In many lines of insurance, claim activity is part of the norm—and it’s expected that you’ll have to underwrite to losses consistently. For example, in casualty lines, it’s common to have workers file for worker’s compensation because of an injury they experienced on a job.
But in cyber insurance, the situation is a bit different—and several steps must be taken:
Without objective data points, you simply have to trust that the information being provided to you by your applicant is accurate. But you’ll likely be left with many questions:
All in all, you need a way to be certain that your applicant is actually putting steps in place to ensure that their organization is safeguarded from future potential cyber events and any circumstance that could increase their risk profile.
Using data from your Security Ratings portal gives you an unprecedented look at your applicant’s current and previous security posture.
The BitSight Security Ratings portal provides you with information about your applicant for the previous year, which allows you to see if they experienced an incident during that time. If they have, you can then see how the applicant responded to and remediated the issues. If the applicant informed you that they put a number of measures in place after a security incident on their network but their company’s rating has dropped drastically, you know the applicant either hasn’t been forthcoming with you or the company hasn’t put the right measures in place.
On top of that, you’ll also gain recommendations on what your applicant can do to improve their security posture. For example, it may be recommended that the applicant focuses on scrutinizing why certain ports are open that may be better closed. This simple suggestion may come with a complex process of improved internal processes for the applicant, but it will help get them on the right path after a breach or a compromising event.
You absolutely should underwrite a company that has experienced a breach or security event in the past (as long as they’re within your risk appetite)—but you should make sure you’ve evaluated all pertinent data and information about the company beforehand. In fact, experiencing a breach may help some applicants learn a lesson and limit the impact of a future breach...because you know it will happen again, right?
Using Security Ratings for Cyber Insurance can help you make or validate your underwriting decisions not just based on observation and subjective information from the applicant but based on objective, verifiable and actionable data. Once you have every data point possible, it’s much simpler to craft a policy that works for you and for the applicant.
It’s not hard to justify why you need property insurance when you’re surrounded by your physical goods that you don’t want to be lost or damaged in your home or business. So why isn’t cybersecurity the same?
The SolarWinds breach is already one of the most significant cybersecurity incidents ever. And as with any unprecedented cyber event, this will have long-term effects on the way businesses and government consider their security programs....
This post was originally published July 18, 2016 and has been updated for accuracy and comprehensiveness.
© 2026 BitSight Technologies. All Rights Reserved. | Privacy Policy | Security | For Suppliers
Contact Us | BitSight Technologies | 111 Huntington Ave, Suite 2010, Boston, MA 02199 | +1-617-245-0469