For years, the cyber insurance conversation has been heavily focused on security controls. Do you have MFA? Are you using EDR? Are your backups protected? Are you patching vulnerabilities? Those questions made sense because insurers were trying to understand how likely it was that someone could get into the environment and cause damage. The problem is that having good security controls has never meant the business is going to be able to keep operating when something actually goes wrong.

A new Risk & Insurance article with MSIG USA caught my attention because it suggests the underwriting conversation is starting to move beyond that. Ryan Kratz, MSIG’s Head of Cyber for North America, talks about insurers putting more emphasis on what happens after something gets through. They want to understand how the company will respond and whether it can actually recover. That may sound like a small change in underwriting, but I think it reflects a much bigger change in how we need to think about cyber risk.

Businesses have spent years investing in prevention while becoming increasingly dependent on technology at the same time. Most companies now rely on a collection of cloud platforms, software providers, managed services and outside partners just to get through a normal business day. AI is being added into that environment incredibly quickly, often becoming part of normal business processes before anyone has really thought through what happens if it becomes unavailable or starts producing results the business can no longer trust.

One of the more interesting comments in the MSIG article is that nearly every cyber event they see today has some type of third-party component. That could be an IT provider, cloud platform or another company the business depends on. I think that gets much closer to the real problem. A company can have perfectly reasonable security and still find itself unable to operate because something outside its control has failed.

This is where the traditional cybersecurity conversation starts to run out of answers. Security can reduce the chance that something happens inside your environment, but it can't eliminate the dependencies that modern businesses have built around themselves. You may have excellent endpoint security and strong authentication, but none of that helps very much when the platform your employees need to do their jobs is unavailable because somebody else's environment was compromised.

The same problem exists with insurance. Cyber insurance can be incredibly valuable when something goes wrong. It can help absorb financial losses and provide access to resources the company may desperately need during an incident. What it can't do is operate the business for you while the claim is being handled. Getting reimbursed for a loss and being able to continue serving customers during the disruption are two very different things.

That difference is where business survivability becomes important. The question isn't whether the company has enough security or whether it bought enough insurance. The question is what actually happens to the business when a critical system or provider suddenly isn't there anymore. If an important technology platform disappears tomorrow, somebody needs to know which parts of the company stop working and how long the organization can realistically function without it.

AI is going to make this more complicated because companies are creating new dependencies faster than most governance processes can keep up with them. An AI tool can start as something employees experiment with and quietly become part of how work gets done. Eventually people begin making decisions or running processes that assume the technology will always be available and behave the way they expect. By the time anyone recognizes it as a critical dependency, the business may already have difficulty operating without it.

That is why I think the MSIG article matters. An insurer saying resilience now deserves more attention than prevention isn't just another prediction about where cybersecurity is heading. It is evidence that the people financially underwriting cyber risk are beginning to look further into the business and consider what happens when preventative controls aren't enough.

I have been making the argument for some time that security, risk management and insurance only solve parts of this problem. They are all necessary, but none of them individually tells you whether the organization can continue operating through a serious disruption. That requires understanding how the business actually works, where its important dependencies are and what happens when one of them fails.

The cyber insurance application of the future may still ask whether you have MFA and EDR, but those answers only tell an insurer so much. The more useful underwriting conversation is starting to move toward understanding what happens after those controls have done everything they can and the business is still disrupted.

That is also the conversation business leaders should be having now. Not because prevention has become less important, but because eventually something will happen that prevention doesn't stop. When that day comes, the thing that matters is whether the business is still capable of functioning.