| 1 | Threat / Category Claims severity Operational downtime and restoration duration[4][7]First cited source May 2026 · Latest cited source Jul 2026 | Why it mattersDowntime repeatedly separates manageable ransomware events from severe claims. | What to monitorRecovery-time tests, backup integrity, clean-room capacity, critical-process dependencies, lost revenue evidence, and restoration cost. | IntelliOS coverage |
| 2 | Threat / Category Fraud BEC and funds-transfer loss pathways[4][8]First cited source May 2026 · Latest cited source Jun 17, 2026 | Why it mattersFinancial fraud can begin with email, identity, SaaS, or direct financial-system access. | What to monitorPayment-change verification, dual approval, new beneficiaries, mailbox rules, impossible travel, help-desk resets, and bank escalation time. | IntelliOS coverage |
| 3 | Threat / Category Ransomware Payment, nonpayment, and negotiation readiness[1][3][4]First cited source May 2026 · Latest cited source May 8, 2026 | Why it mattersA defensible nonpayment position depends on restoration, legal, sanctions, safety, and communications readiness. | What to monitorBackup restore proof, extortion decision tree, sanctions checks, insurer consent, law-enforcement contact, and executive authority. | IntelliOS coverage |
| 4 | Threat / Category Remote access Internet-facing appliances and privileged access[4]Evidence dated May 2026 | Why it mattersRemote access is repeatedly associated with ransomware severity. | What to monitorAsset ownership, exposure, supported versions, MFA, historical logins, credential rotation, configuration drift, and management-interface restriction. | IntelliOS coverage |
| 5 | Threat / Category Third party Dependent-business-interruption triggers[1][4][6]First cited source May 2026 · Latest cited source Jun 17, 2026 | Why it mattersSupplier or customer incidents may be insured differently from internal failures. | What to monitorNamed providers, direct/contingent wording, waiting period, sublimit, restoration period, supplier notice, and fallback capability. | IntelliOS coverage |
| 6 | Threat / Category Policy structure Limits, retentions, sublimits, coinsurance, and aggregation[1][2][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026 | Why it mattersHeadline limits can overstate available recovery for the most likely scenario. | What to monitorSocial-engineering and FTF sublimits, ransomware coinsurance, privacy-defense limits, aggregate erosion, bricking, betterment, and consent. | IntelliOS coverage |
| 7 | Threat / Category Underwriting Evidence behind control attestations[1][2][8]First cited source May 7, 2026 · Latest cited source Jun 17, 2026 | Why it mattersUnderwriters increasingly reward proof, not policy statements. | What to monitorMFA coverage, EDR/MDR monitoring, patch SLAs, backup tests, training outcomes, privileged access, supplier reviews, and exceptions. | IntelliOS coverage |
| 8 | Threat / Category Accumulation Shared cloud, software, identity, and MSP concentration[5][6]First cited source Jun 8, 2026 · Latest cited source Jun 17, 2026 | Why it mattersOne dependency can affect many business units and many insureds. | What to monitorProvider inventory, concentration by revenue process, common software versions, geographic clustering, correlated policy lines, and modeled maximum loss. | IntelliOS coverage |
| 9 | Threat / Category Claims readiness Notice, consent, panel, and evidence obligations[1][3][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026 | Why it mattersDelay or unauthorized vendor engagement can complicate recovery. | What to monitor24/7 notice route, approved counsel/forensics, ransom or restoration consent, loss documentation, privilege plan, and insurer communications. | IntelliOS coverage |
| 10 | Threat / Category Coverage ambiguity AI, non-affirmative cyber, and new loss mechanisms[2][5][6]First cited source May 13, 2026 · Latest cited source Jun 17, 2026 | Why it mattersEmerging technology can create disputes about which policy or exclusion applies. | What to monitorAI use cases, autonomous actions, system-failure versus cyber triggers, silent cyber, contractual liability, and cross-line aggregation. | IntelliOS coverage |