When Jaguar Land Rover’s systems went dark in the autumn of 2025, the shutdown ran for more than a month, wiped out roughly 50,000 vehicles of production, and eventually cost parent company Tata Motors close to $2.4 billion in a single quarter, enough to push one of India’s most prominent industrial groups into the red. Nine months later, Bajaj Auto disclosed a ransomware attack on its own systems and those of a subsidiary. What connected the two incidents, beyond the sector, was a detail that got far less attention than the headline losses: reporting at the time suggested JLR did not have cyber insurance coverage adequate to the scale of what happened. A company sophisticated enough to run precision manufacturing across three continents had, in effect, decided to self-insure against a risk it could not actually price.
That decision, or the absence of one, is becoming the most consequential architecture choice a large company makes, and it is being made in finance and procurement conversations that rarely reach the board. The reason is simple: cyber insurers have quietly become the most effective regulator of corporate technology architecture on the planet, more prescriptive than most national cybersecurity laws and considerably faster to update. Governments are still drafting frameworks. Underwriters have already decided what “adequate” looks like, and they update the definition every renewal cycle.

The de facto standard nobody voted on
Ask a CISO what changed in the last three years and the honest answer, more often than not, is not a regulation. It’s a renewal questionnaire. To get bound today, insurers routinely expect phishing-resistant multi-factor authentication on privileged accounts, endpoint detection and response tools across the estate, immutable or air-gapped backups with regular restore testing, documented patch management with defined timelines, and incident response plans that have actually been rehearsed rather than filed away. Miss enough of these and a company doesn’t just pay more. It gets sublimited, excluded from ransomware coverage specifically, or declined outright. None of this was legislated. It emerged from actuarial tables.
This is a genuinely unusual form of governance. National regulators, including India’s own insurance authority, have tightened rules on how insurers must handle cyber risk internally, mandating six-hour breach reporting to CERT-In and 180-day log retention among other requirements introduced through 2025. But those rules govern the insurers. What governs the insured, in practice, is the underwriting checklist, and that checklist moves at the speed of claims data, not legislative sessions. A regulator revises a framework every few years. An underwriter revises an appetite every renewal, sometimes every quarter, based on what has just gone wrong at companies that look like yours.
The numbers tell an uncomfortable story about who is winning
Coalition’s 2026 Cyber Claims Report found that initial ransomware demands surged 47 percent year over year in 2025, yet 86 percent of businesses refused to pay, a record high. Overall claims frequency rose only 3 percent, while average loss per claim actually fell 19 percent to $116,000. Business email compromise and funds transfer fraud, not ransomware, now account for the majority of incidents, and their average severity is dropping too. Read together, this is not a market getting safer in aggregate. It’s a market bifurcating. A large, disciplined cohort of insured companies is absorbing more attempted attacks at lower cost per incident, because the controls insurers forced on them, immutable backups chief among them, are doing exactly what they were designed to do: making ransom unnecessary rather than merely undesirable.
Then there is the other cohort, and JLR belongs in it more than its balance sheet would suggest it should. Large enterprises with over $100 million in revenue see claims frequency five times higher than smaller firms, according to the same report, and when a company that scale gets hit without the coverage or the architecture to absorb it, the loss is not a rounding error. It shows up in guidance, in a CFO calling a quarter “difficult,” in a hit to a national manufacturing base large enough that Tata’s Indian sales growth was needed to offset it.
The pricing signal makes the bifurcation explicit rather than implicit. Marsh’s Global Insurance Market Index and subsequent S&P Global analysis show cyber premiums falling sharply through 2026, in some markets by close to a fifth, even as claims frequency and severity rose in specific categories. That is not insurers getting careless. It’s insurers having already won the underlying argument. The companies renewing at lower rates are largely the ones that spent the last three years building the architecture insurers demanded. Softening prices are the reward for compliance that never had to be legislated. Everyone else is discovering, usually mid-incident, that the discount was never on offer to them.

Why this matters more in India than the headlines suggest
India’s cyber insurance market remains small relative to the exposure sitting on Indian balance sheets, projected to grow from a modest base to roughly $8.8 billion by the early 2030s at close to 28 percent annually, according to industry estimates, which tells you as much about how underpenetrated the market is today as it does about future growth. Meanwhile the country recorded close to 370 million malware attacks in 2024 alone, with banking, financial services and insurance the most targeted sectors. Star Health, one of India’s largest health insurers, was itself hit by ransomware following a data breach. The gap between exposure and coverage in Indian industry is not a niche actuarial curiosity; it is a live balance-sheet risk sitting inside some of the country’s largest manufacturing and financial groups, most of whom have historically treated cyber insurance as a compliance line item rather than a capital allocation decision.
This is precisely where the strategic miscalculation tends to happen. Executives assume that scale and sophistication substitute for insurer-grade architecture. JLR’s experience argues otherwise. A company can have world-class engineering and still lack the specific, insurer-legible controls, tested backups, segmented privileged access, rehearsed incident response, that determine whether an attack becomes a contained incident or a $2 billion quarter. For Indian conglomerates now running increasingly global, digitally interdependent operations, the underwriting bar is arguably the most concrete, externally validated definition of “reasonable security” available anywhere, more specific than most board risk committees have ever articulated internally.
What this means for how boards should actually govern the risk
The practical implication is not “buy more insurance.” It’s that the renewal conversation with an underwriter has become one of the few external, adversarial stress tests of a company’s actual security architecture, conducted by a counterparty with genuine financial skin in getting the assessment right. Boards that treat this as a procurement exercise, delegated three levels down and reviewed once a year in a five-minute agenda item, are outsourcing their most rigorous architecture review to people who never report back to them. The more useful posture, whether or not a company ultimately buys full coverage, is to ask what an underwriter would say about the current stack, and to treat a “no” or a heavily sublimited “yes” as a governance finding rather than an insurance-market inconvenience.
The companies that will be exposed next are not the ones without a CISO. They’re the ones whose boards still believe cybersecurity is a technical function that gets reported up, rather than a capital-markets relationship that increasingly writes the rules from outside the building.



