Falling cyber alerts may not mean lower risk at renewal
More targeted attacks and blind spots are complicating how brokers assess clients’ exposure
Falling cyber alerts may not mean lower risk at renewal
CYBER
By Roxanne Libatique
25 Sep 2026

Falling alert volumes and declining ransomware detections are giving some clients a misleading picture of their cyber exposure – and regional government data makes the stakes clear.

The numbers that don’t add up

Total network attack volume dropped 79% in the first half of 2026, according to WatchGuard Technologies’ Global Threat Report, released in September. Ransomware endpoint detections fell more than 68% year-over-year.

Read in isolation, both figures suggest improvement. They do not tell the full story.

Over the same period, novel malware rose by more than 2,000% year-over-year on the endpoint. Nearly 96% of endpoint threats appeared on exactly one machine – designed to evade signature-based detection and leave no trace in aggregate statistics. Public extortion claims from ransomware groups reached record levels across the same six months.

WatchGuard’s chief information security officer, Corey Nachreiner, was direct on what the drop in alert totals actually signals. “Attackers are not less dangerous because alert totals declined. They are using every tool at their disposal to become more selective and precise. The recent findings show a shift from reusable payloads and high-volume scanning to malware tailored for individual systems, broad low-and-slow probing, and credential-based access that can go around perimeter defences,” Nachreiner said.

For brokers, the implication is concrete: a client arriving at renewal with a clean security report may be presenting evidence that nothing was caught – not that nothing got through.

Read next: Third-party software breach exposes wider cyber risks for Australian businesses

What regional governments are recording

Government data across the region points in the same direction. In Australia, the Office of the Australian Information Commissioner (OAIC) received 1,205 data breach notifications in 2025 – the highest since mandatory reporting began in 2018, and an 8% rise from 2024. Of those, 716 were attributed to malicious or criminal attacks. The Australian Signals Directorate (ASD) recorded over 84,700 cybercrime reports in FY2024-25, averaging one every six minutes, and notified entities of potentially malicious cyber activity 1,700 times – an 83% increase on the prior year.

In New Zealand, the National Cyber Security Centre’s (NCSC) Cyber Threat Report 2026, released in September, recorded 369 incidents of potential national significance during 2025-26, with 162 linked to criminal or financially motivated actors – an 18% increase on the previous year.

Across Asia and the South Pacific, INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment, drawing on data from 18 member countries, found that more than half of surveyed jurisdictions reported cybercrime now accounting for 30% of all recorded crime nationally. The report recorded more than 135,000 ransomware attacks in the region and a 92% rise in distributed denial-of-service incidents over the period.

Each of these figures covers what was detected and reported. The WatchGuard data suggests a considerably wider picture is going undetected – particularly given that nearly 96% of novel threats in the first half of 2026 were engineered to appear on only one machine.

The encrypted traffic blind spot

One WatchGuard finding converts directly into a claims dispute risk. The report found 95% of malware was delivered over encrypted Transport Layer Security (TLS) channels. Only 20% of deployed devices inspected that traffic. Evasive malware accounted for nearly one-third of all detections overall, rising to 36% on devices using advanced defences with TLS inspection enabled.

A client that does not inspect encrypted traffic cannot verify what has passed through it. When that same client states on a renewal application that their controls are current and effective, the gap between what they declared and what they can evidence becomes a coverage problem – not just a security one.

If an intrusion travels through an uninspected encrypted channel and a claim follows, underwriters will ask whether the controls stated on the application were actually operative. That question becomes much harder to answer when the relevant channel was never checked.

Credential access and the MFA gap

WatchGuard also identified a structural shift in how threat actors gain initial access. Credential access, persistence, remote access, and defence evasion were the dominant themes in threat-hunting activity across the first half of 2026. Attackers increasingly used legitimate account credentials and native system tools to move through networks without triggering the alerts that detection-based reporting relies on.

New Zealand’s NCSC COO, Mike Jagusch, said the pattern is consistent with what the agency is observing locally. “Ensuring basic cyber security measures such as multi-factor authentication, managing who has full access to the network, and protection of the network edges were in place could have helped to defend against these incidents,” Jagusch said.

In Australia, the Australian Prudential Regulation Authority (APRA) has specifically urged banks, insurers, and superannuation funds to strengthen authentication controls as a priority under CPS 234, its information security prudential standard.

Multi-factor authentication (MFA) is a baseline underwriting condition across cyber insurance markets in both countries. But partial MFA rollouts – where authentication applies to some accounts and not others – leave exactly the gaps credential-based attacks target. For clients in APRA-regulated sectors, incomplete MFA also carries a compliance exposure alongside the coverage risk.

Brett Chase, director of sales engineering for Asia-Pacific and Japan at Cohesity, noted that identity compromise underpins the majority of incidents across the region. “Identity is at the core of today’s cyber threat landscape. Nine out of 10 cyberattacks now start with identity through compromised credentials or misused identities. In Australia, the rise of materially significant cyber incidents makes it clear that weak or inconsistent identity management practices remain a major but preventable root cause,” Chase said.

Old flaws, active exploitation

The WatchGuard report found the median vulnerability in its top 50 network-attack signatures was first disclosed in 2014. Of 44 CVE-referenced signatures, 31 targeted flaws at least a decade old. SQL injection alone accounted for more than 17% of network-attack detections.

Clients running unpatched systems or unsupported devices routinely face exclusions or premium loadings at renewal across the region – a direct market response to the sustained value attackers continue to extract from long-known weaknesses.

Ransomware: fewer detections, more extortion

WatchGuard tracked 41 new ransomware groups in the first half of 2026. The top eight accounted for more than half of nearly 5,000 public extortion claims during the period. The Ransomware-as-a-Service model continues to lower barriers to entry, keeping extortion frequency elevated even as endpoint detection figures fall.

Emergence Insurance updated its Cyber Event Protection policy wording in early 2026 in response to claims experience and broker feedback. Chief underwriting officer Jeff Gonlin said: “Cyber risk doesn’t stand still, so our policy wording can’t either.”

The same applies to the risk assessment frameworks brokers use at renewal. One calibrated to alert volumes and endpoint detection rates is measuring a threat environment that has materially changed.

Read next: Australian businesses struggle to recover from cyberattacks as planned

Three questions worth raising before renewal

Does the client inspect encrypted traffic? Given 95% of malware now travels over TLS, a client who cannot answer this clearly has a visibility gap – and a potential gap in their coverage position if a claim follows.

Is MFA complete or partial? Partial rollouts are common among organisations that ticked the underwriting box without completing implementation. They are also the entry point credential-based attacks use most reliably – a point regulators in Australia, New Zealand, and across Asia have each flagged independently.

Are the security metrics measuring what matters now? Falling alert volumes and clean endpoint reports do not, on their own, confirm a secure network. They confirm that the detection methods in use found nothing – which is a different statement.

The gap between what a client reports at renewal and what an underwriter can verify at claims time is where coverage disputes originate. Across Australia, New Zealand, and the broader Asia-Pacific region, threat data from governments and law enforcement indicates that gap is widening – not because clients are misrepresenting their controls, but because those controls are increasingly blind to the methods now being used against them.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB AU.