5 min. read Email this page Bryley Systems Inc.

Listen to this report:

This is part 1 of a 3-part series

IT by a thread

Many organizations haven’t figured the cost of their cyber exposure.

The value of risk

In a recent interview Michael Murphy, president of Murphy Insurance Agency explained insurance as the transfer [of] an exposure from you to an insurance company – you’re moving it from your personal balance sheet over to an insurance company’s.


Expanding on Michael’s thought, this means every business that doesn’t carry cyberinsurance has made a financial decision. It’s decided to self-insure – to absorb whatever comes, whether that’s ransomware, a data breach, business interruption, the post-breach recovery – on its own balance sheet at whatever moment the event occurs.

Organizations self-insure against risks they’ve priced and judged manageable all the time. But most organizations haven’t priced cyber-events. They’ve assumed the risk is small, or remote or someone else’s problem – and in doing so, have taken on an unexamined liability that won’t show up on its financial statements until there’s a crisis.

According to a study by brokerage Aon, the average ransomware claim cost $713,000 in 20251 – about twice the year before. And that figure doesn’t include what insurers call the legal tail, which means lingering litigation, regulatory investigations and liability claims that in cases involving customer data has been shown to rival the cost of the security incident itself. And these numbers cannot show reputational damage or the cost of rebuilding customer trust. If a business is running on normal operating margins, an uninsured event at that scale is an existential threat.

But even with this threat about 80% of small- and mid-sized organizations carry no cyberinsurance. The reason is because either the exposure is not understood or taken seriously. Smaller organizations tend to think they’re not targets. It’s not easy to connect what until-it-happens is an abstract cyber-event with a huge financial cost.

State of insurance

As of this writing cyberinsurance is obtainable, but there is strong evidence that the insurance industry is looking to move on without smaller businesses that do not take the threat seriously.

Insurers are using more sophisticated risk models, tightening underwriting criteria and have forensic teams that are scrutinizing claims against the controls that were documented at the time of the insurance application. The organizations that will remain well-covered got there by building a security posture that insurers recognize.

Pre-insurable

A large number of the uninsured don’t meet basic underwriting criteria of security controls. When an organization applies for cyberinsurance, the application often contains a controls questionnaire. Most insurers want to know whether you have backups, whether they’re offsite, whether multifactor authentication (MFA) is enabled, whether every user device has protection.

The good news: the very controls that make an organization insurable are the ones that need to be deployed to help make a breach survivable. Not every organization starts in the same place – but every organization can move up, and every step reduces exposure and improves insurability.

Good: The Baseline

For organizations with no formal security program, the starting point is establishing controls that demonstrate basic risk awareness. That means automated, offsite data backups that can provide a recoverable copy of your data if ransomware encrypts everything on your network. It means endpoint antivirus on every device. It means MFA on critical operations. These controls can signal to an underwriter that you’ve thought about the problem. This tier won’t satisfy every insurer, but it may move an organization from uninsurable to eligible.

Better: Purposeful Investment

Organizations willing to invest modestly in security tooling can build a posture that satisfies most underwriting requirements and meaningfully reduces exposure. This includes tools like endpoint detection and response (EDR), email filtering to catch phishing attempts before they reach employees, security awareness training to reduce the human error that drives most incidents and a documented patch management process that keeps many software vulnerabilities closed. At this level, organizations can show insurers that controls are actively maintained.

Best: Assessment-Based Security and the Right Cyberinsurance

An assessment-based security program identifies your organization’s specific risks
and builds controls around them. This typically involves a partnership between internal IT staff and a managed security services provider (MSP) that conducts risk assessments, maps controls to recognized frameworks like NIST and provides ongoing monitoring and incident response capability. Insurers recognize this posture. It’s documented, defensible and built to hold up under post-claim scrutiny.

But the security program is only half the equation. The other half is making sure the insurance placed on top is the right coverage. That means working with a broker who understands your organization’s risk profile and who’s fluent in cyberinsurance – to match your controls and exposures to an underwriter that will come through when you need to file a claim. A well-built security posture paired with an inadequate policy is still equates to a gap. But done right, security and insurance reinforce each other with controls that satisfy underwriting criteria, with coverage that reflects what you’ve built and a broker who knows your organization well enough to guide a claim through to resolution.

Wherever your organization is on that cybersecurity/cyberinsurance ladder, Bryley can help you take the next step. Contact Roy Pacitto at rpacitto@Bryley.com or reach him by phone at 978.562.6077 x217.

Self-Assessments and Other Eyes Quiz (#7) (#11) (#12) (#13)

1 cybersecuritydive.com/news/cyber-insurance-policyholders-facing-heavier-scrutiny-underwriting-claims

by Lawrence Strauss, June 20, 2026
Lawrence has written for Bryley since 2015. His coverage of cyber-scams appears on moneywise.com

Connect with Bryley to look at co-managed/managed IT options

Get more New England-based technology and security information. Subscribe to Up Times by Bryley monthly newsletter.
This field is for validation purposes and should be left unchanged.