What Cyber Underwriting Is Missing

Cyber underwriting has become adept at measuring technology. The missing signal may be the condition of the organization responsible for keeping it secure.

Organizational Deterioration

Since the ransomware crunch of 2020, cyber underwriting has gotten steadily more external and more technical: attack-surface scans at quote, patching cadence wired into the catastrophe models, and third-party telemetry now feeding the major vendor platforms. Global cyber rates have kept falling through early 2026 even as claim frequency rises.

All of cyber underwriting measures the current state of technology. Almost none of it measures whether the organization behind those controls is deteriorating: losing the people who understand its systems, struggling through major organizational change, or cutting the resources needed to sustain operations.

Is that kind of operational strain visible from the outside and distinguishable from the ordinary noise any large company produces? To find out, we traced public signals in the year before three major breaches: TCS, CDK Global and Change Healthcare – plus a peer control study for TCS. In each case, the deterioration left a public, dated record months before the loss.

The signals are public posts: employee reviews on Glassdoor, AmbitionBox, Indeed and Blind, and practitioner and customer threads on Reddit. We ignored general dissatisfaction and looked for dated observations tied to identifiable roles, in four categories: organizational instability, security dysfunction, financial distress, service degradation.

The outsourcer

The connection is most direct at TCS, a services business where the workforce is the product it sells. Through 2025, it held an A on SecurityScorecard, a rating that spans everything from patching cadence to how exposed its people are to being targeted.

Across the 201 signals, the recurring themes were constant reorganization, experienced staff leaving faster than they were replaced, and people put on work they weren't equipped for. Four months before the M&S attack, a TCS consultant described being presented to clients as a cybersecurity analyst despite never having worked in that role. Months earlier, a SOC analyst listed "slow incident response" among his team's problems.

In April 2025, attackers called the IT helpdesk TCS had run for Marks & Spencer since 2018 and talked staff into a reset; M&S put the profit impact near £300 million. Jaguar Land Rover followed months later, at an estimated £1.9 billion cost to the UK economy. TCS ran IT there too, though the public record doesn't establish that its people were the ones socially engineered.

The obvious objection is that every Indian IT major generates this kind of noise. So we ran the same collection on Infosys, Wipro and HCLTech: 501 signals across the three, against TCS's 201. All four show reorganization noise. But security staff are about 8% of TCS's signals against roughly 3% at the nearest peers. While the baseline volume varies by firm, only TCS showed a concentration of security-role complaints describing problems within the security function itself.

The buyout

At CDK, the pressure came through ownership. Brookfield took the company private in 2022 in a deal backed by roughly $5.8 billion of debt, and public posts began documenting the operational consequences.

From June 2023 to the day before the attack, employees across engineering, support, sales and training described the same sequence: repeated layoffs, work shifted to the outsourcing partner Genpact, and the people who understood the systems walking out with each cut. A trainer who left in February 2024 traced it to the top: a 30% margin wasn't enough for the CEO, so he cut across the board to reach 40%. That same month, a director's advice to management consisted of three words: "stabilize the talent drain."

Security leadership also became harder to identify. David Hahn, CDK's first publicly identifiable CISO – a role the company first filled in 2020 – joined Ballistic Ventures as CISO-in-Residence in December 2022. We found no public evidence of a successor before the ransomware attack. Across dealership forums, users described repeated outages, with one writing during a July 2023 incident that the platform was "up for 3 minutes and then down for 30."

In June 2024, BlackSuit ransomware hit and froze nearly 15,000 dealerships, about $1 billion in dealer losses. CDK never disclosed the intrusion vector, so no causal link can be drawn. What the public record does show is that the organization operating those systems had been under visible operational pressure for a year beforehand.

The pattern is structural: across private-equity portfolios, where the incentives are the same, S-RM found 72% of firms had a serious cyber incident in their portfolio within three years. In February this year, Bloomberg reported on Ivanti, which Clearlake Capital had taken private. Cost-cutting there stripped out the engineers who understood the company's VPN code, and Chinese state hackers exploited the resulting flaws to reach US government and corporate networks. Some government and corporate buyers, Bloomberg reported, now factor private-equity ownership into how they assess security products. In the same report, Rob Leahy, former CIO of NASA's Goddard Space Flight Center, said ownership structure should be part of any product risk assessment: "Are they investing in the future or are they not?"

The rollup

Change Healthcare was assembled by serial acquisition and run for margin, where cost-cutting meant deferring integration. Optum, UnitedHealth's health-services arm, absorbed it in October 2022.

Across the 142 signals we collected from Change and its new parent, employees repeatedly described experienced staff leaving and the loss of institutional knowledge. One review summarized the effect as "letting the knowledge walk out the door." Another, posted in November 2023, three months before the breach, described acquired companies as "not integrated into network sometimes ever."

In February 2024, attackers got in through a single internet-facing Citrix portal with no multi-factor authentication (MFA). By the CEO's later congressional testimony, it ran on technology acquired in 2022 that had never been brought under the company's own MFA policy. The breach reached 192.7 million people, at a cost UnitedHealth put at $3.09 billion for 2024 alone, the largest healthcare data breach on record.

Change is one of three Optum acquisitions to have been breached since 2023; Solutran and Episource followed, the last hit twice, in 2023 and in 2025. Two years after the attack, UnitedHealth was still consolidating 18 acquired medical-record systems down to three. Acquisitiveness itself leaves a statistical trace: a 2025 study of 5,072 U.S. firms found the more a company acquires, the more breaches it experiences, the effect growing when acquirer and target come from different businesses.

Organizational deterioration is already familiar to cyber insurers. It appears in breach investigations, claims files and post-loss reviews, where staffing shortages, restructurings and operational strain often help explain how technical failures developed. By then, however, those signals are explanatory rather than predictive. The cases here suggest that some of the same patterns are visible months earlier in public operational data.

Three cases chosen for how they ended cannot establish predictive value on their own; that requires knowing how often the same signals appear at companies that never suffer a loss. The TCS peer comparison is a first attempt at that question.

Cyber underwriting has become increasingly sophisticated at measuring the state of the technology. Whether the organization behind those controls is changing in ways that affect cyber resilience is not yet part of how the risk is priced.

Read More