Cyber exposures associated with modern data centres are evolving faster than many traditional cyber insurance policies, creating potential coverage gaps around business interruption, artificial intelligence, operational technology and emerging digital liabilities. Karen Kutger, wholesale production leader for management, professional and cyber at Novatae Risk Group, said brokers need to pay closer attention to both security controls and policy wording when placing data-centre risks.

The financial consequences of cyber incidents are also increasing. According to data cited by Insurance Business from Resilience, the average cost of an individual ransomware attack increased 17% during the first half of 2025. For data centres, a significant cyber event can have consequences extending far beyond the affected facility because numerous customers and businesses may depend on the same infrastructure.

The scale of data-centre operations has changed substantially as the industry has moved from traditional colocation facilities towards hyperscale infrastructure. Kutger highlighted the potentially catastrophic accumulation risk, with billions or even trillions of data points potentially exposed and an incident capable of creating cascading business-interruption losses. Large facilities may also attract state-sponsored cyberattacks, adding another dimension to the threat landscape.

One of the most important coverage considerations is dependent business interruption (BI). Brokers need to examine whether policy wording responds not merely to routine outages but also to catastrophic events affecting interconnected customers, suppliers and technology infrastructure. The definition of dependent exposures must therefore be broad enough to reflect the actual concentration and cascading nature of data-centre risk.

Cyber-security controls are also becoming a significant underwriting and pricing factor. Kutger said differences in controls can produce premium variations of up to 35% between otherwise comparable data-centre facilities. Underwriters are examining whether multi-factor authentication is consistently implemented across remote access, privileged accounts and cloud applications, rather than merely whether an organisation states that MFA is in place.

Weaknesses in endpoint detection and response (EDR), managed detection and response (MDR) and exposed administrator portals can complicate underwriting. Insurers may conduct their own external scans, meaning that open remote-access ports can be detected even where proposal documentation suggests that suitable controls are operating. Carriers are also looking for encrypted backups that are fully disconnected from the main network to strengthen resilience against ransomware and other attacks.

A further challenge is the rapid emergence of AI-related exposures. Artificial intelligence and operational technology are widening the data-centre attack surface while insurance policy language has not necessarily developed at the same pace. Kutger said brokers should seek explicit coverage rather than rely on policy silence, particularly for issues involving AI output such as accuracy, bias, performance and hallucinations.

The insurance market has not yet developed a settled standard for many AI-related risks. Other emerging exposures identified for specific consideration include deepfakes, pixel tracking and biometric claims. Consequently, brokers and risk managers increasingly need to examine not only exclusions but also areas where policies simply do not specify whether coverage applies.

For insurers, brokers and data-centre operators, the development illustrates a broader shift in cyber underwriting. Effective insurance protection increasingly depends on combining robust technical controls with carefully structured coverage for dependent business interruption and emerging AI-related liabilities. With security controls capable of influencing premiums by as much as 35%, cyber resilience is becoming both a risk-management requirement and an important determinant of insurance cost and availability.

Want to deepen your expertise beyond today’s news?

Explore practical certification courses designed for banking, risk, insurance, compliance, ESG, AI, and emerging technologies professionals.

Learn from industry experts and earn certifications from RMAI and BFSI Sector Skill Council of India.

#Insurancenews

Author

Byadmin