Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Cyber insurance and human risk management: what changes for renewals?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 18004
Topic starter  

TL;DR: Cyber insurance underwriting is shifting toward measurable human risk reduction, with Verizon reporting the human element in roughly 68% of breaches and the FBI citing more than $2.9 billion in adjusted BEC losses in 2023, according to Living Security Human Risk Management Platform. Renewal evidence now needs outcome data, not just completion rates, because insurers are pricing exposure, control effectiveness, and repeatable intervention.

NHIMG editorial — based on content published by Living Security Human Risk Management Platform: How Cyber Insurance Human Risk Management Affects Premiums

By the numbers:

Questions worth separating out

Q: How should security teams prove human risk reduction to cyber insurers?

A: Show trend-based evidence, not training attendance.

Q: Why do IAM and PAM teams matter in cyber insurance renewals?

A: Because insurers are evaluating whether risky decisions can actually turn into loss.

Q: What breaks when human-risk programmes stop at awareness training?

A: You lose evidence of control effectiveness.

Practitioner guidance

  • Map underwriting questions to control evidence Build a renewal pack that links human-risk findings to concrete controls, including phishing outcomes, reporting behaviour, privileged-user exceptions, and remediation actions.
  • Segment human-risk data by access context Separate results for finance, executives, administrators, contractors, and other high-impact groups so insurers can see where loss exposure is concentrated.
  • Document the intervention loop end to end Record the trigger, assigned owner, control applied, and post-intervention outcome for each high-risk user population.

What's in the full article

Living Security Human Risk Management Platform's full blog post covers the operational detail this post intentionally leaves for the source:

  • The specific evidence package Living Security recommends for cyber insurance renewal conversations, including what to collect and how to present it.
  • The platform metrics and behavioural indicators used to show that human-risk controls are changing outcomes over time.
  • The comparison between traditional awareness reporting and Human Risk Management evidence for underwriting discussions.
  • The role of automation in routing interventions and documenting repeatable remediation across risk populations.

👉 Read Living Security Human Risk Management Platform's analysis of cyber insurance and human risk management →

Cyber insurance and human risk management: what changes for renewals?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 17593
 

Human risk management has become an underwriting discipline, not a training metric. Carriers are no longer satisfied with proof that users attended awareness sessions. They want evidence that behaviour changed, exposure fell, and controls altered the probability of loss. That makes outcome measurement central to cyber insurance, especially where identity, privilege, and payment authority intersect. Practitioners should treat human-risk evidence as part of their governance and renewal package, not a side report.

A few things that frame the scale:

A question worth separating out:

Q: Who is accountable when cyber insurers demand outcome-based risk evidence?

A: Security leadership, IAM, PAM, and business owners share accountability because the evidence spans behaviour, access, and operational controls. The organisation must be able to explain who owns the baseline, who runs interventions, and who validates that changes reduced the likelihood of loss.

👉 Read our full editorial: Cyber insurance is pricing human risk, not training completion



   
ReplyQuote
Share: