Skip to content

Strategy

Cyber insurance vs. controls: where should the next dollar go?

How to balance spending between security controls that reduce expected loss and cyber insurance that covers the residual, tail-end risk.

Every security leader eventually faces the same fork in the road: the next available dollar can go toward a control that lowers the odds of a bad day, or toward an insurance policy that softens the blow when one arrives. Framed as a versus, it’s a false choice — but the order in which you fund them, and how much you allocate to each, matters a great deal.

Two different jobs

Controls and insurance are not substitutes. Controls reduce the probability and severity of an incident. Insurance transfers a portion of the financial consequence to a third party. Neither one prevents a breach outright, and any vendor or broker who implies otherwise is overselling.

The cleanest way to think about it:

  • Controls lower your expected loss — the probability-weighted cost of incidents over time.
  • Insurance absorbs residual and tail risk — the rare, catastrophic event your controls didn’t stop.

The scale of that tail is the reason insurance exists at all. IBM’s 2025 analysis puts the global average cost of a data breach at $4.44M, and the U.S. average at $10.22M. Most organizations cannot self-fund a loss of that size, which is exactly what insurance is for.

Controls now buy you cheaper insurance later

Here’s the part that resolves the “versus” framing: spending on controls and spending on insurance are increasingly linked. Insurers no longer write broad policies without scrutiny. To qualify for coverage — or to qualify for a reasonable premium — carriers now require baseline controls such as multi-factor authentication, endpoint detection and response (EDR), and tested, offline backups.

So the controls you fund do double duty. They reduce your expected loss, and they reduce what you pay to transfer the rest. Premiums scale with both your revenue and your security posture, which means a well-controlled organization is rewarded twice.

Think of controls as the thing that both lowers your risk and lowers the price of insuring whatever risk remains. The two budgets aren’t competing — one feeds the other.

A practical funding order

When the next dollar is genuinely contested, a defensible sequence looks like this:

PrioritySpendWhy it comes first
1MFA + identity hygieneOften a coverage prerequisite; low cost, high leverage
2EDR / endpoint protectionRequired by most carriers; cuts dwell time
3Tested backups + recoveryDetermines whether ransomware is a crisis or an inconvenience
4Cyber insuranceCovers the residual loss your controls can’t eliminate
5Maturity layers (SIEM, MDR, IR retainer)Reduce expected loss further; may lower premiums

This isn’t a rigid law — your regulatory environment, existing gaps, and threat profile can reshuffle it. But the principle holds: fund the controls that are also coverage prerequisites before you fund coverage itself, because doing so makes the coverage both attainable and cheaper.

Sizing the split

There is no universal ratio, and anyone quoting a precise one is guessing. As a budgeting anchor, IANS benchmarking puts security at roughly 11% of the IT budget for a typical organization, and the bulk of that is controls and the people to run them — not premiums. Insurance is usually a comparatively small line item that grows or shrinks with your revenue and how well you can demonstrate posture at renewal.

A reasonable approach for most teams:

  • Treat baseline controls as non-negotiable — they’re the floor for both risk and insurability.
  • Buy insurance sized to your tail risk, not your everyday risk. The deductible should sting a little; the limit should cover the catastrophic case.
  • Revisit the split annually, ideally just before renewal, when control investments can be translated directly into premium negotiations.

The bottom line

The next dollar usually belongs to a control — especially one your insurer already expects to see — because it reduces loss and lowers your premium at the same time. Insurance earns its place once the baseline is funded, sitting behind your controls to catch the rare event that gets through. Build the floor first, then transfer what’s left.

To pressure-test how controls and insurance fit into your own numbers, try the cybersecurity budget calculator.

References

Related

Put this into a number

Build a sourced, defensible budget from your own risk profile — free and ungated.

Open the calculator