Boards ask the same question at every renewal: are we actually better protected, or just better insured? Insurance, warranties, monitoring and incident response are increasingly sold in overlapping language, often by the same providers, across UK, US and other markets. Knowing what each one actually does is a governance question, not a procurement detail.
Two Different Instruments

Insurance is third-party tisk transfer. A pool of premiums funds claims, tested against policy wording once a loss has occured. A warranty works differently: It's a first-party promise from the provider of a security service, paying up to a defined cap when a qualifying incident happens. That gives the provider a direct stake in the incident not happening, or being resolved fast.
Where each one sits
The two don't compete for the same budget line. They cover different parts of the same loss curve: controls and the warranty behind them handle the frequency and speed of resolution, up to a cap that can rise as those controls mature. Insurance covers whatever exceeds that cap, whatever the cause.
The gap almost every insured business is already carrying
Cyber insurance doesn't respond from the first pound of loss. Nearly every policy carries a deductible or self-insured retention that the business must fund itself before the insurer engages at all, commonly a few thousand pounds for a small business and rising into the tens of thousands at the mid-market. That's real, unbudgeted exposure that most businesses only discover mid-incident, exactly when cash flow and speed matter most.
A capped, fast-triggering warranty is built to sit inside that gap. It doesn't duplicate the insurance or compete with the premium spend. It funds the layer the business already chose to self-carry in exchange for a cheaper policy, and it pays immediately rather than after a claim process.
And for the business with none
The logic holds even harder where there's no cyber insurance in place at all, whether by choice, by cost, or because a sector has become difficult to place in a tightening market. There, the warrant isn't a top-up sitting inside someone else's policy. It's the only backdrop in place, and above its cap the business carries the loss itself in full.
That makes it a first move rather than a finish line, Cover earned through demonstrated security improvement, rather than priced off a static questionnaire, is also the most credible route back into an insurable position: evidence of maturity for an underwriter, not a promise of it. Once insurance is back in place, the warranty returns to the role above, funding the layer below the cap while insurance takes the tail.
What the numbers say
IBM's 2026 Cost of a Data Breach Report puts the global average cost of a breach at $4.99 million, with financial services running higher at $6.3 million1. Organisations with mature security AI and automation save an average of $1.93 million per breach compared with those without, largely through faster detection2. That's the outcome continuous monitoring paired with a fast-triggering warranty is built to produce, and it gives any board a calculation it can run for itself: expected loss without the intervention, minus expected loss with it, minus the cost of the programme.
Being precise about "risk transfer"
A genuine transfer means a third party has taken on an open-ended, contractually certain obligation under a regulated policy. A capped, milestone-gated warranty does something narrower but no less useful. It converts an uncertain future cost into a known, bounded one, conditional on the controls behind it staying in place.
Three questions worth asking any provider:
- what is the cap, and does it move as controls change?
- What triggers funding, and how fast?
- What covers the gap above the cap?
The mindset shift
Cyber risk funding has traditionally been static: a premium set at renewal, then a year of hoping nothing changes. A maturity-linked model changes that.
Thomas Murray's CyberResponse+ is one example: coverage expands as an organisation clears defined, published security-maturity milestones, validated at regular programme reviews rather than a one-off questionnaire, so the client is paid for demonstrated improvement, not for hoping.
That shifts the boardroom question, in London, New York, or anywhere else, from whether cover is adequate to whether the organisation is measurably better than it was at the last review.
Talk to the CyberResponse+ team about how a warranty sits alongside the cyber insurance you already hold.

Incident Response
Thomas Murray’s incident response team is trained to respond quickly and efficiently to incidents and help your business get back on track.
Insights

Schrodinger’s Hack- or How HSBC Was(n’t) Hacked
When a bank is hacked it can quickly generate extensive news coverage. And recent events have shown that even when a bank isn’t hacked it can still generate significant column inches – threatening reputational damage.

Do not go (Micro)softly into that good night: Are we at a technology tipping point?
There’s a strong possibility that we’re now collectively at a technology crossroads in Europe because of a potential move away from Microsoft.

Nursery cyber attack shows there is no honour amongst thieves
The news that a gang of cyber criminals is threatening to publish the details of around 8,000 children is one of the starkest cyber incidents of 2025.

Co-op Reveals £80m Profit Hit: What are the Lessons for UK Retail?
Edward Starkie, a Director in Thomas Murray’s cyber security business, gives his reaction to the latest news from the historic British brand.
