Strategy
Cyber insurance vs. controls: where should the next dollar go?
How to balance spending between security controls that reduce expected loss and cyber insurance that covers the residual, tail-end risk.
Every security leader eventually faces the same fork in the road: the next available dollar can go toward a control that lowers the odds of a bad day, or toward an insurance policy that softens the blow when one arrives. Framed as a versus, it’s a false choice — but the order in which you fund them, and how much you allocate to each, matters a great deal.
Two different jobs
Controls and insurance are not substitutes. Controls reduce the probability and severity of an incident. Insurance transfers a portion of the financial consequence to a third party. Neither one prevents a breach outright, and any vendor or broker who implies otherwise is overselling.
The cleanest way to think about it:
- Controls lower your expected loss — the probability-weighted cost of incidents over time.
- Insurance absorbs residual and tail risk — the rare, catastrophic event your controls didn’t stop.
The scale of that tail is the reason insurance exists at all. IBM’s 2025 analysis puts the global average cost of a data breach at $4.44M, and the U.S. average at $10.22M. Most organizations cannot self-fund a loss of that size, which is exactly what insurance is for.
Controls now buy you cheaper insurance later
Here’s the part that resolves the “versus” framing: spending on controls and spending on insurance are increasingly linked. Insurers no longer write broad policies without scrutiny. To qualify for coverage — or to qualify for a reasonable premium — carriers now require baseline controls such as multi-factor authentication, endpoint detection and response (EDR), and tested, offline backups.
So the controls you fund do double duty. They reduce your expected loss, and they reduce what you pay to transfer the rest. Premiums scale with both your revenue and your security posture, which means a well-controlled organization is rewarded twice.
Think of controls as the thing that both lowers your risk and lowers the price of insuring whatever risk remains. The two budgets aren’t competing — one feeds the other.
A practical funding order
When the next dollar is genuinely contested, a defensible sequence looks like this:
| Priority | Spend | Why it comes first |
|---|---|---|
| 1 | MFA + identity hygiene | Often a coverage prerequisite; low cost, high leverage |
| 2 | EDR / endpoint protection | Required by most carriers; cuts dwell time |
| 3 | Tested backups + recovery | Determines whether ransomware is a crisis or an inconvenience |
| 4 | Cyber insurance | Covers the residual loss your controls can’t eliminate |
| 5 | Maturity layers (SIEM, MDR, IR retainer) | Reduce expected loss further; may lower premiums |
This isn’t a rigid law — your regulatory environment, existing gaps, and threat profile can reshuffle it. But the principle holds: fund the controls that are also coverage prerequisites before you fund coverage itself, because doing so makes the coverage both attainable and cheaper.
Sizing the split
There is no universal ratio, and anyone quoting a precise one is guessing. As a budgeting anchor, IANS benchmarking puts security at roughly 11% of the IT budget for a typical organization, and the bulk of that is controls and the people to run them — not premiums. Insurance is usually a comparatively small line item that grows or shrinks with your revenue and how well you can demonstrate posture at renewal.
A reasonable approach for most teams:
- Treat baseline controls as non-negotiable — they’re the floor for both risk and insurability.
- Buy insurance sized to your tail risk, not your everyday risk. The deductible should sting a little; the limit should cover the catastrophic case.
- Revisit the split annually, ideally just before renewal, when control investments can be translated directly into premium negotiations.
The bottom line
The next dollar usually belongs to a control — especially one your insurer already expects to see — because it reduces loss and lowers your premium at the same time. Insurance earns its place once the baseline is funded, sitting behind your controls to catch the rare event that gets through. Build the floor first, then transfer what’s left.
To pressure-test how controls and insurance fit into your own numbers, try the cybersecurity budget calculator.
References
- IBM Cost of a Data Breach 2025 (opens in a new tab) · verified Jun 2026
- IANS / Artico 2025 Security Budget Benchmark (opens in a new tab) · verified Jun 2026
- Endpoint pricing — CrowdStrike, SentinelOne, Microsoft Defender (list) (opens in a new tab) · verified Jun 2026
Put this into a number
Build a sourced, defensible budget from your own risk profile — free and ungated.