Cyber insurance cost, and the five things that move it either way

Cyber insurance cost is quoted rather than published, and that is not evasion: the same business can be priced twice over with two different answers to the same control questions. What is publishable is the structure. Five things move the number, and four of them are inside the buyer's control, which is why a business that reads the list before asking for a quote usually pays less than one that shops the same risk around three brokers.

Turnover and sector, which set the starting point

Insurers rate cyber against revenue because revenue is a proxy for how much there is to interrupt and how many records there are likely to be. Sector matters as a second adjustment: a clinic, a legal or accountancy practice, a recruiter and an online retailer each present a different mix of data and payments, and the same turnover in two of them will not price the same.

The data you hold, counted rather than described

The notification bill after a breach scales with the number of individuals who have to be told, so the record count is a direct input to the liability section. Sensitive categories, health and financial records above all, raise it further because the harm to the individual is greater and so is the regulator's interest. A firm that can state the number rather than guess it is underwritten more accurately.

Whether money moves on instruction

A business that pays suppliers on emailed invoices, or that holds client money, carries the exposure that produces the most frequent small claims in this market. Adding the crime or social engineering section costs money and is usually worth it for such a business. Where no payments leave on instruction, the section can be dropped and the premium falls.

The limit and the structure you buy

The aggregate limit is the obvious lever, and the sub limits and excesses underneath it are the quieter ones. Accepting a longer business interruption waiting period, or a larger excess on the first party section, reduces the premium materially for a business that can absorb the first day. Those trades are worth making deliberately rather than by accepting a default.

The controls, which are the only lever that also reduces the risk

Multi factor authentication, tested offline backups, a patching routine, restricted administrator rights and a payment verification rule are what the proposal form asks about, and improving them before applying changes both the premium and the number of insurers willing to quote. It is the only item on this list that makes the claim less likely as well as the cover cheaper.

Questions people ask about cyber insurance cost

Why will nobody publish a cyber insurance price?

Because the same turnover prices very differently depending on data held, payment exposure and controls. Any published figure would be an average of businesses unlike yours. The insurers on this site that print a starting price do so for their general business covers, not for cyber.

Is cyber cheaper as part of a package?

The premium is usually lower and so is the cover. A packaged cyber section typically carries a small aggregate limit and no crime section, so compare the section list before treating it as the same product.

Does the price fall at renewal if nothing happened?

Not automatically. It falls when the proposal answers improve. A year with no incident and no change to the controls is usually priced much as the year before.

How much does the limit change the price?

Less than proportionally. Doubling the limit rarely doubles the premium, because the insurer's expected loss is concentrated in the smaller claims. That makes a larger limit better value than buyers expect.

Sources

Related answers

See what insurers printCompare by trade