Data center cyber risk is running ahead of most policies

Novatae's Karen Kutger talks about the BI wording, controls, and AI gaps that expose data center accounts

Data center cyber risk is running ahead of most policies

Cyber

By Mark Rosanes

A data center cyber submission without documented security controls is a missed opportunity, and increasingly, a placement risk. The average cost of an individual ransomware attack rose 17% in the first half of 2025, according to Resilience, and data centers sit at the center of that exposure.

Karen Kutger (pictured), wholesale production leader for management, professional and cyber at Novatae Risk Group, walks through the controls, wording, and coverage questions brokers should be raising with every data center account.

What brokers get wrong about data center scale

Data centers have grown from colocation facilities into hyperscale operations, and the insurance implications have not kept pace with that shift.

"One of the biggest cyber security challenges for data centers is the catastrophic risk," Kutger said. "There could be billions or trillions of data points at risk, not to mention the cascading business interruption issues."

State-sponsored attacks compound that exposure. Kutger said large data centers "will almost certainly be a target for state-sponsored attacks," a threat vector brokers should be raising directly with clients when framing the risk conversation.

The underwriting priority at this scale is dependent business interruption. Kutger said her team reviews dependent BI coverage in every policy to confirm the wording covers catastrophic events, not just standard outages. The definition of dependent exposure also needs to be broad enough to capture the actual cascading risk.

Where underwriting friction starts on data center accounts

Security controls are now a primary pricing variable in data center cyber risk. The difference between a well-documented submission and a poorly prepared one shows up directly in the premium.

Kutger said controls drive up to 35% premium variation between comparable facilities. The issue is not just whether controls exist, but whether they are consistently enforced across the entire environment.

"There are still issues with inconsistent MFA enforcement and gaps in the clients EDR/MDR," she said. "Underwriters want to see MFA on all remote access, privileged accounts, cloud applications, etc. There are still IT teams which implement MFA but leave the administrators portals exposed."

Brokers who surface these gaps before submission are better placed to manage client expectations and negotiate outcomes. Carriers run external scans, and open remote access ports will create underwriting friction regardless of what the submission says.

"The carriers are looking for encrypted backups that are completely disconnected from the network," Kutger said. "When carriers run their external scans and the scans show that there are open remote access ports it can cause friction during underwriting."

What cyber policies are silent on and why it matters for data center accounts

AI and operational technology have expanded the data center attack surface faster than most cyber policy language has adapted. For brokers, the immediate problem is not exclusions. It is silence.

"We are looking for policies to specifically cover AI security related issues, not just be silent on the matter," Kutger said. "We are looking for coverage for general AI output — accuracy, bias, performance, hallucination, etc."

Markets are still working through how to address AI-related exposures, with no settled standard yet, according to WTW's Insurance Marketplace Realities 2026 report. That uncertainty places the burden on brokers to push for explicit language rather than assume broad policy wording will respond.

Kutger said the gaps extend beyond AI output liability. "We are looking for coverage for deepfakes and pixel tracking," she said. "We look for coverage for biometric claims."

For brokers reviewing data center cyber programs, the right question is not just what the policy covers. It is what the policy does not address, and whether that silence will hold up when a claim arrives.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!