
Andreas Wuchner at Panaseer describes how accurate security metrics can help to reduce soaring cyber insurance premiums
Cyber insurance is an important part of enterprise risk management, helping minimise business disruption and provide much-needed financial, legal and regulatory support in the event of a security incident.
But with ransomware breaches surging, cyber insurance premiums in the UK and US are soaring while coverage is shrinking.
The UK saw a 102% increase in pricing in the first three months of 2022, up 10% from the previous quarter. Panaseer’s latest research into the trends impacting the cyber insurance industry shows that most (82%) insurers on both sides of the Atlantic expect these rises to continue.
It doesn’t have to be like this. Three-quarters of insurers admit their lack of visibility into customers’ security posture is impacting price increases. What’s needed is greater urgency in finding a more accurate way of assessing cyber risk that uses evidenced security metrics instead of subjective questionnaires.
Insurance is ultimately a numbers game. Insurers are losing money because they’re having to pay out on so many costly breaches, so premiums are going up. Ransomware is a notable driver. Panaseer found the largest ransom pay-outs by insurers in the past two years average £3.3m in the UK and $3.5m in the US.
How did we get here? Two years of pandemic-era digital investment has made enterprise IT environments more complex. According to Gartner, cloud investment is set to hit nearly $500bn this year and increase a further 21% in 2023, but few organisations can ensure controls effectiveness across a hybrid IT environment.
We’re also seeing threat actors continue to innovate and professionalise. The emergence of ransomware-as-a-service has lowered barriers to entry, while advanced tactics, techniques and procedures are readily shared on dark web forums. In fact, nearly three-quarters (73%) of insurers said the increasing sophistication of threat actors is a leading cause of rising premiums.
At the same time, security teams are struggling to keep up with the increased complexity and workload, despite greater investment in tools. On average, enterprise security teams manage 76 discrete tools, which often create both wasteful overlaps in functionality and coverage gaps.
It means security teams now spend more than half their time (54%) manually producing reports, when their time would be better spent on securing their environment.
The result is more security gaps for threat actors to exploit and less visibility for organisations and insurers into security posture. Research shows that two-thirds of security leaders lack confidence in their ability to prove controls are working as intended.
Panaseer’s research revealed that insurers want to see multiple layers of protection to mitigate cyber risk more effectively, including cloud security, vulnerability management, application security, privileged access management, security awareness and patch management.
And they’re increasingly going to demand proof that controls are working effectively. Some 89% of insurers said they’d value having direct access to customer security metrics and measures proving the status of security controls.
The industry would certainly benefit from a more mature approach to oversight, which could be provided by Continuous Controls Monitoring (CCM). It uses security automation to give organisations immediate access to trusted metrics and measures proving the efficacy of their security controls.
This data is continuously updated, providing near real-time evidence of controls maturity in a single platform, so insurers no longer have to rely on outdated questionnaires. Risk assessments become more accurate, meaning organisations can get access to the best possible insurance pricing and coverage.
Greater use of automation would also free up security teams to focus on higher value tasks, such as patching critical systems. With less time spent on creating reports, cyber hygiene can improve, making organisations a more attractive prospect for insurers.
Cyber insurance is still in its infancy, but change is coming. It will be security automation solutions like CCM that help to transform the sector, by delivering the data-driven insight that insurers crave to accurately price policies. Organisations hit by hefty premiums, or struggling to get coverage at all, should make it a priority to improve visibility into their security posture.
Andreas Wuchner is Field CISO at Panaseer
Main image courtesy of iStockPhoto.com
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543