Cyber insurance is not a security strategy

On this page
  1. The cost of comfort
  2. The changing terms

A director signs a policy document and feels the tension leave their shoulders. The company has paid a premium. In their mind, the risk of a data breach has moved from their ledger to that of the insurer. This is an intuitive leap. It mirrors how one treats fire or flood insurance. If a warehouse burns down, the payout provides the funds for a new building. For a time, it seemed reasonable to treat digital disasters in the same way.

The cost of comfort#

Treating insurance as a primary defence is a gamble. A policy transfers money, not effort. When an attacker locks every server with encryption, the insurer does not suddenly appear to rewrite the code or manually recover lost files. They provide funds to hire people who can do that work. The stress of a crisis remains within the organisation. Recovery is a technical and human struggle. No amount of money removes the midnight phone calls or the sight of an empty database.

Insurance behaves as a financial cushion. It helps a business survive the cost of forensic investigators or legal fees. It does not, however, restore a reputation. A customer who loses their identity theft protection because of a leak will not be comforted by the news that the company has a generous insurance policy. Trust is not a line item on a balance sheet and cannot be bought back once it is spent.

The changing terms#

The insurance market has changed. Insurers have seen too many payouts for the same simple mistakes. They now act more like auditors than passive collectors of premiums. Most policies require a minimum level of security before they will even issue a licence to be insured. Multi-factor authentication, which requires a second piece of evidence beyond a password to verify identity, is often a non-negotiable requirement.

If a company claims it has these controls in place but does not, the insurer may refuse to pay. The fine print transforms the policy from a safety net into a contract for performance. In such cases, the organisation pays the premium and still carries all the risk. It is a costly way to learn that honesty is the best policy when filling out an application form.

Regulators do not care who pays the bill. A data protection authority focuses on whether the organisation protected the people whose data was stolen. A payout from an insurance company does not satisfy a legal requirement to maintain proper security behaviour. It is possible to be fully insured and still face a massive fine or a court order for negligence. The insurer may cover the cost of the fine, but they cannot stop the regulator from publicising the failure of the organisation’s security centre.

Insurance is a backstop for a plan, not the plan itself. A plan involves backups that are kept offline and an incident response team that knows how to operate without an internet connection. Relying on insurance to solve a breach is like relying on life insurance to stop a heart attack. It helps the survivors, but it does nothing for the patient.

Audit the current policy today. Check the specific requirements for due diligence and listed controls. Ensure every security measure mentioned in the application is active and tested. Treat the policy as the final layer of a defence strategy, not the first.

Frequently asked questions#

Does cyber insurance cover all costs of a data breach?

Insurance provides a financial cushion for forensic investigators and legal fees, but it cannot restore a damaged reputation or recover deleted files. A payout helps a business survive the cost, yet the technical struggle of recovery remains an internal burden. Regulators may still impose fines for negligence regardless of whether a policy exists to pay them.

Why might an insurer refuse to pay a claim?

Many insurers now act as auditors and require specific security controls, such as multi-factor authentication, before issuing a policy. If a company claims these measures are in place but fails to implement them, the insurer may view this as a breach of contract. This transforms the safety net into a performance requirement that must be met.

Sources & further reading