Telecoms Clients and Cyber Insurance: Why the Market Is Harder Than It Looks and What You Can Do About It

Telecoms firms may look like easy cyber risks. Underwriters see them very differently, and the gap is usually about evidence, not technology.
Resource: Telecommunications White Paper — How Cyber Risk Assessments Transform Insurability for Telecom Companies
The sector that looks insurable and isn't
Telecommunications is one of those sectors that looks, from the outside, like it should be well equipped to handle cyber risk. These are technology businesses, after all. They run complex networks. They employ technical specialists. They understand infrastructure. Surely their cyber insurance should be straightforward. In practice, the opposite is often true. Telecom companies are among the most challenging risks to place in the cyber insurance market, and the reasons are worth understanding if you have clients in the sector, or if you are looking to grow your book in it.
Why underwriters approach telecoms differently
The threat profile for telecoms is distinctive. These are businesses that hold extensive customer data, often including sensitive personal and financial information. They operate critical infrastructure, the kind that attracts state- sponsored threat actors alongside conventional cybercriminals. They face DDoS attacks, espionage, supply chain compromises and large-scale data breaches as primary risk vectors. When a telecom firm is hit, the consequences cascade across the customers and services that depend on its infrastructure.
That state-actor risk is no longer theoretical. In August 2025, the NCSC joined the NSA and partners from more than a dozen countries in a joint advisory attributing the Salt Typhoon campaign, a multi-year effort that compromised telecoms networks worldwide to track individuals' communications and movements, to China-based technology firms working for state intelligence services. Munich Re's 2026 cyber outlook makes the same point from the underwriting side: around 64% of organisations now expect to be a potential target of geopolitically motivated attack, and those in critical supply chains and infrastructure, telecoms explicitly among them, are the most exposed. The government's own data reflects the pressure. In the 2025/26 Cyber Security Breaches Survey, 63% of businesses in the information and communication sector identified a breach or attack in the previous year, compared with 43% overall.
Insurers are acutely aware of all of this, and it shapes how they approach the sector. Download the white paper here.
Technical security is necessary, not sufficient
The problem, as Infoprotect's telecommunications white paper sets out, is that most standard cyber risk assessments don't address the concerns that drive underwriting decisions in this space. They focus on the technical layer, the firewalls, the encryption, the endpoint protection, while underplaying the governance, process and human factors that insurers know determine whether a risk is well managed.
An insurer wants to know whether the board treats cyber risk as a business issue, whether accountabilities are clear, whether incident response has been tested rather than written, and whether the organisation has thought through its exposure to nation-state threats and supply chain vulnerabilities. Those questions are not answered by a network diagram. It is worth noting that the sector does score comparatively well on the governance question: 51% of information and communication businesses have a board member responsible for cyber security, against 31% across all businesses, but "someone owns it"and "we can evidence it" are not the same claim, and only the second one earns terms.
The loss data supports the emphasis. Across NetDiligence's 2025 claims study of more than 10,000 cyber claims, ransomware and business email compromise were the two leading causes of loss, accounting for roughly half of all SME claims over the five years to 2024. These are governance and human-factor failures as much as technical ones.
Why compliance makes it worse, not better
A compliance-focused assessment can actively mislead here. Regulatory compliance in telecoms addresses technical standards and national security requirements: UK providers are working to the Telecommunications (Security) Act framework, with a revised Code of Practice issued in July 2026 and Ofcom monitoring compliance. That is a serious regime, and firms are right to invest in it. But it is designed to protect network security and national resilience, not to answer an underwriter's questions about governance maturity, tested response and human risk. Meeting the regulatory baseline doesn't mean an underwriter will be comfortable writing the risk.
The white paper sets out what underwriters actually assess on a telecoms submission, and the evidence that satisfies them. [Download it here.]
What Cyber Assess changes
This is the gap Infoprotect's Cyber Assess framework is built to bridge. The assessment looks at the full picture: technical controls, yes, but also governance maturity, human risk management, incident response capability and business resilience. It produces a validated, independent report that gives underwriters something they can genuinely assess, rather than a self-attested questionnaire they must take on trust. For a complex telecommunications environment with extensive network infrastructure and interconnected services, that validated picture makes a significant difference to how the risk is perceived.
Three practical benefits for brokers
First, the submission. A Cyber Assess report alongside a renewal or new business submission is a materially different document from a standard proposal form. The detail and credibility of the assessment can transform the underwriter's perception of the risk, opening doors that might otherwise be closed and supporting the case for broader coverage at better terms.
Second, negotiation. When you have validated risk intelligence, you have data to work with. You can advocate for your client with evidence. You can demonstrate that the risk has been properly understood and that remediation is underway where gaps exist. That is a much stronger position than presenting an unvalidated questionnaire and hoping for the best.
Third, the advisory relationship. Brokers who bring Cyber Assess to their telecoms clients are positioned as strategic advisers rather than policy intermediaries. The assessment process itself adds value: the client comes away with board-level risk intelligence, a prioritised remediation roadmap and a clearer understanding of their own posture. That is valuable independently of the insurance outcome, and it deepens the relationship in a way a pure placement conversation doesn't.
Timing matters
Capacity in the wider cyber market remains ample, and pricing has been broadly stable, so this is not an argument that telecoms risks are about to become unplaceable. It is an argument about differentiation. Insurers are increasingly pricing on evidence rather than assertion, and third-party and supplier oversight, precisely where telecoms exposure concentrates, is now central to how a submission is judged. A client who can demonstrate their position now is doing it from a position of strength rather than under pressure at a difficult renewal.
Present the risk properly
The white paper closes with a point worth taking seriously: for telecoms companies, cyber incidents can have cascading effects well beyond the immediate organisation. That is exactly why underwriters are cautious, and why the quality of the risk presentation matters so much. The broker who can present a telecoms risk with validated evidence of governance maturity, human risk management and business resilience is offering something genuinely different.
Download the white paper
If you have telecoms clients whose cyber insurance is becoming more expensive, harder to place, or both, How Cyber Risk Assessments Transform Insurability for Telecom Companies is a practical starting point.
Download it here: [LINK]
Then speak to Brad or Hazel about what a Cyber Assess engagement could mean for your most challenging telecoms risks.
Sources: NSA/NCSC joint advisory on Salt Typhoon, Aug 2025 · Munich Re, Cyber insurance: risks and trends 2026 · DSIT, Cyber Security Breaches Survey 2025/2026 · Net Diligence, Cyber Claims Study 2025 · DSIT, Telecommunications Security Code of Practice 2026 (v1.1), July 2026
About Infoprotect UK
Infoprotect helps businesses achieve cybersecurity compliance, maturity and customer satisfaction.
We also have a symbiotic relationship with Insurance Brokers to provide effective “cyber risk management” for their clients, which is critical for organisations of all sizes and types as cyber threats continue to evolve and become more sophisticated. It can help prevent data breaches, reduce the impact of cyber-attacks, and protect an organisation’s reputation and financial stability.
Our agile, personalised human approach differentiates us. We deliver business value to our clients through our commitment and dedication to service delivery.
Our Cyber Assess, Cyber GRC and Cyber Protect solutions are industry-leading cybersecurity services.

