Asia Insurance Post
  • Home
  • Articles
  • Blog
  • Data
  • Facts
  • Editorial
  • Interviews
Select Page

Cyber claims accelerating sharply in APAC region, says Aon report

by AIP Online Bureau | Sep 29, 2026 | Workplace/Employee Benefits | 0 comments

Cyber fines may be insurable in 13 of 14 APAC jurisdictions, although the position varies considerably by market and often depends on the nature of the underlying conduct. China is the only jurisdiction reviewed where indemnity for cyber fines is expressly prohibited.

Singapore: Global re/insurance broker Aon in its new report on `The Changing Cyber Risk Landscape in APAC’ has said cyber claims are accelerating sharply in the region, with Aon recording a 233 percent increase in cyber claims in 2025 and a further 80 percent rise in the first half of 2026.

“Cyber incidents are increasingly multi-jurisdictional, with a single event often triggering multiple regulatory investigations across different countries simultaneously,” cautioned the report.

Key points include-

-Financial exposure is rising significantly, with around 50 percent of APAC jurisdictions now applying revenue-linked penalties. -Maximum fines range from about US$6,000 in New Zealand to more than US$35 million or 30 percent of annual turnover in Australia.
-Mandatory reporting requirements are now the norm, with 13 of 14 APAC markets requiring data breach reporting and notification timeframes ranging from one hour to 30 days.
-Cyber fines may be insurable in 13 of 14 APAC jurisdictions, although the position varies considerably by market and often depends on the nature of the underlying conduct. China is the only jurisdiction reviewed where indemnity for cyber fines is expressly prohibited.

Cybersecurity and data privacy regimes across Asia Pacific (APAC) are entering a period of heightened scrutiny. Over the past 12–18 months, many jurisdictions have introduced or expanded regulatory frameworks, increased penalties and strengthened breach notification and reporting requirements.

At the same time, enforcement expectations are hardening. Regulators across the region are becoming more active and coordinated, increasing the likelihood that a single cyber incident would trigger parallel investigations, overlapping sanctions and materially different outcomes depending on jurisdiction.

This report examines how these developments may reshape regulatory exposure and the insurability of cyber related fines and penalties across APAC.

The report identifies several clear themes emerging across APAC markets:

-Regulatory frameworks are expanding and enforcement is intensifying, often faster than organisations’ incident response and insurance strategies have adapted.
-Outcomes following a cyber incident vary significantly by jurisdiction, with different approaches to breach notification, enforcement thresholds and sanctions.
-The insurability of cyber fines and penalties remains highly uneven, shaped by local law, public policy considerations and court practice rather than policy wording alone.
-Multi jurisdictional cyber incidents now routinely generate complex, concurrent regulatory exposure, which may increase financial, operational and reputational risk.

Cyber insurance adequacy is increasingly sensitive to regulatory change, particularly where higher penalties coincide with rising defence and response costs.

Regulatory Trajectories Across APAC
While no two APAC markets are identical, the direction of travel is increasingly clear.

Jurisdictions such as Australia and India are strengthening enforcement regimes and significantly increasing maximum penalties. Others, including Mainland China, are expanding extraterritorial reach and tightening security and reporting obligations.

Across markets such as Indonesia, Japan, Malaysia, New Zealand, Singapore, South Korea, Thailand and Vietnam, recent reforms have formalised breach notification requirements and enhanced regulatory powers. In more developed regimes, experience shows that once enforcement becomes established, scrutiny can escalate rapidly and extend into adjacent regulatory frameworks.

Insurability and Loss Outcomes
As regulatory pressure increases across APAC, the financial consequences of cyber incidents become more difficult to predict. Whether cyber related fines, penalties and associated liabilities are insurable varies significantly across APAC, often depending on the nature of the conduct, the characterisation of the sanction and prevailing public policy principles.

In this environment, organisations can no longer assume that historic loss patterns or single jurisdiction assumptions provide an adequate basis for programme design. Regulatory change can materially shift loss outcomes, exposing gaps in limits, structure and coverage that may only become apparent once enforcement action is taken.

Emma Carolan,Head of Cyber Claims & Coverage, APAC, Aon,said, “ In a fast evolving APAC regulatory landscape, the worst time to discover gaps in your incident response or insurance program is in the middle of a major incident. Well designed simulations may allow organisations to surface those gaps in peacetime – whether in notification processes, internal approvals or policy structure – so they may be fixed before a claim.”Emma Carolan
Head of Cyber Claims & Coverage, APAC, Aon.

Submit a Comment Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • (no title)
  • South Korean banks and insurers hunt for overseas deals
  • French court finds Swiftair guilty of corporate manslaughter over Mali crash
  • Anthropic warns AI may pose ‘existential risks to humanity’ in IPO filing
  • Cyber claims accelerating sharply in APAC region, says Aon report

Categories

  • Articles
  • Banking & Bancassurance
  • Blog
  • Breaking News!
  • Briefs
  • Climate, Environment, Renewable Energy
  • Data
  • Disaster & Management
  • Eco/Invest/Demography
  • Editorial
  • Events
  • Facts
  • Features
  • Health
  • Indian News
  • Intermediaries
  • International News
  • Interviews
  • Life
  • Main Menu
  • Non-Life
  • Pandemic
  • Pension & Social Security
  • Policy
  • Regulation
  • Reinsurance
  • Risk Management
  • Simple
  • Technology
  • Trends, Facts
  • Uncategorized
  • Wealth Management/ Philanthropy
  • Workplace/Employee Benefits
  • Home
  • Articles
  • Blog
  • Data
  • Facts
  • Editorial
  • Interviews
  • Eco/Invest/Demography
  • Indian News
  • International News
  • Health
  • Non-Life
  • Pandemic
  • Technology
  • Risk Management
  • Reinsurance
  • Banking & Bancassurance
  • Wealth Management/ Philanthropy