Cyber insurance may reduce financial exposure after an incident, but it does not replace practical security controls.
|
Author Greg “Dutch” Holland-Merten, MSc, MSyI Reviewed by HMH Physical Security Team |
Best for CFOs, COOs, owners, board members, cyber insurance applicants, and companies handling sensitive client or financial data |
Key takeaway: Insurance may help pay for parts of the response. It does not prevent the incident or replace control validation.
Cyber Insurance Is Not a Security Strategy
Cyber insurance matters. But it is not a security strategy.
It is not an incident response plan. It is not a penetration test. It is not staff training. It is not access control. It is not tested backups. It is not a substitute for leadership understanding the risk.
Cyber insurance may help transfer some financial exposure after an incident. That has value. But it does not stop the incident from happening in the first place.
|
Too many businesses treat the policy as the plan. That is a mistake. |
Insurance responds after the problem
Security should reduce the chance of the problem. That is the difference.
A cyber insurance policy may help with certain costs after a breach, ransomware event, business email compromise, data loss, or interruption.
But by the time you are relying on the policy, the business may already be dealing with operational disruption, legal review, client notification, recovery costs, reputational damage, staff uncertainty, and leadership pressure.
Insurance may help pay for pieces of the response. It does not remove the pain.
The dangerous boardroom assumption
The dangerous phrase is: “We have cyber insurance, so we are covered.”
Covered for what? Under what conditions? With what exclusions? Based on what representations? Using which controls? With what evidence?
Insurance applications often ask about controls such as MFA, backups, endpoint protection, patching, access management, incident response planning, staff training, and vendor oversight.
If leadership answers those questions based on assumption rather than evidence, the business may be creating risk before the incident even occurs.
|
Confidence is not documentation. Hope is not a control. |
What businesses should be able to evidence
A serious business should be able to answer basic questions before an incident, not during one.
- Who owns cybersecurity internally
- Who manages IT support
- Who responds to security alerts
- Whether MFA is enforced across critical systems
- Whether privileged accounts are controlled
- Whether backups are tested
- Whether systems are patched in a reasonable timeframe
- Whether endpoint protection is deployed and monitored
- Whether staff receive security awareness training
- Whether vendors are reviewed
- Whether remote access is controlled
- Whether the incident response plan has been tested
- Whether cyber risk has been independently assessed
- Whether findings have been remediated
These are not luxury questions. They are basic governance questions. After an incident, they become very uncomfortable questions if nobody has clear answers.
Cyber insurance does not replace testing
One of the biggest gaps is independent validation. Businesses often rely on internal reassurance or vendor reassurance. That may not be enough.
An independent assessment or penetration test helps leadership understand whether controls actually work.
- Is MFA enforced on all remote access?
- Are there exposed services that should not be exposed?
- Can a compromised account move laterally?
- Are old user accounts still active?
- Are administrative rights excessive?
- Are critical systems segmented?
- Are backups reachable from the main environment?
- Are cloud storage permissions too broad?
- Are known vulnerabilities still present?
- Are logging and alerting useful?
These questions cannot be answered properly by a policy document alone. They require testing.
The cyber insurance renewal problem
Many businesses only pay attention to cyber controls when renewal comes around. That is too late.
If the first serious review of your controls happens because an insurance form asks the question, the business is already on the back foot.
A better approach is to review the environment before renewal. That gives leadership time to identify gaps, fix high-risk issues, document controls properly, retest where required, improve staff training, update policies, strengthen vendor oversight, and prepare clearer answers.
The role of leadership
Cybersecurity is technical in execution, but it is not only a technical issue. Leadership owns the risk.
The MSP may support the environment. The internal IT team may administer systems. The insurance broker may advise on coverage. The legal team may review contractual exposure. The assessor may test controls. But leadership is still responsible for making informed decisions.
- What are our most important systems?
- Who has access to them?
- How are they protected?
- When were they last tested?
- What are we still exposed to?
- What are we choosing to accept?
- What needs budget?
- What needs fixing first?
- What evidence do we have?
What good looks like
A sensible cyber insurance and security posture should include:
- Clear ownership of cybersecurity
- Current asset understanding
- MFA on critical systems
- Privileged access control
- Patch management
- Tested backups
- Endpoint protection
- Email security controls
- Staff security training
- Incident response planning
- Vendor risk review
- Regular vulnerability management
- Independent penetration testing
- Remediation tracking
- Board or leadership reporting
None of this needs to be overcomplicated. It needs to be real. If the business cannot evidence it, leadership should not assume it exists.
The HMH view
Cyber insurance has a place. But it should sit behind security, not in front of it.
A policy may help the business recover financially from parts of an incident. It does not replace the controls that reduce the chance and impact of that incident.
At HMH Consulting, we help leadership teams separate assumption from evidence. We assess the environment, identify practical exposure, test controls where appropriate, and give leadership a clear route to reduce risk before the painful conversations begin.
Related public references
These references are included for context and editorial grounding. HMH recommendations should be scoped to each client environment.
Book a cyber risk review with HMH Consulting.
Discreet outreach. No obligation