"So if you're a policy holder and get hacked, you get paid. What about your customers/users who actually suffer?"
You offer them two pennorth of fraud protection or whatever - which you claim on your insurance.
But realistically the insurers have got to start laying down the precautions their clients take. No security, no payout.