By NHI Mgmt Group Editorial TeamDomain: Governance & RiskSource: VezaPublished October 6, 2025

TL;DR: Ransomware accounted for 58% of large cyber insurance claims in 2024, while breaches such as Change Healthcare and CDK Global drove insurers to raise premiums and demand proof of stronger identity controls, according to Veza. Identity programmes that cannot demonstrate visibility, least privilege, and NHI governance are now underwriting risks, not just security gaps.


At a glance

What this is: This is a whitepaper on cyber insurance posture that argues identity controls, especially NHI visibility and least privilege, now shape insurability.

Why it matters: It matters because IAM, IGA, PAM, and NHI teams must now produce evidence that underwriting, audit, and access governance can support financial resilience.

By the numbers:

👉 Read Veza's whitepaper on strengthening cyber insurance posture with identity controls


Context

Cyber insurance is increasingly an identity governance problem, not just a finance or risk-transfer problem. If an organisation cannot prove who and what has access, how privileges are scoped, and whether non-human identities are visible and governed, insurers will treat that uncertainty as exposure.

Veza's whitepaper links rising ransomware losses to tougher underwriting expectations around MFA, least privilege, and NHI visibility. For IAM, IGA, and PAM teams, the practical shift is from control implementation to control evidence, because insurability now depends on demonstrable access discipline.

The underlying security issue is familiar: the control gap is not only that identities are over-permissioned, but that organisations often cannot prove remediation, revocation, or ownership at the speed insurers and auditors now expect.


Key questions

Q: How should security teams prove identity controls during cyber insurance renewal?

A: Focus on evidence, not policy statements. Show that password governance, privileged access monitoring, and audit logging are enforced across the environment, including legacy systems and high-risk accounts. Insurers want to see traceable activity, consistent control application, and a credible recovery process if credentials need to be reset or rotated.

Q: Why do NHIs complicate cyber insurance and identity governance?

A: NHIs complicate governance because they are numerous, frequently over-permissioned, and often lack clear human ownership. That makes lifecycle control, access review, and revocation harder to evidence. For insurers, the problem is not the existence of NHIs but whether organisations can prove their access is bounded, monitored, and removable.

Q: What breaks when least privilege is missing?

A: When least privilege is missing, a single compromised identity can reach far more systems and data than the task requires. That increases lateral movement, magnifies the effect of stolen credentials, and makes recovery slower. The failure is not just more access, but larger blast radius.

Q: Who should own cyber insurance readiness across security and identity teams?

A: Ownership should sit across security, IAM, legal, risk, and procurement, because the insurer is evaluating all of them indirectly. Security supplies the technical evidence, IAM supplies identity control maturity, and risk and legal translate that into acceptable terms. No single team can prove insurability on its own.


Technical breakdown

Why cyber insurance now depends on identity evidence

Cyber insurance underwriting has moved toward measurable identity assurance because ransomware claims expose how quickly excessive access turns into operational loss. Insurers are not evaluating identity as a concept; they are looking for proof that access can be bounded, reviewed, revoked, and evidenced across human and non-human identities. That shifts the burden from policy statements to auditable controls, especially where NHIs create hidden privilege paths. In practice, the issue is not whether controls exist, but whether they can be demonstrated quickly and consistently when a claim or audit forces scrutiny.

Practical implication: align insurance questionnaires with access review, revocation, and visibility evidence that can be produced on demand.

Why NHI visibility is part of insurability

Non-human identities often sit outside the governance cadence used for employees, yet they are central to cloud, SaaS, and workflow access. When service accounts, API keys, and tokens are not fully inventoried, organisations cannot show where privileged access lives or how far it can reach. That matters to underwriters because undiscovered access is indistinguishable from unmanaged exposure. The result is a governance problem that spans ownership, lifecycle, and detection, not a single tooling problem.

Practical implication: build an NHI inventory that ties each credential to an owner, purpose, and revocation path.

How least privilege becomes an underwriting control

Least privilege has become more than an architectural principle. In insurance terms, it is evidence that blast radius can be limited if an identity is compromised, whether the identity belongs to a user, service account, or AI-driven workflow. The stronger the access discipline, the easier it is to show that a breach will not automatically become a material loss event. This is why access reviews, PAM governance, and NHI scoping now sit close to the insurability conversation.

Practical implication: document how least privilege is enforced across privileged accounts, secrets, and service-to-service access.


Threat narrative

Attacker objective: The attacker aims to convert one compromised identity into a broader operational event that produces business disruption and a large insurance claim.

  1. Entry occurs when attackers exploit identity weaknesses, such as stolen credentials, exposed secrets, or over-permissioned accounts, to reach systems that carry insurance-relevant business processes.
  2. Escalation follows when privileged access is reused across environments, allowing the attacker to move from a single compromised identity into broader operational control and greater business disruption.
  3. Impact is measured as ransomware, data loss, service outage, and claims severity, which is why insurers now focus on whether access controls can limit the blast radius.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Cyber insurance underwriting is now a test of identity evidence, not policy intent. Insurers are not buying security narratives; they are pricing proof. If an organisation cannot demonstrate who can access what, how quickly access is revoked, and whether NHIs are under control, the underwriting conversation becomes an exposure assessment. Practitioners should treat insurance readiness as an extension of access governance, not a separate risk domain.

NHI visibility has become a financial control, not just a security control. Service accounts, API keys, and tokens often sit outside the review cadence applied to human users, yet they can drive the largest blast radii in cloud and SaaS environments. That makes unknown or partially known NHIs a problem for both incident response and insurability. The practitioner conclusion is straightforward: what cannot be inventoried cannot be defended or insured with confidence.

Least privilege is now a claims-reduction variable. Over-privileged access does not just increase breach likelihood, it increases the scale of the loss that underwriters must price. The organisations that can prove tighter privilege boundaries, stronger PAM discipline, and faster revocation will present a materially lower loss profile. Insurance teams and IAM teams therefore need shared evidence standards, not separate control stories.

Control evidence must be operational, continuous, and audit-ready. Annual attestation is too slow for a market that expects near-real-time proof of identity discipline. That pushes identity governance toward continuous monitoring, central logging, and lifecycle enforcement across both human and non-human identities. Practitioners should assume the next underwriting question will be about evidence quality, not policy existence.

Cyber insurance is exposing a broader identity governance maturity gap. Organisations that still treat NHI management as a secondary concern will find that the gap shows up in premiums, exclusions, and denied coverage discussions. The field is moving toward a single truth: if identity governance cannot be proven, risk transfer becomes harder and more expensive.

From our research:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to the Ultimate Guide to NHIs.
  • 79% of organisations have experienced secrets leaks, and 77% of those incidents resulted in tangible damage, according to the Ultimate Guide to NHIs.
  • For a governance lens on why revocation and offboarding matter, see NHI Lifecycle Management Guide for the lifecycle controls that insurers increasingly expect to see.

What this signals

Identity evidence will become a more common underwriting requirement. Organisations should expect insurers to ask for machine-readable proof of access governance, not just narrative assurance. That means lifecycle controls, privileged access records, and NHI inventories need to be maintained as operational evidence, not retrospective cleanup.

Secret remediation speed is now a risk-pricing input. With 91.6% of secrets still valid five days after notification, the control gap is not theoretical, it is measurable and persistent. Teams that cannot shorten that window will struggle to show that loss containment is realistic when access is abused.

The next step for practitioners is to align insurance readiness with broader access governance, including NHI lifecycle management and authoritative control baselines such as the NIST AI Risk Management Framework where agentic access is present.


For practitioners

  • Map underwriting questions to identity evidence Translate insurer requests into specific evidence for MFA, least privilege, access reviews, and NHI ownership so responses are consistent and repeatable.
  • Inventory all non-human identities Create a single inventory for service accounts, API keys, tokens, and certificates, with named owners, business purpose, and revocation paths.
  • Prove least privilege across privileged access Document how privileged access is scoped, reviewed, and time-bounded across human and machine identities, then retain the evidence in a format usable for audit and underwriting.
  • Shorten revocation and remediation cycles Measure how quickly secrets, credentials, and access grants are removed after role change, incident, or notification, because slow revocation inflates both breach and insurance risk.

Key takeaways

  • Cyber insurance is becoming an identity governance test, because underwriters now care about provable access discipline rather than security intent alone.
  • The hardest gap is still remediation speed, since stale secrets and over-privileged NHIs can turn a contained event into a large financial loss.
  • IAM, IGA, PAM, and NHI teams need shared evidence standards if the organisation wants better underwriting outcomes and fewer coverage surprises.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Least-privilege access and account management are central to insurability claims.
NIST SP 800-53 Rev 5IA-5Authenticator management governs the secrets and credentials insurers want evidence for.
NIST Zero Trust (SP 800-207)Zero trust assumptions are relevant because insurers now expect continuous verification of access.

Use zero trust principles to show access is verified continuously rather than assumed by default.


Key terms

  • Cyber Insurance Posture: The set of identity, security, and governance controls that determines how an insurer views an organisation’s loss exposure. In practice, posture is judged by evidence that access is limited, monitored, and revocable across human and non-human identities, not by claims of maturity alone.
  • Identity Evidence Continuity: The uninterrupted chain of records that shows how a control was defined, approved, executed, and reviewed. In audit settings, it is the difference between claiming compliance and proving it with traceable identity, access, and activity evidence across systems.
  • Exposure-to-Remediation Window: The exposure-to-remediation window is the time between when a credential is compromised and when it is reset, revoked, or otherwise made unusable. Shortening that window is critical because valid credentials often create the first foothold in account takeover and downstream fraud.
  • Insurability: An organisation’s ability to obtain and retain cyber insurance on acceptable terms. In identity security, insurability depends on whether the company can demonstrate control over access, secrets, and lifecycle processes well enough to satisfy underwriters and reduce perceived loss frequency.

What's in the full article

Veza's full whitepaper covers the operational detail this post intentionally leaves for the source:

  • How the whitepaper maps cyber insurance requirements to identity controls such as MFA, least privilege, and NHI visibility
  • Why the authors connect ransomware loss trends to underwriting expectations and premium pressure
  • What evidence organisations can present to prove access governance maturity during insurer review
  • How identity-centric controls are framed as a way to reduce denied coverage risk and financial exposure

👉 The full Veza whitepaper covers insurer requirements, access evidence, and identity controls in more operational detail.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 25, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org