Financial Services3 min read

Read Your Cyber Policy Against Your Risk Register, Not Your Budget

Cyber cover is usually bought on price and limit. The useful exercise is reading the policy's conditions against what your own risk register says is true.

Cyber insurance gets bought the way most insurance gets bought: a broker presents options, somebody picks a limit that feels defensible, and the policy goes in a drawer until renewal.

The problem is that a cyber policy is not only a limit. It is a set of conditions and warranties describing controls the insurer believes you have, and a set of exclusions describing losses it will not pay for. Both are worth reading against what your firm actually does, and the only honest source for that is your own risk register.

The three questions worth an hour

What did we tell them? The application is the foundation of the contract. Somebody answered questions about multi-factor authentication, backups, endpoint protection, patching and privileged access. Those answers are representations. If any of them are more optimistic than reality, that gap is a coverage argument waiting to happen, and it will be argued at the worst possible moment.

What conditions does the policy impose? Many policies now carry warranties: multi-factor authentication on all remote access and privileged accounts, backups held offline or immutable, patching within a stated window. A warranty is not advice. Failing it can void the response to a loss it relates to.

What is actually excluded or sublimited? Social engineering and funds transfer fraud are frequently carved out into a separate endorsement with a much lower limit than the headline. So is loss caused by an unpatched vulnerability known for more than a stated period. So, often, is anything attributable to a state actor, which is a broader exclusion than it first appears.

Why the risk register is the right document to read it against

A risk register that is maintained honestly already records the exceptions. The service accounts without a second factor. The system that cannot be patched on the vendor's schedule. The backup that is replicated but not immutable. The branch office that connects differently.

Every one of those is a line in the policy waiting to be tested.

Reading the two documents side by side takes an hour and produces one of three outcomes per item: the control is in place and the answer was true, the control is not in place and needs to be, or the control is not in place and the insurer needs to know before renewal rather than after a claim.

All three outcomes are better than not knowing.

Renewal is the leverage point, in both directions

At renewal the insurer will ask harder questions than last year, because the market does. That is uncomfortable, but it is also the moment the firm can most easily fund the controls that reduce both premium and actual risk. Multi-factor coverage, immutable backups and privileged access controls are the three that move underwriting decisions most, and they are the three that reduce real exposure most.

Firms that turn up at renewal with a current risk register, a remediation plan with dates, and evidence of what was completed since last year get better terms than firms that turn up with a completed form. Underwriters are reading for the same signal a regulator and a client reviewer read for: is there a programme, and does somebody own it.

What this is not

This is not a recommendation about limits, retentions or which carrier. That is a broker's job and a good broker earns their fee. What is not the broker's job is knowing whether the controls you attested to are actually operating everywhere in your environment. That is yours.