With the acceleration of digitalisation, cybersecurity has gained critical importance across a wide spectrum, from individuals to global corporations. The diversification of threats targeting digital infrastructure has rendered traditional security approaches inadequate and has also triggered a transformation in the insurance industry. Not only physical risks but also digital risks are now insured, and the concept of "cybersecurity and insurance" has come to the fore (Wang & Jones, 2021).
While cybersecurity aims to protect information systems, networks and digital data from malicious attacks, cyber insurance aims to provide coverage for the financial and reputational losses these attacks may cause (Marotta et al., 2017). Organisations in particular must protect themselves against ransomware, data breaches and service disruptions such as DDoS attacks not only with software-based security measures but also with financial protection.
The insurability of cyber risk has presented several technical and legal challenges. First, quantitatively assessing digital risks is inherently difficult. Actuarial calculations, which form the basis of insurance, rely on historical data; cyberattacks, however, are often dynamic, unpredictable and constantly changing (Biener, Eling & Wirfs, 2015). Consequently, uncertainty about the scope, limits and exclusions of cyber insurance policies can arise for both insurers and insureds.
Another important dimension is regulation. Frameworks such as the European Union's General Data Protection Regulation (GDPR) and Türkiye's Personal Data Protection Law (KVKK) impose severe sanctions on organisations in the event of a data breach. In this context, cyber insurance is considered not only a financial safeguard but also a compliance tool (Romanosky et al., 2019). Through such policies, organisations can manage not only their financial losses but also their legal liabilities.
The relationship between cybersecurity and insurance requires a proactive risk management approach. Insurers not only provide coverage against risks; they also offer risk assessments, preventive solutions and crisis management support to their clients (Eling & Schnell, 2016). Cyber insurance products therefore differentiate themselves from traditional products by emerging as "service packages".
As a result, cybersecurity and insurance have become strategic imperatives in the complex risk environment of the digital age. Organisations seeking to secure their digital assets must consider not only the technology itself but also its financial implications. In the future, the integration of technologies such as artificial intelligence and big data analytics into the insurance sector is expected to lead to more flexible, predictive and personalised cyber insurance models.