Estimated reading time: 5 minutes
Most coverage of PwC’s 2027 Global Digital Trust Insights led with budgets. But the boardroom data tells the sharper story. CEOs and directors judge cyber strategy partly by recovery time and by cyber insurability: what the market will cover, and at what price.
Eighty-four percent of security and finance leaders expect cyber budgets to rise, up six points on last year. That number made the headlines.
A less-noticed question asked how leaders know whether the strategy behind that spending works.
PwC asked respondents to rank the five metrics that best show a cyber strategy is reducing enterprise risk. Among CEOs and board members, 42% included cyber insurance premium trends and insurability. Among security leaders, 37% did.
The 2027 Global Digital Trust Insights surveyed 3,934 business and technology leaders in 71 countries between May and July 2026. More than a third work at companies with $5 billion or more in revenue.
Cyber Insurability As A Board Metric
For CEOs and boards, cyber insurability sits level with incident trends and maturity against frameworks, each at 42%. Only three measures ranked higher. Compliance audits and control effectiveness led at 50%. Business continuity and recovery time followed at 47%, then financial exposure or value at risk at 43%.
Security leaders placed cyber insurability eighth of ten.
The gap repeats on financial exposure. Forty-three percent of CEOs and boards ranked it in their top five, against 38% of security leaders. Both measures put cyber risk in financial terms.
PwC’s playbook for chief financial officers points the same way. It urges CFOs to quantify cyber risk in financial terms to inform investment, risk appetite and planning.
The two groups answered separately worded versions of the question. PwC surveyed 720 CEOs and board members and 1,819 security leaders.
Operational Continuity Lags The Board’s Priority
CEOs and boards ranked continuity and recovery time second among their metrics. Readiness lags behind that priority.
Only 39% of security, risk, and operations leaders have fully formalized continuity plans that specifically address cyber threats. Another 38% are developing them. Twenty-three percent are not developing formal plans at all.
“Agreeing about what matters is a good first step,” PwC writes. Putting it into operation is the harder part, the report says.
Recovery time drives the size of a business interruption loss. CFC this week extended its business interruption indemnity period from 12 to 18 months. It said many losses continue long after a business restores its systems.
Geopolitics Reaches The Insurance Program
PwC asked where cyber strategy is changing in response to geopolitics over the next 12 months. Forty-nine percent ranked changes to “cyber insurance, incident response, and crisis management planning” in their top three.
PwC grouped those three areas into one answer. The figure does not isolate insurance.
Changes to vendor and third-party risk management ranked first, at 50%. Forty-three percent are changing the location, resilience, or redundancy of critical infrastructure.
Concentration Risk From The Insured’s Side
Firms are also trying to avoid single points of failure. Fifty-four percent of security and risk leaders are adopting multi-cloud or hybrid cloud strategies. Forty-seven percent are strengthening regional data and technology redundancy. Thirty-seven percent are localizing infrastructure within specific jurisdictions.
That is the accumulation question seen from the buyer’s side. Swiss Re Institute noted that three firms controlled 70% of global cloud infrastructure in 2024.
Get The Cyber Insurance News Upload Delivered
Subscribe to our newsletter!
The AI Findings Behind The Headlines
Half of security leaders named attacks on AI systems among the threats they are least prepared for. That ranked first.
Only 22% of respondents would let AI agents carry out cyber defense actions without human approval. PwC argues an agent’s output should pass “through a control the agent cannot influence.” That applies where an outcome must be right every time. The point echoes the AI Security Institute’s GPT-6 Astra tests, where an automated reply told the model to proceed.
Data foundations remain thin. Only 5% of organizations have fully implemented all seven data risk measures PwC asked about. A year earlier, 7% had.
Phil Venables, a partner at Ballistic Ventures, framed the challenge in the report. “The challenge is building trust and control at the same speed as adoption.”
FAQ – Cyber Insurability
What is PwC’s Global Digital Trust Insights?
An annual cyber survey, now in its 29th year. The 2027 edition surveyed 3,934 business and technology leaders in 71 countries between May and July 2026.
Do boards use cyber insurance to judge cyber strategy?
Partly. 42 percent of CEOs and board members ranked cyber insurance premium trends and insurability among their top five metrics for whether cyber strategy is reducing risk. 37 percent of security leaders did.
Which metrics do boards rank highest?
Compliance audits and control effectiveness (50 percent), business continuity and recovery time (47 percent), and financial exposure or value at risk (43 percent).
How many organizations have formal cyber continuity plans?
39 percent of security, risk and operations leaders say their plans are fully formalized and integrated. 23 percent are not developing formal plans.
Is geopolitics changing cyber insurance arrangements?
49 percent ranked changes to cyber insurance, incident response and crisis management planning in their top three responses to geopolitics. PwC grouped the three, so the figure does not isolate insurance.
How are firms addressing cloud concentration risk?
54 percent are adopting multi-cloud or hybrid strategies, 47 percent are strengthening regional redundancy and 37 percent are localizing infrastructure.
Related Cyber Insurance Posts
- Cyber Cover Follows The Executive Home, And Gets Clearer On AI
- The Price of Complacency: Only 2% of Companies Fully Implement Cyber Resilience – PWC Survey(Opens in a new browser tab)
- Cyber Risk: Squalify Launches U.S. Platform with Dollar Metrics(Opens in a new browser tab)
- CrowdStrike Launches “Falcon for Insurability” to Enhance Cyber Insurance Eligibility(Opens in a new browser tab)
- Shadow AI Is A Boardroom Problem: Protiviti AI Pulse Survey 2026(Opens in a new browser tab)