Table of Contents:
Envisioning Cyber Insurance in the Age of Cyber Attacks Generated by AI
In this digital age, with the rapid advancement of technology, corporations are experiencing cyberattacks more frequently. Given the circumstances, cyber-attacks are becoming an everyday part of business. Worse still, many of these cyber-attacks nowadays are generated by sophisticated AI models. Some recent incidents (as shown below) show the intensity and scale of damage caused by AI-generated cyber-attacks:
- The Healthcare industry accounted for 22% of all ransomware attacks in 2025, costing an average of $7.42M per breach.
- The Aviation industry experienced a 600% surge in AI-generated attacks between 2024 and 2025.
- Approx. $13B loss due to an AI-generated travel scam was experienced in 2025.
- As per Kaspersky, the code for the malware VenomRAT is AI-generated. In 2024, 82% North American hotels were attacked by this malware as a result of an AI-generated phishing scam.
- A leading British retailer experienced a ransomware and data extortion attack carried out using AI-driven phishing and social engineering tools. This resulted in the retailer’s 3rd-party vendor network being infiltrated, causing widespread operational disruption.
With each attempted cyber-attack, malicious AI models have the potential to continuously train themselves, scale their capabilities, and inflict maximum harm on companies. So, the question arises: how do insurance carriers update cyber insurance products that are dynamic enough to cover ever-evolving risks? Traditionally, many cyber-insurance products broadly cover first-party loss, third-party liability, regulatory actions and incident response costs. The policy wordings didn’t specifically categorize the peril being generated by AI. However, AI-generated cyber-attacks are increasing at an alarming level, leading to greater unpredictability in risk. The carriers are dealing with 2 problems, i.e., rising claims costs and difficulty in underwriting (i.e., assessing risk). These problems are creating challenges for carriers to update their cyber insurance products. Worst still, many carriers have started excluding any risk arising from AI and Agentic AI. Even if the risks are covered, the premiums will be unusually high.
The dynamic nature of the risk demands that carriers think beyond conventional risk mitigation techniques. It is also noted that, unlike other insurance products, the coverage offered needs to be tailored to the nature of the exposure (rather than blanket coverage).
AI Driven Threat Landscape: External vs. Internal
Lately, it has been observed that AI-driven threats originate from both internal and external sources. Even though most threats come from external sources, those from internal sources are on the rise. Before proceeding, let us take a quick look at the difference between internal and externally generated ones.
In general, cyber insurance policies cover risks posed by external threats but exclude most internal threats. In most cases, carriers treat internal threats as a result of a lack of security controls. However, there has recently been a drastic increase in attacks due to internal threats. For example, a healthcare administrative service provider incurred a loss of approximately. $1.2 M due to 45K patient records being fed into a public AI tool. Worse still, a vulnerability in the tool’s public API exposed the entire patient file on the open web. The carrier in this case denied the claim due to a lack of minimum security controls and the intentional nature of the incident.
A Layered Cybersecurity Risk Management Model
Given the dynamic nature of AI-initiated cyber-attacks (arising from both external and internal threats), carriers need to continuously help insureds monitor and upgrade their cybersecurity and threat management mechanisms. As a remedy, carriers may provide cyber insurance packaged with cybersecurity risk management consulting services embedded in the policy to enhance the product while mitigating and reducing risk. The service may be structured in three layers:
- Layer 1 – Preventative/Pre-emptive services
- Layer 2 – Detection and Response
- Layer 3 (Top Layer) – Cyber insurance
As AI-generated cyber-attacks become more sophisticated and see an uptick in frequency, cybersecurity portfolios of technology companies like Mphasis empower carriers and insureds to counter them by engaging them throughout the policy lifecycle.
Common Types of AI Generated Cyber Attacks
Before exploring the possibilities, let’s quickly see the most common AI-generated cyber-attacks:
- AI-generated social engineering
- Adaptive malware
- Attacks on AI systems
- AI-driven identity fraud
- Interactive and real-time manipulation
- Deepfake enabled fraud
- AI-generated ransomware(RAAS- Ransomware as a Service has increased the number of attacks)
Below are the common characteristics of these AI-generated cyber-attacks:
- High speed and volume
- Highly realistic and personalized
- Polymorphic and self-adaptive
- Ability to swiftly detect vulnerabilities
- Real-time adaptation to each defender’s response
- Use of open-source AI models
- Ability of autonomous navigation through complex industrial networks
Mphasis offers opportunities to partner with the carriers in the following areas:
- Continuous underwriting – Involves continuous risk assessment (Preventative/Pre-emptive services)
- Continuous Monitoring, Assessment, and Assistance / Remediation of Insured’s Cyber Security Ecosystem (Detection & Response)
- Investigation during claim payout (Cyber Insurance)
- AI-driven cyber insurance control framework
The Continuous Process of Underwriting & Risk Assessment
While it is obvious that carriers define very robust underwriting guidelines, they may lack the technical expertise to perform end-to-end activities. Mphasis’ proven capabilities effectively manage the underwriting process and risk assessment (not exhaustive):
- Assist in defining a comprehensive underwriting scoring mechanism:
- Use No-code platforms like Tines to auto-generate questionnaires from threat intelligence to better assess risk and preparedness for insured events.
- Use AI agents to continuously probe insureds systems and perform continuous monitoring to scale underwriting best practices and workflow.
- Update the underwriting guidelines frequently and on a random basis.
While carriers can update underwriting guidelines, Mphasis helps them gauge the risk posed by ever-evolving malicious AI models to further refine their appetite and pricing. This, in turn, will help carriers to continuously update underwriting guidelines effectively.
- Mandatory compliance with local Data Protection guidelines
Before offering coverage, carriers need to verify if the insured is compliant with the local Data Protection (DP) regulations. Leveraging Mphasis’ expertise, the carrier can ensure that insureds comply with DP regulations before offering coverage and limit the exposure of future regulatory action if there is an event.
Independent vendor risk evaluations provide underwriters with a consistent, evidence-based foundation for comparing applicants - reducing the information asymmetry that has historically plagued cyber portfolio selection.
- Decentralized information exchange among carriers
Cyberattacks represent a systemic risk impacting individuals, enterprises, and carriers alike. Addressing this challenge requires a collaborative, ecosystem-wide approach rather than isolated efforts. Mphasis can help create a blockchain-enabled information-sharing framework that will assist carriers in collectively strengthening cyber resilience through the following measures:
- Sharing underwriting guidelines amongst carriers where permissible
- Sharing any new incident details amongst carriers
- Sharing cybersecurity-related AI model parameters across carriers - Proprietary sharing of model parameters will help carriers develop and train models faster and more efficiently.
Continuous Monitoring, Assessment, and Assistance / Remediation of the Insured’s Cyber Security Ecosystem
Below are some of the solutions that the carrier and tech partners may offer to the insureds (as a part of the continuous assistance and remediation process). Please note that the outcomes provide continuous feedback for ongoing underwriting & risk assessment (as well as updating underwriting guidelines).
- Predictive Threat Intelligence
- Real-time threat intelligence allows carriers to move away from point-in-time risk snapshots toward fluid, continuously recalibrated premium structures that reflect an organization's live exposure.
- When underwriters gain visibility into emerging attack patterns before they materialize into claims, they can build more defensible reserves and protect loss ratios against sudden portfolio-wide shocks.
- Autonomous Threat Detection & Response
- Faster machine-driven containment of security incidents translates directly into shallower financial losses, giving carriers a concrete basis to differentiate payouts between prepared and unprepared policyholders.
- Carriers that tie premium incentives to the deployment of automated response capabilities effectively shift their books toward lower-risk cohorts without sacrificing market competitiveness.
- Ongoing supplier monitoring throughout the policy lifecycle means coverage conditions can evolve in step with an insured's changing third-party footprint, preventing silent exposure gaps from accumulating.
- Automated Moving Target Defense(AMTD)
- Continuously rotating infrastructure configurations erode the tactical advantage that AI-powered attackers rely on, translating into measurable reductions in breach probability that underwriters can factor into deductible structures.
- Organizations deploying AMTD present a materially smaller ransomware target, which over time contributes to lower claims frequency across the segments of an carrier's book most vulnerable to automated attack campaigns.
- Secure SDLC, Continuous Red Teaming
- Carriers writing technology-sector risks can establish verified adherence to secure development practices as a hard eligibility gate, particularly for E&O lines, where software defects are a primary loss driver.
- Regularly scheduled adversarial testing produces an auditable security history that strengthens an carrier's position when determining whether a claimant met its contractual duty of care at the time of loss.
- Zero Trust Network Access (ZTNA)
- Architectures built on strict identity verification and least-privilege access contain the spread of intrusions at their origin, fundamentally shrinking the scope - and cost - of incidents that would otherwise trigger broad-coverage responses.
- Underwriters can stratify maximum coverage limits according to ZTNA maturity, creating a structured commercial incentive for policyholders to eliminate the credential-based vulnerabilities that drive a disproportionate share of large cyber losses.
- Decoy environments engineered to mislead attackers generate granular forensic trails that dramatically compress post-breach investigation timelines, reducing the administrative burden and disputed costs embedded in complex claims.
- Drawing adversarial activity away from live systems shortens the window of unauthorized access within insured networks, directly capping business interruption exposure, one of the costliest triggers in modern cyber policies.
- Mandate Cyber Resiliency for Critical Systems
- Embedding operationally specific recovery benchmarks - including defined restoration windows and acceptable data loss thresholds - into policy language transforms resiliency from a best practice into a contractually enforceable coverage condition.
- When critical system resilience is uniformly required across high-value accounts, carriers effectively reduce the concentration of interdependent risks in their portfolios, lowering the probability of a single event generating correlated, multi-policy losses.
- AI Guardrails and Governance
- Requiring organizations to maintain structured, board-approved AI governance documentation as a policy prerequisite establishes the accountability chain carriers need to clearly assign liability when an AI-related failure triggers a covered event.
- Without enforceable guardrails around internally deployed AI systems, carriers absorb the consequences of models that can be manipulated or misused from within - an underappreciated exposure that governance mandates can convert into a manageable, quantifiable risk.
Thorough Investigation of Claims Arising Due to AI-Generated Cyber-Attack
Once a claim arises from an AI-generated cyberattack, it may be difficult for carriers to investigate it because of the attack's technical nature. Below is a high-level structure of the investigation:
- Verification of As-Is cyber security measures
Mphasis will help the carrier assess the insured’s cybersecurity measures before and during the attack. Some of the verifications would include (not limited to) the following:
- Evaluate the MFA and VPN exposure
- Verify compliance with DP regulations
- Verify compliance with carrier’s underwriting guidelines, as well as policy provisions
- Investigation of the nature of the attack
Mphasis will be instrumental in determining if the attack was caused by any AI model. Subsequently, Mphasis will also help in determining the impact of the attack. This process will enable the carrier to determine how the attack originated and if it took place even after complying with the protocols
- Determining the lapses and immediate controls that need to be implemented
Lastly, Mphasis will be able to determine the lapses (if any) in the insured ecosystem. Subsequently, it will help determine if the breach happened due to the lapse.
Mphasis AI-Driven Cyber Insurance Control Framework:
Assess: Continuously evaluate the insured’s cyber posture, attack surface and AI exposure using real-time data; this supports dynamic Underwriting, Risk scoring, Pricing, etc.
Prevent: Implement and enforce preventive controls such as zero trust, strong identity and access management, secure AI systems, and regulatory compliance. This reduces the attack success probability.
Detect: Leverage AI-Driven Monitoring to identify anomalous behavior, phishing, deepfakes and adaptive attacks in near real time and focus on early detection significantly.
Respond: Automate containment and remediation while enabling AI-assisted forensics. This ensures faster recovery and accurate claims adjudication.yh
Building Robust Cyber Defense and Risk Transfer Mechanisms
AI-generated cyberattacks are not merely escalating risk; they are redefining the very architecture of cyber insurance. In this new reality, static policies, episodic underwriting and reactive claims handling are becoming relics of a bygone era. The future belongs to a living insurance model, one anchored in continuous engagement, real-time intelligence, and collaboration between carriers, insureds and technology partners.
By fusing carriers’ acumen with Mphasis’ advanced AI, cybersecurity services, and digital engineering capabilities, carriers can transcend passive risk transfer and evolve into agents of active risk reduction, building a Cyber Insurance ecosystem that is resilient by design, adaptive by nature, and economically aligned for the age of artificial intelligence.
This Blog is Written by:
Shouvik Lahiri - Senior Principal Consultant, Insurance
Saikrishna B - Associate Vice President, Insurance