Estimated reading time: 7 minutes
Marsh and Resilience launched Cyber Protect across Asia today. The offering is available exclusively to organizations buying cyber insurance brokered by Marsh in the region.
It is also available throughout Asia except in China. The release states the exclusion and does not explain it.
What Cyber Protect Includes
Clients who place cyber cover through Marsh in Asia get access to Resilience’s Risk Operations Center (ROC) at no additional cost.
The ROC continuously scans a policyholder’s external-facing infrastructure. It hunts for zero-day vulnerabilities, known vulnerabilities, exposed high-risk remote services, insecure remote access points, and dark web exposure. Analysts validate the alerts before they reach the client, filtering out noise and attaching remediation guidance.
Resilience says the ROC screens out roughly 95% of known vulnerabilities as low risk each year. It escalates only the small remainder it considers genuinely exploitable. Clients have historically remediated 77% of those escalations.
No software installation is required. The service needs no access to internal systems.
Mario Vitale, president of Resilience, framed the thesis directly. The company was built on the belief that “the highest value we can deliver is a loss that never happens.”

Why Asia, And Why Now
Sean Letz, cyber leader for Marsh Asia, frames it as a shift in what risk management now requires. Prevention on its own no longer suffices, he argues. Managing cyber risk demands both early detection and the financial protection to recover when an incident lands.
Letz stated, “Cyber Protect helps clients detect critical vulnerabilities earlier, take action faster, and strengthen their risk profile, supporting stronger resilience, improved insurability, and greater confidence in recovery.”
The Commercial Logic
Global cyber rates have fallen for three consecutive years. Supply continues to outpace demand in mature markets. Underwriters and brokers are looking for growth where penetration is low, and Asia fits that description on every measure. Fewer than 5% of small businesses in many Asian markets have standalone cyber cover. Companies in Japan, South Korea, Hong Kong and Singapore with revenues in the billions often carry limits in the single-digit millions.
Marsh cites its own Cyber Buyer Study to make the case. Half of Asia-based organizations have confidence in their cyber risk management, the lowest figure of any region and well below the global average of 72%. Almost three in ten cyber and social engineering attacks worldwide target Asia. Marsh reported that confidence gap in March, so the launch follows its own research by six months.
The threat picture has also changed. Asian markets once had natural insulation from foreign attackers because language and cultural knowledge limited the reach of phishing. Large language models removed that barrier. Attackers now generate convincing, context-aware content in any language at scale.
Marsh is not first into this space. WTW launched CyCore Asia in Singapore and Hong Kong, and Blackpanda and ST Engineering established an incident-response partnership for the region in December.
Who Acts On The Alerts
The ROC surfaces and prioritizes. Remediation stays with the client. Resilience’s own description says the guidance enables security teams to close gaps faster.
That assumes a security team exists. UIB and CyberCube found that many Asian companies lack internal cybersecurity leadership. They lack specialist IT security teams and have no structured approach to risk financing. India’s surge in demand is coming from small manufacturers. Those firms are not staffed to act on a validated zero-day alert at speed.
The 77% remediation figure suggests Resilience’s existing clients do act. Those clients are large and middle-market organizations in mature markets, where a security function is standard. Whether the same rate holds among Asian SMEs is an open question, and it is the question that determines whether the bundle reduces loss or simply improves visibility.
That distinction matters for a product sold on prevention. A remediation rate is not a loss rate. The release offers no claims data on either side.
What External Scanning Cannot See
Requiring no software and no internal access is a genuine selling point. It also fixes what the service can observe. The ROC watches the external attack surface. It misses the phishing email, the harvested credentials, and the attacker already moving inside.
Sophos published data last week showing identity-based techniques initiated 85% of ransomware attacks against education institutions, with malicious email the leading root cause. Its State of Ransomware in Education 2026 report put the cross-sector figure at 79%. Exploited vulnerabilities, the category the ROC is built to find, fell sharply.
None of that makes external monitoring worthless. Exposed remote access points remain a real entry route, and dark web credential exposure is genuinely useful early warning. But a buyer treating this bundle as coverage of their principal exposure would be mistaken, and a broker has an obligation to say so.
This is the third instance this year of continuous monitoring being wired into placement, after the Sophos and Spektrum FastTrack program in March and CrowdStrike’s Project QuiltWorks expansion in May, which paired Marsh and Resilience already. The direction is set. The underwriting argument behind it is that verified telemetry beats a completed questionnaire.
The China Question
Which returns to the four words the release does not unpack.
China is the largest economy in the region and the most consequential cyber market in it. Excluding it from a pan-Asia product is a decision, not an oversight.
The likely reasons are structural. China’s Cybersecurity Law, Data Security Law and Personal Information Protection Law together constrain how a foreign vendor may scan domestic infrastructure and, more sharply, how the resulting data may leave the country. Continuous external scanning by an overseas provider sits awkwardly against all three.
There is a second layer. Resilience describes itself as founded by experts from the highest tiers of the US military and intelligence communities. That is the company’s own language, in its own boilerplate. A firm with that provenance running persistent scans across Asian infrastructure, with China carved out, is a fact worth stating plainly, whatever the reason behind it.
Marsh has not said which consideration drove the decision. The answer would tell brokers and multinational clients something useful about where these programs can and cannot follow their exposure. Companies operating across Asia rarely stop at the Chinese border. Their coverage now does.
FAQ – Cyber Insurance Asia
What is Marsh and Resilience Cyber Protect?
It bundles Resilience’s Risk Operations Center with cyber insurance placed through Marsh in Asia. The ROC continuously scans a policyholder’s external-facing infrastructure and delivers human-validated alerts with remediation guidance, at no additional cost to the client.
Where is Cyber Protect available?
Across Asia, excluding China. It is offered exclusively to organisations that purchase cyber insurance brokered by Marsh in the region. The launch announcement does not explain the exclusion of China.
What does the Risk Operations Center actually monitor?
Zero-day and known vulnerabilities, exposed high-risk remote services, insecure remote access points and dark web exposure. It requires no software installation or internal system access, which means it observes only the external attack surface.
Why are insurers targeting Asia now?
Global cyber rates have fallen three years running while penetration in Asia remains low. Fewer than five percent of small businesses in many Asian markets hold standalone cyber cover, and large companies often carry limits far below their exposure.
Does bundled monitoring reduce cyber losses?
The evidence supports improved visibility rather than demonstrated loss reduction. Resilience reports clients remediate 77 percent of escalated issues, which measures response rather than outcome. Neither company published claims data alongside the launch.
Related Cyber Insurance Posts
- Move Fast Get Phished
- Cyber Insurance Industry to be Tested This Year by Cyber War Exclusions: CyberCube(Opens in a new browser tab)
- Tailored Cybersecurity Practices Can Lower Insurance Costs, Gallagher Re Report(Opens in a new browser tab)
- Antiquated Regulations Against “Cyber Insurance Bundling” Slow Innovation(Opens in a new browser tab)
- 97% of Top U.S. Banks Hit by Third-Party Data Breaches in 2024 – SecurityScorecard(Opens in a new browser tab)