Earlier quoted context omitted.
Not surprising. Having insurance just means you're a more attractive target now.
And if the interviews on infosec podcasts are any indication, insurance also means complacency on a management level because "we have insurance", and the insurers don't require you to actually make your security better. So being cyber-insured: - likely to have money to pay the ransom - probably not really implementing strong security policies - management more important than reality, so engineering buy-in unlikely wh…
With money? The cost gets passed on to the customers. In a few decades, the invisible hand of the market might push those customers to firms taking this issue seriously... But I think that to be quite unlikely.