Is your cyber insurance premium really reflecting your company’s security posture?
08 Aug 2025
•
,
3 min. read
Hey there, have you ever received a sky-high cyber risk insurance quote and wondered if it truly reflects your company’s risk level? It turns out, the premium amount may not always be indicative of your environment’s risk. In fact, it could be related to the insurer’s risk exposure to a specific product or service you use, rather than your internal security measures.
At a recent talk during Black Hat USA 2025, it was revealed that insurers may set limits on the usage of certain vendors in your supply chain. If your business exceeds this limit, they might quote you a higher premium to mitigate their risk, rather than outright declining coverage.
This means that the perceived risk lies not within your organization, but with your suppliers. It might not even be a specific risk associated with them, but rather a risk threshold set by the insurer.
As consumers, we can draw parallels from other insurance sectors. For instance, when comparing car insurance quotes, premiums can vary significantly even if the risk level remains constant. This variation could be attributed to insurers capping their exposure to specific car manufacturers.
As the realms of cyber insurance and cybersecurity converge, data-driven insights from insurers’ claims can enhance security practices across the board. For instance, should multi-factor authentication (MFA) not be a default requirement for companies providing remote access via SSL VPN? Surprisingly, statistics show that 45% of new cyber claims in the first half of 2025 were due to SSL VPNs lacking MFA.
It’s eye-opening to see how claims data sheds light on cyber threats. For example, Coalition’s data reveals that a majority of ransomware attacks originate from perimeter security devices, with credential theft being a common method. However, there is a silver lining – efforts to recover funds from fraudulent transfers have shown some success, with an average claw-back of $278,000 per event.
Insurers are stepping up their game to mitigate risks. Some now offer customized cyber threat intelligence based on the insured’s environment, proactive monitoring for vulnerabilities, and even purchasing compromised credentials from the dark web to protect their clients.
As the insurance and cybersecurity sectors intertwine further, one can’t help but wonder how far this collaboration will go. What are your thoughts on this evolving landscape?

