eCommerceNews Asia - Technology news for digital commerce decision-makers
Asia
CISO-CFO alignment key as cyber insurance market shifts

CISO-CFO alignment key as cyber insurance market shifts

Thu, 10th Sep 2026 (Today)
Richard Seiersen
RICHARD SEIERSEN Chief Risk Tech Officer Qualys

Cyber insurance moves in cycles, swinging between soft and hard markets. Today, we are in a soft market, where coverage is relatively inexpensive, capacity is abundant, and insurers compete aggressively to win (and keep) business. Capital is flowing, pricing has stabilised, and many buyers are seeing flat rates.

The temptation in a market like this is to treat cyber insurance as a price-driven renewal exercise: get the forms done, lock in the premium, move on. 

However, the best outcomes don't come from completing underwriting forms faster. They come from something far more basic, and often missing: a shared view between the CISO and CFO of what the business can't afford to lose, how quickly it needs to recover, and what that loss costs in real dollars. 

That shared view matters even more because the market is unlikely to stay this forgiving.  Gallagher's 2026 Cyber Insurance Market Outlook estimates the global cyber insurance market at US$16–20 billion in 2025 and forecasts it could grow to US$30–50 billion by 2030, with Asia-Pacific expected to record the highest growth rate as digitalisation accelerates. Growth is good news for capacity, but it also tends to come with maturing underwriting expectations.

This year, most analysts anticipate moderate hardening: gradual premium increases, more selective underwriting, and closer attention to security controls. It's unlikely we'll return to the severity of past hard markets, when applicants faced exhaustive questionnaires and lengthy underwriting delays – but this still means buyers will need to prove their security posture with clear evidence. 

There's also a wildcard that could harden conditions faster than anyone expects: a systemic cyber event. A major cloud outage, a widespread supply-chain compromise, or a high-impact ransomware wave that hits many insurers at the same time would create the kind of correlated loss that makes insurers slam on the brakes. Macroeconomic factors, such as interest rates, capital flows, and reinsurance pricing can also be a big factor in contributing to a market hardening. 

Why cyber insurance is a CISO-CFO job

This is why cyber insurance can't sit in the "annual procurement and compliance checkbox" bucket anymore. Insurance is a financial instrument. Cyber risk is an operational reality. If those two worlds don't meet, you get poor coverage decisions, avoidable exclusions, and awkward surprises at claim time. The organisations that handle this well treat cyber insurance as part of a coordinated risk-management strategy - and they do it through genuine collaboration between the CISO and CFO.

This collaboration has become more urgent in APAC, where rapid cloud adoption and AI-driven transformation are accelerating. Cyber insurance is most valuable when it's considered alongside risk reduction: not "insurance versus controls", but the right balance between risk transfer (insurance) and risk reduction (controls).

In practice, the CISO–CFO partnership works because each leader holds half the truth. The CISO understands attack paths, control effectiveness, and the messy reality of what can and can't be fixed quickly. The CFO understands cash flow, contractual exposure, margin impact, and what "three days offline" really means in revenue, penalties, and reputational cost. Put them together and you get a credible answer to the question underwriting is really asking: what is your probable loss, and why should we believe you can contain it?

Identify business-critical assets before you buy cover

The starting point is deceptively simple: agree on business-critical assets - and don't confuse that with "everything is important". Many organisations claim to have a critical asset list. Then you look at it and it's 200 items long. That's not a list – it's a filing cabinet. The goal is to clearly identify which assets the business cannot function without - the services and systems that, if disrupted, would materially impact revenue, service delivery, compliance obligations, or customer trust.

Once you have that shortlist, pressure-test it with one question: if this goes offline for 72 hours, for example, what happens? This should be quantified in real numbers: lost revenue, contractual penalties, overtime costs, incident response spend, customer churn, and the reputational impact that shows up later in pipeline and renewals. This is where the CFO is essential. CISOs are often asked to quantify cyber risk, yet they don't have access to the financial details to do so. CFOs can help price risk transfer and impact - because you can't buy the right limits if you don't understand what downtime truly costs.

With that shared business view in place, buying cyber insurance becomes far more strategic - and far less painful. This is also where a Risk Operations Centre (ROC) strengthens this further by consolidating risk signals into a single view, allowing you to measure your biggest risks in business terms, prioritise what matters, and drive remediation to reduce or mitigate exposure before it becomes an incident. It also becomes easier to judge whether your limits reflect your real interruption exposure – especially where cloud reliance and third-party dependencies are high – and it gives insurers the hard evidence they want that your controls are effective and your risk is reducing. 

Just as importantly, this alignment helps you avoid the friction trap. In a soft market, buyers have low tolerance for hassle. Nobody wants a renewal that feels like an audit, but you still need to provide clear, reusable evidence tied to business outcomes. The organisations that invest early in measurable posture and transparency typically find they have more options - and more leverage - as the market tightens.

The key takeaway is simple: cyber insurance works best when the CISO and CFO are aligned on what matters most to the business. A soft market is an opportunity, but not simply because premiums are lower. It's an opportunity because you have breathing room to improve cover economically while also improving resilience measurably - so you're not negotiating from weakness later.