I Need IT Support Now
Managed IT Houston - Cybersecurity
Shane

The Rising Tide of Cyber Threats: Key Insights from At-Bay’s 2025 InsurSec Report

Insights from the 2025 InsurSec Report: Backup Strategies – Your Defense Against Ransomware

Cyber Insurance
Do Cyber Insurance Security Requirements Now Decide Your Premium? At-Bay's 2025 Report Says the Controls You Run Set the Price.

At-Bay's 2025 InsurSec report ties coverage and cost to the security controls you actually deploy. For a Houston SMB, that turns "InsurSec" from jargon into a line item you can move.

TL;DR
Cyber insurance security requirements are no longer paperwork. At-Bay's 2025 InsurSec report shows insurers now price coverage on the controls you run, because those controls decide whether you file a claim. Overall claim frequency rose 16% in 2024, ransomware climbed 19%, and remote access tools were the way in for 80% of ransomware claims. A Houston business with the right controls pays less and files less; one without them pays more, or gets declined.

Cyber insurance security requirements are the specific controls an insurer expects you to run before it writes or prices your policy, and At-Bay's 2025 InsurSec report is the clearest evidence yet that those controls now set your premium instead of a box you check once a year.

"InsurSec" is At-Bay's word for merging insurance with active security. The idea is simple: an insurer that can see your controls, and help you fix the weak ones, ends up paying fewer claims. The 2025 report analyzes a year of real claims data, and it draws a straight line from control choices to loss outcomes. For a Houston business owner, that reframes the whole conversation. You are not buying a policy and hoping. You are choosing controls that lower both the odds of an incident and the price of the coverage.

The core shift: old cyber insurance asked "have you had a breach?" InsurSec asks "what are you running right now?" One looks backward at your history. The other looks at the controls that decide your next twelve months, and prices accordingly.

What Does InsurSec Actually Mean for a Small Business?

Insurance plus security, sold as one thing. The insurer has a direct stake in keeping you from filing a claim.

InsurSec means the company insuring you also monitors your attack surface and flags exposed controls, so the policy and the protection move together instead of the insurer showing up only after the loss.

Traditional cyber insurance behaved like a fire policy: pay the premium, hope nothing burns, argue over the payout later. InsurSec inverts that. The insurer scans what an attacker would see, tells you the gap, and prices the risk on what you fix. At-Bay reports it helped policyholders recover $49 million in stolen funds in 2024, which only happens when the insurer is inside the incident, not waiting outside it. The practical result for a 30-person Katy firm is that your premium becomes a signal. A lower quote means your controls check out. A higher one, or a decline, is the market telling you where you are exposed before a criminal does.

Your Insurer Sees Your Gaps. So Should You.

CinchOps runs the same kind of external and endpoint visibility a cyber insurer uses to price you, then closes the gaps before renewal. It is part of our cybersecurity and managed IT services for Houston-area SMBs.

Explore CinchOps cybersecurity →

Insured With Controls vs Uninsured Without: How Different Is the Outcome?

Same attack, two businesses. The controls decide who files a small claim and who eats a six-figure loss.

A Houston SMB that runs the controls At-Bay rewards, multi-factor authentication, EDR, secured remote access, and tested backups, faces lower premiums and smaller losses; a business without them faces higher pricing, coverage exclusions, or the full uninsured cost of the same incident.

When the attack landsInsured, controls in placeUninsured, controls missing
Ransomware entryMFA and secured remote access block the 80% of ransomware that comes through exposed remote tools.Open VPN or RDP is the front door; the report ties 80% of ransomware claims to remote access.
RecoveryTested, isolated backups restore operations without paying.No clean restore point, so downtime and a ransom demand near $957,000 are on the table.
Financial fraudEmail controls and verification catch the wire before it leaves.83% of fraud starts with an email; the largest single 2024 loss was $5.2 million.
Premium and coverageControls earn a lower quote and full coverage.Higher pricing, exclusions, or no policy to price at all.
Who paysThe insurer absorbs most of the loss; you keep operating.You absorb 100% of the incident, cash, downtime, and reputation.

The gap is not academic. At-Bay's data shows mid-sized companies with $25 million to $100 million in revenue took the hardest hit in 2024, with ransomware frequency up 46% and severity up 47%. The businesses that came through cleanest were the ones whose controls kept the attack small enough to be a claim instead of a closure.

WHAT THE 2025 INSURSEC REPORT MEASURED (2024 CLAIMS) +16% overall claim frequency, year over year +19% direct ransomware, back to 2021 levels 80% of ransomware in via remote access, up from 63% +43% indirect (third party) ransomware frequency Where the money went in 2024 83% of financial fraud began with email $5.2M largest single financial-fraud loss $468K average ransomware claim severity CinchOps · cinchops.com · Source: At-Bay 2025 InsurSec Report (2024 claims data)
The 2025 InsurSec report figures that drive premiums and coverage. Source: At-Bay 2025 InsurSec Report.

Not Sure Which Column You Are In?

Most Houston SMBs assume their policy covers them until a claim proves otherwise. A CinchOps review shows where your controls sit against what insurers now require.

Get a Security Review

What Does At-Bay's 2025 Report Reward, and What Does It Penalize?

The report reads like a pricing sheet. Certain controls pull your risk down; certain gaps push it up.

At-Bay's 2025 InsurSec report rewards businesses that close the two doors attackers used most in 2024, email and remote access, and penalizes the exposures that turned an incident into a large claim.

Two attack paths dominated the year. Email was the entry point for 43% of all claims, and financial fraud, the most common incident type at roughly a third of all claims, began with a malicious email 83% of the time. Remote access tools were the way in for 80% of direct ransomware claims, up sharply from 63% the year before. Those are not exotic threats. They are the ordinary front doors most Houston businesses leave unlocked. Here is how the report sorts the two sides:

  • Rewarded: secured remote access. MFA on VPN and RDP, or eliminating direct exposure, cuts off the path behind 80% of direct ransomware claims.
  • Rewarded: email controls and payment verification. With 83% of financial fraud starting in the inbox, filtering plus a call-back rule on wire changes stops the loss before it moves.
  • Rewarded: tested, isolated backups. A clean restore point turns a ransomware event into a recovery instead of a $957,000 demand negotiation.
  • Penalized: unmanaged third-party risk. Indirect ransomware, an attack on a vendor that hits you, rose 43% in 2024. The CDK Global outage that froze auto dealerships is the textbook case.
  • Penalized: thin control adoption by sector. Manufacturing carried some of the heaviest claim activity, which At-Bay links to lower security-control adoption than more regulated fields.

The pattern is consistent. Every control the report rewards maps to one of the two attack paths that did the most damage. That is the whole InsurSec argument: the insurer is not guessing at your risk, it is measuring the controls that decide it, and pricing you on the same evidence an attacker would exploit.

At-Bay indexed cyber claim frequency by year showing ransomware returning to 2021 levels
Indexed Claim Frequency by Year. Source: At-Bay 2025 InsurSec Report.
At-Bay average cyber claim severity by industry in 2024, with manufacturing among the highest
Average Claim Severity by Industry, 2024. Source: At-Bay 2025 InsurSec Report.

How CinchOps Helps Houston Businesses Meet Cyber Insurance Security Requirements

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area, with the security stack to close the exact control gaps insurers now price on.

CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10-200 employees. The 2025 InsurSec report is, in effect, a checklist of what to deploy before your next renewal. We run that checklist as a live defense:

  • Secured remote access and MFA. We lock down the VPN and RDP paths behind most direct ransomware, closing the door the report ties to 80% of those claims.
  • Email security and fraud controls. Multi-layer filtering plus wire-verification process for the inbox-borne fraud behind 83% of financial-fraud losses.
  • Managed, tested backups and EDR. Isolated recovery and endpoint detection that stop ransomware from becoming a shutdown.
  • Vendor risk and 24/7 monitoring. Coverage for the third-party exposure that drove indirect ransomware up 43%, backed by around-the-clock response for Houston and Katy businesses.

We see this pattern with local firms in manufacturing, construction, and oil and gas every renewal cycle: the businesses that treat controls as a cost keep paying more, and the ones that treat them as a bargaining chip keep paying less. If your policy renews soon and you are not sure which side you are on, talk to CinchOps and we will get your controls ahead of what the insurer is about to ask for.

In 35 years I have never seen the insurance and the security question line up this cleanly. The controls that keep an attacker out are the same ones that lower your premium now. For a Houston business, that means every dollar you spend hardening remote access and email pays you back twice, once in fewer incidents and once in a better renewal.
Shane Stevens, CEO, CinchOps - LinkedIn
100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

What are cyber insurance security requirements?

Cyber insurance security requirements are the controls an insurer expects you to run before it writes or prices a policy, such as multi-factor authentication, endpoint detection, secured remote access, and tested backups. At-Bay's 2025 InsurSec report shows these controls now set premiums directly, because they decide whether a business files a claim.

What is InsurSec?

InsurSec is At-Bay's model of combining cyber insurance with active security. The insurer monitors your attack surface, flags exposed controls, and prices coverage on what you actually run. Because the insurer has a direct stake in preventing claims, it works to reduce your risk rather than only paying out after a loss.

What did At-Bay's 2025 InsurSec report find?

The 2025 report, analyzing 2024 claims, found overall claim frequency up 16% and direct ransomware up 19%, back to 2021 levels. Remote access tools were the entry point for 80% of ransomware claims, email drove 43% of all claims, and indirect third-party ransomware rose 43%.

Why do remote access and email matter so much for coverage?

They are the two doors attackers used most in 2024. Remote access tools were the entry point for 80% of direct ransomware claims, and 83% of financial fraud began with a malicious email. Insurers reward businesses that secure both, because closing those paths prevents most large claims.

What does this mean for a Houston small business?

Your controls now set your premium and your coverage. A Houston SMB running MFA, secured remote access, email controls, and tested backups earns lower pricing and smaller losses. A business without them faces higher costs, exclusions, or a decline, plus the full uninsured cost if an incident lands.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506