Risk Attribute

Cyber Incident History

Expert-reviewed Updated: 2026-09-03 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

Cyber incident history records the frequency, nature and cost of an organisation's past cyber security incidents and data breaches, giving underwriters a key indicator of control effectiveness and future breach likelihood.

Category
History
Data type
List
Risk drivers
Frequency, Severity, Accumulation
Underwriting impact
Premium, Deductible, Sublimit, Exclusion, Declinature

Typical proposal-form questions

  • Please list all cyber security incidents, data breaches and ransomware events of the last 3 years, stating date, incident type, systems affected and cost incurred.
  • Was any incident reported to a data protection authority or resulted in regulatory investigation, notification duty or third-party claims?
  • Have any incidents recurred despite remediation, and what was changed after the most recent event?

Evidence

  • Incident response and forensic investigation reports
  • Cyber loss run report from the current or prior insurer
  • Regulatory notification correspondence, where applicable

Why it matters for underwriting

Prior cyber incidents are a strong leading indicator of control maturity, because a breach that recurs despite an organisation’s stated defences signals that remediation was incomplete or that the underlying vulnerability class remains unaddressed. Underwriters review incident type (ransomware, business email compromise, third-party vendor breach, unauthorised access), the systems and data affected, the time to detection and containment, and the ultimate cost, since these details reveal far more about an applicant’s actual security posture than a static questionnaire on controls alone.

Capturing the attribute and evidence

Cyber proposal forms ask applicants to list all material incidents and breaches over the preceding three years, together with incident type, affected systems, cost and any regulatory involvement. Underwriters corroborate this with the incident response or forensic investigation report prepared after the event, a cyber loss run from the current or prior insurer where cover already existed, and, if applicable, correspondence with a data protection authority documenting the notification and any resulting investigation. Recurrence of a similar incident type after remediation is scrutinised particularly closely.

Effect on coverage, premium and conditions

A clean incident history combined with mature controls supports competitive premium rates and full limits. A disclosed incident history, especially unremediated recurring incidents, commonly leads to higher premiums, increased retentions, sublimits or exclusions for the specific vulnerability class involved, mandatory security warranties as a condition of cover, or, where controls remain materially deficient, a decline to offer terms.

Mitigation measures

Insurers typically require documented closure of the root cause identified in the post-incident forensic report, implementation of multi-factor authentication, endpoint detection and response, and offline backups where these were missing, and a follow-up penetration test or security assessment confirming the gap has been closed before renewal terms are finalised.

Standards and codes

  • ISO 31000:2018 – Risk management, Guidelines