I’ve been asked numerous times whether insurers are actually better at quantifying cyber risk than CISOs. I get why the question keeps coming up, since I write about how insurers are shaping the cybersecurity landscape. But here's the thing, insurers talk in dollars and CISOs often show up with heat maps and control gaps. One side looks like it’s making decisions. The other looks like it’s still describing the problem. That framing misses what’s really going on.

Insurers are built to price risk. That’s their job. They look across thousands of companies and try to answer the very specific question of "what’s the likelihood of loss and what will it cost when it happens?" They’ve got claims data, patterns across industries, and a financial model that forces everything back to exposure and payout. That discipline shows up in how they talk about risk. It lands with finance leaders because it connects directly to money.

CISOs are operating from a completely different vantage point. They’re inside the environment. They see how things actually break. They know where identity is loose, where access has drifted, where recovery hasn’t been tested in a meaningful way. That level of detail matters. It’s the difference between theory and reality. But when it comes time to explain risk, it often gets translated into categories that don’t carry weight outside of security. High, medium, low doesn’t help a CFO decide what to do next. That’s the gap people are reacting to.

At the same time, the idea that insurers have cyber risk figured out better than everyone else doesn’t really hold up. The data is still uneven. The threat landscape moves too fast. You can see it in how the market has behaved. Pricing swings. Coverage tightening. Underwriting questions that keep evolving. That’s not a stable model. That’s a market adjusting under pressure.

Where I think this conversation needs to land, especially for small and mid size businesses, is a bit different.

Insurers may not be better at quantifying cyber risk in a pure sense, but they are absolutely shaping how it gets defined.

That’s something I simply explain in my latest book "Can We Insure This?: The CFO’s Guide to Cybersecurity". The point of the guide wasn’t that insurers have solved cyber risk. It was that insurability is quietly becoming the forcing function for how businesses think about it.

For a lot of small and mid-sized businesses, cybersecurity doesn’t become real until it shows up in an insurance conversation. Renewal. Denial. A questionnaire they can’t answer cleanly. Suddenly things like MFA, endpoint visibility, backup validation, and response readiness aren’t just best practices. They’re tied directly to whether the business can get coverage and what it’s going to cost.

The pressure from an insurer changes behavior. In many cases, more than internal security programs ever did.

So when someone says insurers are better at quantifying risk, what they’re really picking up on is that shift. Insurers are forcing risk into a financial conversation earlier and more consistently than most organizations have done on their own. Especially with small and mid-sized companies where there isn’t a large security function driving that internally. But even there, the picture isn’t complete.

Insurers don’t have full visibility into how a business actually operates. They rely on questionnaires, external scans., and sometimes telemetry. More and more, they’re leaning on security vendors to fill in the gaps. That tells you everything you need to know. They’re working with partial data too. Just from a different angle.

This is about how cybersecurity and insurers are starting to converge.

Insurers are pushing financial accountability into cybersecurity. Cybersecurity practitioners are being pushed to translate technical reality into business impact. And in with small and mid-sized businesses that convergence is happening faster because the insurer is often the one driving the conversation, typically without a CISO, or dedicated cybersecurity leader.

The takeaway isn't that insurers have cracked the code to cyber risk, just that they’ve made it impossible to ignore what it actually costs. The demands for small and mid-sized companies will continue leverage cybersecurity partners and fractional security roles.