Third-party risk biggest driver of cyber insurance claims

Third-party risk was the dominant driver of cyber insurance claims and material losses in 2024, data from cyber risk solutions company Resilience has found.

Threat actors have a track record of exploiting a single point of failure in one company to create a cascading effect of disruption and chaos downstream, as evidenced by recent incidents including the PowerSchool, CDK and Change Healthcare breaches.

New cyber insurance claims data from Resilience’s portfolio illustrates the financial fallout this can have, finding that third-party risk, including ransomware and outages affecting vendors, accounted for 31% of all claims in 2024. Third-party risk led to claims with incurred losses for the first time, making up nearly a quarter (23%) of incurred claims in 2024.

“Third-party risk is...driving unprecedented losses," said Vishaal Hariprasad, co-founder and CEO of Resilience. "While this risk is often invisible until it’s too late, it’s now clear that the industry has reached a tipping point. Businesses can no longer afford to consider their partners’ vulnerabilities as siloed from their own. By understanding this new reality of shared risk, enterprises can make smarter business decisions and meaningfully mitigate material loss.”


See the Q1 2025 issue of CIR Magazine for our in-depth look at the cyber insurance market. Available here next week.



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.