Most UK Retailers Hit By Cyber Disruption Say They Overspend On Cyber

Cyber Insurance News story on UK retail cyber risk showing a shopfront at night with shelves of glowing padlocks behind a half-lowered shutter

Marsh surveyed 350 senior UK retail executives. Among those who went through a major cyber disruption last year, 64% say they are overinvesting in cyber resilience. Marsh says the measure that matters is speed of recovery. Last year, cyberattacks caused mass disruption at major UK retailers, including Marks & Spencer. The sector responded by spending. … Read more

The Phish That Passes MFA: China-Aligned TA419 Targets AI Policy Experts

Cyber Insurance News story on phishing-resistant MFA showing a fake login window layered over a genuine one

Proofpoint says a China-aligned group posed as former White House staff and other AI policy figures to phish US experts. Its kit relays the genuine Microsoft sign-in, so the password and the MFA code both work. Proofpoint recommends phishing-resistant MFA such as passkeys. The first email asks for nothing. It invites an AI policy expert … Read more

The Proposal Form Only Knows What The Insured Declares

Cyber Insurance News story on silent AI exposure showing a scan beam revealing hidden AI nodes behind a blank website window

KYND has launched an AI detection capability aimed at silent AI exposure. It identifies AI technologies across an organization’s external footprint from a single domain, with no input from the business. A cyber proposal form can ask about AI. The answer depends on what the applicant knows and chooses to say. KYND says underwriters now … Read more

Headquarters Pays The Ransom. Franchisees Set The Rules.

Cyber Insurance News story on franchise cyber risk showing a row of shopfronts with one store's red glow spreading to its neighbors

VikingCloud surveyed large multi-location brands, which the report calls “distributed enterprises,” on how attacks spread and who pays. Headquarters makes the ransom call far more often than it mandates security. The survey did not ask whose cyber policy responds. When ransomware hits one location of a large brand, headquarters usually makes the ransom call. That … Read more

No Insurer Has Asked Which SaaS Apps You Use

Cyber Insurance News story on SaaS supply chain risk showing two app tiles joined by a cracked connector leaking red light

Nudge Security CEO Russell Spitler says cyber insurance applications miss the question that decides SaaS supply chain risk. He has yet to see an insurer ask for a company’s list of applications. In August 2025, attackers stole OAuth tokens from Salesloft’s Drift integration. They used them to pull data out of Salesforce instances across many … Read more

×