Insurers know a mega cyber-loss is coming. So why is capacity still growing?

CrowdStrike, AWS, Change Healthcare: the near-misses keep piling up. The market keeps writing more business anyway

Insurers know a mega cyber-loss is coming. So why is capacity still growing?

Cyber

By Matthew Sellers

Every so often, an event comes along that gives the cyber insurance market a genuine scare about aggregation: the risk that one single failure knocks out hundreds or thousands of policyholders at once, rather than one at a time. According to a panel of UK cyber brokers who spoke to Insurance Business TV, the last two years have produced several of these moments. Capacity in the market keeps growing regardless.

Ethan Godlieb, associate partner for cyber and fintech at Consilium Insurance Brokers, ran through the recent list: the CrowdStrike outage of July 2024, the AWS outage of October 2025, plus incidents at Change Healthcare and SonicWall. Each is "a clear example that many attacks don't just start as a standalone instance," he said, describing the risk of a single point of failure rippling outward across an entire portfolio rather than affecting one insured at a time.

The scale of some of these events is well documented. The CrowdStrike failure on 19 July 2024, a faulty software update rather than a cyberattack, knocked out roughly 8.5 million Windows devices worldwide, grounding flights and disrupting hospitals and banks. Analysis from Guy Carpenter put the insured loss impact at somewhere between $300 million and $1 billion, while Parametrix estimated Fortune 500 companies alone suffered $5.4 billion in direct losses. The AWS outage of 20 October 2025 was similarly large in scope. CyberCube estimated it affected close to 70,000 organisations globally, yet its insured loss impact came in far more modest, at an estimated $38 million to $581 million, which CyberCube itself described as only a "moderate" event for the market.

That gap between enormous economic disruption and comparatively contained insurance losses is exactly what Godlieb had in mind describing cyber as a catastrophe product, one he said is "not for when the window breaks but rather when the house burns down." Waiting periods and time deductibles, built deliberately into most policies to filter out smaller attritional losses, meant neither CrowdStrike nor the AWS outage triggered anywhere near the volume of claims their headline disruption might suggest.

Colin Fox, cyber insurance consultant at Ntegrity, argued that's precisely why aggregation risk hasn't forced a change in underwriting behaviour. Systemic risk "doesn't seem to be at the forefront of underwriters' minds," he said, largely because the long soft market has pushed insurers to prioritise winning market share over the discipline that would normally accompany rising systemic concern. He pointed to Canopius reportedly now offering full war cover in some cases, a level of breadth he wouldn't typically expect given the current geopolitical backdrop but one the market has extended anyway under competitive pressure.

Selorm Kofi Domeh, broking manager at Talbot Jones, confirmed the practical effect: capacity "seems to be great, everything is good," in his words, despite insurers being privately wary of aggregation exposure. He expects the caution to surface eventually in underwriting discipline and pricing, but not yet. Daniel Winn, a development broker at Jensten London Markets, made a similar point from a different angle, arguing the real problem is simply the absence of a genuine test case. Both CrowdStrike and the AWS outage could have been considerably worse, he said, and the market has so far been saved less by its own preparation than by good fortune around timing and rapid fixes.

There's a reasonable case that the industry's aggregation models are still working from too thin a dataset. Shared cloud providers, common software and managed-service dependencies mean a single point of failure could in theory cascade across an entire book of business, but nobody on the call could point to a UK event that had actually tested that in practice. Insurance Business has separately reported insurers and reinsurers warning that cyber pricing is failing to keep pace with AI-driven threats, with one executive describing rates as "a little disconnected" from the underlying trajectory of risk. The same gap looks to apply just as much to aggregation modelling as it does to day-to-day claims severity. Brokers trying to work out which carriers are actually managing that risk well, rather than simply chasing growth, may find Insurance Business's 5-Star Cyber research a useful starting point.

Until a genuinely systemic event forces the issue, the UK market looks set to keep treating near-misses as near-misses, and keep deploying capacity as if the next one will be too.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!