Cyber insurance is becoming a much more familiar part of business risk management in Singapore. As phishing, ransomware, business e-mail compromise and other forms of cybercrime become more sophisticated, companies are increasingly recognising that cybersecurity tools alone may not be enough. A growing number are now looking at insurance as an additional layer of financial protection when something goes wrong.
One recent incident involving Singapore-based freight forwarding company UEI Logistics shows why interest is rising. In November 2025, two employees received what looked like a routine payment request from a long-standing Chinese shipping partner. The e-mail asked the company to transfer US$18,288, or about S$23,200, to a different bank account, supposedly because the original account was facing high government transaction taxes.
The message was convincing enough to look genuine at first glance. However, the employees felt something was not quite right and escalated the matter to managing director Terrence Tan. After checking more closely, he noticed that the sender's e-mail domain was slightly different from the one normally used by the company's partner. A direct phone call confirmed that the request was fraudulent.
A Convincing Scam Becomes a Wake-Up Call
The attempted fraud highlighted how much business e-mail compromise has evolved. Scammers are no longer relying only on poorly written messages or obvious impersonation attempts. Increasingly, they study real business relationships, mimic familiar communication styles and create fake domains that can easily be mistaken for legitimate ones.
For UEI Logistics, the incident was serious enough to trigger a broader review of its cybersecurity posture. The company had already been receiving more phishing e-mails, but this particular attempt demonstrated how close a routine-looking message could come to causing a substantial financial loss.
In response, the company strengthened its defences by deploying a threat detection system from ST Engineering to monitor suspicious activity around the clock. It also purchased a cyber insurance policy from MSIG, giving the company another form of protection if a future attack results in an actual breach or business disruption.
What Cyber Insurance Can Cover
UEI Logistics now pays an annual premium of S$980 for S$300,000 in cyber coverage. Depending on the circumstances, the policy can help cover costs such as forensic investigations, legal support and hardware replacement following a cyber incident.
This is one of the main reasons cyber insurance is attracting more interest. When a company suffers an attack, the cost is often much greater than simply replacing a compromised computer. Businesses may need cybersecurity specialists to investigate what happened, lawyers to advise on legal obligations, public relations support to manage reputational damage, or replacement equipment to restore operations.
In more serious cases, there may also be costs related to business interruption, data recovery, notification requirements and regulatory investigations. Insurance cannot prevent the breach itself, but it can help reduce the financial impact of the recovery process.
Demand Has Been Rising Across Singapore
Insurers and brokers in Singapore say interest in cyber insurance has been increasing noticeably, particularly over the past two to three years. Eight insurers and brokers reported stronger demand, with more companies either purchasing policies for the first time or making enquiries about available coverage.
Technology companies and financial institutions remain among the most active buyers. Banks, fintech businesses and cloud service providers generally face high levels of cyber risk because they handle sensitive data, financial transactions and critical digital infrastructure.
However, demand is no longer concentrated only in technology-heavy sectors. As more traditional businesses digitise their operations, cyber insurance is becoming relevant across a much wider range of industries, including:
The common factor is digital dependency. Once a company relies heavily on e-mail, cloud platforms, online payments, connected systems or customer databases, a cyber incident can quickly become an operational and financial problem.
Policy Sales Are Growing Rapidly for Some Insurers
Several insurers have reported strong growth in the Singapore market. US-based specialist insurer Markel said its local cyber insurance business has been expanding steadily since 2022. In 2023 and 2024, the number of policies it sold each year reportedly increased by between 56% and 125%.
QBE Asia also saw solid growth, with the number of cyber policies sold to Singapore companies increasing by around 25% to 30% between 2024 and 2026. These figures suggest that cyber insurance is moving beyond a niche product used mainly by large corporations.
Other major players are seeing similar signs of growing interest. AXA XL and insurance broker Marsh reported more policies being purchased by first-time buyers, along with higher enquiry volumes between 2023 and 2025. AWG Insurance Brokers and Howden also observed greater uptake, although they did not disclose specific figures.
MSIG and Allianz similarly reported an increase in customer enquiries in Singapore, reinforcing the view that more companies are actively considering cyber insurance even if they have not yet purchased a policy.
Falling Premiums Are Making Coverage More Accessible
Another factor supporting adoption is improving affordability. As the cyber insurance market matures and insurers gain more experience pricing different types of risk, premiums have become more competitive in some areas.
This matters particularly for small and medium-sized businesses. Cyber insurance was once viewed as something mainly relevant to banks, technology firms or large multinational corporations. Smaller companies often assumed the premiums would be too expensive or the policies too complicated.
That perception is gradually changing. More insurers are offering products designed specifically for SMEs, with clearer coverage structures and lower entry costs. As premiums fall and policy options become easier to understand, smaller businesses may find it more practical to include cyber insurance in their broader risk management strategy.
Why Digitalisation Is Increasing Exposure
Singapore's highly digital business environment has created enormous efficiency, but it has also expanded the number of ways companies can be attacked. A small logistics firm may depend on e-mail, digital invoicing, cloud storage, customer databases and online banking every day. If even one of those systems is compromised, the consequences can spread quickly.
Business e-mail compromise is especially dangerous because it targets human trust rather than software vulnerabilities. Attackers may impersonate executives, suppliers or long-term partners and ask employees to approve payments or change bank account details.
Ransomware creates a different kind of threat, potentially locking employees out of critical systems and halting operations. Data breaches can expose personal information, commercial records or customer details, creating additional legal and reputational risks.
The more digitally dependent a business becomes, the greater the potential impact when those systems are disrupted.
Cyber Insurance Is Not a Replacement for Cybersecurity
Although cyber insurance is becoming more popular, it should not be treated as a substitute for proper security controls. Insurers increasingly expect businesses to demonstrate that they are taking reasonable precautions before offering coverage or favourable premiums.
That can include measures such as multi-factor authentication, endpoint protection, employee security training, secure backups and regular vulnerability management. Companies with weak security practices may find coverage more expensive, more limited or harder to obtain.
In that sense, cyber insurance can encourage stronger cybersecurity practices. Businesses may need to improve their controls before qualifying for certain policies, while insurers benefit from reducing the likelihood of large claims.
The most effective approach is therefore layered. Technical security reduces the likelihood of an incident, employee awareness helps stop social engineering attempts, and insurance provides financial support if prevention measures fail.
Small Businesses Face Real Risks Too
One of the most important changes in the cyber insurance market is the growing recognition that smaller companies can be just as vulnerable as large enterprises. In some cases, they may be easier targets because they have fewer security resources and less specialised IT staff.
A single fraudulent payment request or ransomware infection can have a much larger impact on a small company's cash flow than it would on a large multinational. Recovery costs can also be significant, particularly when external cybersecurity specialists or legal advisers need to be brought in quickly.
For small businesses, cyber insurance can therefore act as a financial safety net. It does not eliminate the disruption caused by an attack, but it can make the difference between a manageable incident and a serious financial crisis.
Businesses Are Becoming More Aware of Their Exposure
The rise in cyber insurance enquiries suggests that business attitudes are changing. Cybersecurity is increasingly being treated as a management and financial issue rather than something handled only by IT departments.
Boards and senior managers are beginning to ask broader questions. What would happen if the company's systems were unavailable for several days? How much would a data breach cost? Would the business have enough cash available to fund an investigation and recovery?
These questions naturally lead to conversations about insurance. Just as companies insure physical property, vehicles and other business assets, digital operations are increasingly being viewed as assets that also need financial protection.
Final Thoughts
Cyber insurance is gaining traction in Singapore because the nature of business risk is changing. Companies are more connected, more dependent on digital systems and more exposed to sophisticated scams than ever before. At the same time, broader coverage and more competitive premiums are making cyber insurance easier for businesses of different sizes to consider.
The UEI Logistics incident shows how quickly a convincing e-mail can create a potentially costly situation. In that case, alert employees identified the scam before money was transferred, but the experience demonstrated how easily an ordinary business process could be exploited.
For many companies, the lesson is not that insurance alone will solve the problem. Strong cybersecurity controls, employee awareness and sensible internal procedures still form the first line of defence. Cyber insurance simply adds another layer of resilience, helping businesses recover more effectively when even good security measures are not enough.


Comments 0