Picture this: It’s your worst day as a CISO. Ransomware takes down your systems, regulators circle, customers rage, and your insurer refuses to pay. Their reason? A patch was missing for a “known vulnerability” (CVE).
This isn’t just hypothetical. Dark Reading recently reported that insurers are moving toward policies that limit or deny payouts if breaches result from unpatched CVEs. It is the latest lever underwriters are pulling to reduce their own risk exposure, and it could leave enterprises holding the bag at the worst possible moment.
Insurance Is Portfolio Defense, Not Your Defense
We like to think of insurance as a safety net. Pay the premium, and when disaster strikes, you are covered. But that is not how insurers see it.
Underwriters do not think in terms of your crisis. They think in terms of their portfolio. Cyber risk is volatile, actuarial models are shaky, and every high-profile breach rewrites the math. When they see concentrations of risk, they do not hesitate. They carve it out with exclusions.
2022: Ransomware exclusions2023: Supply chain dependencies2025: Patch management (CVE exclusions)
Each wave reflects the same play: protect their balance sheet, not yours.
Dark Reading Reports That Insurers Are Actively Pursuing CVE Exclusions. As John Coletti, Head of Cyber Underwriting at Coalition, Cautions: “While we will not name names, there are specific examples of this occurring within the industry. A company should be highly skeptical of buying a policy with a CVE exclusion.”Dark Reading Reports That Insurers Are Actively Pursuing CVE Exclusions. As John Coletti, Head of Cyber Underwriting at Coalition, Cautions: “While we will not name names, there are specific examples of this occurring within the industry. A company should be highly skeptical of buying a policy with a CVE exclusion.”The New Reality: CVE Exclusions
Dark Reading Reports That Insurers Are Actively Pursuing CVE Exclusions. As John Coletti, Head of Cyber Underwriting at Coalition, Cautions: “While we will not name names, there are specific examples of this occurring within the industry. A company should be highly skeptical of buying a policy with a CVE exclusion.”
Dark Reading Reports That Insurers Are Actively Pursuing CVE Exclusions. As John Coletti, Head of Cyber Underwriting at Coalition, Cautions: “While we will not name names, there are specific examples of this occurring within the industry. A company should be highly skeptical of buying a policy with a CVE exclusion.”
As Dark Reading highlighted, the “known vulnerability” exclusion is gaining traction. If a breach can be tied to an unpatched CVE, the insurer may deny payment.
For underwriters, this is clean:
Discourages sloppy patching
Eliminates a high-frequency loss category
Provides a bright-line reason to reject claims
For enterprises, it is brutal:
Patch velocity is impossible to match in real environments
Legacy or vendor-locked systems stall remediation
Disputes over “reasonable patch windows” will spill into litigation
The bottom line: the risk is not gone. It has simply been handed back to you.
Football Season and the Corporate Sideline
With NFL season underway, let’s use football to explain how cyber risk and leadership really work.
The Board of Directors is the Team Owner. They hold ultimate authority, set vision, and decide if leadership is winning or losing.
The CEO is the Head Coach. They set the overall philosophy and decide how aggressive or conservative the organization will be.
The CFO is the General Manager. They manage the salary cap, allocate resources, and decide how much to spend on both offense and defense.
The CIO is the Offensive Coach. They design the plays that move the business forward: cloud migrations, ERP rollouts, digital innovation. Their goal is to score points, sometimes taking calculated risks.
The CISO is the Defensive Coach. They read the opposing offense, design the schemes to stop attacks, and call adjustments when adversaries change tactics. Their job is to prevent big plays from taking the company down.
Together, they make up the sideline leadership team. If the organization wins, it is because all of them played their part. If it loses, blame cannot fall on the Defensive Coach alone.
What CISOs Must Do Now
Identify the Risk – Map exclusions into tangible exposures. “If CVE-based denial holds, we face $5M in uncovered losses annually.”
Propose Mitigation Paths – Patch acceleration, compensating controls, vendor enforcement, or risk acceptance.
Translate into Dollars – Boards do not buy into “high, medium, low.” Quantify exposures and make the tradeoffs clear.
Assign Responsibility – Ensure business leaders, not just the CISO, own residual exposure.
Negotiate Insurance Like a Contract, Not a Commodity – Work with specialized brokers, push back on exclusions, or walk away.
The Coming Clash
Cyber insurance is no longer the backstop it once was. As Dark Reading noted, insurers are tightening coverage to survive, not to guarantee recovery. Enterprises are paying premiums for coverage that may not exist when it matters most.
Litigation and regulatory scrutiny will eventually force a reset. Until then, CISOs must assume the role of Defensive Coach, ensuring that schemes are well-designed, gaps are clearly understood, and the Head Coach and General Manager are fully aware of the stakes before making a call.
Because the only thing worse than a breach is a breach you thought was covered.
AM Best, US Cyber: Hot Pricing Cools Off, Rapid Growth Stalls (2024)“Cyber remains one of the most volatile segments in the insurance market, with underwriting performance highly sensitive to event-driven losses.”AM Best, US Cyber: Hot Pricing Cools Off, Rapid Growth Stalls (2024)“Cyber remains one of the most volatile segments in the insurance market, with underwriting performance highly sensitive to event-driven losses.”Additional Reading on the Topic:
AM Best, US Cyber: Hot Pricing Cools Off, Rapid Growth Stalls (2024)
“Cyber remains one of the most volatile segments in the insurance market, with underwriting performance highly sensitive to event-driven losses.”
AM Best, US Cyber: Hot Pricing Cools Off, Rapid Growth Stalls (2024)
“Cyber remains one of the most volatile segments in the insurance market, with underwriting performance highly sensitive to event-driven losses.”
Dark Reading — “Cyber Insurers May Limit Payouts for Breaches via Flaws” (Aug 22, 2025)https://www.darkreading.com/cyber-risk/cyber-insurers-may-limit-payments-breaches-unpatched-cve
NAIC — “Cyber Insurance Report” (Oct 15, 2024, PDF)https://content.naic.org/sites/default/files/cmte-h-cyber-wg-2024-cyber-ins-report.pdf
AM Best — “US Cyber: Hot Pricing Cools Off, Rapid Growth Stalls” (June 2024, PDF)https://web.ambest.com/docs/default-source/events/best%27s-marketing-segment-report—us-cyber—hot-pricing-cools-off-rapid-growth-stalls.pdf
Marsh — “Global commercial insurance rates fall 4% in Q2 2025; cyber down 7%” (July 24, 2025)https://www.marsh.com/en/about/media/global-commercial-insurance-rates-fall-4-percent-in-q2-2025.html
Journal of Cybersecurity (Oxford) — Romanosky et al., “Content analysis of cyber insurance policies: how do carriers write them?” (2019, peer-reviewed, PDF)https://academic.oup.com/cybersecurity/article-pdf/doi/10.1093/cybsec/tyz002/27992088/tyz002.pdf
USENIX Security 2023 — Woods et al., “Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach Attorneys” (PDF)https://www.usenix.org/system/files/usenixsecurity23-woods.pdf