[Home](https://thecyberexpress.com)[Cyber News](https://thecyberexpress.com/cyber-news/)

# Cyber Insurers Might Not Pay if Vulnerabilities Unpatched

					by[Paul Shread](https://thecyberexpress.com/author/paulshread/)

[August 25, 2025](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/)

in[Cyber News](https://thecyberexpress.com/cyber-news/), [Firewall Daily](https://thecyberexpress.com/firewall-daily/)

[#](#)

[0](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/#respond)

[Cyber insurers CVE exclusionsCyber insurers CVE exclusions Credit: Ron Lach/Pexels](https://thecyberexpress.com/wp-content/uploads/pexels-ron-lach-9783346.jpg)

652

SHARES

3.6k

VIEWS

[Share on LinkedIn](https://www.linkedin.com/shareArticle?url=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F&title=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched)[**Share on Twitter](https://twitter.com/intent/tweet?text=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched%20via%20%40TheCyberExpress&url=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F)

[https://telegram.me/share/url?url=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F&text=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched](https://telegram.me/share/url?url=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F&text=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched)[https://www.facebook.com/sharer.php?u=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F](https://www.facebook.com/sharer.php?u=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F)[//api.whatsapp.com/send?text=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched%0Ahttps%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F](//api.whatsapp.com/send?text=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched%0Ahttps%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F)[https://www.linkedin.com/shareArticle?url=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F&title=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched](https://www.linkedin.com/shareArticle?url=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F&title=Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched)

[#](#)

A cyber insurance provider is taking issue with competitors that won’t pay claims resulting from unpatched vulnerabilities.

In a recent LinkedIn [post](https://www.linkedin.com/pulse/taking-responsibility-age-non-stop-cves-coalitioninc-m7xjc/), cyber insurer Coalition said that while these exclusions are not “widely deployed,” the company has been seeing more of them recently. Some cyber insurers won’t pay if a claim arises from a vulnerability that’s gone unpatched for a certain number of days, the insurer said. Others use a sliding scale, in which the payout falls the longer the [vulnerability](https://thecyberexpress.com/firewall-daily/vulnerabilities/ "vulnerability") has gone unpatched.

One “well-known” U.S. insurer excludes losses arising from CVEs with a CVSS severity score greater than 8.0 if a patch has been available for three weeks and not been applied, Coalition said.

“This logic might make sense if patching were simple and straightforward,” stated Tiago Henriques, Chief Underwriting Officer at Coalition. “But in reality, [vulnerability management](https://cyble.com/knowledge-hub/what-is-vulnerability-management/ "vulnerability management") is complicated and convoluted, even for businesses with sophisticated security teams.”

## Cyber Insurers and CVE Exclusions

Coalition looked at the [data](https://thecyberexpress.com/what-is-data/ "data") surrounding the CVSS 8.0 patching exclusion. As of July 2025, more than 61,000 [vulnerabilities](https://thecyberexpress.com/what-are-vulnerabilities/ "vulnerabilities") would fit that exclusion, yet only a little more than 1% of those vulnerabilities are in CISA’s Known Exploited Vulnerabilities (KEV) catalog, the insurer said.

In an era in which there are more than 40,000 new vulnerabilities a year, “CVE exclusions are putting businesses in an impossible situation,” Henriques said. “Either waste precious resources chasing thousands of low-likelihood vulnerabilities or invest in a cyber insurance policy that [risks](https://thecyberexpress.com/what-are-risks-in-cybersecurity/ "risks") claim denial when an unpatched system is breached.”

[](https://cyble.com/resources/research-reports/)

Coalition didn’t name insurers with patch exclusions or endorsements, but Chubb, for example, may add a “Neglected Software [Exploit](https://cyble.com/exploit/ "Exploit") Endorsement” for policyholders that are lax in applying security fixes.

“For policyholders that lack strong patch management hygiene, Chubb may address this risk by adding the neglected software exploit endorsement,” Chubb’s [website](https://www.chubb.com/us-en/business-insurance/products/cyber-insurance/cyber-insurance-products.html) says. “This endorsement provides policyholders with a 45-day grace period to patch software vulnerabilities that are published as Common Vulnerabilities and Exposures (CVEs) within the National Vulnerability Database operated by the U.S. National Institute for Standards and Technology (NIST). After the 45-day grace period expires, there is risk sharing between the policyholder and insurer incrementally shifting to the policyholder, who takes on progressively more of the risk if the vulnerability is not patched at the 45-, 90-, 180-, and 365-day mark.”

## A Risk-based Approach to Cyber Insurance Patching Requirements

Coalition endorses a more risk-based approach, with technical assistance from the insurer, and rewards policyholders with good security hygiene under its new [Active Cyber Policy](https://www.coalitioninc.com/campaign/active-cyber-policy).

Coalition Security – the insurer’s security affiliate – focuses on vulnerabilities that are similar to those that have been exploited by [ransomware](https://thecyberexpress.com/what-is-ransomware-how-it-work/ "ransomware") gangs, and sends out alerts “for the most urgent, high-impact threats with significant financial risk,” the company says.

In 2024, Coalition said it issued an average of 5.5 such alerts per month, representing just 0.15% of published vulnerabilities, and 90% of its policyholders didn’t receive a single alert last year.

“In other words, if you receive a Coalition [security](https://thecyberexpress.com/ "security") alert, pay attention because it’s important,” the company says.

 

### Share this:

- [Share on LinkedIn (Opens in new window)LinkedIn](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/?share=linkedin&nb=1)
- [Share on Reddit (Opens in new window)Reddit](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/?share=reddit&nb=1)
- [Share on X (Opens in new window)X](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/?share=twitter&nb=1)
- [Share on Facebook (Opens in new window)Facebook](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/?share=facebook&nb=1)
- [More](#)
-

- [Email a link to a friend (Opens in new window)Email](mailto:?subject=%5BShared%20Post%5D%20Cyber%20Insurers%20Might%20Not%20Pay%20if%20Vulnerabilities%20Unpatched&body=https%3A%2F%2Fthecyberexpress.com%2Fcyber-insurers-unpatched-vulnerabilities%2F&share=email&nb=1)
- [Share on WhatsApp (Opens in new window)WhatsApp](https://thecyberexpress.com/cyber-insurers-unpatched-vulnerabilities/?share=jetpack-whatsapp&nb=1)
-

### *Related*

[](https://thecyberexpress.com/china-rednovember-unpatched-edge-devices/ "China-linked RedNovember Campaign Shows Importance of Patching Edge Devices")

#### [China-linked RedNovember Campaign Shows Importance of Patching Edge Devices](https://thecyberexpress.com/china-rednovember-unpatched-edge-devices/ "China-linked RedNovember Campaign Shows Importance of Patching Edge Devices")

A long-running threat campaign linked to a Chinese state-sponsored cyber-espionage group highlights the importance of patching and protecting edge devices and internet-facing assets. RedNovember – previously tracked as TAG-100 and also overlapping with Storm-2077 – targeted unpatched web-facing assets from at least a dozen well-known IT and security vendors in…

[](https://thecyberexpress.com/cve-2025-11001-7zip-vulnerability-nhs/ "Critical 7-Zip Vulnerability CVE-2025-11001 Prompts NHS Cyber Alert")

#### [Critical 7-Zip Vulnerability CVE-2025-11001 Prompts NHS Cyber Alert](https://thecyberexpress.com/cve-2025-11001-7zip-vulnerability-nhs/ "Critical 7-Zip Vulnerability CVE-2025-11001 Prompts NHS Cyber Alert")

CVE-2025-11001 is a high-severity 7-Zip flaw. Update to version 25.00 and use Cyble intelligence to stay ahead of potential exploits.

[](https://thecyberexpress.com/cyber-essentials-in-focus-ncsc-warns/ "Think You’re Too Small to Be Hacked? NCSC Says Think Again")

#### [Think You’re Too Small to Be Hacked? NCSC Says Think Again](https://thecyberexpress.com/cyber-essentials-in-focus-ncsc-warns/ "Think You’re Too Small to Be Hacked? NCSC Says Think Again")

For SMEs everywhere, the time to act is not after a breach — it is before.

Tags: [cyber insurance](https://thecyberexpress.com/tag/cyber-insurance/)[The Cyber Express](https://thecyberexpress.com/tag/the-cyber-express/)[The Cyber Express News](https://thecyberexpress.com/tag/the-cyber-express-news/)[Vulnerabilities](https://thecyberexpress.com/tag/vulnerabilities/)

[Previous Post Indo-U.S. Agencies Dismantle Cybercrime Network Targeting U.S. Nationals](https://thecyberexpress.com/cbi-dismantle-cybercrime-network-targeting-us/)[Next Post China-Linked Espionage Campaign Hijacks Web Traffic to Target Diplomats](https://thecyberexpress.com/china-espionage-campaign-targets-diplomats/)

    Next Post

[MI5, Espionage Campaign, China, PRC Hackers, Southeast Asia, Diplomats](https://thecyberexpress.com/china-espionage-campaign-targets-diplomats/)

### [China-Linked Espionage Campaign Hijacks Web Traffic to Target Diplomats](https://thecyberexpress.com/china-espionage-campaign-targets-diplomats/)

[#](#)

### Upcoming Webinar

 [](https://us06web.zoom.us/webinar/register/WN_XfcOZ7qkQzyUBIZvePUktQ#/registration)

### Threat Landscape Reports 2025

[](https://cyble.com/resources/research-reports/apac-cyber-threat-landscape-report/)[](https://cyble.com/resources/research-reports/australia-and-new-zealand-threat-landscape-report/)

❮❯

 [](https://cyble.com/request-demo/?utm_source=cril&utm_medium=sidebar)

[about:blank](about:blank)

[https://podcasters.spotify.com/pod/show/the-cyber-express/embed/episodes/Satnam-Narang-We-Have-Only-Scratched-The-Surface-of-AI-e23qh3c/a-a9qee6q](https://podcasters.spotify.com/pod/show/the-cyber-express/embed/episodes/Satnam-Narang-We-Have-Only-Scratched-The-Surface-of-AI-e23qh3c/a-a9qee6q)

[Follow Us On Google News](https://news.google.com/publications/CAAqBwgKMNO0vAsw4M_TAw?ceid=US:en&oc=3)  

### Latest **Cyber News**

[ATM jackpotting-FBI](https://thecyberexpress.com/fbi-flags-rise-in-atm-jackpotting-attacks/)

[Cyber News](https://thecyberexpress.com/cyber-news/)

### [ATM Jackpotting Losses Cross $20M as Malware Targets U.S. Cash Machines](https://thecyberexpress.com/fbi-flags-rise-in-atm-jackpotting-attacks/)

[February 23, 2026](https://thecyberexpress.com/fbi-flags-rise-in-atm-jackpotting-attacks/)

[Digital Services ActDigital Services Act](https://thecyberexpress.com/e120m-digital-services-act-penalty/)

[Cyber Essentials](https://thecyberexpress.com/cyber-essentials/)

### [X vs EU: Platform Appeals Against €120M Digital Services Act Penalty](https://thecyberexpress.com/e120m-digital-services-act-penalty/)

[February 23, 2026](https://thecyberexpress.com/e120m-digital-services-act-penalty/)

[Terrorist Cyberattacks, UAE Cyber Security CouncilTerrorist Cyberattacks, UAE Cyber Security Council](https://thecyberexpress.com/uae-blocked-ai-powered-terrorist-cyberattacks/)

[Cyber Warfare](https://thecyberexpress.com/features/cyber-warfare/)

### [UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure](https://thecyberexpress.com/uae-blocked-ai-powered-terrorist-cyberattacks/)

[February 23, 2026](https://thecyberexpress.com/uae-blocked-ai-powered-terrorist-cyberattacks/)

[The Cyber Express Weekly RoundupThe Cyber Express Weekly Roundup](https://thecyberexpress.com/ai-deepfakes-ransomware-weekly-roundup/)

[Firewall Daily](https://thecyberexpress.com/firewall-daily/)

### [The Cyber Express Weekly Roundup: AI Disruption, Regulatory Pressure, and the Evolving Cyber Threat Landscape](https://thecyberexpress.com/ai-deepfakes-ransomware-weekly-roundup/)

[February 20, 2026](https://thecyberexpress.com/ai-deepfakes-ransomware-weekly-roundup/)

### Categories

Categories

Select Category
Appointments
Budgets
Bug Bounty & Rewards
Business News
Compliance
Cyber Essentials
Cyber News
Cyber Warfare
Cybersecurity Awareness Month
Dark Web News
Data Breach News
DDoS Attacks News
Deepfake
Espionage
Features
Firewall Daily
Gitex2022
Governance
Hacker Claims
Hacker News
Hackers Interview
How to
Interviews
Knowledge Hub
Learning & Development
Lockbit Ransomware News
Main Story
Malware News
Market Reports
Mergers & Aquisitions
Partnerships
Podcast
Policy Updates
Press Release
Ransomware News
Regulations
Research
Resources
Sponsored Content
Startups
Threat Actors
Threat Intelligence
Threat Intelligence News
Trends
Vulnerabilities
Vulnerability News
What is
Whitepapers
Workforce

Select Category

### Web Stories

[](https://thecyberexpress.com/web-stories/if-you-do-this-on-telegram-your-bank-account-will-become-zero/)

Do This on Telegram, Your Bank Account Will Become Zero

[](https://thecyberexpress.com/web-stories/ios-18-beta/)

If You Install the iOS 18 Beta, Your iPhone Could Be Hacked

[](https://thecyberexpress.com/web-stories/cricket-world-cup-ticketing-systems/)

Cricket World Cup Ticketing Systems Under Cybersecurity

[](https://thecyberexpress.com/web-stories/nba-finals/)

Cyber Threats and Online Ticket Scams During the NBA Finals

[](https://thecyberexpress.com/web-stories/biometric-data-security-protecting-sensitive-information/)

Biometric Data Security: Protecting Sensitive Information