Cyber risk is changing fast. What it means for businesses and insurance in 2026?
Cyber attacks are not new, but the way they happen is changing quickly. For many businesses, the challenge is no longer just having basic protection in place. It is being able to show that those protections are working when it matters.
At the same time, technology such as artificial intelligence is making both attacks and defence faster, more sophisticated and more complex. This is starting to influence how cyber insurance works, including what insurers may expect businesses to demonstrate.
Here are some of the key trends to keep on your radar.

1. It is no longer enough to say you are secure
In the past, insurers often relied on application forms. Businesses would confirm they had certain security measures, and that was usually enough.
That is beginning to change.
Insurers now want more confidence that key protections are in place and working properly. This includes things like:
• Multi factor authentication on accounts
• Endpoint protection software on computers and servers
• Secure backups that are regularly tested
• Regular updates and patching
• Plans for how to respond to an incident
The key difference is that businesses may be asked to provide evidence, rather than simply tick a box.
Those who can clearly demonstrate good security may be better placed when it comes to securing suitable cover and pricing.
2. Artificial intelligence is making attacks faster
Artificial intelligence is becoming more widely used in business, and cyber criminals are finding ways to use it too.
Attackers can use it to:
• Scan systems and find weaknesses more quickly
• Send more convincing scam emails or messages
• Move through networks faster once access is gained
• Analyse stolen data to decide what is most valuable
This last point is important. Criminals may increasingly use AI to sort through stolen files and identify what is most valuable, which could make attacks more targeted and more damaging.
However, AI is also helping defenders. Many security tools now use automation to detect and respond to threats faster than humans can.
For businesses, the takeaway is clear. If you are using AI tools, it is important to understand how they are controlled, what they can access and where the risks could sit.
3. Hackers are finding ways around passwords and MFA
Most businesses now understand the importance of strong passwords and multi factor authentication. These are still essential. But attackers are adapting.
Instead of trying to break passwords, attackers are increasingly looking to steal access tokens or exploit system integrations. These are behind-the-scenes digital keys that allow systems to talk to each other.
If an attacker gets hold of one of these, they may be able to access systems without triggering the usual login alerts.
This is especially relevant for cloud-based systems such as email platforms, file storage and business applications.
The risk is not always obvious because the activity can appear to come from a trusted system.
To reduce this risk, businesses should:
• Limit access rights to what is actually needed
• Regularly review system permissions
• Monitor unusual activity in their systems
4. AI tools bring new risks as well as benefits
Many businesses are starting to use AI tools to improve efficiency. Some of these tools can access internal systems, documents or customer data.
That brings a new challenge. If an AI tool is given too much access, or if it is manipulated in some way, it could expose sensitive information or carry out unintended actions such as deleting data.
A simple way to think about it is this. If you would not give a person full access to a system, it is worth asking whether an AI tool should have that level of access either.
Businesses should make sure:
• AI tools only have the access they genuinely need
• Their activity can be monitored
• Sensitive data is properly protected
5. Businesses need to be ready to respond, not just prevent
No system is completely secure. The businesses that cope best with cyber incidents are often the ones that have taken time to prepare for something going wrong.
This means having clear plans in place, such as:
• How to respond to an attack
• Who to contact for help
• How to communicate with customers and stakeholders
• How to recover systems and data
Testing these plans is just as important as having them.
Cyber insurance can provide access to specialist support during an incident, but preparation can still make a major difference to the outcome.
6. Rules and expectations will keep evolving
Governments and regulators are paying more attention to cyber security and the use of AI. Over time, businesses may see more rules around how they manage cyber risk and data.
For companies that operate internationally, this can become more complex, as rules may differ between countries.
Keeping up to date with these changes will continue to be an important part of managing risk.
What this means in practice
For most businesses, the message is not to panic. It is to focus on getting the basics right and being able to show that they are working.
A good starting point includes:
• Understanding what systems and data you have
• Protecting access with strong authentication
• Keeping software up to date
• Testing backups
• Planning how you would respond to an incident
• Reviewing who and what has access to your systems
• Being careful with how new tools, including AI, are used
Final thought
Cyber risk is becoming more advanced, but the fundamentals still matter. In many cases, they matter more than ever.
The difference now is that insurers, regulators and customers increasingly expect to see those fundamentals in action, not just in theory.
Businesses that take a practical, well organised approach to cyber security are likely to be in a much stronger position, both when preventing attacks and when transferring risk through insurance.
If you would like to understand what these changes could mean for your business or sense-check whether your current approach would stand up to today’s insurer expectations, our cyber specialists can offer a free, no obligation review.
Disclaimer: This article is intended for general information purposes only and does not constitute advice. Cyber insurance availability, terms and underwriting requirements will vary between insurers and individual circumstances

Cyber insurance
Providing organisations with financial protection and the critical first response support required to investigate, control, mitigate and remove cyber security threats.
