There is a wide variation in how cyber insurers deal with non-malicious outages like CrowdStrike and as a result making loss estimates for the software failure is difficult.
Insurers including QBE, Tokio Marine, and Prudential will be subject to the new IAIS standard which will be applied in a two stage process starting in 2026.