Who's who in cyber insurance: carrier, MGA, broker, reinsurer
If you have ever wondered why your cyber “underwriter,” your broker, and someone from a managing general agency all want the same security packet — and then give you different answers — you are not bad at insurance. You are meeting a distribution and capital stack that security teams rarely get taught.
This is a map of the main roles in U.S.-centric cyber placement. Labels blur in practice (people wear multiple hats; programs are nested). The goal is literacy: know who takes risk, who distributes risk, who advises you, and who sits above the primary insurer.
Not legal advice. Not a placement manual. If your program chart disagrees, trust your broker’s chart.
The short version
| Role | What they optimize for | What they usually are not |
|---|---|---|
| Broker / agent | Placing your risk well; market access; advocacy at claim | The party that ultimately pays claims from their balance sheet |
| Insurance carrier (insurer) | Underwriting profit & capital; which risks to write | Always the person who answered your email (often delegated) |
| MGA / program administrator | Underwriting & binding on behalf of capacity providers, inside delegated authority | Automatically “the carrier” — authority is borrowed |
| Reinsurer | Risk taken from insurers (and sometimes MGAs’ capacity providers) | Your day-to-day relationship on a mid-market primary policy |
Premium flows one way. Claims and underwriting appetite flow through constraints you cannot see on the quote PDF.
Broker (and retail agent)
Your broker (or agent, depending on license and market) is typically your advocate in the market: gathers submissions, shops appetite, explains quotes, helps at claim, and gets paid by commission and/or fee.
What security leaders should expect from a good cyber broker:
- Translates your architecture into underwriting language without lying
- Knows which markets are open for your revenue band, industry, and controls maturity
- Separates indication theater from bindable terms
- Prepares you for subjectivities (MFA, EDR, backups) before the declination letter
What brokers are not: a free second CISO, a guarantee of coverage interpretation, or the balance sheet that pays the ransomware demand.
Wholesale brokers sit between retail brokers and specialty markets (including much surplus-lines cyber). If your deal is surplus lines, you may never meet the wholesale layer — but it shapes which forms you see.
Insurance carrier (the insurer)
The carrier is the licensed (or surplus-lines eligible) insurer whose paper you are on — the entity whose capital and claims-paying ability stand behind the contract (subject to reinsurance and corporate structure).
Carriers care about:
- Risk selection — which industries, revenue sizes, and control postures they will write
- Pricing adequacy — premium vs expected loss and expense
- Accumulation — how much correlated cyber risk they already have (cloud concentration, ransomware systemic scenarios, geographic/industry clumps)
- Words — form, endorsements, exclusions, war/cyber-war treatments
When a “market hardens,” it is often carriers (and their reinsurers) tightening appetite and terms — not your broker becoming personally difficult.
Large carriers may underwrite cyber on staff. Others delegate heavily to MGAs and coverholders. The logo on the binder and the person who negotiated subjectivities may live in different companies.
MGA (managing general agent) / coverholder / program admin
An MGA underwrites and often binds coverage under delegated authority from one or more capacity providers (carriers / Lloyd’s syndicates). In Lloyd’s language you will also hear coverholder.
Why buyers meet MGAs so often in cyber:
- Specialty cyber programs move faster when underwriting is concentrated in a team that lives in the product
- Capacity providers like scalable distribution with underwriting rules
- Mid-market and SME cyber is frequently program-shaped
What to remember: an MGA can feel like “the insurance company” in your inbox while the insurer of record is elsewhere. Authority has limits — line size, classes, required controls, referral thresholds. When your deal is “referred,” you have hit the edge of that authority.
For security leaders: treat MGA underwriters as real underwriters. They are. Just know whose capital they are spending.
Reinsurer
Reinsurers insure insurance companies (and participate in capital for portfolios of risk). You rarely negotiate with them on a standard primary cyber buy. You feel them when:
- Primary markets suddenly demand stronger controls
- Ransomware sublimits tighten across many carriers at once
- Capacity for your industry evaporates after a bad loss year
Reinsurance treaties and facultative placements set constraints that cascade into primary appetite. Portfolio-level cyber catastrophe thinking — “what if a major cloud or a widespread vulnerability hits many insureds at once?” — lives heavily at this layer.
If you want a regulator-facing window into how the U.S. cyber market is tracked, start with NAIC cyber insurance market reports (Cyber Supplement materials). They will not name your reinsurer; they will remind you this is a supervised insurance line, not a SaaS category.
Why you keep getting “different answers”
A common failure mode in insured organizations:
- Broker asks for a security questionnaire and evidence
- MGA underwriter asks for screenshots / MFA attestation / scan results
- Carrier referral desk asks for more — or declines
- Security team hears three slightly different “requirements” and assumes incompetence
Often those are the same risk, viewed through different jobs:
- Broker: “What will make this placeable?”
- MGA underwriter: “Does this fit my authority and guidelines?”
- Carrier / reinsurer constraints: “Does this fit our portfolio and treaty?”
Aligning one packet that answers the claim-relevant questions once — controls evidence and outside-in exposure that is actually material — reduces the whiplash. That is also why replacing theater-heavy questionnaires with verified signal is an industry conversation, not only a vendor slogan.
How to use this map in your next renewal
- Ask your broker for a one-page placement diagram: retail → wholesale (if any) → MGA/program (if any) → insurer of record → known reinsurance structure (even high-level)
- Put insurer of record on the internal brief, not only the MGA brand
- When subjectivities appear, ask whether they are program guidelines, carrier mandates, or one underwriter’s preference — the answer changes how hard they are to negotiate
- Do not CC the entire stack on every technical debate; route through the broker unless they ask otherwise
Where BreachBits sits
We sell risk measurement and attacker-emulated assessment to insureds, brokers, and carriers — not policies. Knowing who’s who keeps our conversations honest: a BreachRisk view can inform underwriting and portfolio conversations; it does not replace the carrier’s appetite or the broker’s duty to you.
Next: flip the table entirely — cyber insurance from the carrier’s perspective.