Cyber insurers should combine historical claims data with current attack surface intelligence, because past stability does not guarantee present safety. Underwriting works best when teams assess exposed assets, reachable services, and internet-facing weaknesses the way an attacker would. That approach helps insurers price risk more accurately, reduce surprise losses, and update coverage decisions as a policyholder’s environment changes.
Why Underwriting Needs Live Exposure Signals, Not Historical Claims Alone
When internet-facing conditions change quickly, historical loss data becomes a lagging indicator rather than a full underwriting truth. Insurers need a current view of what is actually reachable, because exposed services, obsolete edge systems, and newly disclosed weaknesses can change loss potential long before claims experience catches up. NHIMG’s Ultimate Guide to NHI is useful here because it frames visibility, rotation, and exposed credentials as active risk drivers, not static inventory items.
That is the same reason recent breach analysis matters. The patterns in The 52 NHI breaches Report and 52 NHI Breaches Analysis show that exposed access paths, stolen secrets, and weak control points often matter more than the age of the policyholder’s last clean year. For insurers, the practical implication is simple: assess what an attacker can touch now, not just what the loss model expected last quarter.
One useful reference point from NHIMG research is that only 5.7% of organisations have full visibility into their service accounts. That kind of visibility gap is exactly why underwriting based only on self-reported controls or historical loss curves can miss current exposure. It also explains why current attack surface intelligence should be treated as underwriting input, not optional enrichment.
What to Measure When the Environment Moves Faster Than the Model
The most predictive indicators are the ones that change close to the point of compromise: externally reachable assets, exposed admin interfaces, weak authentication paths, stale certificates, internet-facing secrets, and newly discovered service exposures. These are operational signals of present-day attackability, so they should influence pricing, deductibles, sublimits, and eligibility decisions more directly than broad organisational averages.
CISA Known Exploited Vulnerabilities Catalog is a strong external benchmark for this approach because it tracks vulnerabilities with confirmed active exploitation, which is closer to underwriting reality than theoretical severity alone. Likewise, CISA cyber threat advisories help insurers and brokers align coverage review with current exploitation trends instead of waiting for quarterly or annual renewal cycles.
For internet-facing risk, the question is not simply whether a vulnerability exists. It is whether the policyholder can be reached, whether the weak point is exposed to the public internet, and whether the control gap is likely to persist long enough for an attacker to find it before remediation occurs.
Risk and Threat Considerations
Underwriting errors happen when insurers treat exposure as a static property. A policyholder can move from acceptable to highly exposed through one new service, one misconfigured endpoint, or one unrotated secret, even if its historical loss record looks stable.
Failure mechanism: Attackers search for reachable systems and weak trust paths, then exploit whatever is currently exposed, including vulnerable services, leaked secrets, and stale access material. Historical claims models do not see that change until after the event.
Impact: Coverage decisions, pricing, and accumulation estimates can lag real exposure, which increases surprise loss, weakens portfolio controls, and can leave insurers unintentionally overcommitted to fast-changing risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS 1 — Inventory and Control of Enterprise Assets | Tracks exposed assets that define current internet-facing attack surface. |
| CIS 4 — Secure Configuration of Enterprise Assets and Software | Misconfiguration often creates the internet-facing weakness insurers need to price. | |
| CIS 7 — Continuous Vulnerability Management | Current exploitable weaknesses matter more than stale historical stability. | |
| Recommendation — Inventory externally reachable assets continuously and flag unmanaged public services for underwriting review. Verify secure baseline configuration for public-facing services before relying on historical loss data. Use continuous vulnerability evidence to update coverage decisions when exposure changes. | ||
| NIST CSF 2.0 | GV.1 — Cybersecurity Risk Management Strategy | Insurance underwriting needs a strategy for combining historical and live risk signals. |
| ID.AM — Asset Management | Current asset inventory is central to measuring internet-facing risk. | |
| DE.CM — Continuous Monitoring | Live monitoring is needed because exposure changes faster than claims data. | |
| Recommendation — Blend loss history with live exposure telemetry in the underwriting risk strategy. Require current asset and service inventory before assigning coverage or limits. Monitor externally reachable changes continuously and feed them into renewal decisions. | ||
| NIST AI RMF | MAP 1 — Context Is Recognized | Underwriting must incorporate operational context and current exposure conditions. |
| MEASURE 1 — Applicable and Evaluable Methods and Metrics Are Identified and Selected | Insurers need metrics that reflect live exposure, not only past claims. | |
| Recommendation — Map policyholder exposure context before relying on historical loss assumptions. Select live exposure metrics that are measurable and decision-useful at renewal time. | ||
| MITRE ATT&CK | T1595 — Active Scanning | Attackers discover current internet-facing weaknesses by scanning what is reachable now. |
| T1190 — Exploit Public-Facing Application | Publicly reachable weaknesses drive loss when exposure changes faster than model updates. | |
| Recommendation — Assess the policyholder as an attacker would by scanning reachable services and exposures. Prioritise public-facing exploitability when pricing and reviewing cyber coverage. | ||
Practitioner Guidance
What to prioritise: Underwriters should weight present attack surface evidence more heavily when the applicant has internet-facing assets that change frequently, especially if they also have weak visibility into asset ownership, credential rotation, or third-party exposure. In those cases, renewal should be a control review, not a calendar exercise.
What to verify: Ask for evidence that the policyholder can inventory externally reachable systems, map exposed services to owners, and show rapid remediation for newly discovered weaknesses. If they cannot produce that evidence, treat the uncertainty as a pricing and eligibility issue, not just a documentation gap.
Practitioner takeaway: The best underwriting signal is not whether a company was safe last year, but whether its current internet-facing footprint can be observed, verified, and re-evaluated quickly enough to keep pace with attacker discovery.
Related resources from NHI Mgmt Group
- How should security teams handle insider risk when behavior changes faster than static policies can track?
- Why do hidden internet-facing assets increase cyber risk in complex enterprises?
- Why do internet-facing AI retrieval services create outsized risk?
- Why do internet-facing PAM systems create outsized identity risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 19, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org