Join our Newsletter — 33% off our NHI Course

What is the difference between having cyber insurance and being insurable?

Having a policy means coverage exists on paper. Being insurable means the organisation can still satisfy the insurer’s control expectations, maintain eligibility at renewal, and avoid exclusions or denials when identity governance, privilege, or response discipline is weak.

Why insurance and insurability are not the same thing

cyber insurance is a financial backstop: it can transfer some loss after a covered event. Insurability is the insurer’s willingness to keep that backstop available. The difference matters because underwriting is not static. If the organisation’s control environment deteriorates, the policy may renew with exclusions, lower limits, higher retentions, or not renew at all.

The practical test is not whether a certificate of insurance exists, but whether the organisation still meets the controls the insurer priced into the policy. That usually includes authentication strength, access governance, backup discipline, logging, patching, incident response readiness, and evidence that the business can recover without treating claims as a substitute for control.

What insurers are really pricing when they assess insurability

Insurability is usually driven by loss likelihood and loss severity, not by the headline policy wording. Underwriters look for a defensible control baseline: who can access critical systems, how privileged access is issued and revoked, whether service and admin credentials are controlled, and whether the organisation can detect and contain misuse quickly enough to limit a claim.

That means weak identity governance can affect insurance even if the company already bought coverage. A policy may still respond after a loss, but the insurer may decide the risk profile no longer fits the renewal appetite. In Sisense breach 2024, a credential reportedly exposed downstream tokens and secrets, which is the kind of control failure that underwriters treat as a sign of elevated exposure.

Insurability also depends on whether the organisation can prove its controls, not just claim they exist. Evidence of privileged access reviews, secret rotation, MFA coverage, monitoring, and tested recovery procedures often matters more than policy statements because it shows the control set is operating consistently rather than aspirationally.

What changes when eligibility starts to slip

When insurability weakens, the financial impact is often indirect before it becomes obvious. The insurer may narrow coverage terms, carve out certain attack types, demand higher deductibles, or require remediation before renewal. That can leave the organisation technically insured but practically underprotected for the scenarios most likely to hurt it.

The risk is especially sharp where identity, privilege, or incident response controls are weak, because those gaps can turn a routine intrusion into a large, claim-generating event. An exposed admin key, an unrevoked service credential, or slow containment can all shift the loss profile enough to make the account unattractive to an underwriter, even if the company has never filed a claim.

That is why insurability should be treated as an operational property, not a procurement event. It changes as your architecture, control maturity, and exposure change. The organisation can lose it gradually through exception sprawl, long-lived credentials, and inconsistent response discipline long before a breach forces the issue.

Risk and Threat Considerations

Insurance can create a false sense of protection if teams assume the policy will offset control drift. The bigger risk is gap formation: the organisation keeps paying premiums while the control weaknesses that drive underwriting decisions remain unresolved, which can lead to exclusions, renewal friction, or uncovered loss scenarios.

Failure mechanism: Underwriters revise terms when they see control failure patterns such as excessive privilege, weak authentication, unrevoked access, poor secret handling, or immature response evidence. Those same patterns also increase the chance that a small compromise becomes a material incident.

Impact: The organisation may still suffer the loss, but with reduced coverage, a denied renewal, or exclusions that remove the very event category it expected the policy to absorb.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Controls credential lifecycle, a core driver of insurability.
IA-2 — Identification and Authentication (Organizational Users) Strong user authentication directly affects underwriting confidence.
AC-6 — Least Privilege Excess privilege raises both incident severity and insurer concern.
Recommendation — Rotate and revoke authenticators promptly to reduce renewal and claim risk. Enforce strong authentication for workforce access to critical systems. Limit privileges to the minimum needed for each role and system.
NIST CSF 2.0 PR.AA-05 — Least Privilege Maps to controlling access exposure that affects insurability.
RS.RP-01 — Response Plan Execution Incident response maturity influences insurer expectations and recovery credibility.
Recommendation — Apply least-privilege access to reduce loss potential and renewal friction. Test and execute response plans so you can evidence operational readiness.

Practitioner Guidance

What to verify: Treat renewal readiness as a control-evidence exercise. Confirm you can show current privilege reviews, MFA or equivalent strong authentication coverage, secret rotation practices, incident response test results, and recovery evidence for the systems the policy implicitly assumes are protected.

Decision rule: If a control gap would materially increase the probability or blast radius of an insured event, fix the gap before relying on premium savings or broader limits. If the gap is in privileged access, credentials, or response timing, expect underwriting pressure first and claims friction later.

Common mistake: Teams often equate “policy bound” with “risk transferred.” In practice, the insurer is pricing your operating discipline, and weak governance can make the policy harder to renew even when no claim has ever been filed.

Practitioner takeaway: Buy insurance for residual loss, but manage insurability through the controls that keep the account renewable, predictable, and within the insurer’s tolerance.