AI News Feed
Market watch
Cybersecurity

Businesses overestimate cyber insurance and lack critical asset data, reports find

Studies show businesses lack reliable data on critical connected devices and most UK CEOs overestimate cyber insurance coverage.

In the first report, security company Claroty analyzed 17 million cyber-physical assets and found that 88% failed to transmit an exact product code, while 76% sent a code that did not match the vendor's own record. Cyber-physical systems include hospital imaging equipment, factory control systems and building HVAC networks, which sit at the convergence of information technology and operational technology. Without a reliable product identifier, security teams cannot quickly determine whether a vulnerability alert applies to a particular device.

The report adds that 41% of devices had no operating system version available, and 24% had no operating system name. The same incomplete vendor data also undermines CVE advisories, the standard mechanism for tracking vulnerabilities. As a result, confirming whether a known vulnerability affects a device can take days and often ends in a guess rather than an answer.

Claroty's research also points to broader anxiety about this situation. In a global survey of 1,100 security leaders, 44% named understanding their organization's risk exposure as among their biggest operational concerns, and 45% said they were struggling to reduce cyber risk to their most important assets and processes. The firm said the connection between that difficulty and an unreliable asset inventory is often missed.

Improving the situation requires treating visibility as more than detecting a device's presence, Claroty said. Security teams need to know what the device does, what process depends on it and what would happen if it were compromised. In one example, an AI-driven mapping technique lifted product code identification in an OEM's device catalogue from 4% to 83%, with 56% of devices receiving a new or updated firmware recommendation as a result.

A separate report from data security company Cohesity surveyed 100 CEOs of large UK enterprises and found that only 22% expect their cyber insurance policy to cover both the additional costs and lost revenue of an attack. A third said the policy would cover additional costs only, another third said it would cover lost revenue only, and one in ten said it would cover neither. Cohesity concluded that cyber insurance in its current state transfers only some financial risk and is not enough to restore systems, data or operations.

The Cohesity study also found that businesses expect a cyberattack to reduce revenue by an average of 15%, but many lack a detailed understanding of the potential cost. As many as 21% of CEOs have not conducted business impact modeling. Among CEOs' biggest fears are data breaches (49%), brand and reputational damage (38%), high recovery costs (36%), revenue loss (34%) and production downtime (30%) - all financial concerns or incidents that could lead to financial loss.

Fraser Hutchison, UK&I vice president at Cohesity, said organizations must be able to identify the systems and data needed to keep the business operating, assign clear responsibility for recovery decisions and regularly test whether critical services can be restored securely.