Broad cyber dependency cover may need limits to last
Restricting exposure to shared technology providers could help preserve cover after a major loss
Broad cyber dependency cover may need limits to last
CYBER
By Bryony Garlick
06 Oct 2026

Technology dependency cover remains readily available in the London market, according to Dan Johnson (pictured), class underwriter, cyber at AEGIS London. Large corporates can commonly secure business interruption cover across their technology supply chain, including non-IT suppliers such as payroll providers, without a separate sublimit, he said. 

"Cover is still very readily available in the London market," he said. "I would say it's basically standard cover now, particularly for large corporates." 

Johnson said the market has softened since 2024, while demand for cover has widened. The 2025 cyberattack on Jaguar Land Rover halted production and disrupted suppliers, drawing attention to losses caused by attacks on customers. Requests for that cover are now reaching the large corporate market, where it tends to be sublimited or written on a named basis. 

The pressure point is concentration with many insureds relying on the same few technology providers, leaving the market to decide how much shared exposure it can sustain. 

What the limits could look like 

Johnson outlined several possibilities, starting with restricting dependent business interruption cover to a client’s most critical vendors. 

"There are multiple ways you can say maybe you look to cap dependent business interruption exposure to named or the most critical vendors, bearing in mind particularly a large organisation, they will probably say they have 300 critical vendors," he said. "So what would that cap be? Would that be top 10? Would that be top 20, top 30?" 

Another would target the largest providers directly. 

"Do you come up with a way where maybe you exclude or you limit exposure to the biggest aggregators, so your Microsofts, your AWSs, in a way where maybe Microsoft and AWS open up points of recovery by having more lenient contractual terms?" 

Those providers are dominant, and smaller insureds in particular have almost no rights of recovery against them, which is why Johnson said the technology companies need to be part of the discussion. A third option would apply higher retentions or longer waiting periods to a truly systemic event, once the market agrees what counts as one. 

"Any one of those is a limitation on cover versus what we have today," he said. 

Limits, not blanket exclusions 

Johnson distinguished targeted restrictions on major providers from blanket supplier exclusions, which he said would strip value from a product designed to respond to evolving technology risks. 

"It's a developing product. It's designed to pick up this technological risk, and that's only ever going to evolve. And if the approach is to every time we see something new to exclude it, you're taking out that inherent value." 

He pointed to ransomware, where restrictions tightened cover without removing it: “the cover was never truly excluded. It was capped. It was sublimited.” 

Where brokers fit 

Restricting cover to named vendors would make identifying critical dependencies more important, but Johnson said that responsibility should not fall to brokers alone. 

"Their role in that should be to help their clients make that identification," he said. "And the underwriter in me would say clients should already know that, particularly in the large corporate space. They should know who their main dependencies are, where their single point of failure fits." 

Insurers already use outside-in scanning tools to spot reliance on services and hosting providers such as AWS and Microsoft. Brokers could use the same tools, and Johnson said he was sure some already do, but he wants the conversation to become part of the client's core IT business continuity risk management. 

Reliance on AI providers belongs in the same aggregation discussion, rather than distracting attention from technology concentration. Johnson acknowledged the position is difficult for brokers, who are acting in their clients' best interests. 

"I personally don't see value in driving for a cover today, if you had a claim tomorrow, you would never get that cover again," he said, adding that brokers should challenge restrictions while recognising their responsibility, alongside insurers, for keeping the market sustainable. 

Preserving broad dependency cover would mean agreeing which providers remain covered, how much exposure insurers can accept and what losses clients would retain in a systemic event. 

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB UK.