
Measuring the cost of a cyberattack for a French company involves comparing two scenarios: one where the business activity halts without financial safety nets, and the other where a cyber insurance policy absorbs part of the shock. Recent data on revenue losses, regulatory requirements related to NIS 2, and new conditions imposed by insurers allow for this comparison to be made on concrete bases.
Cost of a cyberattack and cyber insurance coverage: what the numbers show
| Scenario | Financial impact without insurance | Coverage with cyber insurance |
|---|---|---|
| Revenue loss from the first day of interruption | Fully borne by the company | Compensation for operating losses according to the contract |
| Technical remediation costs (system restoration, forensic) | Charged at high prices urgently, without negotiation | Access to a network of pre-qualified experts by the insurer |
| GDPR notification and crisis management with clients | Legal costs and communication borne by the company | Coverage of notification and legal support costs |
| Ransomware | Dilemma of paying/not paying, without immediate specialized advice | Crisis unit mobilized, structured negotiation, possible compensation |
According to data published by IT Pro, nearly half of French companies lose revenue from the first day of a cyberattack. The gap between the speed of the attack and the slowness of recovery creates a financial chasm that a SME’s cash flow rarely absorbs alone.
Related reading : Best Practices for Effective and Sustainable Management of Municipal Roads
Understanding cyber risk insurance for businesses requires going beyond simple compensation logic. The contract structures the incident response: it provides quick access to technical and legal service providers whose selection, under normal circumstances, takes weeks.

Recommended read : Tips and Tricks for Safely Supporting Baby's First Steps
Cyber insurer requirements in 2026: MFA, backups, and security maturity
The cyber insurance market has changed its logic. Insurers no longer simply price a statistical risk. They now condition underwriting on a verifiable level of cybersecurity maturity.
Three prerequisites consistently appear in underwriting questionnaires:
- Multi-factor authentication (MFA) deployed across all remote access and privileged accounts, with no exceptions for executives or external providers
- Regularly tested backups, with at least one offline or immutable copy, and a documented restoration plan whose recovery time has been verified by a real exercise
- Documented vulnerability management: patches applied within a defined timeframe after release, with traceability of exceptions and end-of-life systems
This tightening has a concrete effect on companies that neglect their IT hygiene. An insurer may refuse coverage or apply exclusions if the level of protection declared at underwriting does not match the reality observed during a claim. The cyber insurance policy thus functions as an implicit ongoing audit.
In just two years, this evolution has transformed the relationship between insurer and insured. Underwriting resembles more of a certification than a simple purchase of coverage.
NIS 2 and risk management obligations: the insurance-prevention trade-off changes
The NIS 2 directive, applicable to so-called “essential” and “important” entities in the European Union, does not make cyber insurance mandatory. However, it imposes risk management and business continuity obligations that are stringent enough to alter the financial trade-off for affected companies.
NIS 2 requires executives to demonstrate active governance of cyber risk, including incident detection, notification to authorities, and the ability to maintain services during a crisis. Non-compliance exposes them to administrative penalties.
In this context, cyber insurance becomes a complementary tool to prevention, not a substitute. It covers the residual risk, the one that persists despite technical and organizational measures. For companies that fall under the NIS 2 scope (energy, transport, health, digital infrastructure, as well as their subcontractors), the question is no longer “should we insure?” but “what level of coverage corresponds to my regulatory obligations?”.
Cyber insurance and the subcontracting chain: an increasing contractual requirement
One angle rarely addressed in discussions about cyber insurance concerns the pressure exerted by clients on their suppliers. In sectors such as aerospace, defense, or pharmaceuticals, some contracts now require subcontractors to hold cyber insurance as a condition for being listed.
The logic is simple: an attack on a weak link in the supply chain can paralyze the entire client. Large groups, already covered, pass this requirement onto their partners to reduce their own exposure. An industrial SME supplying components to a defense player may lose a contract for not having a valid cyber policy.
This dynamic creates a domino effect. Cyber insurance becomes a commercial selection criterion, on par with quality certification or financial audits. Companies that do not anticipate this trend risk losing contracts even before experiencing an attack.

Generative AI and new attack vectors: a rapidly expanding risk
Competing content describes classic threats (ransomware, phishing, malware). A recent evolution deserves particular attention: the use of generative AI as an attack vector against SMEs.
According to Kaspersky, malware attacks impersonating “mainstream” AI tools have increased fivefold in early 2026. Employees download what they believe to be a free AI assistant and actually install malware. This type of attack exploits curiosity and lack of training, two human vulnerabilities against which traditional firewalls are powerless.
For insurers, this multiplication of attack vectors complicates risk modeling. For companies, it reinforces the need for coverage that does not limit itself to known scenarios. A recent cyber insurance contract generally includes incidents related to social engineering, including those facilitated by diverted AI tools.
The cyber protection market is evolving along two simultaneous axes: more sophisticated attacks on one side, stricter coverage conditions on the other. Companies that treat cybersecurity and insurance as two separate subjects expose themselves to discovering, at the time of a claim, that neither is sufficient in isolation.