What Controls Lower Your Cyber Insurance Premium (and Which Ones Get You Declined)
The controls that lower your cyber insurance premium are, for the most part, the same five controls insurers now demand before they'll quote you at all: multi-factor authentication (MFA), endpoint detection and response (EDR), immutable backups, email security, and a documented incident response (IR) plan. These are baseline underwriting conditions — miss one and you don't get a "higher premium," you get declined or offered coverage with a crippling sublimit. The premium reductions come from how well you implement and evidence these controls, plus a second tier of controls (privileged access management, network segmentation, security awareness training) that signal lower loss frequency to an underwriter. This post breaks down which controls move the number, how much coverage typically costs, and the exclusions that quietly gut a policy after you've paid for it.
The five controls that get you in the door
Cyber insurers commonly require MFA, EDR, immutable backups, email security and a documented IR plan as baseline underwriting conditions before quoting. Treat these as pass/fail gates, not premium levers — but the depth of each is what negotiates your rate down:
- MFA — Underwriters no longer accept "we have MFA." They want MFA on remote access (VPN, RDP), on all privileged/admin accounts, and on webmail and cloud admin portals. MFA on email but not on your VPN is the single most common reason a renewal premium jumps. Phishing-resistant MFA (FIDO2/hardware keys) on admin accounts is a documented differentiator that carriers reward.
- EDR — "Antivirus" is not EDR. Insurers ask specifically whether you run a modern EDR/XDR platform, whether it covers 100% of endpoints and servers, and whether it's monitored 24/7 (in-house SOC or MDR). Coverage gaps — that legacy server without an agent — are exactly what get probed on the application.
- Immutable backups — This is the ransomware control. Carriers want backups that are offline or immutable (WORM storage), tested by restore, and segmented from the production domain so ransomware can't encrypt them. The key phrase on applications is "can an attacker who compromises your domain admin delete your backups?" If the answer is yes, expect a ransomware sublimit.
- Email security — Advanced email filtering, DMARC/DKIM/SPF enforcement, and attachment sandboxing. Business email compromise (BEC) is a leading claim driver, so this ties directly to your funds-transfer-fraud coverage.
- Documented IR plan — A written, tested plan with defined roles, an escalation tree, and evidence of at least one tabletop exercise in the past 12 months. "We'll figure it out" costs you both premium and, worse, post-incident coverage disputes.
The second-tier controls that actually move the number
Once you clear the baseline, premium reductions come from controls that reduce the frequency and severity of the claims the insurer expects to pay. Name them specifically on your application — underwriters price what they can see:
- Privileged access management (PAM) — Vaulted admin credentials, just-in-time access, and session monitoring. This directly limits ransomware blast radius, which is the loss scenario driving the market.
- Network segmentation — Separating OT from IT, isolating backups, and micro-segmenting critical systems. Segmentation converts a "whole-environment encryption" claim into a contained one.
- Security awareness training with phishing simulation — Reported click-through rates trending down over time are concrete evidence underwriters can price.
- Vulnerability management and patch cadence — A documented SLA for patching critical vulnerabilities (e.g., internet-facing criticals within 72 hours) beats a vague "we patch regularly."
- Logging and monitoring — Centralized logging with retention long enough to support forensics reduces the insurer's incident-response cost, which they factor in.
The pattern: every control that shortens dwell time, shrinks blast radius, or speeds recovery lowers expected loss — and that is what an actuary discounts.
How much cyber insurance actually costs
Premiums are priced on annual revenue, industry, records held, coverage limit, and — heavily — your control posture. Rather than quote a single figure, understand the mechanics that determine your number:
- Limit and retention are the biggest levers you control at purchase. Raising your retention (deductible) meaningfully lowers premium; buying a $10M limit versus $2M raises it. Right-size the limit to your realistic worst-case (business-interruption days × daily revenue + breach-response costs), not a round number.
- Control posture is the biggest lever you control before purchase. Two companies of identical size in the same sector can see materially different premiums based purely on whether they can evidence the five baseline controls plus PAM and segmentation.
- Industry and data type matter. Healthcare (PHI), financial services, and organizations processing large volumes of PII pay more because their claim severity is higher.
The most reliable way to lower your quote isn't shopping harder — it's completing the security questionnaire honestly and being able to attach evidence (MFA coverage reports, EDR deployment percentages, backup restore test logs). Underwriters price uncertainty; documentation removes it.
What cyber insurance does NOT cover
Knowing the exclusions is part of choosing a policy, because a cheap premium often hides gaps that make the coverage worthless when you claim. Common exclusions and traps:
- Failure to maintain stated controls. If you told the underwriter you enforce MFA everywhere and a breach happens through an account without MFA, the insurer can deny the claim. This is now the leading source of coverage disputes — your application is a warranty.
- Known/prior vulnerabilities. Incidents stemming from unpatched vulnerabilities you knew about before the policy period are frequently excluded.
- Nation-state / act of war. Post-NotPetya, insurers added war-exclusion language that can apply to state-sponsored attacks — read this clause carefully.
- Betterment. The cost to upgrade systems beyond their pre-incident state (rebuilding on a better platform) is usually not covered.
- Loss of future revenue / reputational harm beyond defined business-interruption periods, and often social engineering / funds transfer fraud unless specifically endorsed with its own sublimit.
"Best" carrier is the wrong question — match the policy to your risk
There's no universally best cyber insurer; the right carrier depends on your size, sector, and claims profile. Larger carriers (Chubb, AXA XL, Beazley, Coalition, AIG among the frequently cited names) differ mainly in their incident-response panels, sublimit structures, and how prescriptive their control requirements are. What matters more than the brand:
- Does the ransomware/BEC coverage carry a sublimit, and is that sublimit adequate?
- Is the incident-response panel (forensics, legal, PR) pre-approved, and can you use your own vendors?
- How does the carrier handle the "failure to maintain controls" clause — is it strict or reasonable?
Buy on coverage terms and claims reputation, not on the lowest headline premium.
If you want to estimate where your organization lands before you talk to a broker — and see how implementing the baseline controls shifts the number — try PlayCISO's free Cyber Insurance Premium Calculator. It's a practical way to model the impact of MFA, EDR, and immutable backups on your quote before you fill out a single questionnaire.
Ready to practise the decisions these articles describe?
Run a free War Room →