IntelliOS Threat Intel Operating System
IntelliOSRolling Intelligence|AIRolling Cyber Insurance Watch

Cyber Insurance Claims, Coverage & Underwriting Rolling Intelligence Card

AI-generated, AI-updated weekly, AI quality-checked, and source-cited, this 90-day Rolling Intelligence Card reconciles current carrier claims reports, broker market updates, reinsurer research, supervisory analysis, and incident-response observations into a decision-ready view of loss frequency and severity, ransomware and funds-transfer outcomes, recovery expense, failed controls, pricing and capacity, policy structure, underwriting changes, coverage ambiguity, and systemic accumulation risk.

Coverage
Apr 30–Jul 28, 2026
Record Version
v5
Updated
Jul 28, 2026
AI Monitor
Weekly · Tue 12:30 PM ET
Evidence
15 Retained Sources
Product
Rolling Intelligence Card
Classification
TLP:CLEAR

Research Framing

Reporting-Period Statistics

Rolling 90-Day Intelligence Snapshot

At-a-glance measures from the retained evidence set. Citations identify the source controlling each statistic.

Period Coverage

Apr 30, 2026Jul 28, 2026

90 calendar days, inclusive. Records are included by their first-observed date inside this window; the period does not imply that every underlying incident began or was confirmed during it.

90-day windowWeekly on Tuesday at 12:30 PM ET

1 in 3[4]

Ransomware with downtime

At-Bay 2025 claims cohort; those claims had three-times-higher severity.Evidence dated May 2026

19%[1]

Third-party / supply-chain share

Gallagher referenced 2025 UK incident mix; not a 90-day market rate.Evidence dated May 7, 2026

$82.6K[7]

SME claim severity

Chubb EMEA 2025 average for $0–99M revenue cohort.Evidence dated Jul 2026

1,700+[5]

Survey participants

Munich Re / Triple-I RiskScan across U.S. and UK market segments.Evidence dated Jun 8, 2026

Gallagher referenced incident mix

2025 UK claims mix published in the 7 May 2026 report. This is a broker-observed historical cohort, not the rolling window's incident count.[1]Evidence dated May 7, 2026

Ransomware52%
Third-party / supply chain19%
BEC17%
Other listed causes12%

Intended Reader and Decision Context

Persona / Audience

Who this brief is written for, the geographic and organizational lens it uses, and how readers should apply the intelligence.

Audience fieldPrimary audienceAssessmentBoards, CFOs, risk managers, CISOs, CIOs, general counsel, insurance buyers, brokers, underwriters, claims leaders, incident-response owners, and business-continuity executives.
Audience fieldOrganization profileAssessmentU.S.-oriented and useful to SMB, midmarket, enterprise, healthcare, manufacturing, retail, professional-services, technology, and organizations with material SaaS, remote-access, payment, or supply-chain dependencies.
Audience fieldDecision perspectiveAssessmentUse the card to set renewal priorities, identify evidence required by underwriters, test whether likely loss scenarios fit limits and sublimits, preauthorize incident vendors, and decide which technology or control gaps could cause both a breach and a difficult claim.
Audience fieldEvidence postureAssessmentPortfolio statistics are directional and cohort-specific. They do not predict an individual insured's claim, guarantee coverage, or replace review of the actual policy and facts by broker, insurer, and counsel.

Chronology and Decision Milestones

Timeline of Notable Activity

Carrier reports, broker market updates, reinsurer and supervisory analysis, and practitioner signals are dated by publication. Underlying claims periods remain explicit and are never presented as losses that occurred entirely inside this rolling window.

  1. Broker market report

    Gallagher reports competitive capacity alongside evolving claims and broader terms

    Gallagher describes early-2026 buyer-friendly capacity, ransomware as 52% of its referenced 2025 UK incident mix, third-party events at 19%, and BEC at 17%. It also notes longer business-interruption periods, shorter waiting periods, full-limit bricking, and movement toward per-claim limits in some placements.[1]

  2. Carrier claims report

    Cowbell publishes portfolio loss drivers and ransomware economics

    Cowbell's report separates breach, cybercrime, extortion, and other claims; it also highlights concentrated ransomware actor activity, declining average ransom payments, and recurring systemic-event examples. The underlying claims span more than the active 90-day window.[3]

  3. Market update

    Gallagher keeps cyber capacity and pricing competitive but raises the control bar

    The broker's Q1 update says capacity remains favorable while ransomware, supplier dependence, MFA, network security, training, and AI-related coverage questions stay central to placement.[2]

  4. Carrier loss analysis

    At-Bay connects downtime, remote access, third parties, and liability to severity

    At-Bay reports that one in three ransomware claims in its 2025 cohort involved operational downtime and those claims had three times the severity; remote access carried the highest average severity, and third-party liability increased sharply.[4]

  5. Reinsurer survey

    Munich Re and Triple-I identify cyber, AI, interruption, and protection gaps as connected risks

    RiskScan surveys more than 1,700 U.S. and UK participants across buyers, brokers, and carriers and frames cyber loss as an interconnected operational, liability, supply-chain, and technology-dependency problem.[5]

  6. Supervisory analysis

    BIS elevates coverage ambiguity, pricing, protection gaps, and accumulation

    The Financial Stability Institute synthesizes market interviews and research to show why cyber insurance remains difficult to price and diversify when many insureds share cloud, software, managed-service, and infrastructure dependencies.[6]

  7. Incident-response forum signal

    NetDiligence highlights identity, help-desk impersonation, and SaaS access

    Practitioners report attackers bypassing controls through people, account recovery, identity, and SaaS paths. The signal is qualitative but directly relevant to underwriting questions and claim investigation.[8]

  8. Carrier severity update

    Chubb shows sharply different loss behavior by company size

    Chubb's current report says EMEA SME frequency and severity rose, while frequency fell for middle-market and large companies even as severity increased. It also identifies business interruption as a major ransomware severity driver and U.S. litigation as a loss multiplier.[7]

Bottom Line Up Front

BLUF

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  • Cyber insurance is still available on competitive terms, but evidence of resilience determines the quality of the deal: Gallagher reports strong capacity and broader terms for well-controlled risks, while underwriters continue to scrutinize MFA, monitoring, patching, supplier oversight, staff training, backups, and incident response. The practical renewal question is not simply price; it is whether the organization can prove the controls that support coverage and reduce loss.[1][2]First cited source May 7, 2026 · Latest cited source May 13, 2026

  • Business interruption—not the ransom alone—often determines whether a ransomware claim becomes severe: At-Bay says ransomware claims with operational downtime had three times the severity in its cohort, and Chubb identifies business interruption as a principal ransomware severity driver. Recovery architecture, restoration time, and dependent operations therefore belong in limit selection and exercises.[4][7]First cited source May 2026 · Latest cited source Jul 2026

  • Email fraud and direct funds-transfer pathways remain major insured loss channels: Carrier reporting continues to place BEC and financial fraud near the center of claim volume. Identity verification, payment-change controls, rapid bank notification, and preplanned recovery actions can change the net loss more than another generic awareness module.[4][8]First cited source May 2026 · Latest cited source Jun 17, 2026

  • Shared technology can create one event across many insureds: BIS and Munich Re warn that cloud, software, managed-service, supply-chain, and AI dependencies create correlated loss and accumulation risk. Buyers should identify the providers whose failure could exhaust dependent-business-interruption limits; carriers need portfolio visibility beyond industry labels.[5][6]First cited source Jun 8, 2026 · Latest cited source Jun 17, 2026

Decision Context

Executive Summary

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026

This card answers two different executive questions: what is causing insured cyber losses, and how is the insurance market responding? The retained sources show a functioning, competitive market, but not a simple one. Strong capacity and broader terms coexist with rising severity in important cohorts, stricter evidence demands, coverage ambiguity around new technology, and concern that one shared provider can affect many insureds at once.[1][2][5][6][7]First cited source May 7, 2026 · Latest cited source Jul 2026

Ransomware remains the most visible severity event, yet the ransom payment is only one component. At-Bay links operational downtime to three-times-higher severity in its claims cohort; Chubb similarly identifies business interruption as a primary severity driver. Gallagher reports that ransomware led its referenced incident mix and that data exfiltration accompanied many cases. Executives should therefore size coverage and exercises around restoration time, lost revenue, data response, notification, litigation, and supplier/customer interruption—not just an assumed ransom amount.[1][4][7]First cited source May 2026 · Latest cited source Jul 2026

Nonpayment outcomes are increasingly important. Cowbell reports lower average ransom payments and substantial demand reduction through negotiation, while carrier and broker reporting stresses viable backups, response teams, and law-enforcement engagement. A refusal-to-pay posture is credible only when restoration, safety, legal, sanctions, communications, and customer obligations are rehearsed before the event.[1][3]First cited source May 7, 2026 · Latest cited source May 8, 2026

BEC and funds-transfer fraud continue to create losses through both compromised email and direct access to financial workflows. The control objective is transaction integrity: independent verification of bank-detail changes, limits and dual authorization, identity-resistant help-desk processes, rapid financial-institution escalation, and preserved evidence. The organization must know which policy insuring agreements, sublimits, conditions, and notice requirements apply before a payment leaves.[4][8]First cited source May 2026 · Latest cited source Jun 17, 2026

The market is rewarding demonstrable control maturity, but questionnaires are not proof. Gallagher emphasizes MFA, network security, staff training, patch cadence, and supplier oversight; NetDiligence adds identity recovery and SaaS access. Underwriters and buyers should test whether controls cover privileged accounts, remote access, cloud identities, service desks, and third parties—not merely whether a box is checked.[1][2][8]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

Policy structure matters as much as the headline limit. Waiting periods, restoration periods, bricking language, dependent-business-interruption triggers, named-provider schedules, per-claim versus aggregate limits, social-engineering or funds-transfer sublimits, coinsurance, retentions, and consent requirements can materially change recovery. Competitive conditions create an opportunity to negotiate clarity before a loss.[1][2][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

Systemic accumulation is the portfolio-level concern. BIS and Munich Re describe protection gaps and correlated dependencies; Cowbell supplies concrete event examples. A cloud, identity, remote-management, widely deployed software, or managed-service failure can trigger many organizations and several lines of insurance simultaneously. Buyers should map dependency concentration; carriers should model it across the portfolio.[3][5][6]First cited source May 8, 2026 · Latest cited source Jun 17, 2026

The executive standard is evidence-ready resilience. Maintain a current asset and dependency inventory, prove the operation of key controls, match realistic loss scenarios to actual policy language, preapprove counsel and response vendors, test notice and consent workflows, and preserve the records needed to demonstrate both the incident and the claimed loss.[1][2][4][6][7][8]First cited source May 2026 · Latest cited source Jul 2026

Executive Briefing Priorities

Top 10 Briefing Points

  1. 1

    Do not combine carrier statisticsCowbell, At-Bay, Chubb, and Gallagher observe different insured populations, periods, regions, revenue bands, and claim definitions. Their findings can corroborate a pattern but cannot be arithmetically merged into one market rate.[1][3][4][7]First cited source May 2026 · Latest cited source Jul 2026

  2. 2

    Downtime is a severity multiplierAt-Bay reports three-times-higher severity when ransomware caused operational downtime; Chubb also places business interruption at the center of ransomware severity.[4][7]First cited source May 2026 · Latest cited source Jul 2026

  3. 3

    Remote access remains expensiveAt-Bay associates remote access with the highest average severity in its 2025 cohort and reports that many ransomware cases began through remote-access services.[4]Evidence dated May 2026

  4. 4

    Third-party loss is no longer peripheralGallagher places supply-chain incidents second in its referenced mix, while At-Bay reports insured vendors and customers in 14% of claims and a large increase in third-party liability.[1][4]First cited source May 2026 · Latest cited source May 7, 2026

  5. 5

    BEC is both a claim and a gatewayCarrier and practitioner reporting shows email compromise, social engineering, identity recovery, SaaS access, and financial workflows converging into theft and follow-on intrusion.[1][4][8]First cited source May 2026 · Latest cited source Jun 17, 2026

  6. 6

    Ransom payment is not the loss modelNegotiation and nonpayment can reduce extortion cost, but restoration, interruption, forensics, notification, legal response, liability, and reputation can dominate total severity.[1][3][4][7]First cited source May 2026 · Latest cited source Jul 2026

  7. 7

    Competitive pricing does not eliminate restrictive structureA lower rate can coexist with retentions, waiting periods, coinsurance, sublimits, named-provider restrictions, consent provisions, or narrower dependent-business-interruption language.[1][2][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

  8. 8

    Control evidence influences both underwriting and claimsMFA, monitoring, patching, backups, training, supplier oversight, and identity controls should be continuously evidenced, not reconstructed at renewal or after an incident.[1][2][8]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

  9. 9

    Shared providers create accumulation riskCloud, managed services, identity platforms, widely used software, and infrastructure dependencies can correlate losses across many insureds and policy lines.[3][5][6]First cited source May 8, 2026 · Latest cited source Jun 17, 2026

  10. 10

    Coverage clarity is an executive controlThe board should know which loss scenarios are covered, sublimited, excluded, subject to consent, or dependent on a named provider before approving risk transfer as a resilience strategy.[1][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

Source-Bound Exposure and Targeting

Victimology Matrix

This is not a raw victim list. Publicly named organizations are shown when reliable sources identify them, with confirmation and attribution boundaries preserved. Where no defensible name exists, IntelliOS uses the narrowest supported exposure population. Sector or geography matches remain scoping signals; they do not prove compromise.

Victim / exposure populationSMB and lower-middle-market insureds[7]Evidence dated Jul 2026SectorsCross-industry; especially organizations with limited security and recovery staffingGeographyEMEA evidence with global relevanceConfirmation statusChubb reports both frequency and severity pressure in its SME cohort; carrier-specific, not a universal rate.How companies should use itStress-test retention affordability, incident vendor access, restoration time, notification expense, and whether a single event could exhaust the limit.
Victim / exposure populationManufacturing and retail[1]Evidence dated May 7, 2026SectorsOperationally sensitive, distributed, and supply-chain dependentGeographyUK market evidenceConfirmation statusGallagher identifies both as heavily targeted in its referenced claims landscape.How companies should use itModel production or point-of-sale outage, supplier/customer interruption, data theft, and communications across a distributed workforce.
Victim / exposure populationProfessional services, construction, manufacturing, healthcare, and wholesale[3]Evidence dated May 8, 2026SectorsCowbell claims concentrationGeographyPrimarily U.S. carrier portfolioConfirmation statusNamed as recurrent sectors in Cowbell's report; this is carrier portfolio evidence.How companies should use itCompare owned technologies, payment workflows, sensitive data, and interruption dependencies to sector-specific claim scenarios.
Victim / exposure populationOrganizations dependent on vendors, customers, cloud, or managed services[1][4][5][6]First cited source May 2026 · Latest cited source Jun 17, 2026SectorsCross-industryGeographyGlobalConfirmation statusMultiple sources identify third-party and shared-service loss pathways.How companies should use itMap dependency concentration, contract notice, fallback operations, and the exact policy trigger and sublimit for dependent interruption.

Distinct Operational Records

Claims Scenarios & Loss Drivers

Ransomware, exfiltration, and business interruption

The recurring high-severity scenario combines operational downtime, data theft, restoration, notification, liability, and negotiation expense. Payment is only one branch of the loss tree.[1][3][4][7]First cited source May 2026 · Latest cited source Jul 2026

BEC and funds-transfer fraud

Compromised mailboxes, impersonation, account recovery, SaaS access, and payment-workflow manipulation can produce direct theft, recovery expense, and coverage disputes over the applicable insuring agreement or sublimit.[4][8]First cited source May 2026 · Latest cited source Jun 17, 2026

Third-party and dependent interruption

Supplier, customer, cloud, software, and service-provider failures can create losses without a security failure inside the insured's own environment.[1][4][5][6]First cited source May 2026 · Latest cited source Jun 17, 2026

Privacy and regulatory liability

Data exfiltration, website tracking, notification, litigation, and jurisdictional privacy rules can extend a technical incident into multi-year liability and defense cost.[6][7]First cited source Jun 17, 2026 · Latest cited source Jul 2026

Source-Bound Actor Context

Insurance Market Participants & Evidence Contributors

Carriers: Cowbell, At-Bay, and Chubb

These insurers supply portfolio-specific claims evidence. Their findings are valuable precisely because they are not treated as one interchangeable dataset.[3][4][7]First cited source May 2026 · Latest cited source Jul 2026

Broker: Gallagher

Gallagher contributes placement, capacity, wording, claims-mix, and underwriting observations that connect loss experience to the terms buyers can negotiate.[1][2]First cited source May 7, 2026 · Latest cited source May 13, 2026

Reinsurer and market survey: Munich Re / Triple-I

RiskScan connects buyer, broker, and carrier perceptions to protection gaps, AI, interruption, and connected risk.[5]Evidence dated Jun 8, 2026

Supervisory and practitioner contributors: BIS FSI and NetDiligence

BIS frames market sustainability and accumulation; NetDiligence supplies active practitioner observations about identity and SaaS-enabled incidents.[6][8]Evidence dated Jun 17, 2026

Malware, Implants, and Intrusion Tooling

Malware Summary

Source-backed malware and malicious tooling named in the retained campaigns. The table distinguishes malware families, open-source tools, custom implants, exploit or collection tooling, and reported outcomes that lack a publicly identified sample.

Malware / toolingAkira[3][4]First cited source May 2026 · Latest cited source May 8, 2026Classification and campaignRansomware / extortionCowbell identifies Akira as a major share of ransomware actor cases in its report, and At-Bay links Akira activity to a surge in ransomware claim frequency in the second half of 2025.Capability and potential impactEncryption, exfiltration, and operational disruption can trigger restoration, interruption, forensics, notification, legal, and extortion costs.What defenders should monitorRemote-access activity, identity compromise, lateral movement, backup and hypervisor access, exfiltration, encryption precursors, and recovery-time evidence.
Malware / toolingQilin[3]Evidence dated May 8, 2026Classification and campaignRansomware / extortionCowbell includes Qilin among the concentrated set of ransomware actors in its claims analysis.Capability and potential impactData theft and encryption can expand a first-party interruption claim into privacy, notification, defense, and third-party liability.What defenders should monitorEdge and identity access, staging, privileged account use, exfiltration, virtualization or backup access, and public extortion claims.

Enterprise Exposure

Named Technologies Affecting Policyholder Risk

SonicWall SMA1000 and SonicWall remote-access estates

At-Bay reports that one in three ransomware claims in its 2025 cohort involved SonicWall; that historical carrier cohort is separate from the current CVE-2026-15409/CVE-2026-15410 SMA1000 campaign. SonicWall now confirms active exploitation. A policyholder should identify every SMA1000 6210, 7210, and 8200v, validate its fixed release, investigate historical exposure, rotate appliance-accessible credentials, and test whether compromise reached identity or internal systems.[4][9][10]First cited source May 2026 · Latest cited source Jul 24, 2026

Langflow AI workflow servers — CVE-2026-0770

CISA and NVD identify active exploitation of an unauthenticated code-execution flaw that can run in the server's root context. Langflow is narrower than a mainstream VPN product, but an exposed instance may hold API keys, model credentials, data connectors, flows, and privileged service access. For an insured, the loss path can include secret theft, connected-service compromise, data exposure, trusted-workflow alteration, response cost, and dependent interruption.[9][11]First cited source Jul 21, 2026 · Latest cited source Jul 24, 2026

Oracle PeopleSoft PeopleTools — CVE-2026-35273

CISA marks known ransomware use, while Oracle identifies remotely exploitable affected versions. PeopleSoft commonly concentrates employee, payroll, student, and financial data; compromise can therefore combine extortion, privacy response, business interruption, credential exposure, and notification costs.[9][12]First cited source Jun 10, 2026 · Latest cited source Jul 24, 2026

Check Point Security Gateway IKEv1 VPN — CVE-2026-50751

Check Point confirms active exploitation of an authentication bypass in deprecated IKEv1 remote-access configurations and assesses a financially motivated/Qilin association with medium confidence. Insureds should confirm whether the deprecated configuration exists, apply the hotfix, review VPN activity, and preserve evidence before treating remediation as complete.[9][13]First cited source Jun 8, 2026 · Latest cited source Jul 24, 2026

PTC Windchill and FlexPLM — CVE-2026-12569

CISA marks known ransomware campaign use and PTC directs customers to patch and hunt for web shells. Manufacturers, engineering organizations, and suppliers may face theft of product designs and intellectual property, disruption of engineering workflows, credential compromise, and downstream contractual loss.[9][14]First cited source Jun 18, 2026 · Latest cited source Jul 24, 2026

Microsoft on-premises SharePoint exploitation cluster

The Canadian Cyber Centre groups a current cluster of actively exploited on-premises SharePoint vulnerabilities. Because SharePoint can hold collaboration data, credentials, workflows, and business records, compromise can produce a broad privacy, interruption, legal, and restoration claim. Cloud SharePoint should not be conflated with affected on-premises products.[9][15]First cited source Jul 16, 2026 · Latest cited source Jul 24, 2026

Email, identity, help desk, SaaS, and recovery control planes

Claims and practitioner reporting still show attackers exploiting people, account recovery, cloud identities, backups, hypervisors, and recovery tooling. These controls determine whether a named-product intrusion stays local, becomes a funds-transfer event, or expands into prolonged interruption and ransom pressure.[3][4][7][8]First cited source May 2026 · Latest cited source Jul 2026

Current Carry-Forward Watchlist

Top 10 Specific Threats to Monitor

Prioritized claim drivers, policy mechanics, underwriting controls, technology dependencies, and market signals that require a named monitoring owner.

1Threat / Category

Claims severity

Operational downtime and restoration duration[4][7]First cited source May 2026 · Latest cited source Jul 2026

Why it mattersDowntime repeatedly separates manageable ransomware events from severe claims.What to monitorRecovery-time tests, backup integrity, clean-room capacity, critical-process dependencies, lost revenue evidence, and restoration cost.IntelliOS coverage
2Threat / Category

Fraud

BEC and funds-transfer loss pathways[4][8]First cited source May 2026 · Latest cited source Jun 17, 2026

Why it mattersFinancial fraud can begin with email, identity, SaaS, or direct financial-system access.What to monitorPayment-change verification, dual approval, new beneficiaries, mailbox rules, impossible travel, help-desk resets, and bank escalation time.IntelliOS coverage
3Threat / Category

Ransomware

Payment, nonpayment, and negotiation readiness[1][3][4]First cited source May 2026 · Latest cited source May 8, 2026

Why it mattersA defensible nonpayment position depends on restoration, legal, sanctions, safety, and communications readiness.What to monitorBackup restore proof, extortion decision tree, sanctions checks, insurer consent, law-enforcement contact, and executive authority.IntelliOS coverage
4Threat / Category

Remote access

Internet-facing appliances and privileged access[4]Evidence dated May 2026

Why it mattersRemote access is repeatedly associated with ransomware severity.What to monitorAsset ownership, exposure, supported versions, MFA, historical logins, credential rotation, configuration drift, and management-interface restriction.IntelliOS coverage
5Threat / Category

Third party

Dependent-business-interruption triggers[1][4][6]First cited source May 2026 · Latest cited source Jun 17, 2026

Why it mattersSupplier or customer incidents may be insured differently from internal failures.What to monitorNamed providers, direct/contingent wording, waiting period, sublimit, restoration period, supplier notice, and fallback capability.IntelliOS coverage
6Threat / Category

Policy structure

Limits, retentions, sublimits, coinsurance, and aggregation[1][2][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

Why it mattersHeadline limits can overstate available recovery for the most likely scenario.What to monitorSocial-engineering and FTF sublimits, ransomware coinsurance, privacy-defense limits, aggregate erosion, bricking, betterment, and consent.IntelliOS coverage
7Threat / Category

Underwriting

Evidence behind control attestations[1][2][8]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

Why it mattersUnderwriters increasingly reward proof, not policy statements.What to monitorMFA coverage, EDR/MDR monitoring, patch SLAs, backup tests, training outcomes, privileged access, supplier reviews, and exceptions.IntelliOS coverage
8Threat / Category

Accumulation

Shared cloud, software, identity, and MSP concentration[5][6]First cited source Jun 8, 2026 · Latest cited source Jun 17, 2026

Why it mattersOne dependency can affect many business units and many insureds.What to monitorProvider inventory, concentration by revenue process, common software versions, geographic clustering, correlated policy lines, and modeled maximum loss.IntelliOS coverage
9Threat / Category

Claims readiness

Notice, consent, panel, and evidence obligations[1][3][6]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

Why it mattersDelay or unauthorized vendor engagement can complicate recovery.What to monitor24/7 notice route, approved counsel/forensics, ransom or restoration consent, loss documentation, privilege plan, and insurer communications.IntelliOS coverage
10Threat / Category

Coverage ambiguity

AI, non-affirmative cyber, and new loss mechanisms[2][5][6]First cited source May 13, 2026 · Latest cited source Jun 17, 2026

Why it mattersEmerging technology can create disputes about which policy or exclusion applies.What to monitorAI use cases, autonomous actions, system-failure versus cyber triggers, silent cyber, contractual liability, and cross-line aggregation.IntelliOS coverage

Operational Standards from the Evidence

Best Practices and Lessons Learned

The practices below convert carrier, broker, reinsurer, claims, incident-response, and supervisory evidence into repeatable insurance-buying and claims-readiness standards.

Coverage periodApr 30, 2026Jul 28, 202690 calendar days, inclusiveUpdated Jul 28, 2026
  1. 1

    Best Practice

    Model claims, not just attacks[1][4][6][7]First cited source May 2026 · Latest cited source Jul 2026

    Lesson Learned

    The same intrusion can create interruption, restoration, privacy, liability, fraud, and extortion costs under different policy sections.

    Minimum Operating Standard

    Run at least ransomware, funds-transfer, cloud outage, and vendor-breach loss scenarios against actual limits, sublimits, retentions, waiting periods, and exclusions.

  2. 2

    Best Practice

    Evidence underwriting controls continuously[1][2][8]First cited source May 7, 2026 · Latest cited source Jun 17, 2026

    Lesson Learned

    A renewal answer is less useful than proof that the control operated when loss occurred.

    Minimum Operating Standard

    Retain MFA, monitoring, patch, backup, training, vendor, and access-control evidence with named owners and exception records.

  3. 3

    Best Practice

    Preauthorize the claim response[3][4]First cited source May 2026 · Latest cited source May 8, 2026

    Lesson Learned

    Notice, consent, panel, and vendor-selection friction consumes the hours when containment and funds recovery matter most.

    Minimum Operating Standard

    Maintain a tested 24/7 insurer/broker notice route, panel contacts, consent thresholds, sanctions workflow, and evidence checklist.

  4. 4

    Best Practice

    Map technology accumulation[5][6]First cited source Jun 8, 2026 · Latest cited source Jun 17, 2026

    Lesson Learned

    A shared dependency can create correlated loss across entities, products, and policies.

    Minimum Operating Standard

    Identify cloud, identity, MSP, software, telecom, payment, and data-provider concentration and compare it with policy aggregation language.

  5. 5

    Best Practice

    Negotiate wording while capacity is favorable[1][2]First cited source May 7, 2026 · Latest cited source May 13, 2026

    Lesson Learned

    Competitive conditions are an opportunity to clarify dependent interruption, bricking, restoration, waiting periods, and per-claim structure.

    Minimum Operating Standard

    Document requested improvements, rejected alternatives, and the business scenario each term is intended to protect.

Automation Transparency

AI Agent Run Status

AgentCyber Insurance Claims, Coverage & Underwriting Rolling Intelligence Card Publisher
StatusActive · rolling 90-day automation
CadenceWeekly on Tuesday at 12:30 PM ET
Previous run24 Jul 2026 · 12:30 PM ET · Run cyber-insurance-activity-2026-07-24-1230
Previous resultNamed-technology correction completed; current exploitation records were reconciled with carrier loss evidence without treating vendor advisories as claims.
What the previous run found
  • Retained fifteen carrier, broker, reinsurer, official, vendor, and practitioner sources.
  • Named SonicWall SMA1000, Langflow, PeopleSoft, Check Point, PTC Windchill/FlexPLM, and on-premises SharePoint rather than hiding them inside generic technology classes.
  • Separated current exploitation evidence from historical carrier claims cohorts.
  • No policy outcome or market-wide loss rate was inferred from a single portfolio.
Next run28 Jul 2026 · 12:30 PM ET
Sources monitored
  • Coalition, At-Bay, Beazley, Cowbell, Corvus, Chubb, and other carriers
  • CISA KEV, NVD, national CSIRTs, and vendor PSIRTs for named policyholder technologies
  • Munich Re, Swiss Re, and reinsurer research
  • Marsh, Aon, Gallagher, Howden, Lockton, and broker market updates
  • NetDiligence, Coveware, CyberAcuView, claims and incident-response firms
  • IntelliOS cyber insurance, vulnerability, campaign, and breach-response source trackers
  • PETRA report database query constrained to the active rolling 90-day publication window; older reports remain discovery-only
Publication and alert policyPublish and alert only when a source-backed change materially affects claims frequency or severity, loss causation, payment outcome, recovery expense, underwriting controls, pricing/capacity, policy structure, coverage dispute, or accumulation risk. Suppress no-change messages.

Related Intelligence and CARDS Records

Other IntelliOS Products

Publication History

Version Change Log

Versionv4Date24 Jul 2026ChangeCorrected the policyholder-technology section. Added source-backed rows for SonicWall SMA1000, Langflow, Oracle PeopleSoft, Check Point Security Gateway, PTC Windchill/FlexPLM, and on-premises SharePoint; explicitly separated active-exploitation evidence from historical insurance-claims cohorts; and connected the new Exploitable Technology Risk Rolling Intelligence Card.MonitoringWeekly Tuesday material-change review
Versionv3Date24 Jul 2026ChangeAdded the PETRA report database to the Tier 6 source audit and weekly monitor. The query confirmed that PETRA’s insurance and claims corpus is largely published in arrears: no report had a publication date inside Apr 26–Jul 24, so older annual and period reports remain discovery-only.MonitoringWeekly Tuesday material-change review
Versionv2Date24 Jul 2026ChangeRebuilt Research Framing source coverage as a complete Tier 0–Tier 8 audit. The ledger now identifies 22 checked sources, eight selected publications, 14 checked-but-not-used regulator, carrier, broker, reinsurer, claims, and tracker sources, and the exact role of every tier.MonitoringWeekly Tuesday material-change review
Versionv1Date24 Jul 2026ChangeInitial full rolling 90-day Cyber Insurance Claims, Coverage & Underwriting Rolling Intelligence Card with Research Framing, Timeline, locked BLUF and Executive Summary, top-ten findings and monitoring table, claims scenarios, market participants, malware, technologies, victimology, lessons learned, AI agent status, connected IntelliOS products, and source-role treatment.MonitoringWeekly Tuesday material-change review

Citations

Retained Sources and Claim Treatment

Source1PublisherGallagherPublished2026-05-07Publication / evidenceSource indexprimary researchWhy used / claim treatmentCurrent broker market and claims analysis published within the rolling window. Its incident mix primarily describes 2025 UK claims and is used as a directional underwriting baseline, not as a 90-day incident census.SourceUK Cyber Market Report 2026

https://www.ajg.com/uk/-/media/files/gallagher/uk/news-and-insights/2026/uk-cyber-market-report-2026.pdf

Source2PublisherGallagherPublished2026-05-13Publication / evidenceSource indexprimary researchWhy used / claim treatmentBroker market update used for current capacity, competition, pricing, supplier-risk, control, and coverage observations. It is not a policy quotation or a guarantee of terms for a particular insured.SourceInsurance Focus: Q1 Market Update

https://www.ajg.com/uk/news-and-insights/insurance-focus-q1-market-update/

Source3PublisherCowbellPublished2026-05-08Publication / evidenceSource indexprimary researchWhy used / claim treatmentCarrier claims analysis published within the window. The report aggregates Cowbell claims experience across a longer historical period; percentages are portfolio-specific and are not presented as market-wide 90-day loss rates.SourceCyber Roundup: 2026 Claims Report

https://cowbell.insure/wp-content/uploads/pdfs/CB-US-CyberRoundup-2026ClaimsReport.pdf

Source4PublisherAt-BayPublished2026-05Publication / evidenceSource indexprimary researchWhy used / claim treatmentCarrier analysis of more than 100,000 policy-years published during the rolling window. Findings describe the carrier's 2025 claims cohort and are retained as a current loss-driver baseline, not current-window claim frequency.Source2026 InsurSec Report

https://www.at-bay.com/wp-content/uploads/2026/04/At-Bay-2026-InsurSec-Report.pdf

Source5PublisherMunich Re US and Insurance Information InstitutePublished2026-06-08Publication / evidenceSource indexprimary researchWhy used / claim treatmentReinsurer and industry survey of more than 1,700 U.S. and UK participants. It measures risk perception and protection gaps rather than observed insurance claims.SourceRiskScan 2026 Survey

https://www.munichre.com/en/company/media-relations/media-information-and-corporate-news/business-news/2026/riskscan-2026-survey.html

Source6PublisherBank for International Settlements, Financial Stability InstitutePublished2026-06-17Publication / evidenceSource indexofficialWhy used / claim treatmentSupervisory synthesis based on market interviews and desktop review. Used for coverage ambiguity, underwriting, protection-gap, and accumulation-risk context; cited third-party loss figures are not treated as new BIS claims data.SourceCyber insurance unpacked: the corporate digital safety net

https://www.bis.org/fsi/publ/insights75.htm

Source7PublisherChubbPublished2026-07Publication / evidenceSource indexprimary researchWhy used / claim treatmentCurrent carrier report using historical claims through December 2025. Frequency and severity figures are cohort- and geography-specific; the publication is in-window, but the underlying losses are not described as 90-day activity.Source2026 EMEA Cyber Claims Report: Cyber risk, trends and resources

https://www.chubb.com/ie-en/business/resources/cyber-claims-report-cyber-risk-trends-and-resources.html

Source8PublisherNetDiligencePublished2026-06-17Publication / evidenceSource indexincident responseWhy used / claim treatmentPractitioner synthesis from a private incident-response forum. Used for current identity, help-desk impersonation, SaaS, and broker-control priorities; it is not a statistically representative claims study.SourceRansomware Advisory Board: Identity-Based Attacks Drive Growing Cyber Risk

https://netdiligence.com/blog/2026/06/identity-based-attacks-cyber-brokers-2026/

Source9PublisherCybersecurity and Infrastructure Security AgencyPublished2026-07-24Publication / evidenceSource indexofficialWhy used / claim treatmentCISA's live catalog controls whether a vulnerability has evidence of active exploitation, its federal required-action date, and the catalog's known-ransomware-use field. It does not establish that every exposed policyholder was compromised.SourceKnown Exploited Vulnerabilities Catalog — active rolling-window extract

https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

Source10PublisherSonicWall PSIRTPublished2026-07-14Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling affected SMA1000 models, fixed releases, and active-exploitation status for CVE-2026-15409 and CVE-2026-15410. It is product-risk evidence, not insurance-claim frequency.SourceSMA 1000 Series Appliances Affected by Multiple Vulnerabilities

https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

Source11PublisherNational Vulnerability DatabasePublished2026-07-21Publication / evidenceSource indexofficialWhy used / claim treatmentGovernment vulnerability record used with CISA KEV to establish Langflow's unauthenticated code-execution condition and current exploitation status. It does not quantify deployment prevalence or insured loss.SourceCVE-2026-0770 Detail and KEV Synchronization

https://nvd.nist.gov/vuln/detail/CVE-2026-0770

Source12PublisherOraclePublished2026-06-10Publication / evidenceSource indexofficialWhy used / claim treatmentVendor security alert controlling affected PeopleSoft PeopleTools versions and unauthenticated network exploitability. Campaign and victim claims remain attached to separate incident-response reporting.SourceOracle Security Alert Advisory — CVE-2026-35273

https://www.oracle.com/security-alerts/alert-cve-2026-35273.html

Source13PublisherCheck PointPublished2026-06-08Publication / evidenceSource indexofficialWhy used / claim treatmentVendor advisory controlling affected IKEv1 VPN configurations, active exploitation, remediation, and Check Point's medium-confidence assessment of financially motivated activity associated with Qilin ransomware.SourceActive Exploitation of Check Point VPN Authentication Bypass — CVE-2026-50751

https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/

Source14PublisherPTCPublished2026-06-18Publication / evidenceSource indexofficialWhy used / claim treatmentVendor notice controlling CVE-2026-12569 affected-product, patch, and incident-hunting guidance. CISA separately marks the vulnerability as known ransomware campaign use.SourceCritical Windchill and FlexPLM Remote Code Execution Notice

https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability

Source15PublisherCanadian Centre for Cyber SecurityPublished2026-07-16Publication / evidenceSource indexofficialWhy used / claim treatmentOfficial partner-government alert used to identify the current on-premises SharePoint exploitation cluster and urgent patching requirement. It does not establish loss or compromise for every SharePoint owner.SourceCritical SharePoint Server Vulnerabilities — CVE-2026-56164, CVE-2026-55040, and CVE-2026-58644

https://www.cyber.gc.ca/en/alerts-advisories/al26-017-critical-vulnerabilities-impacting-microsoft-sharepoint-server-cve-2026-56164-cve-2026-55040-cve-2026-58644