Coalition
An insurer that would rather you never make a claim
Coalition writes cyber insurance and monitors the policyholder's internet-facing estate while the policy runs. When it sees an exposure that has historically preceded claims, it tells the customer. The economics are aligned in an unusual way: preventing the incident is cheaper for the insurer than paying for it.
Cyber cover stopped being a formality
For several years cyber insurance was inexpensive and lightly underwritten. Ransomware claims changed that. Premiums rose, capacity tightened, and insurers began asking detailed questions about controls rather than accepting a short declaration.
The practical consequence for most organizations is that the application form has become a security audit. Questions about multi factor authentication, backup immutability, endpoint detection, privileged access and patching cadence are now standard, and the answers determine both the premium and whether cover is offered at all.
This has a useful side effect. The questionnaire is a reasonable summary of the controls that actually reduce loss, assembled by organizations with financial exposure to getting it wrong. Working through it honestly is a worthwhile exercise even for a business that decides not to buy the policy.
Underwriting informed by what is visible from outside
Coalition assesses the applicant's internet-facing footprint as part of underwriting, and continues to monitor it during the policy term. Exposed services, unsupported software and configurations associated with past claims are identified from the outside, in much the way an attacker would survey a target.
Where something significant appears, the policyholder is notified with the specifics. This is not a report generated annually and filed; it is closer to an alert with a recommended action, issued by an organization that will be paying if the exposure is used.
What the policy is actually for
Cyber cover is widely misunderstood as a fund that pays a ransom. The more valuable components are the ones that apply whether or not any payment is made.
- Incident response, retained in advance
- Access to responders, forensic analysts and specialist legal advice, arranged before the incident. Finding those people during a live compromise, at a premium, is how organizations lose their first critical day.
- Business interruption
- Cover for trading losses while systems are unavailable. For most businesses this exceeds the cost of the technical recovery itself, and it is the part that decides whether an incident is survivable.
- Third party liability
- Claims arising from the data of customers or partners held at the time of a breach, including the regulatory consequences that follow.
- Funds transfer fraud
- Losses from fraudulent payment instructions, which remains the most common and most under-insured cyber loss for small and mid sized organizations by a considerable margin.
What changes once cover is in place
The most immediate change is usually not financial. It is that somebody outside the organization is now looking at its exposure and is motivated to mention what they find.
| Situation | Without cover | With this model |
|---|---|---|
| Exposed service appears | Noticed eventually, or not | Flagged by the insurer |
| Ransomware on Friday night | Find responders yourself | Call the retained team |
| Two weeks of lost trading | Absorbed by the business | Claimed under interruption |
| Fraudulent payment made | Usually unrecoverable | Potentially covered |
| Customer data exposed | Legal costs from cash flow | Liability cover applies |
Read the conditions before relying on the cover
Policies are written against the controls declared on the application. If the declaration says multi factor authentication is enforced everywhere and it is not, the claim is exposed to challenge at the worst possible moment. Answer the questionnaire accurately rather than aspirationally, and fix what the answers reveal.
Insurance also does not reduce the likelihood of an incident, and it should never be bought instead of the controls. It transfers financial consequence, which is a genuine and useful function, and it works best sitting on top of defences that are actually in place rather than substituting for them.
Work through the application before you need the policy
The questionnaire will tell you which controls are missing, and every one of them is worth fixing regardless of whether the cover is ultimately purchased.
Review Your Cyber ReadinessGet in touch with Your Company
Questions about this solution? Reach us directly.