# Cyber Insurance Rates Drop While Coverage Gaps Widen: The ClickFix Blind Spot


The cyber insurance market is experiencing a curious paradox. As premiums decline across the industry, driven by increased competition and market maturation, many policies are quietly narrowing their coverage scope—leaving organizations with cheaper policies that may not protect against emerging threats like social engineering attacks.


The specific catalyst for this shift: ClickFix, a growing social engineering scheme that bypasses traditional security controls and has become a flashpoint in insurance underwriting debates. As this threat and similar attacks proliferate, insurers are actively carving out social engineering losses, creating a dangerous gap between what companies think they're insured for and what they'll actually recover.


## The Paradox: Lower Rates, Narrower Coverage


Cyber insurance premiums have been declining modestly over the past 18 months, reversing years of upward pressure. This seemingly positive development masks a troubling industry restructuring.


Market dynamics driving rate decreases:

  • Increased competition among major carriers (Chubb, AIG, Beazley, Hiscox)
  • Better risk modeling and claims data analytics
  • Shift toward smaller, more granular policies
  • Consolidation of underwriting standards

  • However, these rate reductions come packaged with newly restrictive policy language. Insurers are using lower premiums as a competitive hook while simultaneously eliminating or restricting coverage for specific attack vectors—particularly social engineering and business email compromise (BEC) schemes.


    "We're seeing a bifurcation in the market," explains coverage counsel at major brokerages. Carriers are essentially offering two tiers: budget-conscious policies with significant exclusions, and premium-tier products with broader coverage. The catch: companies shopping on price are likely landing in the first category.


    ## ClickFix: The Attack That Exposures Miss


    ClickFix represents a particularly insidious evolution of social engineering. Unlike traditional phishing, ClickFix attacks don't rely primarily on credential theft or malware distribution. Instead, attackers place deceptive advertisements on search results or social media that direct users to fake support pages. When victims "click to fix" purported browser issues, they're guided through remote access procedures or tricked into downloading legitimate-looking (but malicious) files.


    Why ClickFix is uninsurable under many new policies:


  • It requires user interaction and deception, not technical vulnerability exploitation
  • Policies increasingly define it as "social engineering" — now a common exclusion
  • The attack bypasses email security, making traditional BEC coverage irrelevant
  • Attribution is difficult, complicating claims investigation
  • Loss amounts are often scattered across multiple users, creating aggregation headaches for insurers

  • In late 2024 and early 2025, multiple major insurers began explicitly excluding or severely limiting coverage for social engineering losses, particularly those resulting from user deception rather than malware or credential compromise. ClickFix became the poster child for this exclusion wave.


    A typical updated policy now reads: *"Coverage excludes losses arising from social engineering, confidence schemes, or user deception attacks where no malware was deployed or credentials were not directly compromised."*


    This language would exclude ClickFix attacks entirely, even though they can result in six-figure system access losses or data exfiltration.


    ## Why Insurers Are Tightening: The Claims Data Story


    The shift toward social engineering exclusions isn't arbitrary. Insurers are responding to measurable claims trends:


    | Metric | Observation |

    |--------|-------------|

    | BEC/Social Engineering Claims | Now represent ~20-25% of all cyber claims by frequency |

    | Average Loss Amount | $180,000–$380,000 per social engineering incident |

    | Claim Predictability | Highly variable; difficult to model and price accurately |

    | Fraud Risk | Elevated; social engineering claims are easier for insured parties to misrepresent |

    | Recovery Rate | Often poor; funds moved quickly by attackers |


    Because social engineering claims are high-frequency, unpredictable in severity, and difficult to verify, they're actuarially problematic for insurers. By excluding them, carriers can stabilize loss ratios and justify lower premiums. It's a rational risk management move—but it shifts significant uninsured risk onto policyholders.


    ## The Coverage Landscape: What's Actually Protected?


    Organizations need to understand the new insurance reality. Most modern cyber policies now contain a tiered approach:


    Typically Covered:

  • Ransomware and extortion losses
  • Data breaches caused by technical vulnerabilities
  • Malware deployment and infection
  • Business email compromise involving direct credential compromise
  • System failure and data destruction
  • Notification and forensics costs

  • Often Excluded:

  • Social engineering (broad definition)
  • Employee mistakes or policy violations
  • Unverified social engineering losses
  • "Pure" social engineering (no malware or credential theft)
  • Losses from third-party impersonation

  • Uncertain/Negotiable:

  • Attacks involving both social engineering and malware
  • Losses from supply chain social engineering
  • Credential theft via phishing, if followed by manual attacker action

  • ClickFix falls squarely in the excluded category under most refreshed policies.


    ## Who's Most Vulnerable?


    The coverage gap disproportionately affects smaller to mid-sized organizations:


  • Fewer dedicated security resources to train employees against social engineering
  • Lower bargaining power to negotiate broader coverage
  • Tighter budgets making them price-sensitive to premium increases
  • Higher click-through rates on malicious ads (less sophisticated user base, smaller IT teams)

  • Manufacturing, construction, and professional services firms—industries with less cybersecurity sophistication—are seeing the highest ClickFix incident rates.


    ## Recommendations for Affected Organizations


    1. Audit Your Current Coverage

    Request a detailed endorsements list from your broker. Specifically ask about social engineering, BEC, and social engineering exclusions. Map these against your actual risk profile.


    2. Reframe Your Cyber Insurance Strategy

    Don't optimize solely for premium cost. Identify your actual top three risk scenarios (ransomware? supply chain breach? social engineering?), then ensure at least one carrier covers each. This may mean splitting policies or paying slightly higher premiums for broader coverage on critical exposures.


    3. Strengthen Prevention, Assume Non-Coverage

    Given the shrinking insurance safety net for social engineering, treat prevention as primary defense:

  • Implement mandatory multi-factor authentication (MFA) on all critical systems
  • Deploy browser isolation or sandboxing for high-risk users
  • Conduct quarterly social engineering testing with third parties
  • Maintain detailed incident response plans that don't rely on insurance recovery

  • 4. Document Everything

    If a social engineering incident occurs, meticulously document the attack method, user interaction, and any technical components. Insurance disputes often hinge on whether the attack "qualifies" as social engineering or has technical elements.


    5. Work with a Broker, Not a Price Aggregator

    Use a broker who understands exclusion language and can negotiate coverage tailored to your risk. One-size-fits-all online platforms won't catch these gaps.


    ## HackWire Analysis


    The cyber insurance market's pivot deserves scrutiny. Dropping premiums are attracting smaller organizations into the cyber insurance market—a necessary and positive development. But the accompanying exclusion wave reveals a troubling reality: insurance companies are redefining what "cyber risk" means, and social engineering is being quietly reclassified as not-a-cyber-problem.


    This is a market failure masquerading as efficiency. Social engineering attacks are growing, costly, and increasingly sophisticated. ClickFix is not an edge case; it's a direct reflection of how modern attackers are thinking. By excluding these attacks from coverage, insurers are externalizing a real and growing risk to businesses.


    The timing is also suspicious. Why now? Because the competitive pressure to win market share has given way to margin pressure—and social engineering losses are difficult to price and defend. Exclusions are easier than accurate pricing. Organizations being quoted "bargain" cyber premiums should ask their brokers the uncomfortable question: *"What exactly isn't covered anymore, and why?"*


    For defenders, this changes the equation. Insurance was never a substitute for security, but it was a useful financial shock absorber. If that absorber is shrinking without transparent communication, organizations need to over-invest in prevention and response capability. You can't outsource what insurance won't cover.


    The real cost of a ClickFix breach isn't declining—just the number of organizations who'll actually recover it. — HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)