started · updated
CNA Financial ransomware underscores need for proactive cyber insurance
In March 2021, CNA Financial Corporation, one of the largest U.S. commercial insurers, detected a sophisticated ransomware attack that disrupted internal systems and exposed personal information of employees, contractors and some policyholders. The incident prompted immediate activation of incident‑response procedures, engagement of cybersecurity experts, and notification of law‑enforcement agencies including the FBI. CNA’s experience illustrates that insurers, which hold extensive sensitive data, are attractive targets and must treat cyber risk as an enterprise‑wide governance issue.
Industry analysts note a shift away from purely claim‑based cyber insurance toward a prevention‑focused model. Insurers are increasingly embedding proactive services—such as round‑the‑clock legal counsel, incident‑response expertise, employee training, and continuous threat monitoring—directly into policies. This pre‑loss engagement aims to reduce vulnerabilities, improve claim outcomes and lower overall costs, reflecting a broader move toward risk‑management as a core insurance offering.
Entities
CNA Financial Corporation · Duane Folkard · Federal Bureau of Investigation