Cyber insurance gains ground in Singapore as coverage widens, premiums fall网络保险在新加坡越来越受欢迎,覆盖范围扩大,保费下降
Small and medium enterprises as well as mid-market companies are taking up cyber coverage. Read more at straitstimes.com.
UEI Logistics managing director Terrence Tan took up cyber insurance as the company had increasingly been receiving phishing e-mails from scammers.
Published Sep 14, 2026, 05:00 AM
Updated Sep 14, 2026, 05:00 AM
Cyber insurance demand in Singapore is rising, with more SMEs and mid-market firms buying coverage due to increasing cyber threats
Premiums for cyber insurance have fallen since 2022, making it more affordable and encouraging companies to seek broader protection beyond basic coverage.
Minimum security measures like multi-factor authentication remain mandatory.
SINGAPORE – In November 2025, two sales and operations staff from Singapore-based freight forwarding company UEI Logistics received an e-mail that looked entirely routine.
It appeared to be from a Chinese shipping agency it had worked with for years. The sender asked for payment of US$18,288 (S$23,200) to be transferred to a different bank account, claiming that the original account was hit with high government transaction taxes.
Sensing something was amiss, the staff alerted managing director Terrence Tan. He noticed the sender’s e-mail domain was subtly different. A quick call to the Chinese partner confirmed his suspicions. The e-mail was a scam.
He said: “It was very scary and convincing because the attackers impersonated someone we work regularly with.”
The incident was a wake-up call for UEI Logistics, which has increasingly been receiving phishing e-mails from scammers. It prompted the firm to deploy a threat detection system from ST Engineering to look for suspicious activities round the clock, and purchase a cyber insurance plan from MSIG.
An annual premium of $980 gives UEI Logistics $300,000 coverage in the event of a breach for the cost of forensic investigations, legal counsel and hardware replacement, among others.
UEI Logistics is among a growing number of companies in Singapore which are taking up cyber insurance.
Eight insurers and brokers that The Straits Times spoke to reported increasing demand, especially over the past two to three years.
Insurers said that technology and financial firms , including banks, fintech and cloud providers, remain among the strongest buyers, with growing demand from manufacturing, transport and logistics, retail, healthcare, hospitality and professional services as they digitalise.
US-headquartered speciality insurer Markel said its cyber insurance business in Singapore has been increasing steadily since 2022. Most recently in 2023 and 2024, the number of policies sold yearly grew between 56 per cent and 125 per cent.
Regional insurer QBE Asia, meanwhile, sold 25 per cent to 30 per cent more policies to companies in Singapore from 2024 to 2026.
French-based insurer AXA XL and American insurance broker Marsh also said they sold more policies to first-time buyers here and fielded more queries from 2023 to 2025, but did not reveal business growth numbers.
Singapore-based AWG Insurance Brokers and London-headquartered broker Howden said more companies bought cyber insurance policies, but they did not reveal figures.
Japanese insurer MSIG and German insurer Allianz reported an increase in the number of Singapore customer queries, but did not reveal exact numbers.
Cybersecurity policies typically insure firms against the costs of recovering from data breaches and ransomware attacks , such as hiring forensic experts and lawyers, and restoring lost data . Premiums depend on a company’s size, sector, where it operates, claims record, cyber defences, risk exposure, and the amount and breadth of coverage purchased, among others.
Media reports of damaging cyber attacks have brought the potential financial and operational fallout into sharper focus, prompting more businesses to seek coverage against losses for ransomware, sophisticated social engineering techniques and prolonged business outages.
At the same time, AI is enabling faster, larger-scale and more sophisticated attacks – a threat already felt by businesses here.
A May 2026 QBE survey involving 400 Singapore companies found that 39 per cent of firms had experienced at least one AI-related cyber incident in the past year. These incidents include AI-generated malware, cyberattacks where AI was used to identify vulnerabilities, and phishing messages with AI-enhanced content.
“Cyber risk is no longer viewed solely as an IT or operational issue. It is increasingly being discussed at the board and senior management level as a governance and enterprise risk concern, leading many organisations to review and enhance their cyber insurance programmes as a fail-safe,” said Howden Singapore’s director of cyber and technology solutions for financial lines, Kenny Tan.
More stringent regulations in Singapore are also making breaches costlier. For example, in October 2022, Singapore increased the maximum penalty for data protection breaches to 10 per cent of an organisation’s annual local turnover, or $1 million, whichever is higher. Previously, the maximum fine was $1 million.
“A mid-sized business with an annual turnover of $20 million faces a potential $2 million fine for a single compliance failure, forcing them to purchase higher limits simply to protect against regulatory liabilities,” said a spokesperson for AWG Insurance Brokers.
Large multinational corporations and government bodies have also made cyber insurance a prerequisite for vendors bidding for contracts.
This is their way of strengthening an oversight of their suppliers’ cybersecurity defences after seeing a growing trend of attackers entering their networks through less-secure vendors, said AXA XL’s head of cyber for Asia and the Middle East, Samuel Bye.
Market conditions have also swung in buyers’ favour. Cyber insurance rates in Singapore have eased from their 2021 to 2022 highs as competition intensified.
Some of the latest entrants include US-based Liberty and Japan-headquartered Sompo, while established insurers such as Chubb, AIG and MSIG offered significantly broader coverage, said industry players.
AWG Insurance Brokers said annual premiums for small businesses with revenue below $2 million have halved since 2022. Such firms can now obtain $250,000 in coverage for premiums starting from $1,000 a year, down from $2,000 previously.
For mid-market firms with annual revenue of between $10 million and $50 million, the starting premium for $2 million in coverage has fallen 25 per cent, from $8,000 in 2022 to $6,000 today.
With premiums falling, some companies are using the room in their budgets get more comprehensive coverage.
The expanded coverage covers losses from cloud outages, failures of critical third-party technology providers, cyber extortion and expenses to recover from reputational harm after a cyber incident, said Olga Wong, head of Markel’s professional & financial risks and cyber team.
Businesses with weaker cyber defences also stand a better chance of obtaining coverage today. In the past, they would have to fill up checklists of the technical measures they have in place, and may be declined coverage if they fell short even in one area, said industry players.
But after several years of gathering data from cyber incidents and insurance claims, insurers are now better able to estimate the potential cost of an attack for different types of businesses.
This allows them to calibrate and offer coverage to companies with less-developed defences, although they may charge higher premiums or impose more restrictions to account for the greater risk.
Karlis Trops, head of cyber and technology professional indemnity at Allianz Commercial Asia, said the industry used to ask extensive questions when assessing a company for cyber coverage, regardless of size.
“Now, we’ve reached a balance where the number and technicality of questions asked is reflective of the size of the company, what they do and the risks their business face,” said Trops.
Still, there are minimum requirements to meet. These typically include multifactor authentication for all remote access, a robust back-up strategy that includes offline or disconnected back-ups and a formal patch-management process, with faster remediation for high- and critical-severity vulnerabilities.
Insurers are encouraging companies to take advantage of the market conditions to get covered. “Cyber policies have become better value for buyers,” said Trops.
AI/artificial intelligence
UEI物流公司总经理陈德伦购买了网络保险,因为该公司越来越多地收到诈骗分子发送的网络钓鱼电子邮件。
发布于 2026 年 9 月 14 日上午 5:00
更新于2026年9月14日凌晨5:00
由于网络威胁日益增加,新加坡的网络保险需求正在上升,越来越多的中小企业和中型企业购买了网络保险。
自 2022 年以来,网络保险的保费有所下降,使其更加实惠,并鼓励公司寻求基本保险以外的更广泛保障。
多因素认证等最低安全措施仍然是强制性的。
新加坡——2025 年 11 月,新加坡货运代理公司 UEI Logistics 的两名销售和运营人员收到了一封看起来完全例行的电子邮件。
邮件似乎来自一家与其合作多年的中国货运代理公司。发件人要求将18,288美元(约合23,200新元)转入另一个银行账户,声称原账户被征收了高额政府交易税。
员工察觉到异样,立即通知了总经理陈先生。他注意到发件人的电子邮件地址域名略有不同。他迅速致电中国合作伙伴,证实了自己的怀疑:这封邮件是诈骗邮件。
他说:“这起袭击非常可怕,而且极具说服力,因为袭击者冒充了我们经常一起工作的人。”
此次事件对UEI物流公司敲响了警钟,该公司近期收到的钓鱼邮件数量不断增加。事件促使该公司部署了新加坡科技工程公司的威胁检测系统,全天候监控可疑活动,并购买了MSIG的网络保险计划。
UEI Logistics 每年只需缴纳 980 美元的保费,即可获得 30 万美元的保险,用于支付数据泄露事件中的取证调查费用、法律咨询费用和硬件更换费用等。
UEI Logistics是新加坡越来越多购买网络保险的公司之一。
《海峡时报》采访的八家保险公司和经纪公司表示,需求不断增长,尤其是在过去两到三年里。
保险公司表示,包括银行、金融科技公司和云服务提供商在内的科技和金融公司仍然是最强劲的买家,随着制造业、运输和物流业、零售业、医疗保健业、酒店业和专业服务业的数字化转型,这些行业的需求也在不断增长。
总部位于美国的专业保险公司Markel表示,其在新加坡的网络保险业务自2022年以来一直在稳步增长。最近在2023年和2024年,每年售出的保单数量增长了56%至125%。
与此同时,区域保险公司 QBE Asia 预计,从 2024 年到 2026 年,其向新加坡公司销售的保单数量将增加 25% 至 30%。
法国保险公司 AXA XL 和美国保险经纪公司 Marsh 也表示,他们在 2023 年至 2025 年期间向首次购房者销售了更多保单,并收到了更多咨询,但没有透露业务增长数据。
总部位于新加坡的 AWG 保险经纪公司和总部位于伦敦的经纪公司 Howden 表示,购买网络保险的公司数量有所增加,但他们没有透露具体数字。
日本保险公司MSIG和德国保险公司安联报告称,新加坡客户的咨询量有所增加,但没有透露具体数字。
网络安全保险通常为企业提供保障,以应对数据泄露和勒索软件攻击后的恢复成本,例如聘请取证专家和律师以及恢复丢失的数据。保费取决于公司的规模、行业、运营地点、索赔记录、网络防御措施、风险敞口以及所购买保险的金额和范围等因素。
媒体对网络攻击造成的破坏性报道,使潜在的财务和运营损失更加凸显,促使更多企业寻求保险,以防范勒索软件、复杂的社会工程技术和长期业务中断造成的损失。
与此同时,人工智能正在催生速度更快、规模更大、更复杂的攻击——这种威胁已经给本地企业带来了压力。
QBE于2026年5月进行的一项针对400家新加坡公司的调查发现,39%的公司在过去一年中至少经历过一次与人工智能相关的网络安全事件。这些事件包括人工智能生成的恶意软件、利用人工智能识别漏洞的网络攻击以及包含人工智能增强内容的网络钓鱼信息。
“网络风险不再仅仅被视为IT或运营问题。它越来越多地被董事会和高级管理层视为治理和企业风险问题进行讨论,促使许多组织审查并加强其网络保险计划,以作为一项安全保障措施,”豪顿新加坡金融险网络和技术解决方案总监Kenny Tan表示。
新加坡更严格的监管也使得数据泄露的代价更高。例如,2022年10月,新加坡将数据保护违规行为的最高罚款额提高至企业本地年营业额的10%或100万新元,以较高者为准。此前,最高罚款额为100万新元。
AWG 保险经纪公司的一位发言人表示:“一家年营业额为 2000 万美元的中型企业,如果出现一次违规行为,就可能面临 200 万美元的罚款,这迫使他们购买更高的保额,仅仅是为了防范监管责任。”
大型跨国公司和政府机构也已将网络保险作为供应商竞标合同的先决条件。
AXA XL 亚洲及中东网络安全主管 Samuel Bye 表示,这是他们加强对供应商网络安全防御监督的一种方式,因为他们发现攻击者越来越多地通过安全性较低的供应商进入他们的网络。
市场状况也已转向有利于买方。随着竞争加剧,新加坡的网络保险费率已从2021年至2022年的高位回落。
业内人士表示,最新加入的保险公司包括总部位于美国的 Liberty 和总部位于日本的 Sompo,而 Chubb、AIG 和 MSIG 等老牌保险公司则提供了更为广泛的保险范围。
AWG保险经纪公司表示,自2022年以来,年收入低于200万美元的小企业的年度保费已经减半。这类公司现在可以以每年1000美元起的保费获得25万美元的保险,而此前的保费为2000美元。
对于年收入在 1000 万美元至 5000 万美元之间的中型企业而言,200 万美元的保险起保费已下降 25%,从 2022 年的 8000 美元降至目前的 6000 美元。
随着保费下降,一些公司正在利用预算中的空间来获得更全面的保险。
Markel 专业及金融风险和网络团队负责人 Olga Wong 表示,扩大后的保险范围涵盖了云服务中断造成的损失、关键第三方技术提供商的故障、网络勒索以及网络事件后声誉损害的恢复费用。
如今,网络安全防御能力较弱的企业反而更有可能获得保险保障。业内人士表示,过去,这些企业需要填写一份技术措施清单,如果哪怕只有一个方面不达标,都可能导致保险申请被拒。
但经过数年收集网络安全事件和保险索赔数据后,保险公司现在能够更好地估算不同类型企业遭受攻击的潜在成本。
这使得他们能够调整并为防御能力较弱的公司提供保险,尽管他们可能会收取更高的保费或施加更多限制以应对更大的风险。
安联商业亚洲网络和技术专业责任保险主管卡利斯·特罗普斯表示,无论公司规模大小,业内人士过去在评估公司是否适合网络保险时都会提出大量问题。
“现在,我们已经达到了一种平衡,所提问题的数量和技术性反映了公司的规模、业务内容以及公司面临的风险,”特罗普斯说。
不过,仍需满足一些最低要求。这些要求通常包括对所有远程访问进行多因素身份验证、包含离线或断网备份的强大备份策略,以及正式的补丁管理流程,以便更快地修复高危和严重漏洞。
保险公司鼓励企业利用当前的市场条件投保。“网络保险对买家来说更具性价比,”特罗普斯说。
人工智能