Cyber awareness isn’t enough – it’s time to get cyber resilient
IN Partnership with
Human error drives the majority of breaches. So why are organizations still treating cyber risk as an IT problem?
More
As cyber threats continue to become more and more sophisticated, being “cyber aware” simply isn’t enough anymore. For organizations to really thrive in the months to come, they need to level up their cyber resilience. According to Cowbell’s Cyber Roundup 2026 Claims Report, cyber resilience means going beyond traditional cyber coverage and looking at preparedness as a part of the whole organizational structure and strategy.
Speaking to Insurance Business, Nurishah Knushaj, director of claims at Cowbell, explained that cyber resilience can no longer be viewed as something an organization purchases through an insurance policy alone.
“While insurance remains an important financial safeguard, resilience today requires a combination of prevention, preparedness, response, and recovery. Cowbell’s report also highlights that data breaches, fraud, and extortion events account for the vast majority of activity, while human error continues to play a significant role in many incidents.”
Cowbell is a leader in Adaptive Cyber Insurance, offering SMEs and middle-market businesses AI-driven coverage tailored to evolving threats. Its continuous underwriting platform streamlines the insurance process to under five minutes. Backed by 25 global (re)insurance partners, Cowbell serves businesses with revenues up to $1 billion across the US, UK, and Australia. It also provides cybersecurity services through Cowbell Resilience Services (CRS). Founded in 2019, Cowbell is based in the San Francisco Bay Area, with a global team across the US, the UK, Australia, Canada, and India.
Find out more
“Technology and people must be viewed as complementary, not competing, investments”
Nurishah Knushaj,
Cowbell
Published July 27, 2026
Share
“The most successful insurers will not simply indemnify losses after an incident; they will help organizations reduce the likelihood and impact of those incidents in the first place”
Nurishah Knushaj,
Cowbell
A business risk – not just an IT issue“At the same time, AI is making phishing campaigns, business email compromises, and social engineering attacks more convincing and scalable. In this environment, operational resilience depends on more than technology alone. It requires strong security controls, employee awareness, incident response planning, backup strategies, and effective third-party risk management.”
As Knushaj went on to explain, the organizations that perform best are the ones that treat cyber risk as a business risk rather than just an IT issue.
“Insurance should be one component of a broader resilience strategy that enables companies to anticipate threats, withstand attacks, and recover quickly when incidents occur,” she told IB.
But it’s not just the face of cybercrime that’s changing; the claims landscape as a whole is also being impacted. According to an AM Best report, cyber insurance premiums declined for the first time to $9.14 billion, while claims rose 40 percent – suggesting increased loss activity despite reduced premium volume.
“That divergence suggests that cyber risk is intensifying, even as market pricing remains highly competitive for the industry,” added Knushaj. “This reinforces the importance of
disciplined underwriting, proactive risk management, and claims expertise. The future sustainability of the cyber insurance market will depend on insurers helping policyholders reduce losses and not simply transfer risk after an event has occurred. At Cowbell, we expect underwriting to become increasingly data-driven and focused on measurable cybersecurity controls.
“Organizations that invest in resilience, employee training, incident response readiness, and strong security hygiene are likely to be rewarded with better coverage options and more favorable pricing. The market’s long-term health, I would say, depends on aligning incentives between insurers, brokers, and policyholders to reduce loss frequency and severity.”
Technology and people: complementary, not competing But in today’s rather crowded cyber coverage market, there’s a danger that organizations could fall prey to the “shiny, new tech” conundrum and forget that the main driver of success here depends on one element – your employees. Because if you’re not reinforcing your tech investment with ongoing employee education and behavioral risk management, the process is doomed before it’s even begun.
“Technology and people must be viewed as complementary, not competing, investments,” said Knushaj. “The Cowbell report found that human error remains a contributing factor in most breaches – underscoring that technology alone cannot solve cyber risk. Organizations should certainly invest in foundational controls, such as Multi-Factor Authentication (MFA), endpoint protection, secure email technologies, and monitoring capabilities. However, they should invest equally in creating a culture of security awareness. Focus on reducing risk behaviors while making secure behaviors easier – because cyber resilience is strongest when technology processes and people work together.”
Think of the relationship between technology and your people as a marriage – you can’t really have one without the support of the other. For Knushaj, the human element is even more intrinsic to what she does day in, day out – claims.
“I’m a passionate claims person,” she told IB. “I’d say that the cyber claims have evolved significantly over the last several years and, in my experience, today’s incidents often involve legal, forensic, regulatory, operational, and reputational challenges simultaneously. As the threats become more complex, the claims team must function as incident response coordinators as much as claims administrators – and the Cowbell report demonstrates the impact of that.”
According to Cowbell’s report, effective claims handling can mean average ransomware payments decline by approximately 44 percent, while proactive negotiations reduced average ransom demands by as much as 65 percent – highlighting the value of experienced response teams.
“I would say that the best-in-class cyber claims experience should provide immediate access to breach counsel, forensic investigation, ransomware negotiations, recovery specialists, and communications experts,” added Knushaj. “Brokers and clients should expect rapid engagement, clear communication, coordinated decision-making, and practical guidance throughout the life cycle of an incident. The objective is not simply paying a claim; it’s helping organizations recover as quickly and as effectively as possible.”
And while being proactive and having that backup support there before an incident unfolds, no one can ever really predict what the next few months will bring. As quickly as cyber coverage evolves, so too do cybercrime tactics. It’s a constant game of cat and mouse between the threat actors and the cyber experts – one that demands resiliency and adaptability to stay ahead. In terms of emerging threat patterns, Knushaj told IB that she’s seen some seismic shifts recently, and that while ransomware attacks have decreased slightly, there has been a spike in multi-extortion frameworks.
“While traditional ransomware relied on encrypting a victim’s files, threat actors have modified their approach because organizations have significantly improved their backup and disaster-recovery capabilities. With encryption-optional attacks, many modern groups now completely skip the time-consuming and noisy encryption phase, meaning they rely purely on data exfiltration –
stealing sensitive files and threatening to leak them on dedicated public shaming sites. We’ve seen multi-extortion frameworks recently – attackers maximizing leverage by applying layers of pressure.”
These levels of multi-extortion frameworks include:
Level 1: Single extortion (encryption)The traditional approach where attackers infiltrate a network, encrypt critical files or systems, and demand payment for the decryption key.
Level 2: Double extortion (exfiltration + leakage)Attackers copy and exfiltrate sensitive data before encrypting it. If the victim restores backups and refuses to pay, attackers threaten to publish the stolen data on public or dark web leak sites, causing reputational damage and compliance violations.
Level 3: Triple extortion (disruption + harassment)
Attackers add operational or psychological warfare. This frequently includes launching Distributed Denial of Service (DDoS) attacks to prevent the victim from recovering or accessing their systems.
Level 4: Quadruple extortion (ecosystem targeting)Attackers aggressively target the victim’s interconnected business network. This involves contacting third-party associates, clients, or suppliers whose data was also stolen, demanding that they pay to prevent the release of their own information or to force the primary victim to comply.
And, as Knushaj added, AI is playing an increasingly intrinsic role in these attacks, with threat actors using it to enhance social
Proportion of claims by incident type
Data breach
33.5%
Cybercrime
31.8%
Extortion event
18.3%
Other
16.4%
Source: Cowbell’s Cyber Roundup 2026 Claims Report
Who’s behind the attacks?
Akira: Double extortion ransomware targeting small and mid-sized enterprises (SMEs) via VPN and remote access exploitation
Qilin: Ransomware as a service (RaaS) group using data exfiltration plus encryption against high-value enterprise targets
RansomHub: Operates as an RaaS group, enabling affiliates to carry out fast-moving, opportunistic attacks
Lynx: Emerging group targeting smaller organizations with rapid encryption and extortion tactics
InterLock: Developing threat actor exploiting remote access weaknesses for data theft and extortion
PLAY (PlayCrypt): Targeting large enterprises with tailored ransomware and data leak extortion techniques
Inc. (INC Ransom): Newer double-extortion group focusing on organizations with less mature security controls
38.8%
14.2%
3.7%
3.7%
3.0%
3.0%
3.0%
Source: Cowbell’s Cyber Roundup 2026 Claims Report
engineering to accelerate efficient impersonation and make business email compromise attacks more convincing.
“Supply chain vulnerabilities, credential theft, and attacks targeting remote access technologies will continue to present significant risks. Business leaders, I would say, should pay close attention to threats that combine technical compromise with human manipulation, because those attacks increasingly drive both frequency and severity of claims.”
To really help organizations weather the unknown in the months and years to come, cyber insurers must evolve from financial backstops to holistic, strategic cybersecurity partners. And, what’s more, the broker’s role needs to go further than simply providing clients with access to a cyber insurance policy. They must become educators in the resources that insurance providers offer.
“Cowbell was built specifically to work as a strategic cybersecurity partner for policyholders,” added Knushaj. “The future of cyber insurance is proactive rather than reactive. The most successful insurers will not simply indemnify losses after an incident; they will help organizations reduce the likelihood and impact of those incidents in the first place.
“Here, claims data provides unique insights into what drives losses, allowing insurers to offer practical guidance on controls, training, risk monitoring, and preparedness. As cyber threats continue to evolve, businesses will increasingly look to insurers for intelligence, benchmarking, risk assessment, incident response support, and resilience planning.
“Ultimately, the strongest cyber insurance relationships will be partnerships focused on improving outcomes. That said, when insurers, brokers, and policyholders all work together to strengthen cyber resilience, everyone benefits. Their organizations will suffer fewer losses, claim severity will decline, and the market will become more sustainable too.”