---
title: "Cyber Insurance Guide: physical controls | Firevault"
description: "Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance.…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls#webpage",
      "url": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls",
      "name": "Cyber Insurance Guide: physical controls",
      "description": "Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance.…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcyber-insurance-physical-controls.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Cyber Insurance and Physical Controls",
          "item": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Cyber Insurance and Physical Controls",
      "description": "Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.",
      "url": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcyber-insurance-physical-controls.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-02-19T09:13:51.962911+00:00",
      "dateModified": "2026-08-28T07:05:10.849702+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/cyber-insurance-physical-controls"
      },
      "inLanguage": "en-GB",
      "articleSection": "Insurance",
      "wordCount": 510,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

The Insurance Market Is ChangingWhat Underwriters Are AskingThe Premium ImpactEvidence That Insurers ValueThe Claims PerspectivePractical StepsConclusionMore

[Guides](/learn/knowledge?filter=guides)/ Insurance 

Insurance · 19 February 2026 

# Cyber Insurance and Physical Controls

Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-insurance-physical-controls)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-insurance-physical-controls&text=Cyber%20Insurance%20and%20Physical%20Controls%0A%0ACyber%20insurers%20are%20increasingly%20differentiating%20between%20organisations%20that%20rely%20solely%20on%20software%20controls%20and%20those%20that%20implement%20physical%20governance.%20Understanding%20this%20shift%20can%20reduce%20premiums%20and%20improve%20coverage%20terms.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-insurance-physical-controls)[](mailto:?subject=Cyber%20Insurance%20and%20Physical%20Controls&body=Cyber%20insurers%20are%20increasingly%20differentiating%20between%20organisations%20that%20rely%20solely%20on%20software%20controls%20and%20those%20that%20implement%20physical%20governance.%20Understanding%20this%20shift%20can%20reduce%20premiums%20and%20improve%20coverage%20terms.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fcyber-insurance-physical-controls)

![Cyber Insurance and Physical Controls](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides%2Fcyber-insurance-physical-controls.jpg)

Insurance 

Why it matters

## What this means for organisations holding critical data

Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.

**On this page**[The Insurance Market Is Changing](#section-0)[What Underwriters Are Asking](#section-1)[The Premium Impact](#section-2)[Evidence That Insurers Value](#section-3)[The Claims Perspective](#section-4)[Practical Steps](#section-5)[Conclusion](#section-6)

On this page

1.  [The Insurance Market Is Changing](#section-0)
2.  [What Underwriters Are Asking](#section-1)
3.  [The Premium Impact](#section-2)
4.  [Evidence That Insurers Value](#section-3)
5.  [The Claims Perspective](#section-4)
6.  [Practical Steps](#section-5)
7.  [Conclusion](#section-6)

## The Insurance Market Is Changing

The cyber insurance market has undergone significant hardening since 2020. Premiums have increased, coverage has narrowed, and underwriters are asking increasingly specific questions about security controls. The era of broad, affordable cyber insurance without rigorous scrutiny is over.

What has changed most significantly is what underwriters consider adequate. Software-based security controls that were sufficient for policy issuance five years ago are now viewed as baseline expectations. Insurers are looking for differentiation, and physical controls provide exactly that.

## What Underwriters Are Asking

Modern cyber insurance applications increasingly include questions about:

-   Whether backup credentials are stored separately from production systems
-   Whether recovery procedures exist offline and have been tested
-   Whether privileged access is governed with controls beyond software-based PAM
-   Whether the organisation maintains air-gapped copies of critical recovery assets
-   Whether incident response plans are accessible during a total system compromise

Each of these questions maps directly to capabilities that OSS provides. Organisations that can answer "yes" with evidence of physical controls are positioned for more favourable terms.

## The Premium Impact

While premium reductions vary by insurer and risk profile, organisations that demonstrate physical governance controls typically benefit from:

-   **Lower deductibles:** Insurers may reduce self-insured retention amounts for organisations with demonstrably stronger controls
-   **Broader coverage:** Physical controls may qualify organisations for coverage extensions that are unavailable to those relying solely on software controls
-   **Simplified renewal:** A strong control posture reduces the scrutiny and documentation required at renewal
-   **Claims advantage:** In the event of a claim, documented physical controls strengthen the organisation's position during the claims process

## Evidence That Insurers Value

Insurers are evidence-driven. The following documentation strengthens your insurance position:

-   **Crown Jewels Register:** A documented inventory of critical assets with proportionate protection measures
-   **Offline access logs:** Tamper-evident records demonstrating regular governance of offline assets
-   **Recovery test results:** Documented exercises demonstrating that recovery credentials were accessed and validated from offline storage
-   **Governance procedures:** Written policies for offline asset management, including update schedules and access controls

## The Claims Perspective

Physical controls also strengthen your position in the event of a claim. Organisations that can demonstrate they maintained offline recovery credentials are more likely to recover quickly, reducing the total claim value. Faster recovery means lower business interruption costs, which benefits both the organisation and the insurer.

Additionally, demonstrating that certain data was stored in physically disconnected systems can reduce the scope of a [data breach](/learn/breaches), potentially limiting notification obligations and associated costs.

## Practical Steps

1.  **Review your current policy.** Identify security control requirements and assess which can be strengthened through physical controls.
2.  **Brief your broker.** Ensure your insurance broker understands and can articulate your physical governance capabilities to underwriters.
3.  **Document everything.** Create an evidence pack demonstrating your OSS governance, including access logs, test results, and governance procedures.
4.  **Align renewal timing.** Implement physical controls ahead of your renewal cycle to maximise premium impact.

## Conclusion

Cyber insurance is a risk transfer mechanism, not a security strategy. But the insurance market increasingly rewards organisations that demonstrate genuine governance maturity. Physical controls through OSS provide the tangible, evidence-based differentiation that underwriters are actively looking for.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Control by Firevault governs the physical paths into your systems.**[Explore Control →](/solutions/control)

Keep a clean copy**Offline Secure Storage® holds a copy no attacker can reach.**[Why #OSS →](/why-oss)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

## Continue learning

-   [
    
    ### NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
    
    A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.
    
    Read guide ](/learn/guides/ncsc-caf-guide)
-   [
    
    ### NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
    
    A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.
    
    Read guide ](/learn/guides/nist-csf-2-0-guide)
-   [
    
    ### Crown Jewels Audit: What Deserves Disconnection
    
    Not everything needs to go offline. The Crown Jewels Audit is a structured framework for identifying exactly which assets deserve the protection that only physical disconnection can provide.
    
    Read guide ](/learn/guides/crown-jewels-audit)
-   [
    
    ### Credential Governance: Managing Your Keys
    
    Every system, every backup, every recovery procedure depends on credentials. When those credentials are compromised or inaccessible, technical capability becomes irrelevant. Credential governance through OSS ensures the keys to your kingdom survive any incident.
    
    Read guide ](/learn/guides/credential-governance)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up