Cyber policy wordings in market today were drafted for a threat environment that no longer exists. Ransomware has moved the dominant loss from data breach to operational shutdown, with average downtime now reaching 24 days and average incident costs of USD 5.08 million. AI-generated attacks like the USD 25 million Arup deepfake case in Hong Kong have introduced a class of fraud that sits awkwardly between Cyber, Crime, and Social Engineering wordings. Supply chain compromise is now the most common attack path, involved in 30 percent of all breaches in 2025. Cyber insurance in APAC has become a coordination problem across policies that were rarely designed to work together. Our August 2026 Risk Insight maps the three emerging risk gaps and where the cover most often falls short.

What This Report Covers

  • Why cyber insurance in APAC needs to be sized to the outage, not the data breach
  • What a modern cyber policy actually buys you, and why the vendor panel matters more than the indemnity
  • How AI-generated attacks like the Arup deepfake fraud sit between Cyber, Crime, and Social Engineering Fraud cover
  • Where AI-specific exposures, supply chain risk, and social engineering fraud consistently fall short in mid-market wordings
  • What a defensible cyber programme looks like across Cyber, Crime, and PI

Download the PDF →