Blog
The Next Nation-State Cyberattack May Be Too Large to Insure

Cybersecurity risk is usually discussed as a technology problem, but a recent war game suggests the largest attacks may ultimately become a financial-stability problem.
Earlier this year, approximately 30 insurance executives gathered in New York for a closed-door simulation designed around an extreme but increasingly plausible scenario. In the exercise, a Chinese cyber operation disabled 5,000 American water utilities while geopolitical tensions around Taiwan were escalating. The simulated effects spread rapidly beyond water systems, contributing to broken water mains, hospital disruption, pressure on data centers, medical-supply problems, manufacturing impacts, and escalating demands on cybersecurity incident-response capacity. WIRED revisited the exercise on August 20 as part of its reporting on Volt Typhoon, the China-linked operation that U.S. officials say has spent years establishing access inside American civilian critical infrastructure.
The exercise was fictional. The underlying threat is not.
U.S. authorities have repeatedly warned that Volt Typhoon and related actors have compromised or sought access to communications, energy, water, transportation, and other critical infrastructure. The concern is that those intrusions may be intended not primarily for espionage but for disruption during a future geopolitical crisis.
The insurance war game introduced another question that receives far less attention. If thousands of critical-infrastructure operators were affected simultaneously, who would have enough money, technical expertise, and response capacity to restore them?
The answer from the exercise was uncomfortable because some participants concluded that a sufficiently large attack might exceed what the private cyber-insurance market could reasonably absorb.
Cyber Risk Changes When Thousands of Organizations Fail at Once
Insurance works partly because losses are distributed. An insurer can pay for a major incident at one customer because the majority of other customers are not experiencing the same catastrophic loss at the same time.
Systemic cyber risk challenges that assumption.
A vulnerability in widely deployed technology, a cloud outage, a supply-chain compromise, or a coordinated nation-state attack can affect large numbers of organizations simultaneously. When those organizations provide essential services, the financial consequences can spread well beyond the systems that were initially compromised.
The water-system scenario modeled in the exercise demonstrated how quickly those dependencies can propagate. A loss of water does not affect only the utility. Hospitals depend on water for patient care and sanitation. Data centers depend on water and cooling systems. Manufacturers rely on reliable utilities. Food and pharmaceutical supply chains depend on functioning infrastructure. Military installations rely on surrounding civilian services as well as dedicated systems.
The financial loss is therefore not confined to repairing compromised computers or controllers. It can include business interruption, physical damage, emergency response, healthcare disruption, supply shortages, lost productivity, legal expenses, and secondary losses across organizations that were never directly hacked.
That is why a nation-state infrastructure attack can begin as a cybersecurity event and develop into an economic event.
The Insurance Industry Becomes Part of the Incident-Response System
The war game also highlighted a role that is often invisible outside the cybersecurity industry. Insurance providers do not simply reimburse victims after an incident. They frequently help activate the response itself.
A cyber-insurance carrier may approve incident-response firms, forensic specialists, attorneys, negotiators, and other resources immediately after a breach. When incidents occur one organization at a time, this model can help victims mobilize expertise quickly.
A simultaneous attack on thousands of infrastructure operators creates resource scarcity.
The exercise assumed that many major incident-response firms were already operating at capacity. Insurance executives were therefore forced to decide which customers would receive scarce technical resources first. The scenario eventually required them to weigh commercial relationships against public-health consequences, economic losses, and national-security priorities.
That is an extraordinary transition for a private financial product.
An insurer could theoretically find itself deciding whether response capacity should go first to a large corporate client, a hospital-dense municipality, a defense-related facility, or an infrastructure operator supporting the greatest number of people.
At that point, cyber insurance becomes entangled with national resilience.
Nation-State Cyberwar Creates an Attribution Problem for Finance
The financial challenge becomes even more complicated when a cyberattack is connected to military conflict.
Insurance policies commonly contain exclusions related to war or hostile state action. Cyber operations complicate those clauses because attribution can take months, remain classified, or never reach a level of certainty that every party accepts.
An attack may be conducted by a government intelligence service, an affiliated group, a criminal organization acting with state tolerance, or an independent actor whose activity happens to benefit a state.
The technical evidence may not produce a clean legal conclusion.
For an infrastructure operator facing catastrophic losses, that uncertainty matters. If an insurer determines that a cyber event constitutes an act of war, policy exclusions may become relevant. If the insurer pays every claim resulting from a truly systemic attack, the scale of the losses could threaten the carrier itself.
Participants in the exercise confronted precisely this tension. CyberAcuView CEO Mark Camillo told WIRED that a sufficiently catastrophic scenario could become effectively uninsurable unless the industry relied on war exclusions, which would create its own crisis of public confidence. The exercise raised the possibility that governments may eventually need mechanisms similar to terrorism-risk backstops for truly systemic cyber catastrophes.
The financial architecture around cybersecurity may therefore need to evolve alongside the technical architecture.
Prevention Becomes More Valuable When Response Capacity Has a Ceiling
One of the most important conclusions from the exercise was that there are scenarios no amount of incident response can manage effectively after they begin.
If thousands of utilities require emergency technical assistance simultaneously, there may not be enough experienced professionals available. If specialized replacement equipment is needed across hundreds of sites, supply chains may not deliver quickly enough. If insurers receive catastrophic claims across an entire portfolio, financial capacity may also become constrained.
This changes the economic value of prevention.
When the response system has a finite ceiling, investments that reduce the probability or impact of compromise become more valuable than they appear when evaluated against an ordinary single-company breach.
Critical infrastructure therefore needs security architecture designed around containment and resilience rather than the assumption that every intrusion can be remediated after detection.
A compromised credential should not automatically provide unrestricted access to operational systems. One vulnerable device should not become an easy path into unrelated infrastructure. One cryptographic key should not provide persistent trust after the organization has reason to revoke it.
Segmentation, hardware-rooted identity, protected keys, auditable policies, and cryptographic lifecycle management can reduce the ability of one compromised relationship to spread across a larger environment.
The financial value of those controls becomes clearer when the alternative is a loss too large for the response ecosystem to absorb.
Volt Typhoon Makes Pre-Positioning More Important Than Malware
The concern surrounding Volt Typhoon is also different from the conventional ransomware model. U.S. officials and security researchers have described the operation as pre-positioning, where access is established inside critical infrastructure and maintained quietly rather than immediately monetized.
The attackers have also been associated with living-off-the-land techniques that use legitimate administrative functions and existing tools rather than introducing easily identifiable malware. That approach can make malicious activity look similar to normal operations.
For defenders, this creates a trust problem rather than simply a malware-detection problem.
If an attacker has obtained valid credentials and is using legitimate tools, the security system must understand more than whether a command matches a known malicious signature. It needs context around the identity, device, authorization, and relationship producing the action.
That is especially important across operational technology, where systems may prioritize availability and where unusual but legitimate maintenance activity can resemble malicious behavior.
Architecture therefore becomes critical. The infrastructure must be capable of establishing whether a device is trusted, whether credentials remain valid, whether cryptographic keys are protected, and whether access relationships still correspond to operational requirements.
The more effectively an attacker can imitate legitimate behavior, the more valuable verifiable trust becomes.
Cryptographic Risk Can Also Become Systemic
The insurance exercise focused on conventional cyberattacks, but its larger lesson applies to post-quantum security as well.
A cryptographic vulnerability can become systemic when the same algorithms, certificates, libraries, or identity mechanisms are deployed across enormous numbers of organizations. Unlike a software vulnerability that may be isolated to one product, widely adopted cryptography can sit underneath banking, healthcare, government, industrial systems, communications, and digital identity simultaneously.
This is why post-quantum migration is an infrastructure challenge rather than a narrow cybersecurity upgrade.
Organizations need to know where cryptography exists, which business or operational functions depend on it, how long protected information must remain confidential, and whether algorithms and keys can be replaced without disrupting the underlying service.
If large numbers of organizations wait until a cryptographic transition becomes an emergency, they may encounter the same resource problem surfaced by the war game. Specialists, hardware, integration capacity, testing environments, and vendor support are not unlimited.
The security community often describes cryptographic transition as a technical timetable. The insurance exercise suggests another way to think about it: transition capacity itself may become a scarce resource during a systemic event.
Planning before crisis conditions exist therefore has financial as well as technical value.
The Cyber Balance Sheet Is Becoming Part of National Security
The scale of modern digital dependence means cybersecurity increasingly influences economic resilience.
Critical infrastructure operators carry cyber risk directly, but the consequences also sit on the balance sheets of insurers, lenders, suppliers, investors, municipalities, healthcare systems, and governments. A large enough attack can move risk from one company to an entire economic network.
This is why cybersecurity increasingly resembles other forms of systemic risk.
Financial markets build capital buffers because they assume some institutions can fail. Energy systems maintain reserve capacity because individual generators can become unavailable. Defense planning relies on redundancy because no single asset can be assumed to survive every conflict.
Cybersecurity architecture increasingly requires the same thinking.
The objective is not to guarantee that no device will ever be compromised. It is to design systems so that compromise does not automatically propagate into systemic failure.
That means understanding dependencies before an adversary exploits them.
Where QVH Fits
Quantum Vision Holdings develops security infrastructure technologies focused on crypto-agile systems, hardware root-of-trust technologies, and post-quantum cryptographic development. QVH’s current website emphasizes environments where long-term security, resilience, adaptability, and operational continuity are important considerations, including government, defense and aerospace, healthcare, critical infrastructure, and data-sensitive enterprises.
The platform is being developed around several layers of cryptographic infrastructure. Ramanujan-1 is designed to support cryptographic key protection, device identity, and system integrity at the hardware level. PhotonFlux is hardware-based entropy technology under development to support cryptographic randomness and secure key generation. EnQrypta technologies are being developed around crypto-agile integration, cryptographic lifecycle management, policy enforcement, and post-quantum transition planning.
Thymos adds a discovery and assessment component by scanning environments for cryptographic vulnerabilities and helping identify where post-quantum transition planning may be required. QVH’s technology roadmap currently identifies Thymos as in development, EnQrypta Keystone, Source, and Forge as available for prospective pilot integration, PhotonFlux as in development, and the R1 Chip as having a PCB in production.
These technologies relate to the systemic-risk problem because resilience requires organizations to understand the trust relationships that connect their environments. When infrastructure is highly interconnected, risk cannot be evaluated solely by looking at each device or vendor independently.
Organizations need visibility into which identities, applications, cryptographic keys, certificates, devices, and third-party systems depend on one another. They also need the ability to change trust relationships when an identity, device, algorithm, or vendor becomes compromised.
The war game involving 5,000 water utilities was hypothetical, but the financial lesson is concrete. Cybersecurity eventually reaches a scale at which technical failure becomes economic failure, and the ability to recover after an incident cannot be assumed to be unlimited.
The strongest defense against an uninsurable cyber catastrophe may therefore begin long before the first claim is filed. It begins with infrastructure designed to understand dependencies, verify trust, contain compromise, and adapt security without waiting for crisis conditions to force the transition.
Quantum Vision, Infrastructure for the Quantum Era.
Sources
WIRED, “China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure. Is the US Ready?” (August 20, 2026)
https://www.wired.com/story/china-is-strapping-digital-bombs-to-civilian-infrastructure-is-the-us-ready/
WIRED, “What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out” (July 8, 2026)
https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/
Cybersecurity and Infrastructure Security Agency, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure”
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
National Institute of Standards and Technology, “Post-Quantum Cryptography”
https://csrc.nist.gov/projects/post-quantum-cryptography
Quantum Vision Holdings, “Platform Overview”
https://www.qvhinc.com/
Quantum Vision Holdings, “Technology Overview”
https://www.qvhinc.com/technology
Forward Looking Statement
This article contains forward-looking information within the meaning of applicable Canadian securities laws, including statements regarding the development of post quantum security infrastructure, anticipated industry migration toward post quantum cryptography, and the potential impact of evolving computational capabilities on cybersecurity frameworks.
Forward-looking information reflects management’s current expectations, estimates, projections, and assumptions as of the date of publication and is subject to known and unknown risks and uncertainties that could cause actual results to differ materially from those expressed or implied. Such risks include, but are not limited to, technological development risks, regulatory developments, adoption timelines for post-quantum standards, competitive factors, supply chain considerations, capital requirements, and general economic conditions.
Readers are cautioned not to place undue reliance on forward-looking information. Quantum Vision Holdings undertakes no obligation to update or revise forward looking information except as required by applicable securities laws.
more news

