Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026NHS ScotlandUndisclosed records stolen2026HertzUndisclosed records stolen2025Marks & Spencer9.4M records stolen2025PayPal35K records stolen2025Jaguar Land RoverUndisclosed records stolen2025Co-operative GroupUndisclosed records stolen2024National Public Data2.9B records stolen2024Ticketmaster560M records stolen2024Change Healthcare100M+ records stolen2024AT&T73M records stolen2024Dell Technologies49M records stolen2023Progress Software (MOVEit)77M+ records stolen202323andMe6.9M records stolen2023Royal MailOperations halted records stolen2023British LibraryUndisclosed records stolen2023MGM ResortsUndisclosed records stolen2022Uber57M records stolen2022LastPass33M records stolen2022Optus9.8M records stolen2022Medibank9.7M records stolen2022Twitter5.4M records stolen2026NHS ScotlandUndisclosed records stolen2026HertzUndisclosed records stolen2025Marks & Spencer9.4M records stolen2025PayPal35K records stolen2025Jaguar Land RoverUndisclosed records stolen2025Co-operative GroupUndisclosed records stolen2024National Public Data2.9B records stolen2024Ticketmaster560M records stolen2024Change Healthcare100M+ records stolen2024AT&T73M records stolen2024Dell Technologies49M records stolen2023Progress Software (MOVEit)77M+ records stolen202323andMe6.9M records stolen2023Royal MailOperations halted records stolen2023British LibraryUndisclosed records stolen2023MGM ResortsUndisclosed records stolen2022Uber57M records stolen2022LastPass33M records stolen2022Optus9.8M records stolen2022Medibank9.7M records stolen2022Twitter5.4M records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →
Back to Guides
Insurancebeginner

Cyber Insurance and Physical Controls

Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.

9 min read
Share

The Insurance Market Is Changing

The cyber insurance market has undergone significant hardening since 2020. Premiums have increased, coverage has narrowed, and underwriters are asking increasingly specific questions about security controls. The era of broad, affordable cyber insurance without rigorous scrutiny is over.

What has changed most significantly is what underwriters consider adequate. Software-based security controls that were sufficient for policy issuance five years ago are now viewed as baseline expectations. Insurers are looking for differentiation, and physical controls provide exactly that.

What Underwriters Are Asking

Modern cyber insurance applications increasingly include questions about:

  • Whether backup credentials are stored separately from production systems
  • Whether recovery procedures exist offline and have been tested
  • Whether privileged access is governed with controls beyond software-based PAM
  • Whether the organisation maintains air-gapped copies of critical recovery assets
  • Whether incident response plans are accessible during a total system compromise

Each of these questions maps directly to capabilities that OSS provides. Organisations that can answer "yes" with evidence of physical controls are positioned for more favourable terms.

The Premium Impact

While premium reductions vary by insurer and risk profile, organisations that demonstrate physical governance controls typically benefit from:

  • Lower deductibles: Insurers may reduce self-insured retention amounts for organisations with demonstrably stronger controls
  • Broader coverage: Physical controls may qualify organisations for coverage extensions that are unavailable to those relying solely on software controls
  • Simplified renewal: A strong control posture reduces the scrutiny and documentation required at renewal
  • Claims advantage: In the event of a claim, documented physical controls strengthen the organisation's position during the claims process

Evidence That Insurers Value

Insurers are evidence-driven. The following documentation strengthens your insurance position:

  • Crown Jewels Register: A documented inventory of critical assets with proportionate protection measures
  • Offline access logs: Tamper-evident records demonstrating regular governance of offline assets
  • Recovery test results: Documented exercises demonstrating that recovery credentials were accessed and validated from offline storage
  • Governance procedures: Written policies for offline asset management, including update schedules and access controls

The Claims Perspective

Physical controls also strengthen your position in the event of a claim. Organisations that can demonstrate they maintained offline recovery credentials are more likely to recover quickly, reducing the total claim value. Faster recovery means lower business interruption costs, which benefits both the organisation and the insurer.

Additionally, demonstrating that certain data was stored in physically disconnected systems can reduce the scope of a data breach, potentially limiting notification obligations and associated costs.

Practical Steps

  1. Review your current policy. Identify security control requirements and assess which can be strengthened through physical controls.
  2. Brief your broker. Ensure your insurance broker understands and can articulate your physical governance capabilities to underwriters.
  3. Document everything. Create an evidence pack demonstrating your OSS governance, including access logs, test results, and governance procedures.
  4. Align renewal timing. Implement physical controls ahead of your renewal cycle to maximise premium impact.

Conclusion

Cyber insurance is a risk transfer mechanism, not a security strategy. But the insurance market increasingly rewards organisations that demonstrate genuine governance maturity. Physical controls through OSS provide the tangible, evidence-based differentiation that underwriters are actively looking for.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Put this guide into practice

Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy