Cyber insurance
15 articles.
Three ways to measure cyber risk — and why only one proves anything
Scanners, ratings services, and pen-test firms each see part of the picture. Here's why a proven, attacker's-eye view is the only one you can actually price a decision on.
Portfolio heat vs one account: how carriers watch cyber risk
Underwriting a single company is only half the job. Carriers and MGAs also watch books — industries, technologies, accumulations, and correlated loss. Why 'the market' feels like weather, and what portfolio heat means for your renewal.
Why underwriters obsess over a short list of controls
MFA, EDR, backups that restore, privileged access, email security — not a random security sermon. How those asks map to claim patterns, show up as warranties and subjectivities, and what 'checkbox compliance' still misses.
Application → bind → renew: the cyber insurance lifecycle
What actually happens between 'we need cyber' and 'you're on risk' — then what renewals reopen. A practical lifecycle map for CISOs and finance leaders on their first or fifth policy.
Attestation vs evidence: why "yes we patch" isn't underwriting data
Applicants answer questionnaires hopefully. Attackers don't read the PDF. Here's how to map cyber-insurance questions to outside-in evidence — and why verified exposure beats another checkbox.
What is loss ratio? (and why cyber insurance people won't stop saying it)
Loss ratio is incurred losses divided by earned premium — the basic scoreboard for whether an insurance book is paying out more than it takes in. Here's the plain definition, its cousins, and how to hear it in a cyber conversation without mythology.
Kill the questionnaire — what underwriters actually need instead
The cyber insurance questionnaire was always a proxy for one question: can an attacker get in? Here's what replaces the form when you can prove outside-in exposure instead of asking applicants to attest to it.
Why verified findings are the only questionnaire replacement that sticks
If what replaces the cyber questionnaire cries wolf — immaterial perimeter noise, unverified estimates — underwriters go back to the form. Verification is how Kill the Questionnaire earns trust.
Cyber insurance from the carrier's perspective
Premium is the input. Claims are the cost. Capacity, appetite, accumulations, and wording are the constraints. Why a strong security story still gets declined — and what carriers are actually optimizing for.
From application to bind: less friction, better signal
Kill the Questionnaire as a process — what gets flagged before bind, what applicants stop typing, and how brokers and carriers move faster without swallowing unverified ratings noise.
What a broker should ask for beyond the form
A practical checklist for brokers: continuous external proof, verified findings, and a trendable breach-risk view — questions that separate claim-relevant signal from ratings noise and questionnaire hope.
Who's who in cyber insurance: carrier, MGA, broker, reinsurer
Why three people ask for the same questionnaire — and still aren't the same job. A plain map of carriers, MGAs, brokers, and reinsurers for security leaders buying cyber for the first time (and a sanity check for insurance readers).
Ratings estimate risk. Attackers exploit paths.
Outside-in letter grades are easy to consume — and easy to pad with findings that aren't material to a breach or a claim. Underwriting needs verified break-in paths, not another estimate built from soft perimeter signals.
Understanding the terms in your cyber insurance quote
Limit, retention, sublimits, aggregates, waiting periods, named insured — the quote PDF is a coverage design, not just a price. Here's how to read it before you compare premiums.
A milestone: Lloyd's backs BreachBits
We took attacker-grade tech we'd already built into Lloyd's Lab — and learned the cyber insurance market's real pain points so we could apply it where underwriting needs proof, not paperwork. Lloyd's has now made a strategic investment in BreachBits.