TL;DR: Cyber insurance underwriting is shifting toward measurable human risk reduction, with Verizon reporting the human element in roughly 68% of breaches and the FBI citing more than $2.9 billion in adjusted BEC losses in 2023, according to Living Security Human Risk Management Platform. Renewal evidence now needs outcome data, not just completion rates, because insurers are pricing exposure, control effectiveness, and repeatable intervention.
At a glance
What this is: This analysis argues that cyber insurance is moving from training checklists to evidence of measurable human risk reduction.
Why it matters: For IAM and security teams, that changes how human behaviour, identity context, and privileged access evidence are packaged for renewal, audit, and loss-prevention conversations.
By the numbers:
- Verizon's 2024 DBIR found the human element involved in roughly 68% of breaches.
- The FBI reported more than $2.9 billion in adjusted losses from business email compromise in 2023.
- Living Security reports that its platform automates 60% to 80% of routine remediation tasks.
Context
Cyber insurance is increasingly tied to whether organisations can show that human-driven exposure is falling, not just that security awareness activities were completed. In practice, that pushes human risk management into the same evidence conversation as IAM, PAM, and identity lifecycle controls, because insurers want proof that decisions, access, and behaviour are changing outcomes.
The primary governance gap is that completion data measures activity, while underwriting now wants exposure reduction. In identity-heavy environments, that means teams must connect risky behaviour to access context, privileged populations, and measurable intervention results rather than treating workforce training as a standalone control.
Key questions
Q: How should security teams prove human risk reduction to cyber insurers?
A: Show trend-based evidence, not training attendance. Include phishing click rates, reporting speed, repeat-risk counts, targeted intervention outcomes, and how those metrics changed across roles or access tiers. Insurers respond better to a clear baseline, a consistent measurement method, and a documented control loop than to a completion percentage alone.
Q: Why do IAM and PAM teams matter in cyber insurance renewals?
A: Because insurers are evaluating whether risky decisions can actually turn into loss. Identity and privilege context shows which users can approve payments, access sensitive data, or trigger administrative actions, so it helps explain why the same behaviour has different financial impact in different roles.
Q: What breaks when human-risk programmes stop at awareness training?
A: You lose evidence of control effectiveness. Training can improve awareness, but it does not show whether risky behaviour declined, whether repeat offenders changed, or whether a higher-risk population was actually reduced. Without that proof, underwriting conversations revert to activity reporting instead of exposure management.
Q: Who is accountable when cyber insurers demand outcome-based risk evidence?
A: Security leadership, IAM, PAM, and business owners share accountability because the evidence spans behaviour, access, and operational controls. The organisation must be able to explain who owns the baseline, who runs interventions, and who validates that changes reduced the likelihood of loss.
Technical breakdown
Why training completion no longer satisfies underwriting questions
Cyber insurers are looking for indicators that correlate with loss reduction, not attendance records. A completed course says a user received information, but it does not show whether phishing susceptibility fell, whether risky transactions were intercepted, or whether repeat offenders were redirected into safer workflows. Human risk management therefore behaves more like a control system than a communications campaign. It combines behaviour analytics, identity context, and threat signals to create a measurable view of exposure. That model is especially relevant where users hold privileged access or can authorise payments, because those roles carry outsized loss potential.
Practical implication: build renewal evidence around outcome metrics such as click-rate reduction, reporting speed, and repeat-risk decline, not course completion.
How behaviour, identity, and access data change risk scoring
Human risk management works by correlating what users do with what they can access and what threats they face. That means a finance user, a privileged administrator, and a contractor should not be scored with the same logic if their exposure is materially different. Behavioural telemetry becomes more useful when it is joined to identity and access data, because the same unsafe action has very different consequences depending on role, privilege, and data sensitivity. This is where IAM and PAM intersect with human-risk programs: the objective is to identify where risky decisions can turn into material loss, then intervene before the decision is repeated.
Practical implication: segment human-risk metrics by role, access level, and business function so insurers see a real control model, not a generic awareness score.
Why automation matters in proving sustained reduction
Insurers care less about one successful intervention than about whether improvement can be sustained. Automation helps security teams route targeted learning, trigger reminders, adjust controls, and escalate exceptions without relying on manual follow-up for every case. That matters because human risk tends to recur, especially in high-pressure workflows such as invoicing, executive email, and data handling. In underwriting terms, repeatability is evidence. A program that can show an intervention, the population affected, and the subsequent trend is more credible than one-off campaign reporting.
Practical implication: document the full intervention loop, including trigger, owner, action taken, and measured change over time.
Threat narrative
Attacker objective: The attacker wants to turn a single human decision into measurable financial loss or account compromise at scale.
- Entry often begins with phishing, impersonation, or another human-targeted lure that reaches a user with meaningful access.
- Escalation follows when the victim approves a payment, discloses credentials, or allows a malicious workflow to proceed.
- Impact occurs when the attacker converts that human decision into financial loss, fraud, or broader business email compromise activity.
Breaches seen in the wild
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Human risk management has become an underwriting discipline, not a training metric. Carriers are no longer satisfied with proof that users attended awareness sessions. They want evidence that behaviour changed, exposure fell, and controls altered the probability of loss. That makes outcome measurement central to cyber insurance, especially where identity, privilege, and payment authority intersect. Practitioners should treat human-risk evidence as part of their governance and renewal package, not a side report.
Cyber insurance is pushing IAM and PAM teams closer to the human-risk conversation. The strongest underwriting story now connects behaviour with identity context and access scope. A risky click matters more when it comes from a user who can approve payments, access sensitive data, or trigger administrative actions. That means identity teams need shared metrics with security awareness, fraud, and governance functions. Practitioners should align access governance with measurable human-risk outcomes.
Outcome-based evidence is the new control language: completion rates, by themselves, do not describe exposure reduction. The field is moving toward repeatable intervention, documented change, and trend analysis across roles and access tiers. That shift validates the broader move from static compliance to measurable security governance. Practitioners should insist on evidence that ties interventions to reduced loss likelihood.
Cyber insurance underwriting is becoming a proxy for security programme maturity. Organisations that cannot show trend improvement, exception handling, and intervention effectiveness will look operationally opaque to insurers. That is not just a finance issue. It is a signal that human-risk governance, IAM evidence, and privileged access oversight are not yet joined up. Practitioners should prepare for insurers to ask the same questions boards should already be asking.
From our research:
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to 2024 ESG Report: Managing Non-Human Identities.
- From our research: Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to 2024 ESG Report: Managing Non-Human Identities.
- From our research: Review NHI Lifecycle Management Guide for the access, rotation, and offboarding controls that reduce standing exposure.
What this signals
Cyber insurance is now acting as a forcing function for better human-risk governance, especially where identity and payment workflows intersect. Teams that already track access context and behavioural outcomes will find renewal conversations easier because they can show whether risk is falling rather than simply describing policy coverage.
Exposure evidence gap: insurers want an evidence chain from behaviour to impact, and that chain usually breaks when organisations only report training completion or awareness activity. The next maturity step is to join IAM, PAM, and human-risk telemetry into one defensible control story.
For identity programmes, this is a reminder that risk evidence must travel across teams. Human behaviour, privileged access, and fraud exposure are now part of the same governance conversation, and the organisations that can prove correlation will look materially stronger at renewal time.
For practitioners
- Map underwriting questions to control evidence Build a renewal pack that links human-risk findings to concrete controls, including phishing outcomes, reporting behaviour, privileged-user exceptions, and remediation actions. Use the same baseline, measurement period, and ownership model across every metric.
- Segment human-risk data by access context Separate results for finance, executives, administrators, contractors, and other high-impact groups so insurers can see where loss exposure is concentrated. Connect those segments to identity and access data, not just awareness campaign results.
- Document the intervention loop end to end Record the trigger, assigned owner, control applied, and post-intervention outcome for each high-risk user population. This shows repeatability and helps distinguish durable reduction from a one-time campaign effect.
- Use privileged-access evidence in renewal discussions Show how risky behaviour is handled when the user has elevated access, payment authority, or access to sensitive data. Insurers will care more about those populations than about broad workforce averages.
Key takeaways
- Cyber insurance is shifting toward measurable human-risk outcomes, not compliance theatre.
- Identity, privilege, and behaviour data now matter because insurers are pricing loss exposure, not policy intent.
- Teams that can prove intervention-led reduction will have a stronger underwriting story than teams that only show training completion.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-01 | Human-risk evidence supports risk measurement and governance for underwriting. |
| NIST SP 800-53 Rev 5 | AT-2 | Awareness training is referenced, but only as one component of a broader evidence model. |
| ISO/IEC 27001:2022 | A.6.3 | Awareness and training remain relevant, but only as part of measurable control effectiveness. |
Document awareness as one control input and pair it with outcome-based effectiveness evidence.
Key terms
- Human Risk Management: The practice of managing how people interact with security controls, especially under pressure, distraction, or deception. It combines training, policy, and friction management so identity systems are still usable enough that users do not bypass them in day-to-day work.
- Outcome-Based Evidence: Outcome-based evidence is proof that a control changed a measurable security result, not just that activity occurred. In cyber insurance contexts, it includes trend data such as reduced phishing clicks, faster reporting, fewer repeat failures, and lower exposure in high-risk populations.
- Behavioural Risk Signal: A behavioural risk signal is an observable action or pattern that suggests increased likelihood of unsafe security behaviour. Examples include repeated simulation failures, risky handling of data, or ignoring recommended actions. Used well, these signals inform targeted guidance rather than broad, generic awareness campaigns.
- Underwriting Evidence: The control, process, and documentation proof an insurer uses to assess cyber risk. This usually includes MFA coverage, access management, incident response testing, and compliance artefacts. For identity teams, underwriting evidence is the bridge between technical control maturity and the commercial terms attached to a policy.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific evidence package Living Security recommends for cyber insurance renewal conversations, including what to collect and how to present it.
- The platform metrics and behavioural indicators used to show that human-risk controls are changing outcomes over time.
- The comparison between traditional awareness reporting and Human Risk Management evidence for underwriting discussions.
- The role of automation in routing interventions and documenting repeatable remediation across risk populations.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security and identity practitioners connect access evidence to governance decisions across their programmes.
Published by the NHIMG editorial team on August 19, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org