Data Center Cyber Risks Outpace Standard Insurance Policies

Data Center Cyber Risks Outpace Standard Insurance Policies

Karen Kutger stands at the forefront of the high-stakes world of cyber insurance as the wholesale production leader for management, professional, and cyber at Novatae Risk Group. With a career dedicated to dissecting the complexities of digital liability, she has become an essential bridge between data center operators and the wary eyes of global underwriters. As data centers evolve into the backbone of the global economy, Kutger provides a masterclass on how to navigate a landscape where a single security oversight can lead to staggering financial losses or even catastrophic systemic failure.

Our discussion navigates the turbulent waters of modern cyber threats, beginning with the sharp rise in ransomware costs and the specific vulnerabilities of massive data repositories. We examine the critical importance of rigorous security controls—such as multi-factor authentication and endpoint detection—and how these technical details directly influence insurance premiums. Furthermore, we address the “silent” gaps in existing policy language regarding artificial intelligence and the evolving nature of state-sponsored attacks, offering a strategic look at how brokers can better protect their clients in an increasingly hostile digital environment.

With the average cost of ransomware attacks jumping 17% in just the first half of 2025, how are you seeing the risk profile of data centers shift from a standard liability to a potential catastrophic event?

The reality is that data centers are no longer just storage facilities; they have become the central nervous system of global commerce, which makes them the ultimate prize for bad actors. When we look at these accounts, we aren’t just talking about a few leaked records; we are staring down the barrel of a catastrophic risk involving billions or even trillions of data points. A single successful breach doesn’t just halt operations for one company—it triggers a cascading business interruption that can paralyze entire supply chains and multiple industries simultaneously. This concentration of risk is why we see underwriters becoming much more surgical in their assessments, moving away from broad assumptions to a granular focus on how a facility handles that massive exposure. It’s a high-pressure environment where the sheer scale of the potential loss means there is absolutely no room for error in the security narrative.

State-sponsored attacks are becoming a primary concern for high-value infrastructure. How should brokers be framing this specific threat when discussing coverage and risk management with their data center clients?

It is no longer a matter of if a large data center will be targeted by a nation-state, but when, and brokers need to be incredibly direct about that inevitability. We tell our clients that these facilities will almost certainly be a target for state-sponsored attacks because of the strategic value the data holds. When framing the conversation, it’s vital to move beyond the idea of a “standard outage” and focus on the necessity of dependent business interruption coverage that is broad enough to handle truly catastrophic events. We spend a significant amount of time reviewing policy wording to ensure that if a sophisticated actor takes down a facility, the definition of dependent exposure actually captures the real-world cascading risk. Brokers who fail to raise these state-sponsored threat vectors directly with their clients are leaving them dangerously exposed to gaps that standard policies might not fill.

You’ve noted that security controls can cause a 35% variation in premiums between similar facilities. What are the most common technical “friction points” that lead to these higher costs or even a total refusal of coverage?

The difference between a well-prepared submission and a poor one is immediately visible in the premium, often swinging as much as 35% for comparable facilities. Underwriters are looking for total consistency in enforcement, yet we still see glaring issues with inconsistent multi-factor authentication (MFA) and gaps in EDR or MDR implementation. One of the most frustrating friction points is when an IT team implements MFA for the general workforce but leaves the administrator portals exposed, which is like locking the front door but leaving the vault wide open. Carriers are also looking for encrypted backups that are completely disconnected from the network to prevent them from being wiped during an attack. When a broker can surface and fix these gaps before the submission hits the underwriter’s desk, they are in a much stronger position to negotiate a favorable outcome for the client.

In an era where carriers run their own external scans before even looking at an application, how can data centers ensure their “digital footprint” matches the security narrative they present on paper?

The days of simply “checking the box” on an insurance application are long gone because carriers are now performing their own reconnaissance through external scans. If a client claims to have a fortress-like environment but the scan reveals open remote access ports, it creates immediate and often irreparable friction during the underwriting process. We tell our clients that their digital reality must match their documentation, as any discrepancy makes the underwriter lose confidence in the entire management team. These scans act as a sort of “truth serum” for the submission, highlighting vulnerabilities that the client’s internal IT team might have overlooked or deemed unimportant. To avoid these pitfalls, facilities must proactively manage their external-facing assets and ensure that every remote entry point is either strictly guarded or completely shuttered before the carrier ever takes a look.

Many current cyber policies are “silent” on emerging technologies like AI, pixel tracking, and biometrics. Why is this silence so dangerous for data center accounts, and what should brokers be demanding in updated policy language?

Silence in a policy is not a protection; it is a massive question mark that usually ends in a coverage dispute once a claim is filed. As AI and operational technology expand the attack surface, we are actively looking for policies that specifically address AI security issues rather than just ignoring them. We want to see explicit coverage for general AI output concerns, including things like accuracy, bias, performance failures, and the increasingly common phenomenon of hallucinations. Beyond that, the gaps extend into newer vectors like deepfakes, pixel tracking, and biometric claims, all of which are becoming central to data center operations. For a broker, the goal should be to eliminate that silence and replace it with concrete language that acknowledges these risks, ensuring the client isn’t left holding the bag for a modern threat that the policy forgot to mention.

What is your forecast for the future of data center cyber insurance?

I expect the market to move toward an even more rigorous, data-driven underwriting model where continuous monitoring replaces the annual application process. As the 17% rise in ransomware costs shows no signs of slowing, carriers will likely demand real-time visibility into a facility’s security posture to justify offering high limits of coverage. We will also see a major push for standardized language around AI and biometric liability, as the current “silence” in many forms becomes untenable for both the insured and the insurer. Ultimately, data centers that can demonstrate hyper-consistent controls and a transparent relationship with their carriers will thrive, while those with legacy gaps or poor documentation will find themselves increasingly uninsurable in a landscape that no longer tolerates “good enough” security.

Subscribe to our weekly news digest.

Join now and become a part of our fast-growing community.

Invalid Email Address
Thanks for Subscribing!
We'll be sending you our best soon!
Something went wrong, please try again later