Cyber insurance from the carrier's perspective
Most security leaders meet cyber insurance as a buyer: fill the form, argue about MFA screenshots, flinch at the premium, renew under mild duress.
Carriers meet cyber insurance as a risk factory. Premium is revenue. Claims (and the expenses of handling them) are cost of goods. Capital, reinsurance, regulation, and reputation constrain how much risk they can take. “Do we like this company’s security deck?” is only one input — and sometimes not the decisive one.
This essay is an empathy exercise for insureds and a fluency check for insurance readers. It is not a defense of every declination letter ever written. It is a clearer picture of what the other side of the table is optimizing for.
The carrier’s scoreboard is not your scoreboard
Your internal scoreboard might be: patch SLA, phishing fail rate, audit findings closed, uptime.
A cyber carrier’s scoreboard looks more like:
- Loss ratio / combined ratio on the cyber book (see our companion piece on what loss ratio is)
- Growth vs. profitability — writing premium that will not return as claims
- Capacity utilization — how much limit they can responsibly put into the market
- Accumulation risk — correlated loss across many insureds from one cause
- Treaty compliance — what their reinsurers allow them to write
- Franchise risk — claims handling quality, regulatory scrutiny, brand after a messy ransomware panel experience
A company can be a “good security shop” on an internal dashboard and still be an awkward fit for a particular carrier’s appetite this quarter.
Appetite is a product, not a vibe
Appetite means: which industries, revenue bands, geographies, technologies, and control postures a carrier (or program) wants to write right now.
Appetite moves because:
- Last year’s ransomware severity taught expensive lessons
- Reinsurance renewals tightened
- A vertical (healthcare, education, certain manufacturing) ran hot
- Systemic scenarios (widespread vulnerability, major cloud dependency) got restressed
- Leadership decided to grow or shrink cyber as a line
So when you hear “the market,” it is often shorthand for many appetites moving together — not a single conspiracy against your ticketing system.
Why “we have MFA” is necessary and not sufficient
Carriers learned — painfully — that certain control failures correlate with large cyber losses: missing MFA on remote access, weak backup/restore reality, flat networks, unpaid attention to privilege, email paths that make BEC easy, internet-facing remote tools left exposed.
That is why applications and subjectivities obsess over a short list. It is not because underwriters think those controls equal “secure.” It is because, in portfolio experience, those failures show up in claim files.
But carriers also know:
- Attestation is gameable
- Screenshots age out
- A control can be “deployed” and still bypassed
- The exposed attack surface can contradict the questionnaire
Which is why serious underwriting conversations are moving toward evidence of exploitable exposure, not only policy PDFs. We have written about that shift in Kill the questionnaire. From the carrier chair, the point is simple: price and select on what drives claims, not on what is easy to ask.
Accumulation: the fear behind “systemic”
Property insurance worries about hurricanes hitting many homes. Cyber worries about one cause hitting many insureds:
- A critical vulnerability in a widely deployed VPN or email gateway
- A major cloud or identity provider disruption
- Ransomware crews industrializing against a common remote-access pattern
- A software supply-chain event
Even if your company looks fine in isolation, you sit inside a portfolio. If the carrier is already heavy on your industry, your cloud, or your remote-access stack, the underwriter may decline or shrink limit for reasons that feel personal and are actually portfolio math.
This is also why war / hostile-cyber and catastrophic cyber wording became so contested after high-profile incidents: carriers and reinsurers are trying to define which losses are fortuitous retail cyber vs. something closer to systemic / hostility — debates with real legal and capital consequences. Your broker lives in those wording fights; your CISO does not need to litigate them alone, but you should know they exist.
Pricing is not a moral judgment
Premium reflects (imperfectly): expected loss, uncertainty, expenses, capital cost, competitive position, and how much the insurer wants your segment.
A high premium does not mean “you failed security.” A low premium does not mean “you are safe.” Cheap cyber after a soft market has historically been a warning light for someone — often the carrier’s future loss ratio.
Security leaders help most when they improve real loss drivers and make that improvement legible to underwriting — not when they argue that premium should track their favorite framework score.
Claims are part of the product
From outside, insurance looks like underwriting. From inside, claims and breach-response panel performance are the product customers remember.
Carriers care whether:
- Notice happens early enough to help
- Panel firms contain cost and chaos
- Coverage fights destroy trust
- Ransomware payment pathways are lawful and controlled
- Business interruption documentation is coherent
A security team that treats the insurer as an enemy until claim day makes claim day worse. A security team that understands the carrier’s incentives — reduce severity, document timelines, involve panel early — gets more help.
What a declination often means (decoded)
| What you hear | What it often means |
|---|---|
| “Not a fit for our appetite” | Industry, size, or tech stack outside guidelines — or portfolio full |
| “Unable to offer terms” | Risk above what authority / treaty allows at any sensible price |
| “Subject to…” long list | Writable if controls become real and provable |
| “Limited ransomware sublimit” | Severity concern; not necessarily a personal insult |
| “Need more information” | Submission incomplete or something in OSINT contradicts the form |
Push your broker for the real reason in private. Sometimes it is fixable (controls, scope, limit). Sometimes you need another market.
How to brief leadership after you understand this
Bad brief: “Insurance companies are ridiculous; we have SOC 2.”
Better brief: “Carriers are managing a portfolio of breach costs under reinsurance constraints. Our job is to reduce claim-relevant exposure, prove it, and pick a structure (limit, retention, sublimits) that matches how we’d actually get hurt. Premium is an output of that system — not a grade on our culture deck.”
Where BreachBits fits from the carrier side
We built BreachRisk for the question carriers already ask in plain language: can an attacker get in, and is that getting worse? Continuous discovery, attacker emulation, and verified findings are underwriting-shaped signals. They do not replace appetite, wording, or claims. They make the technical half of selection less dependent on hopeful checkboxes.
If you are an insured reading this: use it to have a more adult conversation with your broker. If you are in insurance reading this: we are fluent on purpose — because the channel only works when security vendors respect how capital actually behaves.
Next: the metric everyone name-drops — what loss ratio is, without the mythology.