<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Continuum</title>
	<atom:link href="https://www.continuuminsure.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.continuuminsure.com/</link>
	<description>Risk, Insurance, Technology</description>
	<lastBuildDate>Wed, 09 Sep 2026 04:11:42 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.4</generator>

<image>
	<url>https://www.continuuminsure.com/wp-content/uploads/2023/08/cropped-Continuum-Logo-Icon-Pink-BlueBG-1280px-1-150x150.png</url>
	<title>Continuum</title>
	<link>https://www.continuuminsure.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How Prospectus Liability Puts Directors on the Line</title>
		<link>https://www.continuuminsure.com/articles/how-prospectus-liability-puts-directors-on-the-line/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 04:11:42 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[D&O Insurance]]></category>
		<category><![CDATA[IPO]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6992</guid>

					<description><![CDATA[When a company files a prospectus to go public in any APAC market, the document becomes a liability instrument the moment regulators ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/how-prospectus-liability-puts-directors-on-the-line/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<p dir="ltr"><div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/09/Sep9Weekly-Carousel.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Sep9Weekly Carousel</a></div>
<p dir="ltr">When a company files a prospectus to go public in any APAC market, the document becomes a liability instrument the moment regulators receive it. Directors who sign off on that prospectus assume personal liability for every statement in it. Whether you&#8217;re listing in Hong Kong, Singapore, or elsewhere in Asia-Pacific, this isn&#8217;t corporate liability. This is individual exposure that can attach to directors&#8217; personal assets, regardless of their role or seniority on the board.</p>
<h2 dir="ltr">The Prospectus Creates Statutory Liability for Individual Directors Across APAC</h2>
<p dir="ltr">A prospectus is more than marketing material. Across APAC markets, statutory frameworks create binding liability for individuals who authorise prospectus disclosures.</p>
<p dir="ltr">In Hong Kong, <a href="https://www.elegislation.gov.hk/hk/cap32">Section 40 of the Companies (Winding Up and Miscellaneous Provisions) Ordinance</a> establishes civil liability for directors, promoters, and anyone who authorised the issue of a prospectus. In Singapore, the <a href="https://sso.agc.gov.sg/Act/SFA2002">Securities and Futures Act</a> imposes similar personal liability on directors for prospectus misstatements. Across APAC, the pattern is consistent: statutory frameworks place liability directly on individuals.</p>
<p dir="ltr">This liability is strict. Investors who subscribed for shares based on an untrue statement in the prospectus can recover losses directly from named individuals. The statute doesn&#8217;t require investors to prove negligence or intent. It doesn&#8217;t require proof that the director personally knew the statement was false. If the statement was untrue, and an investor relied on it, the director faces civil liability across APAC jurisdictions.</p>
<p dir="ltr">The scope is broad. The prospectus includes not just the formal offering document filed with the <a href="https://www.sfc.hk">Securities and Futures Commission (SFC)</a>, but also supplementary information, amendments, and any documents incorporated by reference. Every statement in these documents becomes a director&#8217;s personal exposure.</p>
<h2 dir="ltr">Criminal Liability Extends Beyond Civil Claims Across APAC</h2>
<p dir="ltr">Civil liability is only the first layer. Across APAC, statutory frameworks create criminal exposure for prospectus misstatements. In Hong Kong, <a href="https://www.elegislation.gov.hk/hk/cap32">Section 40A of the Companies Ordinance</a> creates criminal liability. In Singapore, <a href="https://sso.agc.gov.sg/Act/SFA2002">Section 340 of the Securities and Futures Act</a> establishes similar criminal exposure. This is criminal liability—not just money damages, but potential criminal prosecution.</p>
<p dir="ltr">The civil-criminal distinction is critical. Civil liability is often strict (no proof of intent required). Criminal liability typically requires knowledge or recklessness, but the penalties are steeper. Directors can face criminal fines and imprisonment for fraudulent prospectus disclosures across APAC markets.</p>
<p dir="ltr">Most private-company D&amp;O policies were never designed to cover criminal defence costs. When criminal exposure emerges, directors discover that their insurance doesn&#8217;t extend to legal defence in regulatory investigations or criminal proceedings. This gap becomes acute when regulatory investigations follow a prospectus dispute.</p>
<h2 dir="ltr">Cross-Border Prospectus Liability Across APAC</h2>
<p dir="ltr">Directors of companies listing across multiple APAC markets face layered liability across jurisdictions. A company listing in Hong Kong via <a href="https://www.elegislation.gov.hk/hk/cap32">Section 342E of the Companies Ordinance</a> faces Hong Kong prospectus liability. A company simultaneously or subsequently listing in Singapore faces liability under the <a href="https://sso.agc.gov.sg/Act/SFA2002">Singapore Securities and Futures Act</a>. Companies listing across APAC markets accumulate prospectus liability in each jurisdiction.</p>
<p dir="ltr">This matters because directors often assume that prospectus liability attaches only to the jurisdiction where the IPO occurs. APAC market reality is different. A director of an Indonesian, Thai, or Malaysian company listing on the Hong Kong Stock Exchange faces Hong Kong prospectus liability even if the director is not resident in Hong Kong and the company is incorporated abroad. Similarly, a Singapore company listing in Hong Kong faces both Singapore and Hong Kong prospectus liability simultaneously.</p>
<h2 dir="ltr">Roadshow Statements Create Undocumented Liability Across APAC</h2>
<p dir="ltr">The formal prospectus is filed and documented. Roadshow presentations are not. Yet across APAC, securities laws and listing rules treat roadshow statements as part of the offering record. <a href="https://listing.hkex.com.hk/en/Listed-Companies/Listing-Rules-and-Guidance">Hong Kong&#8217;s Listing Rules</a> and Singapore&#8217;s listing requirements both recognize roadshow materials as part of the disclosure process.</p>
<p dir="ltr">When executives present to institutional investors before an IPO, they make claims about business performance, market opportunity, competitive position, and financial projections. These oral statements form investor expectations. When investors later subscribe based on prospectus disclosures, they rely on consistency between what was said in the roadshow and what appears in the prospectus across all APAC markets where the company is listing.</p>
<p dir="ltr">If there&#8217;s a discrepancy, or if roadshow claims diverge from prospectus language, directors face liability for the roadshow statements even though they sit outside the formal prospectus. Roadshow materials—slide decks, notes, recordings—become evidence in litigation. What was said informally becomes part of the liability record formally.</p>
<h2 dir="ltr">Pre-IPO Communications Sit in the Offering Record Across APAC</h2>
<p dir="ltr">Roadshow presentations aren&#8217;t the only pre-IPO communications that create liability. Analyst briefings, pre-IPO investor presentations, management meetings with underwriters, and even guidance given to major investors can form part of the offering record across APAC.</p>
<p dir="ltr">Under Hong Kong&#8217;s <a href="https://www.elegislation.gov.hk/hk/cap571">Securities and Futures Ordinance</a> and Singapore&#8217;s <a href="https://sso.agc.gov.sg/Act/SFA2002">Securities and Futures Act</a>, liability attaches to any statement a director made in connection with the offering, not just statements in the prospectus itself. This extends liability backward to everything said during the IPO process and forward to statements made after listing if they&#8217;re connected to prospectus disclosures. APAC regulators treat the entire offering communication record—not just the formal prospectus—as the basis for director liability.</p>
<p dir="ltr">Directors face a paradox: the prospectus must be comprehensive to satisfy regulators, yet it can&#8217;t contain all the nuance and context directors want to communicate. Statements made outside the prospectus to flesh out context or address investor concerns create liability if they later diverge from prospectus language or if investors claim those outside statements affected their investment decision.</p>
<h2 dir="ltr">Forward-Looking Statements Create Ongoing Exposure</h2>
<p dir="ltr">Prospectus liability doesn&#8217;t end when the prospectus is filed. Forward-looking statements—projections, guidance, and forecasts—create liability that extends well past the IPO.</p>
<p dir="ltr">When directors include revenue projections, earnings guidance, or market growth assumptions in the prospectus, those projections become the benchmark against which future performance is measured. If actual results diverge significantly from prospectus projections, investors can claim they were misled by forward-looking statements.</p>
<p dir="ltr">This exposure extends across years. A projection made in the prospectus can become the subject of litigation three years later, when actual performance falls short. The statute of limitations for Section 40 claims is typically long enough to accommodate this lag. Directors need to anticipate that prospectus projections will be scrutinised against actual results for years after the IPO.</p>
<h2 dir="ltr">Independent Directors Carry Equal Statutory Liability</h2>
<p dir="ltr">A common misconception is that independent directors carry less liability than executives. The statute says otherwise. <a href="https://www.elegislation.gov.hk/hk/cap32">Section 40</a> applies equally to all directors who authorized the prospectus, regardless of whether they&#8217;re independent, non-executive, or executive.</p>
<p dir="ltr">This matters because it means independent directors can&#8217;t rely on the assumption that executives bore responsibility for the prospectus. Each director who signed off on the prospectus—or whose board approval was required for the prospectus—faces personal liability. Independent directors, audit committee chairs, and even newer board members can be named as defendants in prospectus litigation.</p>
<p dir="ltr">The exposure is uniform across the board. This is why a properly designed D&amp;O programme has to provide Side A coverage (individual director protection) that protects all directors equally, not just the executives.</p>
<h2 dir="ltr">The Role of Reasonable Grounds Defence</h2>
<p dir="ltr">Section 40A creates an exception: criminal liability only applies if a director made an untrue statement &#8220;without reasonable grounds to believe it true.&#8221; This &#8220;reasonable grounds&#8221; defence is the only statutory escape hatch from criminal exposure.</p>
<p dir="ltr">But the defence is narrow and fact-intensive. It requires that a director conducted reasonable due diligence, had credible information supporting the statement, and actually believed the statement was true. In practice, this defence is difficult to sustain without documented evidence of the director&#8217;s investigation and the basis for their belief.</p>
<p dir="ltr">Demonstrating reasonable grounds requires contemporaneous documentation—emails, due diligence reports, legal opinions, financial audit work papers, market research, and management representations. Without this documentation, a director&#8217;s claim to have had reasonable grounds collapses. With it, the defence has teeth.</p>
<p dir="ltr">This is why prospectus due diligence processes matter so much. They create the documentary evidence that can later support a reasonable grounds defence if liability questions emerge.</p>
<h2 dir="ltr">D&amp;O Insurance Has to Respond to Statutory Liability</h2>
<p dir="ltr">Private-company D&amp;O policies focus on operational claims: employment disputes, product liability, contract breaches. Prospectus liability is categorically different. It&#8217;s statutory liability that attaches the moment the prospectus is filed.</p>
<p dir="ltr">A properly structured D&amp;O programme for an IPO has to include coverage that explicitly addresses prospectus liability. This means:</p>
<p dir="ltr"><strong>First, statutory liability coverage</strong> that responds to Section 40 civil claims by investors. This coverage has to be broad enough to cover not just the formal prospectus, but all communications that form part of the offering record (roadshow materials, analyst briefings, pre-IPO presentations).</p>
<p dir="ltr"><strong>Second, criminal defence coverage</strong> that addresses Section 40A exposure and regulatory investigation costs. Most private-company policies exclude or sub-limit criminal defence. At IPO, this becomes a critical gap.</p>
<p dir="ltr"><strong>Third, Side A coverage</strong> that protects individual directors when the company&#8217;s interests diverge from theirs. In a prospectus claim, company and individual directors can be on opposite sides. Side A is the only coverage layer that protects directors independently of the company.</p>
<p dir="ltr"><strong>Fourth, sufficient limits</strong> to address the scale of prospectus claims. Investor class actions arising from prospectus misstatements can settle in the tens or hundreds of millions. Inadequate limits leave directors personally exposed for the shortfall.</p>
<h2 dir="ltr">Prospectus Liability Begins the Moment the Document Is Filed</h2>
<p dir="ltr">IPO liability doesn&#8217;t start at trading commencement or at the close of the offering. It starts the moment the prospectus is filed with regulators. From that moment forward, every statement in the prospectus creates potential director liability.</p>
<p dir="ltr">This timing matters for insurance placement. D&amp;O coverage has to be in place before the prospectus is filed, not after. Insurance purchased after filing leaves directors unprotected for the initial exposure period. Some claims arise immediately—from investors who read the prospectus and invest based on statements later shown to be false. Coverage gaps in the initial period leave directors bearing this early exposure personally.</p>
<p dir="ltr">Moreover, the prospectus filing date typically occurs months before the IPO actually closes. This extended period—from prospectus filing through trading commencement—is when most of the investor acquisition happens. It&#8217;s also when most prospectus-related disputes emerge if there are issues with prospectus accuracy or completeness.</p>
<h2 dir="ltr">The First Three Years Post-IPO Are the Highest-Risk Period</h2>
<p dir="ltr">Prospectus claims cluster in the years immediately after an IPO. Stock volatility is high in early trading. Investor expectations are fresh from the prospectus disclosures. When stock prices decline or company performance misses guidance, investor litigation follows within months or a few years.</p>
<p dir="ltr">This means directors face the highest prospectus liability exposure in the first three years after going public. This is when regulatory investigations are most likely to commence. This is when shareholder derivative actions targeting prospectus representations are most likely to be filed. This is when forensic questions about prospectus accuracy are most acutely litigated.</p>
<p dir="ltr">A defensible D&amp;O programme has to prioritise coverage in this window. Claims-made policies have to be carefully structured to ensure continuous coverage through this period. Tail coverage or extended reporting period endorsements have to be considered to protect directors for claims arising from the prospectus but reported after the initial D&amp;O policy period ends.</p>
<h2 dir="ltr">Building a Defensible D&amp;O Programme Around Prospectus Liability</h2>
<p dir="ltr">Understanding prospectus liability is the foundation of a defensible D&amp;O programme for IPO. The liability is personal, it&#8217;s statutory, and it&#8217;s immediate. It attaches to directors individually, it doesn&#8217;t require proof of negligence, and it begins the moment the prospectus is filed.</p>
<p dir="ltr">Directors who understand this exposure can take steps to minimise it: rigorous due diligence on every prospectus statement, documented reasonable grounds for forward-looking projections, careful alignment between roadshow materials and prospectus language, and insurance coverage that actually responds to statutory prospectus liability.</p>
<p dir="ltr">The prospectus isn&#8217;t just an offering document. For directors, it&#8217;s a personal liability instrument. The D&amp;O programme has to be built on that foundation.</p>
<div role="region" aria-label="Primary pane">
<div>
<div>
<div>
<div>
<div>
<div>
<div tabindex="-1" aria-hidden="false">
<div>
<div>
<div tabindex="-1">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div tabindex="0">
<div>
<div>
<p dir="ltr"><strong>Understand your prospectus liability before you go public.</strong> Review your D&amp;O coverage now to ensure it responds to statutory prospectus liability across APAC markets. <a href="https://www.continuuminsure.com/contact/">Contact us</a> to identify coverage gaps before listing day.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Continuum Emerging Risk Radar &#124; Issue #001</title>
		<link>https://www.continuuminsure.com/articles/continuum-emerging-risk-radar-issue-001/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Fri, 04 Sep 2026 09:33:17 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6954</guid>

					<description><![CDATA[Our weekly snapshot of the developments reshaping technology risk, translated into what they mean for coverage. Three developments this week highlight how ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/continuum-emerging-risk-radar-issue-001/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<p>Our weekly snapshot of the developments reshaping technology risk, translated into what they mean for coverage.</p>
<p>Three developments this week highlight how quickly the nature of technology risk is changing.</p>
<p>🔴 AI &amp; Cyber | The exploit window is shrinking<br />
OpenAI says its forthcoming Astra model has become the first classified at its “Critical” cybersecurity threshold, identifying unknown vulnerabilities and building working exploit chains in testing.<br />
<strong><a href="https://openai.com/index/path-to-astra/">Read More</a></strong></p>
<p>🟠 Fintech &amp; Payments | Transaction authority becomes the attack surface<br />
Google has detailed attacks against banks and payment providers aimed at core payment infrastructure and authenticated transaction credentials.<br />
<a href="https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil"><strong>Read More</strong></a></p>
<p>🟡 Digital Assets | Stablecoin resilience moves beyond reserves<br />
Singapore has proposed legislation covering stablecoin reserves, redemption, stress testing, and cross-border issuance.<br />
<strong><a href="https://www.mas.gov.sg/news/media-releases/2026/mas-consults-on-legislative-amendments-to-implement-stablecoin-regulatory-framework">Read More</a></strong></p>
<p>Continuum View<br />
Emerging risk is moving from access to action. The question: what is the most consequential action a technology, credential, or person is authorised to take, and what prevents one failure from allowing it?</p>
<div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/09/Sep4-Emerging-Risk-Radar.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Sep4 Emerging Risk Radar</a></div>
<div role="feed" aria-label="Chat messages" aria-describedby="_r_du_">
<div>
<div>
<div tabindex="0" role="article" aria-setsize="24" aria-posinset="24" aria-label="Message 24 of 24">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<p dir="ltr">Want to talk through what this means for your risk exposure? <a href="https://www.continuuminsure.com/contact/">Get in touch</a> with us today.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Role of D&#038;O Insurance During an IPO</title>
		<link>https://www.continuuminsure.com/articles/the-role-of-do-insurance-during-an-ipo/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 04:55:55 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[D&O Insurance]]></category>
		<category><![CDATA[IPO]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6937</guid>

					<description><![CDATA[IPO day transforms director liability. Directors who sign the prospectus assume statutory and civil liability personally. Public disclosure obligations—quarterly filings, earnings guidance, ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/the-role-of-do-insurance-during-an-ipo/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<p dir="ltr"><strong><div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/09/Sep3Carousel.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Sep3Carousel</a></div></strong></p>
<p>IPO day transforms director liability. Directors who sign the prospectus assume statutory and civil liability personally. Public disclosure obligations—quarterly filings, earnings guidance, regulatory updates—carry personal exposure. Stock price movements trigger shareholder claims naming them as defendants. Meanwhile, the private-company D&amp;O insurance policy, built to protect against operational claims, fails to contemplate this exposure category.</p>
<h2 dir="ltr">D&amp;O Insurance Becomes Essential at Listing</h2>
<p dir="ltr">Most companies treat <a href="https://www.continuuminsure.com/coverage/do-insurance/">D&amp;O insurance</a> as a renewal item, something the broker handles on an annual cycle. However, IPO changes that entirely. D&amp;O insurance becomes a <a href="https://www.jdsupra.com/legalnews/2026-guide-to-d-o-insurance-for-ipos-2263194/">placement document</a>, sitting alongside the prospectus and underwriter agreements as a core piece of the <a href="https://www.hubinternational.com/products/proex/the-advocate/2026/02/ipo-readiness-and-do-strategy-for-public-market-success/">IPO structure</a>.</p>
<p dir="ltr">The reason is straightforward: going public creates new director liability that didn&#8217;t exist as a private company. Consequently, the D&amp;O policy must protect against this new exposure. Otherwise, directors absorb the risk personally.</p>
<p dir="ltr">Most companies attempt to layer IPO-specific coverage onto their existing private-company policy through endorsements and side letters. Unfortunately, this approach fails because private-company wordings were never designed to contemplate securities claims. Bolt-on coverage creates gaps, sub-limits, and conflicts that expose directors exactly when they need protection most.</p>
<h2 dir="ltr">The Prospectus Creates Statutory and Civil Director Liability</h2>
<p dir="ltr">The prospectus is the liability document of the IPO. Every statement in it carries personal exposure for the directors who sign off on its accuracy.</p>
<p dir="ltr">In Hong Kong, <a href="https://www.charltonslaw.com/hong-kong-law/potential-liabilities-under-hong-kong-law-in-connection-with-the-publication-of-a-prospectus-on-the-listing-of-a-company-on-the-stock-exchange-of-hong-kong/">the Companies (WUMP) Ordinance</a> imposes dual liability for prospectus misstatements. <a href="https://www.charltonslaw.com/hong-kong-law/potential-liabilities-under-hong-kong-law-in-connection-with-the-publication-of-a-prospectus-on-the-listing-of-a-company-on-the-stock-exchange-of-hong-kong/">Section 40</a> establishes civil liability on directors for untrue statements in the prospectus, creating exposure to shareholder claims for losses incurred based on prospectus reliance. Section 40A further establishes criminal liability for knowingly including untrue statements.</p>
<p dir="ltr">This dual regime matters significantly because it expands exposure beyond the traditional insurance coverage model. D&amp;O insurance typically covers civil claims. Criminal liability, by contrast, sits in a different category entirely—and most private-company policies were never drafted to include criminal defense costs.</p>
<p dir="ltr">Moreover, the prospectus exposes directors to underwriter liability. Underwriters conduct due diligence on prospectus disclosures. When that diligence identifies issues, underwriter disputes and indemnification claims follow—and those disputes often name individual directors, not just the company.</p>
<p dir="ltr">Critically, this exposure begins the moment the prospectus is filed. It doesn&#8217;t wait for closing or trading to commence. Directors face liability from filing day forward.</p>
<h2 dir="ltr">Post-Listing Disclosure Obligations Attach Personally</h2>
<p dir="ltr">IPO liability doesn&#8217;t end with the prospectus. Instead, it accelerates.</p>
<p dir="ltr">Going public imposes continuous disclosure obligations on directors. They face personal exposure for quarterly earnings announcements, annual financial reporting, regulatory filings, and forward-looking guidance given to the market. Each disclosure carries potential liability to investors who rely on inaccurate statements.</p>
<p dir="ltr">Public disclosure liability differs fundamentally from prospectus liability. Prospectus liability is a one-time event. Public disclosure liability, by contrast, is recurring—quarterly, annually, whenever material information must be disclosed. It persists for as long as the company remains listed.</p>
<p dir="ltr">Under Hong Kong&#8217;s Securities and Futures Ordinance and the Listing Rules, directors bear responsibility for the accuracy of continuous disclosure. Failure to disclose material information creates regulatory exposure and shareholder liability. Additionally, misleading guidance in earnings calls creates reliance claims, and forward-looking statements that don&#8217;t materialize trigger securities litigation.</p>
<p dir="ltr">The cumulative effect is substantial: directors carry ongoing personal exposure for every material disclosure the company makes. This exposure class barely exists for private companies. Yet for public companies, it becomes a permanent liability category.</p>
<h2 dir="ltr">Securities Claims Are A New Loss Type</h2>
<p dir="ltr">Private companies face operational claims: employment disputes, product liability, contract breaches, regulatory investigations. Standard commercial insurance and D&amp;O policies built around operational risk typically cover these claims.</p>
<p dir="ltr">Public companies face securities claims—a different liability category entirely. Securities class actions are triggered by stock price movements and name directors as individual defendants. Moreover, these actions involve regulatory investigations by the SEC or equivalent authorities and carry reputational costs that far exceed the financial settlement.</p>
<p dir="ltr">Securities claims are not optional exposure for public companies. Rather, they are inevitable. A stock price decline of sufficient magnitude will trigger shareholder litigation, name directors, and force the company&#8217;s insurance to contemplate this as core exposure.</p>
<p dir="ltr">Most private-company D&amp;O policies were not designed with securities claims in mind. Coverage language focuses on operational claims. Additionally, sub-limits apply to securities exposure, and exclusions carve out entire categories of securities liability. When the securities claim arrives, coverage gaps emerge—and directors discover they are underinsured.</p>
<h2 dir="ltr">Side A Cover Becomes The Single Most Important Layer</h2>
<p dir="ltr">D&amp;O insurance has three components: Side A, Side B, and Side C.</p>
<p dir="ltr"><a href="https://www.gbainsurance.com/facets_side_a_dic_918">Side A</a> covers individual directors and officers for their personal liability when the company cannot indemnify them—either because the company lacks financial capacity, because the company&#8217;s own coverage is exhausted, or because a conflict of interest prevents the company from providing indemnification.</p>
<p dir="ltr">For private companies, this distinction is largely academic. The company and board typically share aligned interests, and the company indemnifies directors as a matter of course.</p>
<p dir="ltr">For public companies, this alignment breaks down significantly. In securities litigation, the company&#8217;s interests often diverge from the board&#8217;s. The company may settle, cutting a deal that leaves directors exposed. Alternatively, the company may become insolvent, unable to fund indemnification. Or conflicts of interest may prevent the company from providing coverage.</p>
<p dir="ltr">When these situations arise, Side A becomes the only protection directors have. It covers them personally, independently of the company&#8217;s financial status or indemnification decision.</p>
<p dir="ltr">This is why Side A becomes the single most <a href="https://dreamassurancegroup.com/blog/side-a-d-and-o/">important part</a> of the policy at IPO. It&#8217;s not ancillary—it&#8217;s essential. Directors need it to protect themselves when company and board interests split.</p>
<p dir="ltr">Finally, Side A coverage levels, attachment points, and exclusions must be carefully calibrated at placement. Underestimating Side A need ranks among the most common errors in IPO policy restructuring.</p>
<h2 dir="ltr">Historic Pre-IPO Acts Create Runoff Exposure</h2>
<p dir="ltr">IPO liability doesn&#8217;t start at listing. Instead, it reaches backward.</p>
<p dir="ltr">Actions taken before going public face new scrutiny under securities claim standards after listing. A pre-IPO business decision that seemed reasonable in a private context can become the subject of shareholder litigation after the company goes public, based on its impact on future performance or market expectations.</p>
<p dir="ltr">Additionally, regulatory investigations reach into pre-listing conduct. Audits and SEC investigations often examine decisions made months or years before the public offering, looking for patterns or disclosure failures that should have been disclosed in the prospectus.</p>
<p dir="ltr">This backward reach creates runoff exposure. Directors need protection not just for forward-looking liability, but for the liability legacy they&#8217;re bringing to the public markets from their private-company past.</p>
<p dir="ltr">Typically, this runoff exposure requires either tail coverage (extended reporting period endorsements that continue coverage after the D&amp;O policy ends) or runoff policies purchased specifically to cover pre-IPO acts. However, standard placement coverage may not adequately address this exposure.</p>
<p dir="ltr">Many companies overlook runoff exposure because they assume IPO coverage begins at listing and protects from listing forward. Unfortunately, this assumption is wrong. Runoff protection must be built into the policy structure.</p>
<h2 dir="ltr">Restructuring the Policy: Placement, Not Renewal</h2>
<p dir="ltr">The timing of D&amp;O restructuring is critical. It must happen at placement, not at renewal.</p>
<p dir="ltr">IPO placements create a window of opportunity. The IPO working group includes legal counsel, underwriters, and investment bankers all focused on disclosure and risk management. Moreover, the underwriter&#8217;s due diligence process creates a forum for reviewing insurance coverage gaps, and the prospectus itself provides an opportunity to disclose insurance arrangements and policy details to investors.</p>
<p dir="ltr">If companies defer D&amp;O restructuring to the renewal cycle—months or a year after listing—these opportunities disappear. The IPO working group has disbanded. Underwriter leverage has evaporated. The prospectus is filed and locked.</p>
<p dir="ltr">More importantly, deferring restructuring leaves directors exposed in the months immediately after listing, when securities risk is highest. Stock volatility is pronounced around IPO. Investor expectations are freshly set by prospectus disclosures. Shareholder litigation risk is most acute in the weeks and months following public trading.</p>
<p dir="ltr">Conversely, restructuring at placement means coverage is in place before any of this exposure hits. Additionally, the D&amp;O policy is built with IPO-specific knowledge—what the prospectus actually says, what disclosures were made, what exposure the underwriter identified.</p>
<p dir="ltr">The placement timing also affects pricing and terms. Underwriters and insurers are engaged in the IPO process, so companies can negotiate coverage as part of the broader placement transaction. Deferring to renewal means negotiating D&amp;O coverage in isolation, without the context or leverage of the IPO itself.</p>
<h2 dir="ltr">Know Your D&amp;O Coverage</h2>
<p dir="ltr">Typically, companies treat D&amp;O insurance as a back-office function. However, at IPO, it becomes a front-office issue. Directors need to know exactly what they&#8217;re protected against and what gaps remain.</p>
<p dir="ltr">Companies should take the following steps:</p>
<p dir="ltr">First, review what prospectus liability the policy actually covers—including criminal defense costs and underwriter indemnification disputes.</p>
<p dir="ltr">Next, confirm that securities claims protection is built into the core coverage, not carved out or sub-limited.</p>
<p dir="ltr">Additionally, understand Side A coverage levels and confirm they&#8217;re sufficient for worst-case scenarios where the company and board diverge.</p>
<p dir="ltr">Further, verify that runoff and tail coverage address pre-IPO acts and historic exposures.</p>
<p dir="ltr">Finally, test the vendor relationships and claims processes before an actual incident occurs.</p>
<p dir="ltr">The companies that complete this work are the ones that discover coverage gaps in time to fix them. Conversely, the companies that don&#8217;t are the ones that discover gaps when a securities claim arrives—months after the prospectus was filed.</p>
<p dir="ltr">Continuum helps companies audit their D&amp;O policy before going public and build coverage that actually protects directors when it matters most: on listing day and in the months that follow.</p>
<p dir="ltr">The D&amp;O policy your company has today isn&#8217;t the policy it needs on listing day.</p>
<div role="region" aria-label="Primary pane">
<div tabindex="-1" aria-hidden="false">
<div tabindex="-1">
<div tabindex="0">
<div>
<div>
<p dir="ltr"><strong>Audit your D&amp;O coverage before going public.</strong> Contact Continuum to review your policy structure, identify coverage gaps, and ensure directors are protected when it matters most: on listing day and in the months that follow. <a href="http://www.continuuminsure.com/contact/">Contact us</a> to discuss your IPO insurance strategy.</p>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Risk Insight Series: Cyber Insurance and the Emerging Risk Gap in APAC</title>
		<link>https://www.continuuminsure.com/articles/risk-insight-series-cyber-insurance-and-the-emerging-risk-gap-in-apac/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 03:42:21 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6926</guid>

					<description><![CDATA[Cyber policy wordings in market today were drafted for a threat environment that no longer exists. Ransomware has moved the dominant loss ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/risk-insight-series-cyber-insurance-and-the-emerging-risk-gap-in-apac/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<p dir="ltr">Cyber policy wordings in market today were drafted for a threat environment that no longer exists. Ransomware has moved the dominant loss from data breach to operational shutdown, with average downtime now reaching 24 days and average incident costs of USD 5.08 million. AI-generated attacks like the USD 25 million Arup deepfake case in Hong Kong have introduced a class of fraud that sits awkwardly between Cyber, Crime, and Social Engineering wordings. Supply chain compromise is now the most common attack path, involved in 30 percent of all breaches in 2025. Cyber insurance in APAC has become a coordination problem across policies that were rarely designed to work together. Our August 2026 Risk Insight maps the three emerging risk gaps and where the cover most often falls short.</p>
<p dir="ltr"><strong>What This Report Covers</strong></p>
<ul dir="ltr">
<li>Why cyber insurance in APAC needs to be sized to the outage, not the data breach</li>
<li>What a modern cyber policy actually buys you, and why the vendor panel matters more than the indemnity</li>
<li>How AI-generated attacks like the Arup deepfake fraud sit between Cyber, Crime, and Social Engineering Fraud cover</li>
<li>Where AI-specific exposures, supply chain risk, and social engineering fraud consistently fall short in mid-market wordings</li>
<li>What a defensible cyber programme looks like across Cyber, Crime, and PI</li>
</ul>
<div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/09/Continuum-Risk-Insight-Series-Cyber-Insurance-and-the-Emerging-Risk-Gap-in-APAC.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Continuum Risk Insight Series - Cyber Insurance and the Emerging Risk Gap in APAC</a></div>
<p class="p1"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/09/Continuum-Risk-Insight-Series-Cyber-Insurance-and-the-Emerging-Risk-Gap-in-APAC.pdf">Download the PDF →</a></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Weekly Risk Update August 28, 2026</title>
		<link>https://www.continuuminsure.com/news/weekly-risk-update-august-28-2026/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 00:53:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Crime Insurance]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<category><![CDATA[FinTech]]></category>
		<category><![CDATA[Tech PI Inc Cyber]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6948</guid>

					<description><![CDATA[Welcome back to Continuum Risk Update. Every Friday we pull the top Asia headlines on digital-asset regulation, cyber risk, industry moves and ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/news/weekly-risk-update-august-28-2026/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<div class="row-start-1 col-start-1 min-w-0">
<div class="min-w-0 pl-2 py-1.5">
<div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/09/Aug28Carousel.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Aug28Carousel</a></div>
<p>Welcome back to Continuum Risk Update. Every Friday we pull the top Asia headlines on digital-asset regulation, cyber risk, industry moves and insurance signals, with concise takeaways and practical actions for insurers and corporate risk teams.</p>
<p>🏛️ REGULATORY<br />
Japan&#8217;s FSA has issued its first new crypto exchange licence in four years to Nomura&#8217;s Laser Digital, signalling a selective reopening of one of Asia&#8217;s most tightly gated markets.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/g3hY2Pc3" target="_self" data-test-app-aware-link="">https://lnkd.in/g3hY2Pc3</a></p>
<p>The MAS unveiled tax exemptions for fund managers and family offices in a direct response to Hong Kong&#8217;s recent cuts, escalating the rivalry between the two hubs for Asia&#8217;s wealth management business.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/gz8JSd_x" target="_self" data-test-app-aware-link="">https://lnkd.in/gz8JSd_x</a></p>
<p>🔐 HACKING &amp; PHYSICAL RISKS<br />
Taiwan dismantled a USDT laundering network routing funds through Hong Kong-based exchanges, highlighting stablecoins as the go-to vehicle for cross-border financial crime in Asia.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/gz8JSd_x" target="_self" data-test-app-aware-link="">https://lnkd.in/gz8JSd_x</a></p>
<p>South Korea is launching a Joint Virtual Asset Crime Investigation Unit in October with over 2,500 investigators targeting crypto fraud, phishing, and money laundering.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/gz8JSd_x" target="_self" data-test-app-aware-link="">https://lnkd.in/gz8JSd_x</a></p>
<p>📊 INDUSTRY &amp; MARKETS<br />
SBI Holdings led a $68 million Series C in Fasset at a $1 billion valuation, with the digital asset platform planning a licensed digital bank in Malaysia.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/gaPU7rXv" target="_self" data-test-app-aware-link="">https://lnkd.in/gaPU7rXv</a></p>
<p>Standard Chartered became the first bank to distribute Hong Kong&#8217;s new HKDAP stablecoin, setting a precedent for bank participation in stablecoin distribution without direct issuance risk.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/gz8JSd_x" target="_self" data-test-app-aware-link="">https://lnkd.in/gz8JSd_x</a></p>
<p>🛡️ INSURANCE SPOTLIGHT<br />
With $750 billion flowing into APAC data centres, Willis says insurers are moving to ecosystem-based underwriting, scrutinising power, cooling, connectivity, and cyber resilience rather than assets alone.<br />
<a class="tMyQkGlnBiclmoXhIydugfVwhkdxOjoCQUeQ " tabindex="0" href="https://lnkd.in/g9jvNPCR" target="_self" data-test-app-aware-link="">https://lnkd.in/g9jvNPCR</a></p>
<p><a href="https://www.continuuminsure.com/contact/">Get in touch</a> with Continuum to see how we can help cover your business&#8217; risk.</p>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Does your Cyber Insurance Cover you for Emerging Risks?</title>
		<link>https://www.continuuminsure.com/articles/does-your-cyber-insurance-cover-you-for-emerging-risks/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Wed, 26 Aug 2026 02:47:37 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[business interruption]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6905</guid>

					<description><![CDATA[Most cyber insurance policies were written for attacks that don&#8217;t happen anymore. Attackers targeted your perimeter. They tried to breach your data. ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/does-your-cyber-insurance-cover-you-for-emerging-risks/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<p dir="ltr"><div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/08/Aug26Carousel-2.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Aug26Carousel</a></div>
<p dir="ltr"><strong>Most cyber insurance policies were written for attacks that don&#8217;t happen anymore. Attackers targeted your perimeter. They tried to breach your data. They deployed ransomware against your infrastructure. Cyber policies were built to respond to those scenarios. But the threat landscape has fundamentally shifted. Attackers now exploit AI vulnerabilities, compromise your vendors, and use social engineering to trigger voluntary transfers. The policies haven&#8217;t kept pace.</strong></p>
<h3 dir="ltr">AI Is Rarely Named Explicitly In Policy Language</h3>
<p dir="ltr">AI has become a primary attack vector. Model manipulation, prompt injection, data poisoning, deepfake fraud. These are real threats that organizations face today.</p>
<p dir="ltr">But most cyber policies don&#8217;t explicitly reference AI. Cover for these threats is inferred, not guaranteed. The <a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI Risk Management Framework</a> provides a comprehensive approach to managing AI risks, but most cyber policies predate this framework and don&#8217;t incorporate its recommendations.</p>
<p dir="ltr">A policy might cover &#8220;fraud&#8221; or &#8220;unauthorized access,&#8221; but it doesn&#8217;t explicitly state whether that covers AI-generated deepfakes or model poisoning attacks. The <a href="https://owasp.org/www-project-top-10-for-large-language-model-applications/">OWASP Top 10 for Large Language Model Applications</a> identifies specific LLM vulnerabilities that organizations should protect against, yet standard cyber policies remain silent on these threats.</p>
<p dir="ltr">This creates ambiguity. When an organization experiences an AI-enabled attack and files a claim, the insurance company can argue: this threat wasn&#8217;t contemplated in the policy language. Cover is disputed. The organization absorbs the gap.</p>
<p dir="ltr">Explicit coverage for AI-specific threats is beginning to appear in new policy wordings. But most organizations are still operating under older language that treats AI threats as variations of traditional fraud or system compromise, rather than as distinct attack vectors.</p>
<h3 dir="ltr">Supply Chain Risk Sits In Contingent BI—And It&#8217;s Sub-Limited</h3>
<p dir="ltr">The most common attack path today isn&#8217;t through the insured&#8217;s own perimeter. It&#8217;s through a vendor or SaaS provider. Attackers compromise a less-secure supplier. The insured&#8217;s operations stall because they depend on that supplier&#8217;s service.</p>
<p dir="ltr">The <a href="https://www.cisa.gov/resources-tools/resources/securing-software-supply-chain-recommended-practices-guide-customers-and">CISA Securing the Software Supply Chain</a> guidance outlines best practices for managing supply chain risk, but most cyber policies don&#8217;t adequately cover the financial impact when a vendor is compromised.</p>
<p dir="ltr">This is contingent business interruption exposure. It&#8217;s covered under most cyber policies—but typically as a sub-limit well below the main aggregate. An organization with $10 million in cyber coverage might have only $1 million in contingent BI sub-limits.</p>
<p dir="ltr">For an organization losing $500,000 daily when a critical vendor goes offline, a $1 million sub-limit covers two days of losses. The remaining exposure is uninsured.</p>
<p dir="ltr">Additionally, contingent BI coverage often requires proof that the vendor&#8217;s outage directly caused a demonstrable loss. Establishing that causal chain takes time. By the time the claim is approved, the organization has already absorbed months of recovery costs.</p>
<h3 dir="ltr">Social Engineering Cover Is Scattered Across Cyber And Crime Wordings</h3>
<p dir="ltr">Social engineering attacks result in voluntary transfers. An employee believes they&#8217;re following legitimate instructions from an executive. The money moves to an attacker. The system worked correctly. But the loss is real.</p>
<p dir="ltr">This loss sits between cyber insurance and crime insurance. Neither policy owns it cleanly. Cyber insurance covers system breaches, not voluntary transfers. Crime insurance covers theft, but often excludes &#8220;voluntary parting&#8221;—situations where the victim willingly transferred money because they were deceived.</p>
<p dir="ltr">Social engineering fraud (SEF) coverage attempts to bridge this gap. But SEF is placed inconsistently across cyber and crime wordings. Some organizations have it under cyber. Some under crime. Some under both, but with different sub-limits and exclusions.</p>
<p dir="ltr">When a social engineering attack occurs, the claim gets disputed. Is this cyber? Is this crime? Does the voluntary parting exclusion apply? By the time the coverage question is resolved, the organization has already spent months without recovery.</p>
<h3 dir="ltr">Regulators Are Expanding AI Enforcement</h3>
<p dir="ltr">Regulators in the UK, EU, and APAC are expanding enforcement around AI governance, model integrity, and data security. When an organization experiences an AI-enabled attack or discovers model poisoning in their systems, regulators open investigations.</p>
<p dir="ltr">The <a href="https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20241202-2-EN/TM-C-1.pdf">HKMA Supervisory Approach on Cyber Risk Management</a> and <a href="https://www.hkma.gov.hk/eng/regulatory-resources/regulatory-guides/by-subject-current/technology-risk-management/">HKMA Technology Risk Management Guidelines</a> set expectations for Hong Kong institutions. In Singapore, the <a href="https://www.mas.gov.sg/who-we-are/mas-advisory-panels-and-committees/cyber-and-technology-resilience-experts-panel">MAS Cyber and Technology Resilience Experts Panel</a> and the <a href="https://www.mas.gov.sg/news/media-releases/2026/mas-and-abs-establish-taskforce-to-strengthen-cyber-and-technology-resilience">MAS AI-Driven Cyber and Technology Risk Taskforce</a> are actively working to strengthen defenses against AI-enabled threats.</p>
<p dir="ltr">The <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">EU AI Act</a> and <a href="https://artificialintelligenceact.eu/ai-act-explorer/">AI Act Explorer</a> set a comprehensive regulatory framework. The <a href="https://www.ropesgray.com/en/insights/viewpoints/2026/06/102n7e3/from-principles-to-practice-the-fcas-evolving-expectations-on-ai-governance">FCA&#8217;s AI governance expectations</a> in the UK emphasize governance and operational resilience.</p>
<p dir="ltr">These investigations trigger notification requirements, defense costs, and compliance obligations. Traditional cyber policies address notification costs for data breaches. They don&#8217;t explicitly address notification for AI governance failures or model compromise incidents.</p>
<p dir="ltr">As regulatory enforcement expands, organizations are facing investigation costs that their cyber insurance doesn&#8217;t contemplate. The gap between actual exposure and insured exposure widens.</p>
<h3 dir="ltr">The Three Gaps Show Up In Almost Every Mid-Market Programme</h3>
<p dir="ltr">When Continuum reviews cyber insurance programmes for mid-market and fintech organizations, three gaps consistently appear:</p>
<p dir="ltr"><strong>First, AI threats are inferred, not explicit.</strong> Cover for model manipulation, prompt injection, or deepfake fraud depends on how broadly the policy interprets &#8220;fraud&#8221; or &#8220;cyber attack.&#8221; That ambiguity creates claims disputes.</p>
<p dir="ltr"><strong>Second, supply chain risk is sub-limited.</strong> Contingent BI coverage exists but is capped well below the organization&#8217;s actual exposure to vendor outages. The most likely attack path is under-insured.</p>
<p dir="ltr"><strong>Third, social engineering sits in a grey zone.</strong> Whether the claim is covered depends on how cyber and crime policies interact, how SEF sub-limits are structured, and whether voluntary parting exclusions apply. The coverage landscape is unclear.</p>
<h3 dir="ltr">A Defensible Cyber Programme Aligns Wordings Across Cyber, Crime, And PI</h3>
<p dir="ltr">Organizations need cyber insurance that explicitly addresses AI threats. They need contingent BI sub-limits that reflect their actual vendor dependencies. They need clear coverage for social engineering fraud without voluntary parting exclusions.</p>
<p dir="ltr">Most importantly, they need alignment. Cyber, crime, and professional indemnity policies should work together to close gaps, not create them. When a loss occurs, the organization should know which policy responds—not spend months disputing coverage.</p>
<p dir="ltr">This requires reviewing wordings against the current threat environment, not the environment they were drafted for. Most cyber programmes were built three to five years ago. The threat landscape has evolved. The policies haven&#8217;t.</p>
<h3 dir="ltr">Understanding Your Coverage Against Today&#8217;s Threats</h3>
<p dir="ltr">Before renewing cyber insurance, organizations should ask:</p>
<p dir="ltr"><strong>Does the policy explicitly cover AI-specific threats?</strong> Or does cover depend on broad interpretations of &#8220;fraud&#8221; and &#8220;system compromise&#8221;?</p>
<p dir="ltr"><strong>What are the contingent BI sub-limits?</strong> Are they adequate for a multi-day vendor outage? Or do they cover only a fraction of your actual exposure?</p>
<p dir="ltr"><strong>How is social engineering covered?</strong> Is it under cyber, crime, or SEF? Are there voluntary parting exclusions? What are the sub-limits?</p>
<p dir="ltr"><strong>How do your cyber, crime, and PI policies interact?</strong> Do they work together to close coverage gaps, or do they create overlaps and exclusions?</p>
<p dir="ltr">Most organizations can&#8217;t answer these questions. They renew based on premium, not on whether the coverage aligns with their actual threat environment.</p>
<h3 dir="ltr">Continuum Helps Close The Gaps</h3>
<p dir="ltr">Cyber policies need to evolve. The <a href="https://www.iii.org/press-release/cyber-insurance-market-growing-dramatically-triple-i-finds-020724">Insurance Information Institute&#8217;s latest cyber insurance market analysis</a> shows the market is growing, but coverage gaps persist. Until policies evolve, organizations need to understand where their coverage falls short and what gaps exist between their actual cyber risk and their insured exposure.</p>
<p dir="ltr">Continuum reviews cyber, crime, and PI policies against the threat environment organizations actually face today. We identify where AI threats are under-covered, where supply chain risk is sub-limited, and where social engineering sits in a grey zone. We help organizations align their wordings to close those gaps before a loss occurs.</p>
<p dir="ltr">Before renewing cyber insurance, understand what your policies actually cover—and what they don&#8217;t. <a href="#">Contact Continuum</a> to review your coverage against the current threat landscape.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Weekly Risk Update August 21, 2026</title>
		<link>https://www.continuuminsure.com/news/weekly-risk-update-august-21-2026/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Fri, 21 Aug 2026 06:07:26 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Crime Insurance]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<category><![CDATA[FinTech]]></category>
		<category><![CDATA[Tech PI Inc Cyber]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6867</guid>

					<description><![CDATA[Welcome back to Continuum Risk Update. Every Friday we pull the top Asia headlines on digital-asset regulation, cyber risk, industry moves and ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/news/weekly-risk-update-august-21-2026/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<div class="row-start-1 col-start-1 min-w-0">
<div class="min-w-0 pl-2 py-1.5">
<div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/08/Aug21Weekly-Risk-Update.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Aug21Weekly Risk Update</a></div>
<p>Welcome back to Continuum Risk Update. Every Friday we pull the top Asia headlines on digital-asset regulation, cyber risk, industry moves and insurance signals, with concise takeaways and practical actions for insurers and corporate risk teams.</p>
<p>🏛️ REGULATORY<br />
Singapore has finalised its CARF crypto tax reporting framework, requiring digital asset firms to report customer transaction data to tax authorities from 2027, bringing the city-state in line with OECD global standards.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gvnaRK4V" target="_self" data-test-app-aware-link="">https://lnkd.in/gvnaRK4V</a></p>
<p>South Korea&#8217;s National Assembly has passed a bill expanding FIU powers to freeze suspicious crypto accounts without court approval in urgent cases, marking a significant step up in the country&#8217;s AML enforcement toolkit.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gwFYXSDf" target="_self" data-test-app-aware-link="">https://lnkd.in/gwFYXSDf</a></p>
<p>🔐 HACKING &amp; PHYSICAL RISKS<br />
Hong Kong&#8217;s SFC flagged 65 fake websites impersonating licensed exchange HashKey, warning investors of a coordinated phishing campaign targeting retail crypto users in the city.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gvnaRK4V" target="_self" data-test-app-aware-link="">https://lnkd.in/gvnaRK4V</a></p>
<p>BitMart&#8217;s founder has been accused of withholding user funds owed since the exchange&#8217;s 2021 hack, with new claims alleging millions in unpaid compensation remain outstanding.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gvPkd5Ab" target="_self" data-test-app-aware-link="">https://lnkd.in/gvPkd5Ab</a></p>
<p>📊 INDUSTRY &amp; MARKETS<br />
Hong Kong has kicked off live beta testing for its HKD-backed stablecoin through the HKDAP programme, with licensed participants transacting under the regulatory sandbox ahead of a broader rollout.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gBB9ZiWa" target="_self" data-test-app-aware-link="">https://lnkd.in/gBB9ZiWa</a></p>
<p>South Korea&#8217;s Shinhan Bank has tokenised one of its investment funds on Plume&#8217;s blockchain network, becoming one of the first major Korean banks to put a traditional financial product onchain.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gNhN6d5g" target="_self" data-test-app-aware-link="">https://lnkd.in/gNhN6d5g</a></p>
<p>🛡️ INSURANCE SPOTLIGHT<br />
Lloyd&#8217;s Asia held GWP flat at US$1.2bn in 2025 after the prior year&#8217;s 17% surge, but underwriting gains jumped 24% and net profit climbed 10% according to MAS filings, pointing to a deliberate shift toward quality over volume.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gy_-f-gs" target="_self" data-test-app-aware-link="">https://lnkd.in/gy_-f-gs</a></p>
<p><a href="https://www.continuuminsure.com/contact/">Get in touch</a> with Continuum to see how we can help cover your business&#8217; risk.</p>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Deepfake Era of Cyber Crime</title>
		<link>https://www.continuuminsure.com/articles/the-deepfake-era-of-cyber-crime/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Wed, 19 Aug 2026 09:44:22 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[business interruption]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6845</guid>

					<description><![CDATA[A finance employee at Arup received a video call. The person on screen looked like the group CFO. They sounded like the ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/the-deepfake-era-of-cyber-crime/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<div role="feed" aria-label="Chat messages" aria-describedby="_r_68g_" data-find-provider-scope="">
<div data-sizer-excess="0" data-rocksteady-sizer="">
<div data-rs-index="419" data-index="419" data-last-message="true">
<div tabindex="0" role="article" aria-setsize="420" aria-posinset="420" aria-label="Message 420 of 420">
<div data-test-render-count="1">
<div class="group group/message-row">
<div class="group relative relative pb-[var(--msg-assistant-pb,0.75rem)]" data-is-streaming="false">
<div class="font-claude-response relative leading-[1.65rem] [&amp;_pre&gt;div]:bg-bg-000/50 [&amp;_pre&gt;div]:border-0.5 [&amp;_pre&gt;div]:border-border-400 [&amp;_.ignore-pre-bg&gt;div]:bg-transparent [&amp;_.standard-markdown_:is(p,blockquote,h1,h2,h3,h4,h5,h6)]:pl-2 [&amp;_.standard-markdown_:is(p,blockquote,ul,ol,h1,h2,h3,h4,h5,h6)]:pr-8 [&amp;_.progressive-markdown_:is(p,blockquote,h1,h2,h3,h4,h5,h6)]:pl-2 [&amp;_.progressive-markdown_:is(p,blockquote,ul,ol,h1,h2,h3,h4,h5,h6)]:pr-8">
<div class="grid grid-rows-[auto_auto] min-w-0">
<div class="row-start-2 col-start-1 relative grid grid-rows-[auto_auto] isolate min-w-0">
<div class="row-start-1 col-start-1 relative z-[2] min-w-0">
<div class="standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3 [&amp;_&gt;_*:last-child]:mb-0 print:block print:[&amp;_&gt;_*_+_*]:mt-3 standard-markdown">
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr"><div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/08/Aug19Carousel-1.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Aug19Carousel</a></div>
<p dir="ltr"><strong>A finance employee at Arup received a video call. The person on screen looked like the group CFO. They sounded like the CFO. They gave wire transfer instructions. The employee authorized 15 transfers in a single day. US$25 million moved before anyone realized the CFO on the call was artificial. <a href="https://www.theguardian.com/technology/article/2024/may/17/uk-engineering-arup-deepfake-scam-hong-kong-ai-video">This attack—one video call, one fabricated executive, one devastating loss</a>—represents a fundamental shift in how cyber crime works.</strong></p>
<h3 dir="ltr">The Attack Looked Real Because It Was AI-Generated</h3>
<p dir="ltr">The attacker didn&#8217;t hack the video conferencing system. They didn&#8217;t compromise Arup&#8217;s network. They generated a deepfake video of the CFO using AI tools. The audio was synthesized to match the CFO&#8217;s voice. When the finance employee answered the call, they saw what appeared to be their actual CFO authorizing wire transfers.</p>
<p dir="ltr">There was nothing obviously artificial about the call. The video quality was high. The audio was natural. The instructions were credible because they came from someone who looked and sounded like the person authorized to give them.</p>
<p dir="ltr">This is the first shift: deepfakes are now indistinguishable from reality. An employee can&#8217;t tell the difference between a real CFO and a fabricated one. The attacker doesn&#8217;t need to compromise systems. They just need a convincing video.</p>
<h3 dir="ltr">Multi-Participant Deepfakes Make The Attack More Convincing</h3>
<p dir="ltr">Single deepfake calls are suspicious. One person on a video call authorizing unusual transactions might trigger questions. But what if the call included multiple executives? What if the CFO was joined by the COO and the board chairman, all deepfaked, all confirming the wire transfer?</p>
<p dir="ltr">Attackers are now creating multi-participant deepfake meetings where multiple fabricated executives appear on the same call, creating false consensus. An employee seeing three deepfaked executives all agreeing on a wire transfer is far less likely to question the request.</p>
<p dir="ltr">The attack escalates from &#8220;one suspicious call&#8221; to &#8220;multiple executives confirming the same instruction.&#8221; The psychology shifts from skepticism to compliance.</p>
<h3 dir="ltr">Before The Deepfake Call Comes Personalized Phishing</h3>
<div role="feed" aria-label="Chat messages" aria-describedby="_r_lp_">
<div tabindex="0" role="article" aria-setsize="490" aria-posinset="490" aria-label="Message 490 of 490">
<p dir="ltr">The deepfake video call didn&#8217;t happen in isolation. Before it occurred, the target received personalized phishing emails. These weren&#8217;t generic messages. They referenced the employee&#8217;s actual role, their actual manager, and actual company details.</p>
<p dir="ltr">An AI tool had already profiled the organization and identified the finance employee as the target. It generated phishing emails specifically designed to make that employee trust subsequent communications. By the time the deepfake call arrived, the employee had already been primed to expect contact about wire transfers.</p>
<p dir="ltr">Traditional phishing sends the same message to thousands of people. AI-generated phishing creates thousands of unique messages, each tailored to a specific person. The volume and personalization exceed what human awareness training can address.</p>
<h3 dir="ltr">The Attacker Already Knows Your Infrastructure</h3>
<p dir="ltr">Before executing the attack, the attacker needs intelligence. Who is the CFO? What is their authority level? Who reports to them? What is the company&#8217;s wire transfer process? What are the approval thresholds? Which financial institutions does the company use?</p>
<p dir="ltr">This reconnaissance used to take weeks of manual work. AI reconnaissance tools now answer these questions in hours. They scan your website, LinkedIn profiles, org charts, SEC filings, and banking information. They build a complete picture of your company&#8217;s structure, decision-making authority, and financial flows.</p>
<p dir="ltr">The reconnaissance happens invisibly. There&#8217;s no alert when an AI tool profiles your infrastructure. By the time you&#8217;re aware of the threat, the attacker has already completed their homework and moved to execution.</p>
<p dir="ltr"><strong>Where Does This Loss Actually Land?</strong></p>
<p dir="ltr">The Arup deepfake attack resulted in a $25 million voluntary wire transfer. It&#8217;s not a data breach. It&#8217;s not malware or ransomware. It&#8217;s not employee theft or embezzlement.</p>
<p dir="ltr">So which insurance policy responds?</p>
<p dir="ltr">That&#8217;s the question organizations need to answer before the next deepfake attack occurs. The answer isn&#8217;t straightforward. And that gap between the threat and the coverage is where organizations absorb losses they shouldn&#8217;t have to.</p>
<p dir="ltr">Before deepfakes hit your organization, review your policies and understand what&#8217;s actually covered. Continuum helps organizations map deepfake risk across their insurance portfolio.</p>
<p dir="ltr"><a href="https://www.continuuminsure.com/contact/">Contact Continuum</a> to understand your coverage when deepfakes occur.</p>
<p dir="ltr">
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Weekly Risk Update August 14, 2026</title>
		<link>https://www.continuuminsure.com/news/weekly-risk-update-august-14-2026/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Fri, 14 Aug 2026 06:05:41 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Crime Insurance]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<category><![CDATA[FinTech]]></category>
		<category><![CDATA[Tech PI Inc Cyber]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6866</guid>

					<description><![CDATA[Welcome back to Continuum Risk Update. Every Friday we pull the top Asia headlines on digital-asset regulation, cyber risk, industry moves and ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/news/weekly-risk-update-august-14-2026/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<div class="row-start-1 col-start-1 min-w-0">
<div class="min-w-0 pl-2 py-1.5">
<div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/08/Aug14WeeklyRiskUpdate.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Aug14WeeklyRiskUpdate</a></div>
<p>Welcome back to Continuum Risk Update. Every Friday we pull the top Asia headlines on digital-asset regulation, cyber risk, industry moves and insurance signals, with concise takeaways and practical actions for insurers and corporate risk teams.</p>
<p>🏛️ Regulatory<br />
South Korea sentenced the CEO of crypto lender Delio to 15 years in prison for embezzling $50M in digital assets from over 1,100 customers. One of the harshest enforcement outcomes the country has handed down for crypto fraud.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gWwAZcvf" target="_self" data-test-app-aware-link="">https://lnkd.in/gWwAZcvf</a></p>
<p>🔓 Hacking &amp; Physical Risks<br />
Trezor warned 14,000 customers that their shipping addresses were exposed in a breach at a third-party fulfilment partner, the first time physical customer data has leaked from the hardware wallet maker.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/giVXChX8" target="_self" data-test-app-aware-link="">https://lnkd.in/giVXChX8</a></p>
<p>Japan&#8217;s FSA and National Police Agency jointly asked crypto exchanges to impose withdrawal delays and require pre-registration of withdrawal addresses, citing a sharp rise in losses from sophisticated scams.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gj8FFjgR" target="_self" data-test-app-aware-link="">https://lnkd.in/gj8FFjgR</a></p>
<p>📈 Industry &amp; Markets<br />
MUFG is preparing to test real-time blockchain settlement for Japanese government bond trades using the Canton network, a significant step toward tokenised sovereign debt infrastructure in Asia.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/ghW9Vdre" target="_self" data-test-app-aware-link="">https://lnkd.in/ghW9Vdre</a></p>
<p>MSCI&#8217;s new proposal would exclude companies like Japan&#8217;s Metaplanet from major stock indices on the grounds that holding crypto as a primary asset with no core operating business does not meet index criteria.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gfqxMe3K" target="_self" data-test-app-aware-link="">https://lnkd.in/gfqxMe3K</a></p>
<p>🔎 Insurance Spotlight<br />
Tether completed its first-ever Big Four audit, with KPMG signing off on the reserves backing $180B in USDT. For institutions and platforms with significant stablecoin exposure, a verified reserve audit changes the risk picture.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/gnRWKBRJ" target="_self" data-test-app-aware-link="">https://lnkd.in/gnRWKBRJ</a></p>
<p>MSIG Thailand has appointed its first dedicated cyber insurance manager, signalling growing demand for specialist cyber cover across Southeast Asia&#8217;s mid-market.<br />
<a class="uNTKIXSVhTqFErRXENtjrKtJWDUMLqCWM " tabindex="0" href="https://lnkd.in/g6qRpC7S" target="_self" data-test-app-aware-link="">https://lnkd.in/g6qRpC7S</a></p>
<p><a href="https://www.continuuminsure.com/contact/">Get in touch</a> with Continuum to see how we can help cover your business&#8217; risk.</p>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>What Would Two Weeks Offline Cost Your Business?</title>
		<link>https://www.continuuminsure.com/articles/what-would-two-weeks-offline-cost-your-business/</link>
		
		<dc:creator><![CDATA[Continuum Editor]]></dc:creator>
		<pubDate>Thu, 13 Aug 2026 02:57:50 +0000</pubDate>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[business interruption]]></category>
		<category><![CDATA[Cyber Insurance]]></category>
		<guid isPermaLink="false">https://www.continuuminsure.com/?p=6831</guid>

					<description><![CDATA[When a board asks &#8220;what would a cyber event cost us?&#8221; they&#8217;re asking the wrong question. The real loss in a ransomware ... <p><a class="btn btn-secondary understrap-read-more-link vc_general vc_btn3 vc_btn3-size-md vc_btn3-color-success" href="https://www.continuuminsure.com/articles/what-would-two-weeks-offline-cost-your-business/">Read More</a></p>]]></description>
										<content:encoded><![CDATA[<div role="feed" aria-label="Chat messages" aria-describedby="_r_68g_" data-find-provider-scope="">
<div data-sizer-excess="0" data-rocksteady-sizer="">
<div data-rs-index="419" data-index="419" data-last-message="true">
<div tabindex="0" role="article" aria-setsize="420" aria-posinset="420" aria-label="Message 420 of 420">
<div data-test-render-count="1">
<div class="group group/message-row">
<div class="group relative relative pb-[var(--msg-assistant-pb,0.75rem)]" data-is-streaming="false">
<div class="font-claude-response relative leading-[1.65rem] [&amp;_pre&gt;div]:bg-bg-000/50 [&amp;_pre&gt;div]:border-0.5 [&amp;_pre&gt;div]:border-border-400 [&amp;_.ignore-pre-bg&gt;div]:bg-transparent [&amp;_.standard-markdown_:is(p,blockquote,h1,h2,h3,h4,h5,h6)]:pl-2 [&amp;_.standard-markdown_:is(p,blockquote,ul,ol,h1,h2,h3,h4,h5,h6)]:pr-8 [&amp;_.progressive-markdown_:is(p,blockquote,h1,h2,h3,h4,h5,h6)]:pl-2 [&amp;_.progressive-markdown_:is(p,blockquote,ul,ol,h1,h2,h3,h4,h5,h6)]:pr-8">
<div class="grid grid-rows-[auto_auto] min-w-0">
<div class="row-start-2 col-start-1 relative grid grid-rows-[auto_auto] isolate min-w-0">
<div class="row-start-1 col-start-1 relative z-[2] min-w-0">
<div class="standard-markdown grid-cols-1 grid [&amp;_&gt;_*]:min-w-0 gap-3 [&amp;_&gt;_*:last-child]:mb-0 print:block print:[&amp;_&gt;_*_+_*]:mt-3 standard-markdown">
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr"><div class="wp-block-pdfemb-pdf-embedder-viewer"><a href="https://www.continuuminsure.com/wp-content/uploads/2026/08/Aug12Carousel.pdf" class="pdfemb-viewer" style="" data-width="max" data-height="max" data-toolbar="bottom" data-toolbar-fixed="off">Aug12Carousel</a></div>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">When a board asks &#8220;what would a cyber event cost us?&#8221; they&#8217;re asking the wrong question. The real loss in a ransomware event isn&#8217;t the data breach—it&#8217;s the business interruption that follows. Most cyber insurance policies were built for data breach scenarios, which means most boards are radically underinsured for their actual exposure.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">How Cyber Insurance Has Been Sized Wrong</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Cyber insurance evolved to address data breach liability and regulatory exposure. Both are quantifiable. A breach of 1 million records triggers notification costs, <a class="underline underline underline-offset-2 decoration-1 decoration-current/40 hover:decoration-current focus:decoration-current" href="https://gdpr-info.eu/">GDPR-mandated regulatory fines</a>, and customer litigation. You can model it. You can price it. You can buy a cyber insurance policy around it.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Business interruption is harder to quantify. It depends on your revenue model, your system architecture, your incident response speed, and factors outside your control like customer behavior during recovery. So boards sidestep the question. They size cyber insurance based on data breach scenarios and regulatory exposure, not on what systems actually cost when they stay down.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">This worked when most cyber losses were breach-related. It doesn&#8217;t work anymore.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">Why Cyber Insurance Misses Business Interruption Losses</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">The ransomware event of 2020-2026 changed what cyber actually costs. Attackers don&#8217;t care about your data. They care about your operations. Lock your systems. Demand payment. You lose revenue while systems are offline. The longer the outage, the higher the loss.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">For a SaaS platform losing $500,000 daily, two weeks offline is a $7 million revenue hole. For a retail business, two weeks is bankruptcy. For a supply chain company, two weeks is customer contracts voided and market share permanently lost.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">This loss dwarfs the data breach indemnity. But most cyber policies are sized assuming the data breach is the primary loss driver.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">Contingent Cyber Insurance Gaps Most Boards Ignore</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Ask your board: &#8220;What would a two-week outage cost this business?&#8221;</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Most boards can&#8217;t answer. They know the data they hold. They can estimate regulatory exposure. But they can&#8217;t model lost revenue, operational costs that don&#8217;t stop, contractual penalties, and customer churn in the weeks after recovery.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">This gap between known exposure and unknown exposure is where underinsurance lives.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">Business Interruption Is Sub-Limited, Often Below Real Exposure</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Most cyber policies include business interruption coverage. But it&#8217;s often sub-limited well below the main aggregate. A $10 million cyber policy might include only $2 million in business interruption coverage. That $2 million covers a 4-day outage, not a 2-week outage.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Contingent business interruption—coverage for when your suppliers or vendors go down—is sub-limited even more aggressively. You depend on three critical vendors. One gets ransomware-attacked. Your operations stall. Your contingent business interruption sub-limit covers 10% of your actual exposure.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Boards rarely review these sub-limits. They see the main aggregate and assume they&#8217;re covered.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">Reputational Harm Shows Up In Following Quarters</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">A public cyber event triggers customer churn immediately. But the full reputational cost extends across the following two to four quarters. Customers leave. New customer acquisition costs spike. Market share shifts. The revenue impact compounds.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Most cyber policies focus on the incident window. Coverage for notification costs, forensics, legal counsel, and ransom negotiation. But coverage for the 12-month revenue recovery that follows is absent or minimal.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Boards rarely budget for reputational recovery. They assume revenue bounces back the day systems recover. It doesn&#8217;t.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">The Right Tower Reflects Operational Continuity, Not Just Compliance</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">A properly sized cyber tower reflects the scenario most likely to occur: a multi-week operational outage triggered by ransomware, followed by months of customer recovery and regulator investigation.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">This tower includes:<br />
Business interruption coverage sufficient for a multi-week outage across all revenue channels. Contingent business interruption coverage for suppliers and vendors. Reputational harm and customer churn coverage. Extended regulator investigation costs. Crisis communication and recovery support.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Most towers include fragments of this. Few boards have modelled the full scenario.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">Why This Matters Now</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Cyber events are no longer rare. They&#8217;re becoming routine. And they&#8217;re no longer small. A one-week outage for a mid-market business is a $10+ million loss. Most cyber policies have a $2-5 million indemnity limit.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">The gap between actual exposure and insured exposure is widening, not shrinking.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">The Board Conversation That Needs To Happen</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Before renewing cyber insurance, boards should have this conversation:</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr"><strong>First, model the outage scenario.</strong> What would a two-week outage cost across all dimensions: lost revenue, operational costs, penalties, customer churn, and regulator investigation?</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr"><strong>Second, review your cyber tower against this model.</strong> Is your business interruption coverage sufficient? Are your sub-limits adequate? Do you have coverage for contingent business interruption? For reputational recovery?</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr"><strong>Third, close the gap.</strong> Either increase your cyber cover to match your actual exposure, or accept the underinsurance risk explicitly.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Most boards skip this conversation. They renew their policy year after year without modelling what they&#8217;re actually exposed to.</p>
<h3 class="mt-3 -mb-1 text-[1.125rem] font-bold" dir="ltr">Understanding Your Actual Cyber Exposure</h3>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Cyber insurance sizing should follow operational reality, not historical precedent. The dominant loss today is business interruption. Your tower should reflect that.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Continuum helps boards model the multi-week outage scenario and size cyber cover accordingly. We review your current tower, identify the gaps between your actual exposure and your insured exposure, and rebuild your cover around what a true operational continuity event would cost.</p>
<p class="font-claude-response-body break-words whitespace-normal" dir="ltr">Before the next ransomware event locks your systems, know what that outage would cost. <a class="underline underline underline-offset-2 decoration-1 decoration-current/40 hover:decoration-current focus:decoration-current" href="#">Contact Continuum</a> to model your cyber exposure and size your cover correctly.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Minified using Disk
Database Caching 40/53 queries in 0.054 seconds using Disk

Served from: www.continuuminsure.com @ 2026-09-09 17:18:16 by W3 Total Cache
-->