10,402 actual claims from incidents between 2020 and 2024. For small and mid-sized enterprises, the average total incident cost was $264,000 against an average payout of $183,000. For large companies, the average incident now runs to $10.3 million.
I want to be careful with that gap, because it would be easy to wave it around as insurer stinginess and it isn't. A good part of it is the self-insured retention - the deductible - working precisely as designed, alongside sub-limits and exclusions the buyer agreed to. That's the policy functioning, not failing. But it's still the number that belongs in front of a board, because most boards I meet believe cover means covered, and the structural distance between what an incident costs and what a policy returns is not something they've ever been shown.
And the mechanism I'd half-remembered does hold up. It's simply qualitative. Delinea's survey work, and I should say Delinea sells privileged access management, so it has a horse in this particular race, found back in 2023 that the exclusions most likely to void cover were led by lack of security protocols in place (43%), human error (38%), and failure to follow proper compliance procedures (33%). By 2024, 41% of insurers were demanding evidence of least-privilege access.
Everything since has moved in one direction: wider. Heading through 2026, carriers are carving out AI-related liabilities, attacks attributed to nation states, and systemic or "widespread" events, which, given that the incidents capable of ruining you are precisely the correlated ones, is worth reading your own schedule for tonight.
Note the word running through all of it. Evidence. Not "have." Not "intend to." Prove.
And the lawyers have a name for what happens when you can't. In Columbia Casualty v. Cottage Health System, after a breach exposed tens of thousands of patient records, the insurer moved to avoid coverage under a "Failure to Follow Minimum Required Practices" exclusion, arguing the hospital group hadn't continuously implemented the controls described in its own application - an application expressly made part of the policy. The case never reached a ruling on the merits; it was dismissed on a procedural point about the insurer's own dispute-resolution clause. But it named the risk, and coverage lawyers have called it ever since by a phrase every board should know: post-loss underwriting. The moment you claim is the moment your questionnaire gets audited.
Think about that. A leader buys cover in good faith. Believes, because someone told them, that MFA is enforced, backups are tested, patching is current. Suffers a breach. Files the claim. And the settlement turns not on the reality of their security, but on their ability to prove it. The control the board signed off in a slide deck turns out to have been "in progress," or deployed everywhere except the one legacy server the attacker found, or enabled but never logged — so there's no way to show it was live at the moment it mattered.
AI Changes the Clock, Not the Problem
It’s tempting to bolt AI onto everything and call it insight but AI hasn't created a new insurance problem. It's compressing an old one. Underwriting runs on an annual cycle: you attest once, you renew once, and the picture you painted is assumed to hold for twelve months. AI is shortening the interval over which that picture stays true. Attackers are automating reconnaissance and exploitation. Your own teams are shipping AI-generated code faster than anyone reviews it, and standing up agents holding credentials nobody has mapped.
The estate you described at renewal is not the estate you have at the breach. That's not apocalyptic, it's arithmetic. The gap between attested and actual posture was always the risk. AI simply widens it faster than a yearly questionnaire can track, and Delinea's research already shows AI adoption feeding into how premiums get set.
As I was finishing this, OpenAI disclosed that two of its models had escaped a sandbox during testing and broken into Hugging Face, executing tens of thousands of automated actions across a weekend and compressing into hours work that would have taken a skilled attacker considerably longer. Hugging Face reconstructed more than 17,000 recorded events to establish what had been done to them.
Most organisations I meet could not reconstruct seventeen. And that, rather than the capability itself, is the part that should worry your board.
The Counter-Argument
Here's where I have to be fair, because the strongest case against my view isn't weak at all. And on this one, my correspondent has more ammunition than I first allowed.
Cyber insurance is doing real work. "No MFA, no cover" has probably done more for baseline hygiene across the mid-market than a decade of awareness posters, and unlike the enforcement regimes I wrote about last time, it actually bites, because the consequence lands at renewal rather than in a tribunal five years later. Insurers don't need a prosecutor. They just decline.
The loss data backs it. Coalition reported that 56% of matters reported to them were resolved with no out-of-pocket payment by the policyholder at all, and in its 2026 report, average claim severity fell 19% to $116,000, with a record 86% of businesses refusing to pay ransoms, which is what improving backups and tested response plans look like in a spreadsheet. Carriers increasingly bundle monitoring and telemetry, and the Geneva Association has documented how far underwriting has moved towards observed data rather than self-attestation.
And the moral-hazard charge, that cover makes firms lazy or funds the ransom economy, has never been conclusively demonstrated. The research is genuinely divided.
Every one of those points is reasonable. I mean that.
But here's why it still doesn't add up to a working link.
Deterrence doesn't run on the intentions of insurers. It runs on what the insured actually changes. And what insurance currently rewards is a good questionnaire, not a defensible organisation. The most rigorous study I've read of the ransomware era found that insurers built sophisticated machinery to contain their own liabilities and restore systems fast, but largely left the actual security decisions to the insured, facilitating enterprise in the short run while undermining security over the longer one. Insurance, on its own commercial logic, governs in support of the business continuing. That overlaps with security. It is not the same thing.
So the link isn't broken the way enforcement is broken. It's incomplete. It has become very good at making your security legible to the underwriter, once a year, in a form you compiled yourself. It has not yet done for cyber what the IIHS did for the car: make security legible to everybody, continuously, using an instrument nobody being rated gets to fill in themselves.
What This Means for You
Most of us can't redesign the insurance market from where we sit. But this one is unusually actionable, because the gap is inside your own building.
1. Ask for artefacts, not assurances. For every control on your register, name the thing that would prove it was live on a given Tuesday - the log, the config export, the timestamped dashboard. If nobody can name it, you don't have a control. You have a belief.
2. Read the application as what it is: part of the contract. In Cottage Health, the questionnaire was expressly incorporated into the policy. Answer it the way you'd answer a regulator, and treat "in progress" as "no," because that's how it will be read after a loss.
3. Date-stamp your attestations and re-verify at renewal. Posture drifts. People leave, systems get exempted, an exclusion gets granted for one legacy box and never revisited.
4. Know your retention and sub-limits before the incident, not during it. Much of the recovery gap is structural, agreed at signing, and entirely knowable in advance.
5. Then run the test that matters. Not an audit, a reconstruction. Ask someone to assemble the proof a forensic examiner would demand for your three most important controls. However uncomfortable the result, you'd rather have it now than in week two of a breach.
So, Is Cyber Insurance Working?
Partly. More than I'd have said a month ago, and more than its critics allow. It has raised the floor faster than any regulator has, because it holds the one lever regulators keep failing to pull: a consequence that actually arrives.
But it isn't yet doing the job that made cars safe. It prices and it filters. It doesn't illuminate. And the version of your organisation it insures is the version you described, which is not reliably the one you have.
Which brings me back to where this started. Someone I respect told me I'd got a link wrong, and they were right that I'd been careless. I then found a number I'd been confidently repeating that nobody can source. Two claims I'd never checked, in a fortnight.
Most boards have never spent a single hour testing whether they can prove the controls they sign off every quarter.
In insurance, as in the breach itself: what you cannot evidence, you do not have.
The Proof
For anyone who wants to check my working, or who's been quoting these too:
- "Around 40% of cyber claims are denied." No primary source found. Trails end in secondary posts or unnamed "industry reporting."
- "44% of denials come down to inadequate evidence." Attributed vaguely to "some carriers." No published claims data underneath.
- "82% of denied claims involved organisations without full MFA." Usually credited to Coalition. Doesn't appear in Coalition's published reports, which say that 56% of matters were resolved with no out-of-pocket cost to the policyholder (2025) and that average severity fell 19% to $116,000 (2026).
- "27% of data breach claims are excluded from full payment." More recent, this one, and usually credited to the NAIC. I went hunting for it specifically because I wanted fresher exclusions data than 2023, and found it living in the same aggregator posts that carry the 40%. That doesn't make it wrong. It means I couldn't check it, so I haven't leaned on it.
Two caveats, because fairness matters. Unsourceable is not the same as untrue. Denials and disputes are real, and brokers and breach lawyers see them. And these estimates spread precisely because carriers don't systematically publish denial rates. A vacuum gets filled by whoever's willing to fill it.
Which is its own small irony. The industry that funded the instrument that made car safety visible has not made its own claims outcomes visible.
If you have a primary source for any of the three, send it. I'd like to be corrected.
Now I Want to Hear from You
I reopened this series because someone challenged me and I couldn't prove they were wrong. So let me pass that on.
If you've been through a claim, was the sticking point ever the cover itself, or was it that you couldn't evidence what you were certain you had in place?
And for those of you sitting on boards: when did you last test whether your control register would survive a forensic examiner, rather than an auditor?
Tell me in the comments on LinkedIn. I read every reply.
Note Since Publishing. Since publishing, a good friend, Micheal Colao who has spent decades in cyber insurance pointed me to the source I couldn't find - a 2023 Fitch Ratings analysis, and explained in a post why that figure and the insurers' own high claims-paid rate can both be true. I'm verifying it properly and writing it up as a follow-up.