By Glen Williams, CEO, Cyberfort
Cyber insurance has become one of the most heavily marketed business products of the last decade, and the reasons are easy to understand. Headlines are dominated by warnings of nation state actors, organised ransomware cartels and supply chain compromises that can bring entire sectors to a standstill.
Against this backdrop, boards across the world are under mounting pressure from brokers, regulators, and investors to purchase ever more comprehensive cover. Yet in an ironic twist, the most damaging security breach is rarely the one any insurance policy was designed to anticipate or cover.
The uncomfortable truth is that an intruder is far more likely to walk through the front door in a four pound high-vis jacket and a clipboard in hand than to tunnel through the firewall with a zero day exploit.
That is not a marketing line, it is an operational reality our consultants observe during physical and social engineering assessments. The person asking to read the meter, or holding the door while an employee swipes their pass, represents a far greater form of risk that no policy wording has yet managed to capture.
The pressure to insure against the wrong threat — Cyber insurance premiums have climbed steadily since 2021, and the questionnaires that accompany them have grown longer and more prescriptive with every renewal cycle.
Businesses are being asked to evidence multi factor authentication, endpoint detection, immutable backups, and further controls that stretch into dozens of line items. These are sensible measures and we would encourage any organisation to of course adopt them as standard practices.
The difficulty arises when leadership teams mistake the completion of an insurance schedule for a genuine programme of cyber resilience. A policy is a financial instrument that responds after an incident has occurred, and the payout, where it materialises at all, rarely covers reputational damage, regulatory consequence, or the loss of a customer who decides your organisation is no longer a safe pair of hands.
Treating insurance as the centre of strategy also distorts investment priorities, and we regularly see finance directors commit significant sums to premiums while the budget for staff awareness, access reviews, and physical security remains untouched from one year to the next.
Where risk actually lives
Risk does not reside exclusively in technology, and any assessment that treats it as such will miss the majority of the attack surface.
Risk lives in the new starter who has not been briefed on processes, in the third party supplier whose engineer has unsupervised access to your server room, in the printer that still holds a cached copy of last quarter’s board papers and in the leavers process that allows a departed contractor to retain working credentials for months after their engagement has ended.
The organisations that weather incidents most effectively are those that have mapped their genuine risk landscape across three dimensions, namely people, processes, and data. People covers the behaviours, training, and culture that determine how employees respond to the unexpected visitor or the unusual email. Processes covers everything from vendor management to visitor control and physical access through loading bays and back entrances.
Data addresses where information is held, who can reach it, and what would happen in commercial terms if it were exposed, altered, or held to ransom. When these dimensions are understood together, technology investment becomes far more effective because it is targeted at genuine exposure rather than at threats that happen to be fashionable.
Resilience is earned, not purchased
Cyber insurance has a legitimate role to play in any mature risk programme, and I am not suggesting for a moment that a responsible business should be without it. It should, however, be regarded as a backstop rather than a strategy, the equivalent of the business interruption cover that sits alongside a well run continuity plan rather than replacing it.
True resilience is earned through discipline, through honest assessment, and through a willingness to look beyond the firewall to the receptionist’s desk, the loading bay, and the coffee shop where a contractor is working on an unsecured network.
The £4 high-vis jacket will remain one of the most effective tools in an attacker’s inventory for as long as organisations spend more on insuring against the wrong threat than on understanding the one that is already walking, unchallenged, past the front desk.
Read the article on Business Quarter here https://businessquarter.co.uk/wp-content/uploads/2026/07/Business-Quarter-Issue-4-Q2-2026.pdf





















