
Between ransomware, AI-driven fraud, and expanded regulatory obligations, digital risk now weighs more heavily on balance sheets than most traditional claims. Measuring the gap between the actual cost of a cyberattack and the protection budget mobilized by companies helps to understand why insurance coverage has become a strategic item.
Cost of a cyber claim versus protection budget: the real gaps
The available figures reveal a clear imbalance. The Asterès firm estimates that hundreds of thousands of successful cyberattacks hit French organizations each year, with a total cost estimated in billions of euros. On average, a French SME suffers considerable damage per attack.
The ransom, when there is one, represents only a fraction of the bill. The bulk of the damage comes from business interruption, system restoration, and the erosion of customer relationships. A company like Lise Charmel, placed under judicial recovery after a ransomware attack, illustrates this disproportion between the initial demand from attackers and the operational impact.
| Cost Item | Share in the Claim | Covered by Cyber Insurance |
|---|---|---|
| Business Interruption | Heaviest item | Yes (loss of earnings) |
| System Restoration | Variable depending on infrastructure | Yes (restoration costs) |
| GDPR Notification and Compliance | Fixed cost per incident | Yes (legal and notification costs) |
| Reputation Damage | Difficult to quantify, often lasting | Partially (crisis communication) |
| Ransom Itself | Minor fraction of the total | According to contract and legislation |
This table highlights a often underestimated point: the cost of the claim far exceeds the ransom itself. A cyber policy is not just used to pay an attacker; it absorbs the collateral costs that truly jeopardize the business.
To better understand the coverage mechanisms, cyber risk insurance details the typical guarantees and their relationship with crisis management.

NIS2 and GDPR: dual regulatory pressure for companies
The GDPR has governed the protection of personal data for several years. The European NIS2 directive adds an additional layer of requirements, particularly significant for SMEs and mid-sized enterprises. It expands the scope of entities subject to formal risk management and incident notification obligations.
In practical terms, NIS2 no longer only concerns critical service operators. Mid-sized companies, as long as they are involved in the supply chain of a regulated sector, are now required to demonstrate their level of cybersecurity. A client can demand proof of cyber insurance coverage from its suppliers before contracting.
What NIS2 adds to the existing framework
- An obligation to notify incidents within tight deadlines, with costs for mobilizing technical and legal teams that insurance can cover
- Requirements for digital risk governance at the management level, not just the IT department
- An extended responsibility logic throughout the value chain, where the uninsured link weakens the entire system
The GDPR penalizes the leakage of personal data. NIS2 penalizes lack of preparedness. Both accumulate. A company that suffers an attack without a documented response plan or appropriate coverage exposes itself to sanctions on two simultaneous fronts.
AI-driven threats: the attack surface is widening for SMEs
Classic phishing campaigns relied on generic emails, often riddled with mistakes. Generative AI has erased this warning signal. Fraudulent messages now replicate the style of a known contact, with a level of personalization that deceives trained employees.
Voice and video deepfakes make CEO fraud much harder to detect. A phone call mimicking a leader’s voice is sometimes enough to trigger a transfer. These attacks primarily target organizations where validation relies on a small number of people, which describes the majority of micro and small enterprises.
At the same time, the migration to the cloud multiplies entry points. A misconfiguration of access rights on a hosted service exposes data without any malware being necessary. Identity attacks and cloud configuration errors represent a growing share of claims reported to insurers.
Why cybersecurity tools alone are not enough
Firewalls, antivirus, multi-factor authentication: these measures reduce the likelihood of an attack. They do not eliminate residual risk. A cyber insurance policy specifically addresses this residue, meaning the incident that occurs despite the protections in place.
Insurers have understood this and increasingly condition underwriting on a minimal baseline of technical measures. This requirement creates a virtuous circle: to be insurable, the company must strengthen its cybersecurity, which reduces the frequency of claims and stabilizes premiums.

Coverage rates for French SMEs: a persistent gap
About 60% of SMEs in France have no coverage against cyber threats. This figure contrasts with the reality of attacks: more than half of French companies reported being victims of a cyberattack in 2021.
Several factors explain this gap. The perceived cost of the premium deters small structures, while the amount is generally modest compared to potential damage. The complexity of contracts, with their exclusions and technical prerequisites, also discourages leaders who do not have a dedicated security officer.
However, the market is evolving. Modular offers are emerging, tailored for micro and small enterprises with simplified questionnaires and guarantees suited to limited turnover. Cyber insurance is no longer reserved for large groups with a CISO: it is becoming accessible to small organizations with a few employees that handle customer or supplier data.
The decisive parameter remains the nature of the risk carried. A company that stores health data, bank details, or sensitive contractual information presents a high-risk profile, regardless of its size. Assessing this profile before choosing a level of coverage remains the first useful step, well before comparing rates.