How Cyber Insurance Premiums Are Calculated (And What Moves the Number)
Cyber insurance premiums are calculated by multiplying a base rate — derived from your annual revenue and industry risk class — against a series of modifiers that reflect your security controls, requested coverage limits, retention (deductible), and claims history. The underwriter starts with an exposure figure (usually revenue), applies an industry loss cost, then adjusts up or down based on how well your controls reduce the likelihood and severity of a claim. A healthcare company with weak controls and a $10M limit will pay a multiple of what a well-defended professional services firm pays for the same limit. The single biggest lever you control is the security posture the insurer verifies during underwriting.
The actual formula insurers use
Insurance pricing in general follows a version of this equation:
Premium = (Expected Loss × Exposure Base) + Risk Load + Expenses + Profit Margin
For cyber specifically, it plays out like this:
- Exposure base — almost always annual revenue, sometimes number of records held or employee count. A $50M-revenue firm is inherently a bigger target and a bigger payout than a $5M firm.
- Base rate / loss cost — a per-unit-of-revenue figure the insurer assigns to your industry. Healthcare, financial services, and retail carry higher loss costs because of regulated data and ransomware frequency; a manufacturing firm with little PII carries a lower one.
- Limit and retention factors — higher coverage limits raise premium roughly (but not linearly — excess layers cost less per dollar); a higher retention lowers it because you absorb more of each loss.
- Control modifiers — credits or debits applied based on your answers to the security questionnaire. This is where a strong posture can cut a quote by double-digit percentages, and a weak one can get you declined entirely.
The result is that two companies with identical revenue can receive quotes that differ by 3–5x purely on controls and industry.
What underwriters check before they'll quote you at all
Before pricing enters the picture, insurers apply a set of baseline requirements. If you don't meet them, you don't get a quote — or you get one with crippling ransomware sub-limits. Cyber insurers commonly require the following as baseline underwriting conditions:
- Multi-factor authentication (MFA) — on remote access, email, VPN, and privileged accounts. This is the single most common hard requirement; missing MFA on remote access is a frequent decline reason.
- Endpoint detection and response (EDR) — not just legacy antivirus. Insurers want to see behavioral detection and response capability across endpoints.
- Immutable backups — backups that ransomware cannot encrypt or delete, tested for restoration. This directly caps their ransomware loss exposure.
- Email security — filtering and anti-phishing controls, since email remains the dominant initial access vector.
- A documented incident response plan — evidence you can detect and contain an event quickly rather than letting it metastasize into a full breach.
Treat these five as the price of admission. Each one you can honestly attest to (and prove during a claim) either unlocks a quote or earns a pricing credit. Lying on the questionnaire is worse than not having the control — misrepresentation is grounds for rescinding the policy after a loss.
How the 1-10-60 rule ties into your premium
The 1-10-60 rule is a cybersecurity benchmark for incident response speed: detect an intrusion within 1 minute, investigate within 10 minutes, and contain or remediate within 60 minutes. It comes from the observation that attacker "breakout time" — the window between initial compromise and lateral movement — is short, so defenders who beat it prevent a foothold from becoming a full breach.
This matters for premiums because insurers price on severity, not just frequency. An organization that can demonstrate fast detection and containment — via EDR, a staffed or outsourced SOC, and a tested IR plan — reduces the expected size of any single claim. When you tell an underwriter you have a mature IR capability aligned to something like 1-10-60, you're arguing for a lower severity assumption, which feeds directly into the loss-cost side of the premium formula. It's the operational proof behind the "documented IR plan" checkbox.
Calculating your own cyber risk (what the number represents)
Underwriters are estimating your annualized loss expectancy, and you can model the same thing internally:
Risk = Likelihood × Impact, or more precisely, Annualized Loss Expectancy (ALE) = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO).
Worked example: suppose a ransomware event would cost you $2M in recovery, downtime, and extortion (SLE), and you estimate a 10% chance per year of a successful attack (ARO of 0.1). Your ALE is $200,000. Now add MFA, EDR, and immutable backups that cut both the probability of success and the recoverable-without-paying cost — dropping ARO to 0.04 and SLE to $800K. Your new ALE is $32,000. That 84% reduction in modeled loss is precisely what earns control credits when the underwriter runs their version of the same math. Doing this exercise before you apply lets you predict where you'll get credited and where you'll get debited.
Typical cost and what drives the range
There's no single "typical" cyber insurance cost because the exposure base varies so widely, but the drivers of where you land in the range are consistent. Small businesses with modest revenue and clean controls sit at the low end; mid-market and enterprise firms with regulated data and high limits sit far higher. The factors that move you up or down:
- Revenue and record count — more of either means more exposure and higher base premium.
- Industry — healthcare, finance, education, and retail cost more than low-data sectors.
- Coverage limit and retention — a $5M limit costs materially more than $1M; a higher deductible reduces premium.
- Control maturity — the five baseline controls plus SOC/monitoring, patch cadence, and network segmentation.
- Claims history — prior incidents raise your rate the same way an at-fault accident raises auto premiums.
- Jurisdiction — in states with strict breach-notification and privacy law like California (CCPA/CPRA), the potential regulatory and litigation cost of a breach is higher, which insurers factor into pricing for firms holding California residents' data.
Cyber liability insurance itself covers first-party costs (forensics, recovery, business interruption, extortion) and third-party liability (claims from affected customers and partners, regulatory defense). Understanding which coverages you're buying — and their sub-limits — is as important as the headline premium, because a cheap policy with a $250K ransomware sub-limit may be worthless against a $2M event.
If you want to see how these variables interact for your own profile before talking to a broker, run the numbers with PlayCISO's free Cyber Insurance Premium Calculator — it lets you model how your revenue, limits, and control posture shift the estimate so you know where to focus before you apply.
Ready to practise the decisions these articles describe?
Run a free War Room →