Articles

0.25 CIP Points

bookmark icon

Cyber risk moves from IT to liability

AI & TechnologyConferenceCyberGeneral InsuranceProfessional Services

By Anna Lopata, ANZIIF senior writer Ransomware is changing faster than many businesses can respond, but Coveware’s James Finlay says the biggest cyber failures often begin long before attackers arrive. Cyber risk is no longer a narrow technology issue. For...

calendar icon15 Jun 2026

clock icon3 mins read

A
A
A
Cyber risk moves from IT to liability

Summary

    • AI is accelerating cyber threats, shrinking the time between vulnerabilities being discovered and exploited, leaving organisations with less time to respond.

      Preparation remains the strongest defence, with businesses that regularly test incident response plans recovering faster and avoiding costly operational and reputational fallout.

      Cyber incidents increasingly create liability exposures, extending beyond IT disruption to include regulatory investigations, customer claims, contractual disputes and reputational damage.

      Common weaknesses remain surprisingly basic, with inactive accounts, poor password management and inadequately protected backups continuing to enable many successful attacks.

      Future cyber resilience will depend on board-level understanding, as organisations face growing scrutiny over governance, insurance coverage and the long-term consequences of a cyber event.

By Anna Lopata, ANZIIF senior writer

Ransomware is changing faster than many businesses can respond, but Coveware’s James Finlay says the biggest cyber failures often begin long before attackers arrive.

Cyber risk is no longer a narrow technology issue. For insurers, brokers, boards and liability specialists, it has become a live test of governance, communication, contractual exposure and customer trust.

That is the focus James Finlay, Director, Coveware, will bring to the ANZIIF New Zealand Liability Conference, where he will take delegates inside the pressure, uncertainty and decision-making involved in a ransomware extortion.

Cyber events are preventable

Finlay’s message is blunt: the threat environment is accelerating, but many of the weaknesses that turn cyber events into liability problems remain familiar, preventable and often poorly understood outside the IT function.

“The thing that worries me most is speed,” Finlay says. “Criminals are using AI to find weaknesses in software faster than most organisations can fix them.”

That speed is changing the risk equation for businesses and the insurers that support them.

The window between a vulnerability being identified and exploited is narrowing, leaving organisations with less time to patch systems, assess exposure and communicate effectively.

For liability professionals, the implications are significant. A ransomware event may begin with a compromised account or an unpatched system, but the consequences can quickly extend into regulatory scrutiny, customer claims, supplier disputes and reputational damage.

Tactics are shifting

Finlay says ransomware tactics are also shifting. Data theft and extortion remain serious threats, but he says some criminal groups are returning to a more direct model: locking systems and demanding payment for a decryption key.

The reason is partly commercial. Businesses have become more skeptical about paying for promises that stolen data will be deleted.

“Paying a ransom rarely delivers the clean outcome victims are hoping for,” Finlay says.

That reality matters for insurers and insureds alike. It challenges assumptions about crisis resolution and reinforces the importance of preparation before an incident occurs.

Rehearsing failure

According to Finlay, the organisations that recover best are not always those with the largest cyber budgets or the most sophisticated tools. More often, they are the ones that have rehearsed failure.

“It almost always comes down to preparation,” he says. “Companies that bounce back fast have actually practiced what happens when things go wrong.”

That preparation includes knowing who has authority to make decisions, testing backups, understanding notification obligations and containing an incident before it spreads. It also means being ready to communicate with staff, customers, suppliers, regulators and the media at the same time.

This is where New Zealand organisations can be especially exposed. Finlay says that in larger markets, cyber incidents are so frequent they may attract limited public attention. In New Zealand, they are still more likely to become news.

That creates an additional reputational and operational burden for organisations already trying to restore systems and manage legal obligations. A response plan that looks adequate on paper may fail under pressure if it has never been tested.

“The ones that suffer most had a plan on paper but never tested it,” Finlay says.

This distinction is increasingly important. The quality of an insured’s incident response planning can influence not only the immediate cost of a cyber claim but also the likelihood of secondary liability exposures.

The good news

Finlay says there has been genuine improvement in how businesses respond during cyber incidents.

More organisations are making considered decisions under pressure, rather than defaulting to ransom payment.

He says ransom payment rates across Coveware’s casework reached record lows last quarter, sitting at around 23 per cent.

That is an encouraging signal for the market. However, Finlay cautions that emerging risks are moving into areas where underwriting scrutiny may not yet be fully mature, including cloud access management, supplier relationships and AI governance.

The common weaknesses seen during incident response are still often basic: dormant accounts remain active. Passwords are not rotated after migrations. Backups exist but are connected to the main network, allowing attackers to encrypt them too.

These are not always spectacular failures. Often, they are small unresolved issues that accumulate quietly over time until an attacker finds them.

“Most breaches succeed not because of a clever attack, but because of problems that quietly built up over time,” Finlay says.

That observation is particularly relevant for small and mid-sized organisations. Finlay says about two-thirds of ransomware attacks hit organisations with fewer than 1000 employees, despite many smaller businesses assuming they are not attractive targets.

For liability insurers and brokers, this creates a challenge around client education. Cyber resilience cannot be treated as an enterprise-only concern. Smaller organisations may have fewer resources, less formal governance and thinner crisis management capacity, yet still face severe consequences if systems are locked or data is exposed.

Getting buy-in from the board

Looking ahead, Finlay believes effective cyber risk management will depend on whether boards truly understand their exposure.

“The organisations that will handle this well are the ones where the board actually understands their exposure, not just what the IT team has told them,” he says.

That includes understanding what happens after systems are restored. A business may be operational again within days or weeks, but investigations, claims and customer fallout can continue for much longer.

“You can restore your systems in a week and still be dealing with regulatory investigations, customer lawsuits and reputational fallout a year later,” Finlay says.

This is where cyber insurance and liability intersect most clearly. The financial impact of an incident is not confined to ransom negotiations or restoration costs.

It may include legal advice, regulatory engagement, notification expenses, third-party claims, contractual disputes and long-tail reputational harm.

Finlay says some businesses only discover too late that their insurance does not respond in the way they expected.

Walk through a cyber attack

Delegates at the ANZIIF New Zealand Liability Conference, will find Finlay’s session designed to make that risk tangible.

Rather than speaking about cyber in abstract terms, Finlay will walk through the decisions that unfold during a real ransomware extortion and the mistakes that can turn a manageable incident into a catastrophic one.

He will also examine what happens to stolen data after an attack, including how it can be traded and reused on the dark web.

The session offers liability professionals a timely opportunity to examine cyber risk through a broader lens: not simply as a technology failure, but as a governance, preparedness and liability issue.

As ransomware tactics evolve and threat actors move faster, the organisations best placed to withstand an incident will be those that have tested their assumptions before they are under attack.

Get in before the New Zealand Liability Conference registrations close on 18 June.

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *