Insurance

How Insurers Actually Price Cyber Insurance Policies

XR
Xcigence Research
Cyber Risk Intelligence Team
9 min read

A cyber premium can look arbitrary from the outside — two similar companies, wildly different quotes. It is not arbitrary. It is the output of a five-step calculation, and understanding each step tells a buyer exactly which levers actually move price.

Anatomy of a premium

Every cyber premium, however it is dressed up, is built the same way: an exposure base establishes scale, a loss cost converts scale into expected claims, modifiers adjust for this specific risk's quality, programme structure determines which slice of loss the carrier actually holds, and loadings cover expenses, volatility and capital.

The underlying identity
Premium = (Exposure base × Loss cost × Risk modifiers) adjusted for limit and retention, plus expense, volatility and capital loadings.

Step 1: the exposure base

Underwriters need a measure of how much risk there is to insure. In cyber the primary base is usually annual revenue, because revenue proxies both business interruption exposure and the volume of data and transactions flowing through the organization. Secondary bases refine it: records held, employee count, and — increasingly — the specific systems the business cannot operate without.

This is why revenue growth raises premium even with unchanged security: the amount at stake grew. NAIC market reporting shows premium volume tracking both exposure growth and loss experience across the line.[2]

Step 2: expected loss cost

The loss cost is the expected claims cost per unit of exposure — the actuarial core. It derives from frequency (how often insureds like this one suffer a covered event) and severity (what those events cost), segmented by industry class, size band and jurisdiction.

Class matters enormously because both halves differ by sector: healthcare carries high severity through regulated data volumes, manufacturing carries high business interruption severity through production dependency, and professional services carry high frequency through email-borne fraud. The structure is the same frequency-times-magnitude logic that underpins FAIR-based risk analysis.[4]

Step 3: risk modifiers

This is where an individual applicant diverges from its class average, and where a measured security posture now does real work. Historically these modifiers came from questionnaire answers; increasingly they come from observed evidence.

ModifierEffect on premiumBasis
Verified MFA on remote access & emailStrong reductionDirectly reduces the dominant claim vector
Tested, segmented offline backupsStrong reductionCaps ransomware business interruption severity
EDR deployed and monitored 24/7ReductionShortens dwell time and containment cost
Known-exploited vulnerabilities exposedStrong increaseHigh-confidence indicator of imminent loss
Exposed administrative services (e.g. RDP)IncreaseHistorically a leading ransomware entry point
Prior claims in last 3 yearsIncreasePersistent predictor absent demonstrated remediation
Deteriorating posture trendIncreaseSignals control processes not operating
Concentration in a systemic dependencyIncrease / restrictionContributes to correlated portfolio loss
Typical premium modifiers and their direction of effect.

Note the asymmetry: exposure findings penalise more sharply than good hygiene rewards. A single internet-facing vulnerability in CISA's known-exploited catalogue[5] can outweigh several favourable control credits, because its predictive weight is higher. How these modifiers are measured rather than declared is the subject of score-based underwriting.

Step 4: limits, retentions and attachment

Retention (deductible)

The insured absorbs losses below the retention. Because small and mid-sized claims dominate frequency, raising the retention removes a disproportionate share of expected claims cost — usually the single most effective lever a buyer controls.

Limit and layering

Premium does not scale linearly with limit. Higher layers are cheaper per dollar of cover because the probability of reaching them is lower — the reason large programmes are built as towers of layers from different carriers rather than as one policy. Selecting the right total limit is a quantification exercise, not a benchmarking one; see calculating breach financial impact.

Sub-limits and coinsurance

Ransomware sub-limits, coinsurance on extortion payments, waiting periods before business interruption attaches, and war or systemic-event exclusions all change the carrier's real exposure — and therefore the price. Two quotes at the same headline limit are not comparable until these are read side by side.

Step 5: expense and capital loadings

On top of expected loss the carrier must cover acquisition costs and brokerage, claims handling and included incident-response services, a risk margin for volatility, reinsurance cost, and a return on the capital held against the exposure. Cyber attracts a heavier volatility and capital loading than most lines precisely because losses can correlate across an entire book, the systemic concern Lloyd's has pressed the market to model explicitly.[3]

This is also why market-wide pricing swings can exceed anything happening at an individual insured: when reinsurance costs or capital appetite shift, every premium moves.[1]

A worked illustration

StepInputRunning effect
Exposure base$150M revenueBase scale set
Class loss costManufacturing, mid-marketIndicated $210,000
Control creditsVerified MFA, tested offline backups, EDR−22% → $164,000
Exposure findingsOne KEV-listed vulnerability, exposed RDP+18% → $194,000
Retention selected$500,000 (up from $250,000)−15% → $165,000
Limit$10M single layerLayer priced
LoadingsExpense, volatility, reinsurance, capitalFinal indicated premium
Illustrative build-up for a $150M-revenue manufacturer. Figures are examples, not market rates.

How buyers actually reduce cost

  • Remediate visible exposure before you go to market — Findings a carrier can observe from outside are priced. Closing them is the highest-yield pre-renewal work, and it is measurable — see reading your score and its drivers.
  • Bring evidence, not assertions — Screenshots of MFA enforcement coverage, dated recovery test results and patch-cadence metrics convert claimed credits into granted ones.
  • Take more risk deliberately — A higher retention on losses you can absorb buys down premium more efficiently than negotiating rate.
  • Show a trend, not a scramble — Twelve months of improving posture is worth more than a fortnight of remediation before renewal.
  • Size limits from your own loss model — Quantified exposure lets you argue for the programme you need instead of accepting a peer-benchmark default.

Underneath all of it, the carrier is pricing what it can observe and verify. Organizations that measure their own posture continuously — with the same evidence-based, patented methodology carriers increasingly rely on[6] — negotiate from the same information the underwriter holds, rather than reacting to a quote built from it.

Part of our guide to
Cyber Insurance Underwriting

Evidence-based scoring for pre-bind assessment, monitoring, and accumulation.

References

  1. [1]NAIC. Cyber Insurance — Center for Insurance Policy and Research
  2. [2]NAIC. Report on the Cyber Insurance Market
  3. [3]Lloyd's of London. Systemic risk scenarios and cyber underwriting guidance
  4. [4]The Open Group. Open FAIR — Risk Taxonomy and Risk Analysis standards
  5. [5]CISA. Known Exploited Vulnerabilities (KEV) Catalog
  6. [6]USPTO. Patent application US 16/822,691 — Global Dossier record

See your own cyber risk score

Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.

We use cookies to improve your experience on our site, analyze site traffic, and assist in our marketing efforts. By clicking "Accept All", you consent to our use of cookies in accordance with GDPR, CCPA, and ISO27001 privacy standards.