Nvidia Buys Hugging Face for Over 11 Billion Euros
Eva Mickler
4 min read Nvidia is acquiring Hugging Face for around 11.1 billion euros; the contract was signed on ...
4 Min. read
The policy is in the drawer, MFA only on some access points. When the insurer reviews and denies a claim, what felt like risk transfer becomes a governance failure by the executive board-not the IT department.
Key Takeaways
RelatedCyber Insurance: Managing Risks and Avoiding Losses / NIS-2 Executive Liability Applies Despite Registration
A mid-sized company with around 200 employees had cyber insurance for years. Then ransomware struck: systems encrypted, operations halted. The damage landed with the insurer-and was denied. The application questionnaire had promised company-wide multi-factor authentication. In reality, MFA was only active on some access points. For the insurer, that gap was enough.
This pattern keeps surfacing in incident response cases. It’s rarely malicious intent. It’s the gap between what an organization *thinks* it has and what it can actually prove.
Many leadership teams read their cyber policy as a safety net and breathe a sigh of relief. Understandable-but risky. A cyber insurance policy doesn’t stop an attack. It’s financial risk transfer for when preventive and detective measures fail. It only pays out if all the fine-print obligations were met at the time of the attack. Signing the contract alone doesn’t count.
If you have a policy but no security architecture that lives up to it, you’ve created a false sense of security. This isn’t an IT tweak. It’s a leadership decision about risk transparency.
After years of ransomware waves, the short questionnaire has turned into a technical audit. Full MFA on email, VPN, remote access, cloud platforms, and admin accounts. Endpoint Detection and Response across the entire device fleet. Backups that work and are tested for recovery in an emergency. Consistent patch management. A documented incident response plan.
Fail to meet these, and in 2026 you’ll either get no policy at all-or one that won’t pay out when it counts. If you promise more in the questionnaire than you deliver in operations, you risk claim denial and, in some cases, complete loss of coverage. The Higher Regional Court of Schleswig confirmed this in a ruling in January 2025.
Many companies don’t have a pure security problem. They have a governance problem: the gap between promised and practiced controls rarely makes it into board papers.
Investments in tools, policies, and service providers create a clean picture on paper. In practice, three answers at C-level are often missing:
These questions too often get stuck in IT. NIS-2 pulls them upward: Since December 6, 2025, the NIS-2 Implementation Act has been in force. Around 29,500 companies in 18 sectors are affected. Senior management is personally liable – fines of up to 10 million Euro or 2 percent of worldwide annual revenue. Cybersecurity is a capital and liability decision. A purely technical to-do list falls short.
Three review steps separate a false sense of security from reliable risk transfer:
Background
Deeper dive on false security in the midmarket: We are putting an end to false security (enthus). The guest commentary by Wolfgang Hahl (CRO, enthus) appears in parallel on MyBusinessFuture.
If agreed security measures weren’t fully implemented at the time of the attack-such as MFA only being active on some access points. The denial then stems from policy obligations, not the damage itself.
Full MFA on critical access points, EDR on all endpoints, tested backups, patch management, and a documented incident response plan. Partial coverage counts as a gap.
Because NIS2 introduces personal liability, and a policy denial combined with operational downtime plus fines becomes a capital risk-not something to leave buried in IT tickets.
Compare your policy’s obligations against your actual control status: MFA adoption rate, last restore test date, EDR coverage. The gap is your governance mandate.
Read more on Digital Chiefs
Digital ChiefsModel Harness Instead of Model Marriage: Who Controls the AI Chain?Digital ChiefsWashington decides which AI is allowed to run hereDigital ChiefsTracking Startups: Speed Yes, Operational Risk NoMore from the MBF Media Network
Your cyber insurance won’t pay out-why this isn’t an isolated case
Image source: AI-generated (July 2026)