Two businesses with similar turnover can receive very different insurance quotes for cyber risks. This is because insurers do not determine premiums based on revenue alone. The type of data handled, industry, cybersecurity controls, claims history and level of cover can all influence the premium.
Understanding these factors can help businesses make sense of their cyber security insurance cost and compare policies based on more than the quoted price.
Why Is There No Fixed Cyber Security Insurance Cost?
Cyber insurance is priced according to the risk presented by a business. A company that stores large amounts of customer or financial data may present a different risk from a business with limited digital exposure, even when both have similar revenues. Some of the factors that can influence the premium include:
- Business size and revenue: Larger businesses may have greater transaction volumes and potentially larger losses following a cyber incident.
- Type of data handled: Businesses processing personal, financial or sensitive information may have greater exposure.
- Industry: Sectors such as financial services, healthcare, e-commerce and technology can have significant digital and data-related exposure.
- Cybersecurity controls: Security measures such as access controls, employee training and other protective measures can affect how an insurer assesses risk.
- Claims history: Previous cyber incidents or claims can influence underwriting.
- Policy limit: A higher coverage limit generally means greater potential exposure for the insurer and can increase the premium.
- Deductible: A higher deductible can reduce the amount of risk transferred to the insurer and may affect the premium.
How Does Cybersecurity Affect the Premium?
A business’s security practices can be an important part of underwriting. Insurers may want to understand how the organisation protects its systems and data before determining the level of risk.
For example, controls around employee access, authentication, backups and security awareness can provide information about how a business manages cyber risks. A business with limited controls may present a different risk profile from one with established security processes.
This means that cyber security insurance cost is not simply determined by the number of employees or annual turnover. The quality of the organisation’s existing controls can also influence the assessment.
However, having strong cybersecurity does not guarantee a lower premium or ensure that every cyber incident will be covered. The final terms depend on the insurer’s underwriting and the policy wording.
Does the Coverage Limit Change the Cost?
Yes. The amount of protection selected is an important consideration when determining the premium.
A business choosing a higher policy limit is transferring a potentially larger financial exposure to the insurer. This can result in a higher premium than a policy with a lower limit.
Businesses should therefore avoid choosing a limit solely because it is higher. The appropriate level can depend on the potential financial impact of a cyber incident, the type of data handled, business operations and contractual obligations.
The deductible should also be considered. It represents the portion of an eligible loss that the insured may need to bear before the policy responds, subject to its terms.
How Does Errors and Omissions Insurance Cost Differ?
Cyber security insurance cost and professional liability cover address different types of risks, so their premiums are assessed differently. Errors and omissions insurance cost is generally influenced by factors such as the profession, annual turnover, services provided, coverage limit, claims history, geographical scope and retroactive period.
For example, a professional providing advice or specialised services may face a claim alleging that an error or omission caused financial loss to a client. The nature and value of those services can therefore influence the insurer’s assessment.
Professional indemnity insurance can cover claims relating to professional errors, omissions or negligence, subject to the policy terms. IRDAI has also issued standard professional indemnity guidelines for specified insurance intermediaries.
The two covers can therefore address different exposures:
How Can a Business Compare Cyber Insurance Quotes?
A lower premium does not necessarily mean a policy offers more suitable protection. Businesses should compare what each policy actually covers and the financial limits attached to that cover. Before selecting a policy, businesses can review:
- Coverage limits: Check the maximum amount payable for covered losses.
- Deductibles: Understand how much the business may have to bear itself.
- First-party cover: Check whether the policy addresses eligible losses suffered directly by the business.
- Third-party liability: Review protection for claims made by customers or other affected parties.
- Business interruption: Check whether eligible losses from interruption following a covered cyber event are included.
- Exclusions: Read exclusions carefully, particularly those relating to security failures or specific types of incidents.
- Incident response: Understand whether the policy provides access to specialists or reimburses eligible response costs.
- Claims process: Check notification requirements and documentation needed after an incident.
Conclusion
There is no universal figure for cyber security insurance cost because businesses present different levels of cyber risk. Revenue, data exposure, industry, cybersecurity controls, claims history, policy limits and deductibles can all influence the premium. Similarly, errors and omissions insurance cost depends on the professional risks and liability exposure associated with the business. Comparing the policy scope and terms alongside the premium can provide a more meaningful basis for evaluating coverage.