TL;DR: Ransomware accounted for 58% of large cyber insurance claims in 2024, while breaches such as Change Healthcare and CDK Global drove insurers to raise premiums and demand proof of stronger identity controls, according to Veza. Identity programmes that cannot demonstrate visibility, least privilege, and NHI governance are now underwriting risks, not just security gaps.
At a glance
What this is: This is a cyber insurance analysis arguing that NHI visibility, least privilege, and identity governance are now underwriting requirements, not optional controls.
Why it matters: IAM, IGA, PAM, and NHI teams need to prove who and what can access critical systems because insurers are treating weak identity governance as a measurable risk signal.
By the numbers:
- Ransomware accounted for 58% of large cyber insurance claims in 2024.
Context
Cyber insurance is increasingly evaluating identity control maturity, especially where non-human identities can reach production data, cloud services, and sensitive workflows. In practice, the underwriting question is no longer whether an organisation has security tools, but whether it can evidence governed access across both human and machine identities.
Veza's whitepaper frames insurability as an identity governance problem because claims severity, premium pressure, and coverage decisions are being tied to demonstrable controls. The issue is not limited to one product or one insurer; it reflects a broader shift toward proving access visibility, least privilege, and lifecycle control.
For IAM and NHI programmes, this changes the audience for identity evidence. The same controls that reduce operational risk now also shape financial exposure, audit readiness, and the organisation's ability to negotiate coverage on credible terms.
Key questions
Q: What breaks when cyber insurance depends on NHI controls and visibility is missing?
A: When insurers expect proof of NHI governance, missing visibility breaks the organisation's ability to demonstrate bounded access. Service accounts, tokens, and certificates can remain active without clear ownership or review, so the security team cannot show which identities are controlled, which are stale, or which could magnify a loss event.
Q: Why do service accounts and machine identities matter under NIS2?
A: Service accounts and machine identities matter because they often carry the permissions that move data, trigger reports, and feed AI workflows. If those identities are over-privileged or left out of review cycles, the organisation cannot prove that access is proportionate or necessary. Under NIS2, that creates both security exposure and audit weakness.
Q: How should security teams prove identity controls during cyber insurance renewal?
A: Focus on evidence, not policy statements. Show that password governance, privileged access monitoring, and audit logging are enforced across the environment, including legacy systems and high-risk accounts. Insurers want to see traceable activity, consistent control application, and a credible recovery process if credentials need to be reset or rotated.
Q: Should organisations prioritise NHI governance before renewing cyber insurance?
A: Yes, if the business depends on meaningful coverage terms. NHI governance affects whether the organisation can prove it understands who or what has access, how that access is constrained, and how quickly it can be removed. Without that evidence, premium pressure and coverage disputes become more likely.
Technical breakdown
Why cyber insurers care about identity controls
Cyber insurers are focusing on identity because it is where many high-severity incidents become measurable. Identity controls show whether access is visible, bounded, and revocable, which makes them easier to underwrite than broad security claims. When NHIs hold privileged access, the insurer is effectively asking whether those accounts are inventoried, scoped, and governed with the same discipline as human users. The result is a shift from generic risk scoring to evidence-based access assurance.
Practical implication: build identity evidence packs that show visibility, privilege scope, and lifecycle control for NHIs and human accounts alike.
How NHI governance affects insurability
Non-human identities matter because they often sit outside the control patterns insurers expect to see. Service accounts, tokens, and API credentials can persist longer than the business process that created them, which makes exposure hard to bound and harder to explain during underwriting. If an organisation cannot show what each NHI can access, who owns it, and when it is reviewed or revoked, the insurer may treat that as unmanaged attack surface rather than controlled access.
Practical implication: map every NHI to an owner, a purpose, and a review cadence before insurers ask for proof.
What identity evidence changes in a claims-heavy market
As claims pressure rises, underwriters tend to ask for controls that can be verified quickly and consistently. That means MFA, least privilege, access reviews, and visibility into NHI use become operational proofs rather than policy statements. The deeper issue is that cyber insurance now behaves like a governance test: if the programme cannot produce reliable identity telemetry, it cannot easily demonstrate that loss scenarios are constrained.
Practical implication: treat insurance questionnaires as a recurring control validation exercise, not a once-a-year compliance event.
Threat narrative
Attacker objective: The objective is to turn weak identity governance into operational disruption and financial loss that insurers cannot ignore.
- Entry often begins with abused identity paths, where attackers target credentials, tokens, or delegated access instead of exploiting perimeter controls.
- Escalation follows when privileged accounts or over-scoped non-human identities provide access to backup systems, cloud workloads, or sensitive data stores.
- Impact occurs when the attacker uses that access for encryption, exfiltration, or business disruption severe enough to trigger claims, premium increases, or denied coverage.
Breaches seen in the wild
- Coupang Signing Key Breach: Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Cyber insurance has become an identity governance test: insurers are no longer pricing only perimeter risk; they are pricing the organisation's ability to evidence controlled access. That moves identity from a technical domain into the underwriting conversation, where proof matters more than claims of maturity. For practitioners, the implication is that identity evidence must be structured, repeatable, and defensible.
NHI visibility is now a financial control, not just a security control: service accounts and API credentials can create hidden exposure that underwriters increasingly care about because they expand loss potential beyond human logins. If an organisation cannot inventory and review those identities, it cannot credibly claim bounded access. The practical conclusion is that NHI governance has become part of insurability.
Identity blast radius is the right concept for insurer conversations: the question is not whether access exists, but how far a single compromised identity can move before detection or revocation. That framing is stronger than generic least privilege because it ties governance to loss severity. Practitioners should measure and communicate blast radius in the same language used for financial exposure.
Assumptions built for human access break when machine identities are in scope: periodic review cycles were designed for accounts that persist long enough to be certified. That assumption weakens when NHIs are numerous, service-bound, and often invisible to the business owner that insurers expect to see. The implication is that identity governance must prove continuous control, not just periodic review.
Cyber insurance is pushing the market toward evidence-led identity governance: organisations that can show access inventory, ownership, and review outcomes will negotiate from a stronger position than those relying on policy text alone. This does not replace security architecture, but it raises the value of operational proof. Practitioners should expect insurers to reward demonstrable control maturity over generic assurance claims.
From our research library:
- Only 5.7% of organisations have full visibility into their service accounts, according to the Ultimate Guide to NHIs.
- Read next: Ultimate Guide to NHIs — Key Challenges and Risks
What this signals
Identity evidence is becoming a commercial control surface: underwriting now rewards organisations that can show access inventory, review outcomes, and revocation discipline. That puts IAM and NHI programmes in a far more visible position during financial risk assessment, not just security assessment.
Service account visibility is a governance gap with pricing impact: according to the Ultimate Guide to NHIs, only 5.7% of organisations have full visibility into their service accounts. For insurers and practitioners alike, that means hidden access is still the norm, and hidden access is hard to defend when coverage depends on proof.
For practitioners
- Document NHI ownership and business purpose Assign every service account, token, certificate, and API credential to a named owner and a specific workload or process. If an identity has no owner or no business purpose, it is difficult to defend to an underwriter and should be treated as unmanaged exposure.
- Build an insurer-ready identity evidence pack Assemble screenshots, reports, and logs that prove MFA coverage, least privilege, NHI inventory, access review outcomes, and revocation processes. Keep it current so the organisation can answer underwriting questions without scrambling for ad hoc evidence.
- Reduce standing privilege in NHI estates Identify service accounts and machine credentials that hold broad or persistent access to critical systems, then narrow scope to the minimum operational set. Focus first on identities that can reach backups, production data, and administrative APIs.
- Tie access review cycles to loss scenarios Use claims impact, ransomware exposure, and critical workload access to prioritise which identities get reviewed first. The goal is not just compliance cadence, but showing that the most dangerous access paths are reviewed before they can drive material loss.
Key takeaways
- Cyber insurance is increasingly testing whether identity programmes can produce evidence of control, not just assert that controls exist.
- The biggest underwriting concern is hidden or overprivileged non-human access, because it widens the blast radius of a breach or outage.
- Teams that can document ownership, scope, review, and revocation for NHIs will be better positioned on premiums, audits, and claims scrutiny.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | The article centers on proving and reducing excessive access in service accounts and other NHIs. |
| NHI-03 — Vulnerable Third-Party NHI | Insurance scrutiny extends to externally managed identities and delegated access paths. | |
| NHI-07 — Long-Lived Secrets | Persistent credentials increase the exposure window that insurers view as unmanaged risk. | |
| Recommendation — Audit NHI permissions and remove standing access that increases loss severity. Verify third-party identity ownership, scope, and offboarding for every delegated account. Shorten secret lifetime and revoke stale credentials before coverage reviews expose the gap. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is fundamentally about proving access permissions are governed and bounded. |
| Recommendation — Document and enforce access entitlements so insurers can verify governance outcomes. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account ownership, review, and removal are central to the insurability question. |
| Recommendation — Maintain complete account inventories and remove stale identities on a defined schedule. | ||
Key terms
- Cyber Insurance Posture: The set of identity, security, and governance controls that determines how an insurer views an organisation’s loss exposure. In practice, posture is judged by evidence that access is limited, monitored, and revocable across human and non-human identities, not by claims of maturity alone.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- NHI Visibility: NHI visibility is the ability to discover every non-human identity, classify it with context and keep it continuously accounted for across the environment. Without visibility, lifecycle controls cannot be enforced because the programme cannot tell what exists, who owns it or where it is used.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 25, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org