Cyber insurance rates are dropping. Abundant capacity and intense competition have triggered a period of market softening, keeping prices favorable for corporate buyers.
However, this rate decline hides a critical catch. While base premiums are cheaper, insurers are restricting policy terms and widening coverage exclusions to offset the rise in cyber claims.
Insurers are also relying on baseline security controls during underwriting. Leaving these security gaps unaddressed results in significantly higher premiums or outright policy denial. The largest impacts on rates come from four primary vectors: endpoint defenses, identity and access management (IAM), incident response capabilities, and third-party risks.
Understanding and closing these gaps is essential for maintaining insurability. If an organization falls into a higher risk tier, insurers use heavy-handed mechanisms to offset their exposure.
Why Some Organizations Pay Higher Rates
Cyber insurance rates are down by 5 percent to 11 percent over the past year, marking nearly three consecutive years of declining or flat aggregate rates. However, the claims environment is worsening. Overall claim counts jumped roughly 40 percent, with major ransomware attacks and systemic supply chain threats eating into insurer profitability.
While market averages are down, individual risk profiles govern real-world renewals and rates. Seventy percent of companies reported higher renewal costs or flat pricing because their baseline technical controls fell short of underwriting expectations. High claims activity in sectors such as healthcare and manufacturing has minimized the effect of insurer competition, driving targeted rate hikes in these industries.
In other words, the market has fractured into two risk pools based on the organization’s baseline controls and technical maturity. Organizations in the “elite and premium” risk pool treat security as an active operational requirement, not a check-the-box exercise. Those in the “basic and substandard” risk pool have critical gaps in IAM, supply chain tracking or system recovery capabilities.
Real-World Penalties for Tier 2 Risks
For Tier 2 organizations, a carrier may issue a $5 million overall policy but restrict ransomware extortion and data exfiltration payouts to a fraction of that. Insurers are also inserting 50/50 co-insurance mandates for ransomware losses. This forces the policyholder to pay half of any extortion demand out-of-pocket, regardless of their deductible.
Tier 2 policies frequently include a strict warranty stating that multifactor authentication (MFA) is active across 100 percent of the enterprise. If a breach occurs through a single unmanaged legacy account lacking MFA, the carrier can deny the claim entirely based on misrepresentation.
Organizations in Tier 2 are also facing large retention increases. To avoid paying frequent small-scale claims, insurers force Tier 2 companies to accept significantly higher deductibles, shifting the primary financial burden back onto the insured.
How to Avoid Sliding Into Tier 2
To stay on the profitable side of this market split, organizations should prioritize four technical controls before approaching insurers:
- Implement Continuous EDR/MDR. Organizations should replace legacy antivirus tools with endpoint detection and response and managed detection and response across all endpoints, servers and cloud workloads.
- Move to Phishing-Resistant MFA. Because basic SMS or push notifications are vulnerable to phishing, organizations should implement conditional, identity-based access controls.
- Conduct Annual Tabletop Exercises. It’s not enough to write an incident response plan. Organizations should conduct and document simulations to prove that their recovery timeline can limit business interruption losses.
- Manage Third-Party Risk. Organizations should conduct due diligence before contracting with third-party vendors and suppliers. The goal is to evaluate their ability to guard against supply chain threats.
How Verteks Can Help
The Verteks security team is well-versed in the underwriting requirements of major cyber insurers. We also have extensive experience in helping small to midsize enterprises develop and implement robust security controls. Our managed services deliver the continuous monitoring and threat response that insurers increasingly require.
Together, these capabilities enable us to help you obtain comprehensive cyber insurance coverage at competitive rates. Contact us to schedule a confidential consultation.




