A reinsurer is paying $575 million for a security company that sells insurance
On 19 August 2026, Munich Re announced it had agreed to acquire At-Bay, Inc., the US insurtech that pairs cyber insurance with proactive cybersecurity for small and mid-sized enterprises, at an enterprise value of USD 575 million. Closing is expected in Q1 2027, subject to regulatory approvals. At-Bay, founded in 2017, has grown into a top-10 US cyber insurer with gross written premiums of USD 278 million, and the business will sit under HSB within Munich Re Specialty.
The price is worth pausing on. An enterprise value a little over twice gross written premium is not what you pay for a book of SME cyber policies in a softening market. It is what you pay for the machinery around the book: the scanning infrastructure, the security telemetry, the claims data joined to that telemetry, and a distribution model in which the insurer is also the insured's outside security monitor.
Munich Re said as much in its release. The group framed the acquisition as positioning for a cyber market that is, in its words, rapidly evolving from standalone coverage towards integrated, continuously managed risk mitigation platforms. That sentence deserves attention in India, because it comes from one of the reinsurers standing behind Indian cyber capacity. When a capacity provider of that weight decides that scanning and intervention belong inside the insurance product, the terms Indian insurers can offer, and the conditions they attach, eventually follow.
What InsurSec actually means
InsurSec is shorthand for a model in which underwriting and security operations are one business. In the At-Bay version, the insurer scans an applicant's external attack surface before quoting, prices on what it observes rather than what the proposal form claims, and then keeps scanning for the life of the policy. When a new exposure appears, an open remote-access port, a vulnerable appliance, credentials in a breach dump, the insurer alerts the insured and in some cases works the fix with them, because every avoided incident is an avoided claim.
Three things distinguish this from a conventional cyber placement:
- The assessment is continuous, not annual. A proposal form describes one day. A monitored insured is observed every day between inception and expiry.
- The insurer has an economic reason to intervene. Loss prevention is not a value-added brochure service; it is how the loss ratio is managed.
- The data compounds. Scan findings joined to claims outcomes tell the insurer which exposures actually produce losses, which sharpens both pricing and the interventions.
Indian brokers have already seen the front half of this model arrive. Most large cyber carriers now run an external scan before binding, a shift we covered in detail in how security ratings and attack-surface scans work in Indian cyber underwriting. What the At-Bay acquisition signals is the back half: the scan does not stop at binding, and the policy is written on the assumption that it continues.
Indian mid-market buyers ask for exactly this and rarely get it
The gap InsurSec fills is one Indian mid-market buyers describe in almost every cyber conversation. A company with 200 to 2,000 employees typically has no security operations centre, a small or outsourced IT team, and no one whose job is to watch the external perimeter. What such a buyer wants from a cyber insurer is not just a promise to pay after an incident but someone competent watching for the incident. What they are usually offered is a questionnaire, a premium, and an annual renewal call.
The timing of the Munich Re move also lands in a favourable market for buyers. The Marsh Global Insurance Market Index for Q2 2026 recorded Asia composite rates falling 5% in the quarter, led by cyber. A soft cyber market gives Indian mid-market insureds negotiating room they did not have in 2021 or 2022, and services are the natural thing to negotiate for when rate reductions start to flatten. A broker who can extract monitoring, pre-binding scan reports shared with the insured, or funded remediation support from a carrier is converting soft-market conditions into something durable.
Uptake remains the structural problem. Indian SME and mid-market cyber penetration is thin relative to the exposure, for reasons we examined in why MSME cyber insurance uptake stays low: affordability, low awareness, and products that feel abstract until the first incident. A policy that arrives with visible, continuous security value is one plausible answer to that abstraction problem, which is precisely the commercial thesis Munich Re just paid for.
Could an InsurSec product be filed in India?
There is no regulatory wall that stops a scan-led cyber product in India, but the construction questions are real.
Product filing
Commercial lines products in India operate under IRDAI's use and file regime, so an Indian general insurer can bring a cyber wording with scan-based conditions to market without prior approval, provided the wording is filed and the rating logic is defensible. The harder design question is where the security service sits. If continuous monitoring is a policy benefit, it belongs in the filed wording and its cost sits inside premium. If it is a separate service agreement with an affiliated or third-party security vendor, the insurer keeps the filing simple but loses the contractual tightness that makes the model work, because the policy conditions then reference a service the policy does not itself provide.
Who brings the capability
The realistic near-term path is not an Indian carrier building an At-Bay. It is capability arriving through the reinsurance stack: treaty terms that reward monitored portfolios, reinsurer-provided scanning tools offered to cedants, and facility arrangements where the scanning vendor is specified. Brokers should expect the first visible artefact to be underwriting requirements, not a new product brochure: submissions that must include a scan report from a named tool, and quotes conditioned on findings being closed.
DPDP and the scanning data problem
Continuous scanning of an Indian insured raises questions under the Digital Personal Data Protection Act, 2023 that a US-built model does not have to answer.
Most of what an external scan collects is technical rather than personal: IP addresses of corporate infrastructure, open ports, software versions, certificate status. But the highest-value underwriting signal, compromised-credential intelligence, is different. Breach dumps contain employee email addresses and passwords, which are personal data of identifiable Indian data principals. An insurer that continuously ingests, stores, and acts on that data is processing personal data and needs a lawful basis for doing so, along with purpose limitation and retention discipline.
The practical points a broker or buyer should force into the placement:
- Who is the data fiduciary for scan-derived personal data: the insurer, the ratings vendor, or both, and under what contract.
- What happens to scan data on declined or non-renewed risks. A dossier of a company's vulnerabilities held by a counterparty with no continuing relationship is itself a security exposure.
- Whether scan findings can migrate across functions, from underwriting into claims investigation, and whether the insured has notice of that.
- Retention and deletion commitments in writing, not in a privacy policy that can change.
None of this makes the model unworkable in India. Employee credential monitoring is defensible processing when it is disclosed and scoped. But the contracts have to be drafted for DPDP from the start, and a buyer who signs a monitoring-linked policy without asking where the scan data lives has created a new exposure while insuring an old one.
The coverage consequence: security conditions move from the proposal form into the policy
The underwriting mechanics of a scan-led market show up in the wording long before any InsurSec product is filed here. Four artefacts are already appearing in Indian cyber placements and will become standard.
Scan-based pre-binding conditions. The quote is issued subject to specific external findings being closed: an exposed RDP port shut, an end-of-life server patched or isolated, email authentication configured. These are testable and time-bound, which is their virtue; the insurer re-scans and the condition is objectively met or not.
Subjectivity deadlines. Where a finding cannot be closed before inception, cover binds with a subjectivity: remediate within 30 or 60 days or the related cover restricts, a ransomware sublimit drops, or a co-insurance percentage applies. The dangerous version is the silent one, where the deadline passes unnoticed and the restriction takes effect automatically.
MFA warranties. A statement that multi-factor authentication is enforced on all remote access and privileged accounts, elevated from proposal-form answer to policy warranty. Under Indian policy interpretation, breach of warranty can discharge the insurer from liability even where the breach did not cause the loss, which makes an absolute MFA warranty far more dangerous than most insureds realise.
EDR conditions. A requirement that endpoint detection and response is deployed and operational across a stated percentage of the estate, sometimes drafted as a condition precedent to liability for ransomware and business email compromise claims.
How to avoid a declinature for drifting out of a security condition mid-policy
The novel claims risk in a monitored policy is drift. The insured was compliant at inception, then something moved: MFA was temporarily disabled during a migration and never re-enabled, EDR agent coverage decayed as new machines were imaged without it, an acquisition brought unscanned infrastructure inside the perimeter. Twelve months later a claim arrives and the insurer's own scan history shows the insured outside a condition for five of them.
The defence is operational, and it belongs to the insured with the broker as auditor:
- Extract every security condition into a register at binding. Not the whole wording, just the testable obligations: MFA scope, EDR coverage threshold, patching timelines, backup requirements, notification duties. One page, named owner per line.
- Calendar the subjectivity deadlines and treat them like premium payment dates. Evidence of completion goes to the insurer before the deadline, and the insurer's acknowledgement goes in the placement file.
- Tie the register to change management. Any migration, acquisition, or vendor change triggers a check against the register before it goes live, because that is exactly when drift happens.
- Negotiate remediation windows into the wording. The clause you want says the insurer will notify identified drift and the insured has a defined period to remediate before any cover consequence, rather than a condition whose breach silently suspends cover from the moment of drift. In a monitored policy this is a fair ask: if the insurer is scanning continuously, it sees the drift, and a model built on intervention should intervene rather than wait to decline.
- Keep dated evidence. Screenshots, configuration exports, and vendor confirmations with dates. A drift dispute is an evidence dispute, and the insurer arrives with a scan log.
The limit conversation matters as much as the conditions. A monitored policy that responds cleanly is worth little if the limit is a fraction of the realistic loss, which is why the register exercise should sit alongside proper limit sizing through cyber risk quantification.
What brokers should do between now and Q1 2027
The Munich Re and At-Bay transaction will not change an Indian placement this quarter. What it changes is the direction every serious cyber market is moving, and the broker work that pays off is preparation for a market where the insurer sees the client continuously.
Three concrete moves. First, run outside-in scans on cyber clients before submission as standard practice, so the first scan the market sees is never the client's worst. Second, start treating security conditions as a managed register rather than boilerplate, on current placements, not just future ones, because MFA and EDR language is already in Indian wordings today. Third, in a market where Asia cyber rates are falling, spend the soft-market negotiating room on structure: remediation windows, written subjectivity confirmations, conditions drafted narrow and testable, and DPDP-clean data terms around any scanning the insurer performs.
All of that work runs through the wording. Sarvada gives commercial insurance brokers structured, searchable access to insurer policy wordings and the intelligence around them, so a cyber placement can be argued clause by clause: which carrier drafts MFA as a warranty and which as a claim-linked condition, where remediation windows have been conceded, and how subjectivities are expressed. Request Access to bring that depth to your next cyber renewal.