Insurance·19 February 2026

Cyber Insurance and Physical Controls

Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
3 min read
Share
Cyber Insurance and Physical Controls
Insurance

Why it matters

What this means for organisations holding critical data

Cyber insurers are increasingly differentiating between organisations that rely solely on software controls and those that implement physical governance. Understanding this shift can reduce premiums and improve coverage terms.

The Insurance Market Is Changing

The cyber insurance market has undergone significant hardening since 2020. Premiums have increased, coverage has narrowed, and underwriters are asking increasingly specific questions about security controls. The era of broad, affordable cyber insurance without rigorous scrutiny is over.

What has changed most significantly is what underwriters consider adequate. Software-based security controls that were sufficient for policy issuance five years ago are now viewed as baseline expectations. Insurers are looking for differentiation, and physical controls provide exactly that.

What Underwriters Are Asking

Modern cyber insurance applications increasingly include questions about:

  • Whether backup credentials are stored separately from production systems
  • Whether recovery procedures exist offline and have been tested
  • Whether privileged access is governed with controls beyond software-based PAM
  • Whether the organisation maintains air-gapped copies of critical recovery assets
  • Whether incident response plans are accessible during a total system compromise

Each of these questions maps directly to capabilities that OSS provides. Organisations that can answer "yes" with evidence of physical controls are positioned for more favourable terms.

The Premium Impact

While premium reductions vary by insurer and risk profile, organisations that demonstrate physical governance controls typically benefit from:

  • Lower deductibles: Insurers may reduce self-insured retention amounts for organisations with demonstrably stronger controls
  • Broader coverage: Physical controls may qualify organisations for coverage extensions that are unavailable to those relying solely on software controls
  • Simplified renewal: A strong control posture reduces the scrutiny and documentation required at renewal
  • Claims advantage: In the event of a claim, documented physical controls strengthen the organisation's position during the claims process

Evidence That Insurers Value

Insurers are evidence-driven. The following documentation strengthens your insurance position:

  • Crown Jewels Register: A documented inventory of critical assets with proportionate protection measures
  • Offline access logs: Tamper-evident records demonstrating regular governance of offline assets
  • Recovery test results: Documented exercises demonstrating that recovery credentials were accessed and validated from offline storage
  • Governance procedures: Written policies for offline asset management, including update schedules and access controls

The Claims Perspective

Physical controls also strengthen your position in the event of a claim. Organisations that can demonstrate they maintained offline recovery credentials are more likely to recover quickly, reducing the total claim value. Faster recovery means lower business interruption costs, which benefits both the organisation and the insurer.

Additionally, demonstrating that certain data was stored in physically disconnected systems can reduce the scope of a data breach, potentially limiting notification obligations and associated costs.

Practical Steps

  1. Review your current policy. Identify security control requirements and assess which can be strengthened through physical controls.
  2. Brief your broker. Ensure your insurance broker understands and can articulate your physical governance capabilities to underwriters.
  3. Document everything. Create an evidence pack demonstrating your OSS governance, including access logs, test results, and governance procedures.
  4. Align renewal timing. Implement physical controls ahead of your renewal cycle to maximise premium impact.

Conclusion

Cyber insurance is a risk transfer mechanism, not a security strategy. But the insurance market increasingly rewards organisations that demonstrate genuine governance maturity. Physical controls through OSS provide the tangible, evidence-based differentiation that underwriters are actively looking for.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

HardwareYour copy sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
RecoveryA known-clean copy to rebuild from, on your timetable
LocationHeld in a secure Firevault Bunker
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Put this guide into practice

Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up