US round-up for August
18th August 2026Updates and highlights from our US cyber experts
Increasing our market presence
Cybersecurity leaders are facing a new challenge: information overload.
Every week brings another breach headline, emerging threat, or security product promising to eliminate cyber risk. As a result, many organizations are looking for trusted advisors who can cut through the noise and help connect cybersecurity decisions to business outcomes.
This creates a significant opportunity for both brokers and carriers. Increasingly, clients value conversations about resilience, preparedness, and measurable risk improvement as much as discussions around limits and coverage terms. Industry research continues to show that ransomware, credential theft, and third-party risk remain among the most common drivers of cyber incidents, reinforcing the need for practical risk guidance rather than technical jargon.
The cyber insurance market is also evolving. Leading insurers are increasingly positioning themselves as risk management partners by sharing claims insights, underwriting expertise, and cybersecurity best practices that help clients strengthen their overall resilience posture.
Phishing-resistant MFA: The next evolution of identity security
For years, cyber insurance applications included a simple question: "Do you use multi-factor authentication (MFA)?"
Today, that question is becoming more nuanced.
Recent attacks have demonstrated that traditional MFA methods, including SMS codes, push notifications, and some authenticator-based approaches, can still be compromised through advanced phishing techniques and adversary-in-the-middle attacks. In response, CISA and federal cybersecurity agencies have increasingly advocated for phishing-resistant authentication methods such as FIDO2 security keys, passkeys, and WebAuthn-based solutions.
The discussion is no longer simply whether MFA is deployed, but whether it can withstand modern attack techniques.
That shift is particularly relevant for larger and more sophisticated organizations, where attackers continue to target user credentials as a pathway to broader network compromise. The organizations making the greatest investments in identity security are increasingly prioritizing phishing-resistant authentication as part of their long-term cyber strategy.
Healthcare: A sector under continued cyber pressure
Healthcare remains one of the most closely watched industries in cyber insurance.
Healthcare organizations are a culmination of extremely sensitive data, mission-critical operations, and often complex technology ecosystems. In this environment, cyber events can quickly become operational events, impacting patient care, revenue cycles, and day-to-day service delivery.
Few incidents illustrated this more clearly than the Change Healthcare ransomware attack. Reuters reported widespread financial and operational disruption across healthcare organizations, while the American Hospital Association described the incident as one of the most significant healthcare cyber events in recent history. The disruption affected claims processing, payments, pharmacy services, and provider operations across the United States, highlighting the systemic risk that can emerge when a critical third-party provider experiences a cyber event.Trium's CEO, Josh Ladeau, recently published a paper on the hidden weakness in third-party cyber risk transfer.
The event fundamentally changed how many insurers, brokers, and risk managers think about vendor concentration and third-party dependencies.
Healthcare's challenges also reflect a broader reality across many industries: cyber risk is increasingly interconnected. A disruption at a single vendor can have cascading effects throughout an entire ecosystem.
Efficiency without sacrificing expertise
Technology continues to transform the underwriting process, but the goal is not simply to move faster.
Across the industry, underwriters are increasingly leveraging automation, AI-assisted analysis, external intelligence, and integrated data sources to eliminate repetitive administrative work and devote more time to evaluating risk. The broader trend reflects an understanding that technology can enhance expertise but not replace it.
This is especially true in cyber insurance, where threat actors, attack techniques, and exposure profiles change constantly. Speed matters, but informed decision-making matters more.
For brokers, the benefit is a more efficient experience, faster response times, and underwriting conversations that focus on what truly matters.
Closing thoughts
Cyber insurance continues to evolve beyond a traditional risk transfer product.
Whether the discussion centers on phishing-resistant authentication, healthcare resilience, third-party dependencies, underwriting discipline, or operational efficiency, the common theme is preparedness.
Organizations that invest in cybersecurity maturity, understand their evolving exposures, and engage proactively with their insurance partners will be better positioned to navigate today's threat landscape.
As always, we'd welcome your perspective. What cyber risk trends are generating the most client discussions in your market today?
