Risk Controls, Under Control: What Cyber Insurers Want to See
Cyber insurers are not simply rewarding good security with cheaper premiums. The controls your business has in place can determine whether cover is available, how much protection is offered and on what terms.
I recently had the opportunity to ask a senior cyber insurance underwriter a fairly simple question.
Which cyber-security measures make the biggest difference to the cost of insurance?
I expected a list of controls, each potentially earning a business a better discount. The answer was more interesting.
It is now less about receiving a discount for having a particular control and more about whether the insurer considers the risk acceptable in the first place.
Every business is considered on its own merits. Its sector, size, systems, data and potential exposure all matter. However, there are several controls insurers generally want to see:
- Strong multi-factor authentication
- Tested backups that are offline or air-gapped and protected by MFA
- Business continuity, incident response and disaster recovery plans
- Effective patching procedures
- Regular employee awareness training and phishing simulations
- Network separation and segmentation
- Endpoint detection and response
- Effective security monitoring
- External testing and recognised accreditations
None of this will be surprising to a cyber-security professional. What may be less obvious to a business leader is how much these measures can affect the insurance available to them.
The controls can influence the amount of cover an insurer is willing to provide, the excess, the policy conditions and any exclusions. They can also affect whether the insurer is prepared to offer cover at all.
That changes the question businesses should be asking.
It is not simply, “Will better cyber security reduce our premium?”
It should be, “Can we demonstrate that our business represents an acceptable risk?”
The word demonstrate matters. It is not enough to say that backups are in place. When were they last tested? It is not enough to have MFA on some accounts. Does it protect email, remote access and administrator accounts? It is not enough to own security software. Who monitors it, and what happens when it raises an alert?
External testing and accreditations can help because they provide evidence that controls have been independently examined. But a certificate alone will not compensate for poor day-to-day security.
This conversation reinforced something I have learned from working alongside our engineers: good cyber security is rarely about owning more products. It is about whether the right controls are in place, whether they work and whether the business can prove it.
Cyber insurance still has an important role. But insurers increasingly expect businesses to do more than transfer the risk. They want to see that it is being properly managed.