Recovery And Insurability: How Boards Judge Cyber Strategy, PwC Finds

Estimated reading time: 5 minutes

Most coverage of PwC’s 2027 Global Digital Trust Insights led with budgets. But the boardroom data tells the sharper story. CEOs and directors judge cyber strategy partly by recovery time and by cyber insurability: what the market will cover, and at what price.

Eighty-four percent of security and finance leaders expect cyber budgets to rise, up six points on last year. That number made the headlines.

A less-noticed question asked how leaders know whether the strategy behind that spending works.

PwC asked respondents to rank the five metrics that best show a cyber strategy is reducing enterprise risk. Among CEOs and board members, 42% included cyber insurance premium trends and insurability. Among security leaders, 37% did.

The 2027 Global Digital Trust Insights surveyed 3,934 business and technology leaders in 71 countries between May and July 2026. More than a third work at companies with $5 billion or more in revenue.

Cyber Insurability As A Board Metric

For CEOs and boards, cyber insurability sits level with incident trends and maturity against frameworks, each at 42%. Only three measures ranked higher. Compliance audits and control effectiveness led at 50%. Business continuity and recovery time followed at 47%, then financial exposure or value at risk at 43%.

Security leaders placed cyber insurability eighth of ten.

The gap repeats on financial exposure. Forty-three percent of CEOs and boards ranked it in their top five, against 38% of security leaders. Both measures put cyber risk in financial terms.

PwC’s playbook for chief financial officers points the same way. It urges CFOs to quantify cyber risk in financial terms to inform investment, risk appetite and planning.

See also  "Bright" Future Forecast For Cyber (Re)Insurance Market

The two groups answered separately worded versions of the question. PwC surveyed 720 CEOs and board members and 1,819 security leaders.

Paired bar chart comparing the metrics CEOs and boards and security leaders use to judge cyber strategy, with cyber insurance premiums and insurability at 42 percent for boards and 37 percent for security leaders, from PwC
Share of CEOs and boards, and of security leaders, ranking each metric in their top five. Source: PwC 2027 Global Digital Trust Insights.

Operational Continuity Lags The Board’s Priority

CEOs and boards ranked continuity and recovery time second among their metrics. Readiness lags behind that priority.

Only 39% of security, risk, and operations leaders have fully formalized continuity plans that specifically address cyber threats. Another 38% are developing them. Twenty-three percent are not developing formal plans at all.

“Agreeing about what matters is a good first step,” PwC writes. Putting it into operation is the harder part, the report says.

Recovery time drives the size of a business interruption loss. CFC this week extended its business interruption indemnity period from 12 to 18 months. It said many losses continue long after a business restores its systems.

Geopolitics Reaches The Insurance Program

PwC asked where cyber strategy is changing in response to geopolitics over the next 12 months. Forty-nine percent ranked changes to “cyber insurance, incident response, and crisis management planning” in their top three.

PwC grouped those three areas into one answer. The figure does not isolate insurance.

Changes to vendor and third-party risk management ranked first, at 50%. Forty-three percent are changing the location, resilience, or redundancy of critical infrastructure.

Concentration Risk From The Insured’s Side

Firms are also trying to avoid single points of failure. Fifty-four percent of security and risk leaders are adopting multi-cloud or hybrid cloud strategies. Forty-seven percent are strengthening regional data and technology redundancy. Thirty-seven percent are localizing infrastructure within specific jurisdictions.

See also  Dell Findings Show Cyber Resilience Plans, Weak Proof

That is the accumulation question seen from the buyer’s side. Swiss Re Institute noted that three firms controlled 70% of global cloud infrastructure in 2024.

Get The Cyber Insurance News Upload Delivered
Subscribe to our newsletter!

The AI Findings Behind The Headlines

Half of security leaders named attacks on AI systems among the threats they are least prepared for. That ranked first.

Only 22% of respondents would let AI agents carry out cyber defense actions without human approval. PwC argues an agent’s output should pass “through a control the agent cannot influence.” That applies where an outcome must be right every time. The point echoes the AI Security Institute’s GPT-6 Astra tests, where an automated reply told the model to proceed.

Data foundations remain thin. Only 5% of organizations have fully implemented all seven data risk measures PwC asked about. A year earlier, 7% had.

Phil Venables, a partner at Ballistic Ventures, framed the challenge in the report. “The challenge is building trust and control at the same speed as adoption.”

FAQ – Cyber Insurability

What is PwC’s Global Digital Trust Insights?

An annual cyber survey, now in its 29th year. The 2027 edition surveyed 3,934 business and technology leaders in 71 countries between May and July 2026.

Do boards use cyber insurance to judge cyber strategy?

Partly. 42 percent of CEOs and board members ranked cyber insurance premium trends and insurability among their top five metrics for whether cyber strategy is reducing risk. 37 percent of security leaders did.

See also  Cyber Risk: Squalify Launches U.S. Platform with Dollar Metrics

Which metrics do boards rank highest?

Compliance audits and control effectiveness (50 percent), business continuity and recovery time (47 percent), and financial exposure or value at risk (43 percent).

How many organizations have formal cyber continuity plans?

39 percent of security, risk and operations leaders say their plans are fully formalized and integrated. 23 percent are not developing formal plans.

Is geopolitics changing cyber insurance arrangements?

49 percent ranked changes to cyber insurance, incident response and crisis management planning in their top three responses to geopolitics. PwC grouped the three, so the figure does not isolate insurance.

How are firms addressing cloud concentration risk?

54 percent are adopting multi-cloud or hybrid strategies, 47 percent are strengthening regional redundancy and 37 percent are localizing infrastructure.

Leave a Comment

×