TL;DR: Cyber insurers are shifting from checklist-based underwriting to evidence of how quickly organisations can validate exposure, prioritise remediation and prove risk removal when AI accelerates vulnerability discovery and exploitation, according to Tonic. The real test is no longer whether controls exist, but whether security teams can adapt at machine speed before exposure becomes loss.
NHIMG editorial — based on content published by Tonic: Cyber insurers are underwriting response speed, not just controls
By the numbers:
- The cost of running a full attempt had fallen to approximately £65.
Questions worth separating out
Q: How should security teams prove that a vulnerability has really been remediated?
A: They should require evidence that the vulnerable condition is no longer reachable or exploitable, not just that a ticket is closed.
Q: Why do AI-accelerated attacks change cyber insurance expectations?
A: AI shortens the time between vulnerability disclosure and exploit execution, so insurers care more about how quickly a policyholder can validate exposure and act.
Q: What do teams get wrong about patching and resilience?
A: Teams often mistake patch completion for risk reduction after compromise, but patching only addresses known vulnerabilities.
Practitioner guidance
- Measure verified remediation, not just ticket closure Track the time from vulnerability discovery to evidence that the exposure is no longer reachable, exploitable or externally exposed.
- Join asset ownership to remediation routing Maintain a current map of system owners, service accounts and administrative paths so vulnerable assets can be assigned immediately when a new issue appears.
- Prioritise reachable and business-critical exposures Score findings by exploitability, internet exposure, business service dependency and compensating controls before escalating patch work.
What's in the full article
Tonic's full article covers the operational detail this post intentionally leaves for the source:
- How Mean Time to Adapt is measured in practice across discovery, triage and verified remediation.
- The specific operational questions insurers are asking about exposure validation, patching and recovery speed.
- Examples of how contextual prioritisation changes vulnerability handling when AI compresses attack timelines.
- The way exposure management workflows can connect security, IT and ownership data for faster closure.
👉 Read Tonic's analysis of why cyber insurers are underwriting response speed →
Mean time to adapt is the new cyber insurance question?
Explore further
Response speed is becoming a governance control, not just an operational metric. Cyber insurers are effectively pricing the time it takes to move from exposure discovery to verified reduction. That matters because many programmes still measure activity, such as tickets closed or patches deployed, rather than evidence that the viable attack path is gone. Practitioners should treat validated remediation as a control outcome.
A question worth separating out:
Q: Who is accountable when exposure remains open after a vulnerability is disclosed?
A: Accountability should sit with the asset or service owner, but only if ownership records are current and tied to privileged access paths. In practice, that means IAM, infrastructure and security teams need a shared operating model for assigning remediation, approving exceptions and proving closure. Otherwise, gaps linger because no one can act decisively.
👉 Read our full editorial: Cyber insurers are underwriting response speed, not just controls