Interest in cyber insurance has started to grow as Sri Lankan businesses become more dependent on digital systems and face tighter requirements around data protection. The market is still relatively small compared to more developed markets, including those in Asia such as Singapore and India.
While banks and other regulated financial institutions account for the main buyers, demand is also emerging from businesses serving international clients, with the scope of cyber insurance moving beyond financial compensation to risk management services.
In an interview with The Sunday Morning Business, George Steuart Insurance Brokers Director Dharini Fernando discussed the changing demand for cyber insurance in Sri Lanka, the risks that traditional insurance policies did not cover, and the factors insurers and reinsurers considered when assessing cyber risks.
She also spoke about the growing range of cyber insurance products available internationally and the need for more accessible products for smaller businesses in the future.
Following are excerpts:
How has demand for cyber insurance changed in Sri Lanka over the past few years and where does Sri Lanka stand when compared to global markets?
Demand has been sporadic, but interest has grown noticeably over the last two years. I can trace the earliest enquiries, mostly from banks, back to 2017 when the WannaCry and NotPetya attacks made global headlines and a handful of local banks and large corporates were concerned about cyberattacks and emanating losses.
It’s still coming off a very low base, though, and purchasing is still driven by specific triggers than by broad market maturity, such as a foreign principal making cover a condition of contract, a board director making enquiries about the product, an actual incident making media headlines, and, now increasingly, the tightening compliance environment around data protection.
On scale, Sri Lanka is a tiny market in the global context for insurance. Internationally, cyber insurance premiums reached an estimated $ 15.6 billion in 2025 (Swiss Re), with North America alone accounting for roughly two-thirds of that, and the whole of the Asia-Pacific (APAC) including India, Japan, Australia, China, and everyone else in the APAC combined at only around 8–10% and Europe at about 20%.
Sri Lanka’s share of that regional figure is a small fraction, effectively negligible in global terms. There isn’t yet a reliable, independently audited figure for Sri Lanka’s standalone cyber premium pool. The major rating agencies and reinsurers who publish country-level breakdowns generally start doing so only once a market crosses a certain premium threshold, and Sri Lanka hasn’t reached that point yet.
What we can discuss with more confidence is the trajectory. Even in mature markets like the US and the UK, where cyber insurance has existed for two decades, only 10–20% of Small and Medium-sized Enterprises (SMEs) actually carry cover (Swiss Re). Sri Lanka’s penetration is insignificant by comparison. But as the local economy digitalises and regulation tightens around it, demand for cyber insurance is poised to increase.
Which sectors are buying most actively, where are the biggest gaps, and is purchasing incident-driven or strategic?
Banks and other regulated financial institutions lead, largely because they operate under formal risk management regulations, and cyber insurance is rightly seen as one tool to mitigate the losses an attack can cause. Larger BPO/IT firms serving foreign clients and a handful of big conglomerates follow, often because a foreign customer’s procurement contract specifically requires evidence of cyber cover.
The gaps are wide, considering that there are various data protection regimes such as General Data Protection Regulation (GDPR) in place. Hospitality and tourism handle large volumes of foreign payment cards and passports – data that is classified as Personally Identifiable Information (PII).
Along with healthcare, education, and public and Government institutions, businesses now operating in the digital economy remain significantly exposed relative to their actual and growing risk exposures, now exacerbated by Artificial Intelligence (AI)-enabled tools.
On the incident-driven versus strategic question, honestly, it’s still mostly the former. Outside of a handful of institutions, interest in the product isn’t yet coming from ground-up risk assessment or a genuine risk management mindset. That said, in recent months I have seen early signs that this is starting to shift, slowly.
What cyber-related risks do businesses commonly assume are covered by their traditional insurance but aren’t?
There are two consequential misunderstandings I run into most often about insurance coverage.
First, a standard fire and burglary or property policy responds to physical loss or damage; a server destroyed in a fire is covered, but that same server’s data being encrypted by ransomware, with no physical damage at all, is not covered by traditional insurance policies.
A general liability policy typically won’t respond to a data breach claim from a third party either. And crime or fidelity policies, which do cover employee dishonesty and theft, are often narrower than people assume.
When a loss involves an external fraudster impersonating a supplier or executive by email, coverage can depend heavily on the precise mechanics of how the money left the business, which is exactly the kind of detail that gets fought over at claim time.
Since 2020, the Lloyd’s market and most major insurers globally have required non-cyber policies to explicitly state whether cyber-related losses are included or excluded, precisely because so much ‘silent’ cyber exposure had crept unintentionally into traditional wordings with potential legal ramifications.
The second related misunderstanding is that when a business does buy a cyber policy, there is a common assumption that it automatically covers social engineering or imposter fraud types of losses. It doesn’t, by default.
What a better cyber insurance policy might include is 24/7 incident response and triage services (access to digital forensics, breach lawyers, PR/crisis communications, and relevant support for ransomware situations among other services); business interruption cover or loss of income, cyber extortion, and privacy and security breach liability; and depending on the risk carrier (reinsurer), various risk management and loss prevention services and other additional benefits/covers such as media liability, data restoration, bricking, third-party service provider failure, and system failure, among others. Insurance cover for social engineering fraud, if available, is usually a separate negotiation.
Understanding the mechanics of a cyber insurance policy is a discussion by itself. It’s important for buyers to understand exactly how their product works, since each international risk carrier offers its own variation of the generic template.
What are the most common misconceptions you come across?
In roughly the order I hear them, the first one is that it’s too expensive. In context, it’s a modest price to pay against an unexpected shock to the balance sheet. And if a company’s security posture and hygiene aren’t up to baseline standards, it’s very likely a carrier will decline to cover altogether, or, at best, offer terms that are considerably more expensive.
It is important to clearly note that a cyber insurance policy is neither a cyber security tool nor a defence mechanism. A cyber insurance policy, like any other insurance policy, provides financial compensation resulting from an unexpected loss to the organisation as per a defined scope.
Secondly, many businesses believe they are too small to be a target. However, attackers increasingly favour smaller businesses precisely because their defences are weaker and there is no dedicated security team. With Ransomware-as-a-Service (RaaS) and AI-assisted tooling, most attacks today are largely automated and require no special skill from the attacker; the size of the target is irrelevant. Vulnerability is fair game for attackers.
Some believe a business’s security and antivirus tools are state of the art, therefore well secured and not requiring insurance. While good IT hygiene reduces the chance of an incident, it doesn’t cover the cost of one when it happens. With advances in AI technology, even the latest and the best anti-virus or security tools are not attack-proof.
There is also the misconception that conventional general business insurance covers digital assets, although it is usually not the case. Certain buyers also believe that cyber insurance covers all types of ‘hacking’ attacks. Many buyers are surprised that social engineering and email-based fraud (Business Email Compromise, commonly referred to as BEC) are often excluded or need a separate add-on. One should never assume it’s bundled into the policy without clarifying from the service provider.
Moreover, some believe insurance is just a compliance box-tick for the Data Protection Authority, when it’s balance sheet protection first, and regulatory compliance is a secondary benefit.
What do insurers look at before offering cover, and are Sri Lankan businesses generally meeting those expectations?
Cyber insurance underwriters typically ask about Multi-Factor Authentication (MFA) on email and remote access, regularly tested and offline/immutable backups, a documented patch management process, staff phishing-awareness training, endpoint detection tools, and a written incident response plan, among other things.
Globally, these baseline controls have become ‘must-haves’ rather than ‘nice-to-haves’. Marsh McLennan data shows roughly 41% of cyber insurance applications are declined at first submission, usually because one or more of these controls are missing.
Candidly, many Sri Lankan businesses – SMEs in particular – aren’t meeting that baseline yet. MFA and properly tested backups, which underwriters increasingly treat as non-negotiable, are still inconsistently implemented here. This is the real driver of the ‘cover is hard to get’ perception some businesses report.
Unlike in previous years (especially during the Covid and Aragalaya times) it’s less about reinsurers refusing Sri Lankan risks outright and more about the fact that applicants simply aren’t control-ready yet.
Has the Personal Data Protection Act (PDPA) changed the conversation?
Yes, to a certain extent. Businesses are implementing compliance and insurance frameworks in place ahead of enforcement, rather than scrambling once the penalty provisions do go live (which is likely in early 2027 as reported in the media recently).
How has the local cyber insurance product and market evolved? Is broader or more specialised cover available now than a few years ago?
The local market has been slow to evolve, and in one important aspect, hasn’t evolved much at all. All local insurance operators, including multinational insurers, still don’t underwrite cyber insurance locally in any meaningful sense. It remains almost entirely reinsurer-dependent, probably for several layered reasons.
Globally, over the past two-plus decades, the cyber insurance product itself – its coverage, benefits, and the services bundled around it – have become far more sophisticated, and underwriting protocols have evolved just as fast. International cyber insurers now use technology, including automated, non-invasive external attack-surface scanning and risk scoring, to assess a company’s risk – a marked shift from the older underwriting process of exchanging a multitude of emails back and forth to clarify security matters on lengthy application procedures.
The international reinsurance capacity behind cyber insurance is concentrated among a relatively small group of players – leading global insurers and reinsurers, Lloyd’s of London, and specialist cyber (re)insurers – who supply capacity both through traditional reinsurance structures and via instruments like Insurance-Linked Securities (ILS) and catastrophe bonds, which transfer insurance risks directly to capital market investors, alongside or instead of traditional reinsurance structures.
Because the cyber insurance product is more complex than most traditional insurance products; this segment of the market is heavily dependent on intermediaries – insurance and reinsurance brokers – to bring it to customers.
Cyber insurance products are strategically driven by large global reinsurers on a wholesale rather than retail basis. Brokers bring specialised expertise to the table, helping clients understand the technical fine print of the policy wording that scopes out coverage, terms and conditions, exclusions, and other contractual aspects, whilst also sourcing international quotations through reinsurance market relationships, and comparing products across carriers in a way most buyers – and often insurance companies themselves – can’t do in-house.
For corporate buyers, the product menu today spans breach response and triage services, business interruption, cyber extortion, and privacy and security breach liability, each with its own limits and sub-limits plus specialist risk management services and access to cybersecurity tools at discounted pricing. The exact suite of benefits and services depends on the reinsurer and the pricing threshold involved. Some covers, notably social engineering fraud, still need to be separately negotiated, if available, rather than assumed as standard.
Set against that, the Sri Lankan market is still at an early stage compared with more mature Asian markets like Singapore or India – fewer carriers, far less local claims data to price against, and heavy reliance on London or regional reinsurance capacity to support any large limit meaningfully.
In addition to a payout, what does cyber insurance actually do for a business after an attack?
This is genuinely where the value shows up most; in my opinion, the claim payout is usually the secondary part of the story.
A good global policy gives you immediate access to a panel of vetted specialists, a 24/7 incident response line connecting you to digital forensics experts (to work out what actually happened and contain it), breach lawyers (to manage regulatory notification obligations and legal exposure), PR and crisis communications support (to manage the reputational side, which businesses tend to underestimate most), and practical support for ransomware situations.
Policies also typically cover customer notification and credit monitoring where personal data is affected, and cover the income lost while systems are down. For a business with no in-house cybersecurity team, which may describe most Sri Lankan SMEs, having that expert response network on call and pre-vetted is often more valuable in the first 48 hours than the indemnity itself.
What would you like to see change to make cyber cover more accessible and better understood in Sri Lanka?
There are indeed a few changes I would like to see. Roughly in order of what I think would move the needle most, the first would be published market size data.
There is currently no reliable, published figure for the size of Sri Lanka’s cyber insurance market. The regulator’s website publishes market size data for major classes – motor, health, fire, and marine – but not yet for cyber and several other specialist classes. That absence makes it harder for insurers, brokers, and policymakers alike to gauge the state of the market.
The next is local claims data. Pricing here still leans heavily on international loss data because there’s no meaningful domestic claims history to underwrite against. If more claims are recorded and shared, in aggregate, across insurers, pricing should become more accurate, and over time, more competitive.
Regulatory clarity from the PDPA’s substantive provisions coming into force would also be of importance, so businesses have a firm compliance deadline to plan around rather than an open-ended one (likely in early 2027 as reported recently).
It is also vital to have simpler, SME-sized products. Much of what’s available is still priced and structured for larger corporates; the market needs lighter-weight, lower-friction policies scaled to a small business’s actual risk and budget.
Moreover, continued public awareness campaigns by relevant authorised bodies such as the Sri Lanka Computer Emergency Readiness Team (Sri Lanka CERT), Insurance Regulatory Commission of Sri Lanka (IRCSL), Central Bank of Sri Lanka (CBSL), etc. is essential.
Sri Lanka CERT’s own numbers show numerous cybersecurity and fraud-related complaints reported annually in recent years. Exposure is real and present, and the insurance conversation needs to keep pace with that reality rather than trail behind it.