How Insurers Actually Price Cyber Insurance Policies
A cyber premium can look arbitrary from the outside — two similar companies, wildly different quotes. It is not arbitrary. It is the output of a five-step calculation, and understanding each step tells a buyer exactly which levers actually move price.
Anatomy of a premium
Every cyber premium, however it is dressed up, is built the same way: an exposure base establishes scale, a loss cost converts scale into expected claims, modifiers adjust for this specific risk's quality, programme structure determines which slice of loss the carrier actually holds, and loadings cover expenses, volatility and capital.
Step 1: the exposure base
Underwriters need a measure of how much risk there is to insure. In cyber the primary base is usually annual revenue, because revenue proxies both business interruption exposure and the volume of data and transactions flowing through the organization. Secondary bases refine it: records held, employee count, and — increasingly — the specific systems the business cannot operate without.
This is why revenue growth raises premium even with unchanged security: the amount at stake grew. NAIC market reporting shows premium volume tracking both exposure growth and loss experience across the line.[2]
Step 2: expected loss cost
The loss cost is the expected claims cost per unit of exposure — the actuarial core. It derives from frequency (how often insureds like this one suffer a covered event) and severity (what those events cost), segmented by industry class, size band and jurisdiction.
Class matters enormously because both halves differ by sector: healthcare carries high severity through regulated data volumes, manufacturing carries high business interruption severity through production dependency, and professional services carry high frequency through email-borne fraud. The structure is the same frequency-times-magnitude logic that underpins FAIR-based risk analysis.[4]
Step 3: risk modifiers
This is where an individual applicant diverges from its class average, and where a measured security posture now does real work. Historically these modifiers came from questionnaire answers; increasingly they come from observed evidence.
| Modifier | Effect on premium | Basis |
|---|---|---|
| Verified MFA on remote access & email | Strong reduction | Directly reduces the dominant claim vector |
| Tested, segmented offline backups | Strong reduction | Caps ransomware business interruption severity |
| EDR deployed and monitored 24/7 | Reduction | Shortens dwell time and containment cost |
| Known-exploited vulnerabilities exposed | Strong increase | High-confidence indicator of imminent loss |
| Exposed administrative services (e.g. RDP) | Increase | Historically a leading ransomware entry point |
| Prior claims in last 3 years | Increase | Persistent predictor absent demonstrated remediation |
| Deteriorating posture trend | Increase | Signals control processes not operating |
| Concentration in a systemic dependency | Increase / restriction | Contributes to correlated portfolio loss |
Note the asymmetry: exposure findings penalise more sharply than good hygiene rewards. A single internet-facing vulnerability in CISA's known-exploited catalogue[5] can outweigh several favourable control credits, because its predictive weight is higher. How these modifiers are measured rather than declared is the subject of score-based underwriting.
Step 4: limits, retentions and attachment
Retention (deductible)
The insured absorbs losses below the retention. Because small and mid-sized claims dominate frequency, raising the retention removes a disproportionate share of expected claims cost — usually the single most effective lever a buyer controls.
Limit and layering
Premium does not scale linearly with limit. Higher layers are cheaper per dollar of cover because the probability of reaching them is lower — the reason large programmes are built as towers of layers from different carriers rather than as one policy. Selecting the right total limit is a quantification exercise, not a benchmarking one; see calculating breach financial impact.
Sub-limits and coinsurance
Ransomware sub-limits, coinsurance on extortion payments, waiting periods before business interruption attaches, and war or systemic-event exclusions all change the carrier's real exposure — and therefore the price. Two quotes at the same headline limit are not comparable until these are read side by side.
Step 5: expense and capital loadings
On top of expected loss the carrier must cover acquisition costs and brokerage, claims handling and included incident-response services, a risk margin for volatility, reinsurance cost, and a return on the capital held against the exposure. Cyber attracts a heavier volatility and capital loading than most lines precisely because losses can correlate across an entire book, the systemic concern Lloyd's has pressed the market to model explicitly.[3]
This is also why market-wide pricing swings can exceed anything happening at an individual insured: when reinsurance costs or capital appetite shift, every premium moves.[1]
A worked illustration
| Step | Input | Running effect |
|---|---|---|
| Exposure base | $150M revenue | Base scale set |
| Class loss cost | Manufacturing, mid-market | Indicated $210,000 |
| Control credits | Verified MFA, tested offline backups, EDR | −22% → $164,000 |
| Exposure findings | One KEV-listed vulnerability, exposed RDP | +18% → $194,000 |
| Retention selected | $500,000 (up from $250,000) | −15% → $165,000 |
| Limit | $10M single layer | Layer priced |
| Loadings | Expense, volatility, reinsurance, capital | Final indicated premium |
How buyers actually reduce cost
- Remediate visible exposure before you go to market — Findings a carrier can observe from outside are priced. Closing them is the highest-yield pre-renewal work, and it is measurable — see reading your score and its drivers.
- Bring evidence, not assertions — Screenshots of MFA enforcement coverage, dated recovery test results and patch-cadence metrics convert claimed credits into granted ones.
- Take more risk deliberately — A higher retention on losses you can absorb buys down premium more efficiently than negotiating rate.
- Show a trend, not a scramble — Twelve months of improving posture is worth more than a fortnight of remediation before renewal.
- Size limits from your own loss model — Quantified exposure lets you argue for the programme you need instead of accepting a peer-benchmark default.
Underneath all of it, the carrier is pricing what it can observe and verify. Organizations that measure their own posture continuously — with the same evidence-based, patented methodology carriers increasingly rely on[6] — negotiate from the same information the underwriter holds, rather than reacting to a quote built from it.
Evidence-based scoring for pre-bind assessment, monitoring, and accumulation.
References
- [1]NAIC. Cyber Insurance — Center for Insurance Policy and Research
- [2]NAIC. Report on the Cyber Insurance Market
- [3]Lloyd's of London. Systemic risk scenarios and cyber underwriting guidance
- [4]The Open Group. Open FAIR — Risk Taxonomy and Risk Analysis standards
- [5]CISA. Known Exploited Vulnerabilities (KEV) Catalog
- [6]USPTO. Patent application US 16/822,691 — Global Dossier record
Continue reading
Underwriters are replacing self-attested questionnaires with continuously measured evidence. What that changes for pre-bind triage, pricing and in-force monitoring.
A cybersecurity risk score turns observable security evidence into a standardized number decision-makers can compare, price, and act on. Here is what goes into one and what makes it defensible.
The five bands of the Xcigence 300–850 scale, what each one signals to insurers and procurement teams, and how to read score movement over time.
See your own cyber risk score
Xcigence computes a standardized 300–850 cyber risk score for your organization and every vendor in your ecosystem — no agents, no questionnaires.