TL;DR: Cyber insurance underwriting is shifting toward measurable human risk reduction, with Verizon reporting the human element in roughly 68% of breaches and the FBI citing more than $2.9 billion in adjusted BEC losses in 2023, according to Living Security Human Risk Management Platform. Renewal evidence now needs outcome data, not just completion rates, because insurers are pricing exposure, control effectiveness, and repeatable intervention.
NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How Cyber Insurance Human Risk Management Affects Premiums
By the numbers:
- Verizon's 2024 DBIR found the human element involved in roughly 68% of breaches.
- The FBI reported more than $2.9 billion in adjusted losses from business email compromise in 2023.
- Living Security reports that its platform automates 60% to 80% of routine remediation tasks.
Questions worth separating out
Q: How should security teams prove human risk reduction to cyber insurers?
A: Show trend-based evidence, not training attendance.
Q: Why do IAM and PAM teams matter in cyber insurance renewals?
A: Because insurers are evaluating whether risky decisions can actually turn into loss.
Q: What breaks when human-risk programmes stop at awareness training?
A: You lose evidence of control effectiveness.
Practitioner guidance
- Map underwriting questions to control evidence Build a renewal pack that links human-risk findings to concrete controls, including phishing outcomes, reporting behaviour, privileged-user exceptions, and remediation actions.
- Segment human-risk data by access context Separate results for finance, executives, administrators, contractors, and other high-impact groups so insurers can see where loss exposure is concentrated.
- Document the intervention loop end to end Record the trigger, assigned owner, control applied, and post-intervention outcome for each high-risk user population.
What's in the full article
Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:
- The specific evidence package Living Security recommends for cyber insurance renewal conversations, including what to collect and how to present it.
- The platform metrics and behavioural indicators used to show that human-risk controls are changing outcomes over time.
- The comparison between traditional awareness reporting and Human Risk Management evidence for underwriting discussions.
- The role of automation in routing interventions and documenting repeatable remediation across risk populations.
Cyber insurance and human risk management: what changes for renewals?
Explore further
Human risk management has become an underwriting discipline, not a training metric. Carriers are no longer satisfied with proof that users attended awareness sessions. They want evidence that behaviour changed, exposure fell, and controls altered the probability of loss. That makes outcome measurement central to cyber insurance, especially where identity, privilege, and payment authority intersect. Practitioners should treat human-risk evidence as part of their governance and renewal package, not a side report.
A few things that frame the scale:
- Two-thirds of enterprises have endured a successful cyberattack resulting from compromised non-human identities, with a quarter encountering multiple attacks, according to 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, according to 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
Q: Who is accountable when cyber insurers demand outcome-based risk evidence?
A: Security leadership, IAM, PAM, and business owners share accountability because the evidence spans behaviour, access, and operational controls. The organisation must be able to explain who owns the baseline, who runs interventions, and who validates that changes reduced the likelihood of loss.
👉 Read our full editorial: Cyber insurance is pricing human risk, not training completion