Cyber insurance coverage declare values are an efficient option to quantify the affect of cyberattacks on organizations. A better declare worth signifies that the sufferer skilled appreciable monetary and operational penalties from the assault, whereas a low declare worth displays restricted disruption.
Decreasing the worth of cyber insurance coverage claims is to everybody’s benefit. For purchasers, decrease claims show improved cyber resilience whereas insurers profit from decrease payouts. It additionally creates a virtuous circle: If insurers are spending much less overlaying claims, they can drop premiums, delivering additional benefit to purchasers.
Whereas there may be broad consensus that stronger defenses scale back the monetary and operational impacts of cyberattacks and the worth of the ensuing claims, nobody has been capable of quantify it. Till now.
Sophos not too long ago commissioned a vendor-agnostic research to quantify the monetary affect of varied cyber controls on cyber insurance coverage declare values. The research reveals the differing affect of endpoint safety options, EDR/XDR applied sciences, and MDR companies on attack-related claims, offering invaluable insights for insurers and organizations alike.
Key findings on this research embrace:
- Organizations that use MDR companies declare 97.5% lower than those who depend on endpoint safety alone ($75,000 vs $3M).
- Organizations that use EDR/XDR options declare one-sixth (1/6) that of organizations that solely use endpoint safety ($500,000 vs. $3M).
- Organizations that use MDR companies have essentially the most predictable claims; those who use EDR/XDR instruments have the least predictable.
- Organizations that use MDR companies get better quickest from vital cyberattacks with nearly half (47%) absolutely recovered inside every week in comparison with simply 18% of those who depend on endpoint safety alone and 27% of those who use EDR/XDR options.
- Organizations that use MDR companies have essentially the most predictable restoration time from ransomware incidents; EDR/XDR customers the least.
Why this research issues
Organizations spend huge sums on cybersecurity yearly. By quantifying the affect of cyber controls on cyberattack outcomes, this analysis allows organizations to direct their investments the place they are going to see best return.
In parallel, insurers exert vital affect on cybersecurity spend by requiring sure controls as circumstances of protection and providing reductions if others are in place. This analysis allows them to make sure that they’re incentivising the investments that actually do make a constructive distinction to incident outcomes and the ensuing declare values.
Analysis standards
282 declare occasions from 232 organizations with between 50 and three,000 workers have been studied on this analysis program. Respondents used cybersecurity options from a variety of suppliers, together with 19 totally different endpoint safety distributors and 14 separate MDR service suppliers. All organizations have been utilizing multi-factor authentication (MFA) on the time of the claim-triggering cyberattacks. The analysis was carried out for Sophos by Vanson Bourne.
Responses have been segmented into three statistically vital teams based mostly on the cyber defenses that they had deployed on the time of the claim-resulting assaults:
- Endpoint customers: Had been utilizing an endpoint safety answer for a minimum of a 12 months, however weren’t utilizing endpoint detection and response (EDR) or prolonged detection and response (XDR) instruments or MDR companies (n=63 organizations, 83 declare occasions).
- EDR/XDR customers: Had been utilizing an endpoint safety answer and an EDR/XDR software for a minimum of a 12 months however weren’t utilizing MDR companies (n=109 organizations, 129 declare occasions).
- MDR customers: Had been utilizing an endpoint safety answer and an MDR service for a minimum of a 12 months (n=60 organizations, 70 declare occasions).
We use this phase terminology all through the report.
For the avoidance of doubt, the analysis focuses solely on claims ensuing from cyberattacks and excludes claims made on a cyber insurance coverage coverage for different causes (for instance, the enterprise affect of cybersecurity vendor outages or unintentional information loss).
Discovering #1: Organizations that use MDR companies declare 97.5% lower than those who depend on endpoint safety alone
The analysis reveals that the median declare worth by organizations utilizing MDR companies is 97.5% decrease than that of endpoint customers. The common (median) declare by MDR customers was simply $75,000 in contrast with $3M for endpoint customers. Put one other means, endpoint customers sometimes declare 40X extra attributable to cyberattacks than MDR customers. The decrease declare worth seemingly displays the flexibility of the MDR service to rapidly detect and neutralize malicious exercise, ejecting adversaries earlier than critical injury is completed.
The info additionally affirms the good thing about utilizing an EDR or XDR software along with endpoint safety, with the common declare by EDR/XDR customers coming in at one sixth (1/6) that of endpoint customers ($500,000 vs. $3M).

FINDING #2: MDR customers have essentially the most predictable claims; EDR/XDR customers the least predictable
Declare predictability is a vital indicator of the consistency and reliability of cyber controls in lowering the affect of cyberattacks. To know how totally different controls examine, a theoretical instance declare for a corporation with $100M annual income was modeled for every of the segments. That is based mostly upon the output outcomes generated from the multi-variate regression mannequin used for the evaluation (see ‘Concerning the survey’ on the finish of this weblog for extra particulars).
The evaluation reveals two necessary insights:
- MDR customers’ claims are the most predictable
- EDR/XDR customers’ claims are the least predictable
The predictability of MDR customers’ claims displays the consistency with which MDR suppliers rapidly detect and neutralize threats. By offering 24/7 monitoring, investigation, and response delivered by safety operations specialists, MDR companies can take swift motion at any time of the day or evening.
Steady protection is especially necessary on condition that many adversaries intentionally goal “off hours” to hold out their assaults within the hope that it’ll delay detection till they’ve achieved their objectives – evaluation by Sophos X-Ops reveals that 91% of ransomware assaults begin outdoors the usual enterprise hours of 8am-6pm, Monday to Friday.
The unpredictable nature of claims by EDR/XDR customers demonstrates that the efficacy of those instruments in stopping cyberattacks earlier than main injury is completed is wholly depending on the abilities and responsiveness of the person. Some organizations use EDR/XDR instruments to nice impact, stopping assaults swiftly and successfully. Nevertheless, others usually are not capable of ship efficient safety operations regardless of having invested in EDR/XDR know-how – with anecdotal suggestions suggesting that is usually attributable to an absence of capability to ship 24/7 protection and/or a scarcity of experience.
The invention that EDR/XDR customers’ claims cowl a wider band than these of endpoint customers additional means that the poor use of those instruments can, in actual fact, exacerbate the state of affairs. For instance, organizations might delay bringing in exterior incident response consultants to help whereas they attempt to resolve the state of affairs themselves.

FINDING #4: MDR customers have essentially the most predictable restoration time from ransomware incidents; EDR/XDR customers the least
Modeling restoration time based mostly on a theoretical instance of a corporation that experiences a major ransomware assault reveals appreciable variation based mostly on the safety management used. On this evaluation we modeled each the restoration window (the time between the quickest and slowest attainable restoration) and in addition the anticipated restoration time based mostly on the common restoration time reported.
- Endpoint customers are “mid-table” with a 40-day restoration window and predicted restoration time of 40 days.
- EDR/XDR customers are the slowest to get better, with each the widest restoration window (66 days) and the longest predicted restoration time (55 days).
- MDR customers get better quickest, with a five-day restoration window and a predicted restoration time of simply three days.
These findings additional show that utilizing an MDR service materially reduces the affect of cyberattacks on organizations. It additionally reveals the extremely unpredictable nature of EDR/XDR customers’ restoration. It’s necessary to keep in mind that EDR/XDR options are instruments, and their efficacy and affect relies on how nicely they’re used.

Conclusion
The analysis confirms what many have identified instinctively: the kind of cyber controls used has a fabric affect on cyber insurance coverage claims. MDR customers have each the bottom and most predictable declare values. Endpoint customers have the very best common declare worth, whereas EDR/XDR customers have the least predictable declare worth.
Cyberattacks are inevitable. How organizations defend towards them shouldn’t be. These findings are a great tool for organizations that need to optimize their cyber defenses and cybersecurity return on funding, and for insurers trying to scale back publicity and make right-sized coverage presents to purchasers.
Concerning the survey
The analysis was carried out for Sophos by Vanson Bourne within the second half of 2024 and lined claims ensuing from cyberattacks that had occurred inside the earlier 12 months. All findings have been topic to rigorous and strong statistical validation, utilizing multi-variate regression fashions.
These fashions take the first variable (on this case, the safety answer used) and examine how this impacts different key variables (equivalent to declare quantity, and restoration time). Management variables (group sector, group measurement, sort of cyber insurance coverage, stage of safety posturing on the time of assault, standing of declare) have been additionally constructed into the fashions. The findings outlined on this report are the conclusions of those analyses.