Cyber insurance applications used to ask a simple yes-or-no question: does your company run security awareness training? That question has gotten considerably more specific. Underwriters now want to know which topics are covered, how often testing happens, what the click and report rates actually look like, and whether any of it is documented well enough to survive a claims dispute.
This guide covers what cyber insurers actually evaluate around phishing and human risk, why documented simulation data has become part of that evaluation, and how organizations can use it to their advantage during underwriting and renewal.
In Short: Cyber insurers increasingly treat documented phishing simulation data as evidence of real, ongoing risk reduction, not just a policy checkbox. Organizations that can show consistent testing, trending click rates, and dated evidence over time are generally better positioned during underwriting and renewal than those relying on a single annual training session.
Why Phishing Behavior Specifically Matters to Insurers
Phishing remains the most common entry point for the incidents cyber insurance actually pays out on, which is exactly why insurers scrutinize it closely during underwriting. According to Consilien’s 2026 breakdown of cyber insurance requirements , recurring security awareness training paired with phishing simulation is one of the cheapest controls an organization can implement relative to the risk it addresses, and it is a control carriers now ask about by name rather than treating as an assumed baseline.
This shift reflects a broader pattern in underwriting: insurers have moved from asking whether a control exists to asking for evidence that it actually operates, consistently, over time. A single training session completed a year ago satisfies neither.

What Underwriters Actually Want to See
Modern cyber insurance applications and renewal reviews increasingly ask for specific, documented evidence rather than general assurances. According to Vigil’s overview of cyber insurance evidence requirements , common underwriter expectations now include quarterly phishing simulation results with a visible click-rate trend, training coverage documented across employees and segmented by role, and evidence covering newer risk categories specifically.
One data point stands out: the same analysis notes that deepfake and voice-clone simulation evidence, a requirement that barely existed a few years ago, is now requested by roughly 30 percent of carriers in 2026, up from under 5 percent in 2024. This tracks closely with the real-world rise in deepfake-enabled fraud our own research has covered in the top 10 deepfake video call scams , and it signals that insurers are actively adjusting underwriting criteria to match how attacks are actually evolving, not lagging years behind them.
Documentation That Actually Holds Up
Insurers increasingly dispute claims where a policyholder cannot prove the controls they attested to were genuinely in place. This makes the quality of documentation nearly as important as the underlying practice itself. Useful, defensible evidence generally includes:
Dated, recurring campaign records, not a single training completion certificate from onboarding.
Click-rate and report-rate trends over multiple campaigns, showing direction of change rather than a single snapshot.
Coverage data by role or department, since insurers increasingly want to see that high-risk groups, such as finance staff, are tested specifically, not just included in a general company-wide campaign.
Evidence spanning more than email alone, as underwriting criteria expand to cover voice, SMS, and deepfake-based social engineering alongside traditional phishing.
Our guides on how phishing simulation reports help organizations achieve regulatory compliance and 10 ways phishing simulation reports boost company security cover the reporting side of this in more depth, and much of the same documentation that supports a compliance audit also supports an insurance renewal.
Building an Ongoing Program, Not a One-Time Event
The clearest theme across current underwriting practice is that insurers reward consistency, not a single strong data point. An organization that ran one excellent phishing campaign eight months ago looks meaningfully different on paper than one currently running recurring campaigns with a visible improving trend, even if their underlying risk is similar today.
Organizations building this kind of ongoing evidence typically start with a baseline phishing test for employees , then track results over successive campaigns through an employee phishing risk score , which produces exactly the kind of longitudinal, role-segmented data underwriters increasingly ask to see, without requiring a separate reporting process built just for insurance purposes.
Final Thoughts
Phishing simulation was never designed around cyber insurance requirements, but the two have converged for a simple reason: both are trying to answer the same underlying question, how likely is a human-targeted attack to succeed here, and how would we know. Organizations that already run consistent, documented, trending simulation programs are not just reducing their actual risk. They are building exactly the kind of evidence that makes underwriting conversations faster and renewal terms more favorable.
FAQ
Can phishing simulation actually lower my cyber insurance premium?
It can contribute to a more favorable underwriting outcome. Insurers increasingly evaluate documented, recurring phishing simulation data as evidence of active risk reduction, though the effect on premium varies by carrier and is generally part of a broader risk assessment rather than a guaranteed discount on its own.
What phishing-related evidence do cyber insurers typically ask for?
Common requests include recurring, dated simulation campaign results, click-rate and report-rate trends over time, training coverage broken down by role or department, and increasingly, evidence covering channels beyond email, including voice and deepfake-based social engineering.
Is a single annual phishing test enough for cyber insurance purposes?
Generally not for the best underwriting outcomes. Insurers increasingly favor recurring, trended evidence over a single point-in-time test, since it demonstrates ongoing risk management rather than a one-time compliance exercise.
Why are insurers starting to ask about deepfake simulation specifically?
Deepfake and voice-clone fraud attempts targeting businesses have grown significantly in recent years, and underwriters have adjusted their criteria accordingly. Requests for this kind of evidence have grown from a small minority of carriers to a meaningfully larger share within just a couple of years.
Does phishing simulation data help with insurance claims, not just applications?
Yes. Insurers increasingly dispute or scrutinize claims where a policyholder cannot demonstrate that the controls they attested to were genuinely operating. Dated, consistent simulation records can support a claim by showing the control was real and active, not just declared on paper.
Content Reviewed By

Nawaz is a practising security analyst specializing in phishing simulation campaigns, employee awareness assessments, red team exercises, and ethical hacking. He leads phishing simulation deployments at PhishCare, a product developed by CyberSapiens, with hands-on experience evaluating and deploying phishing simulation tools across organizations in multiple industries and regions globally.
View LinkedIn ProfileConsistent, documented phishing simulation data supports both stronger security and stronger insurance conversations. See how to build that evidence with a free PhishCare demo account, no credit card required.







