Can Zero Trust Access Actually Lower Your Cyber Insurance Bill?
Picture a mid-sized manufacturer that gets hit with ransomware, files a claim, and six weeks later gets a denial letter citing a policy exclusion for “failure to maintain reasonable access controls.” This is a composite scenario, not a single named case, but it mirrors a pattern that shows up in Coalition’s own claims data: denials that trace back to access controls that existed on paper but weren’t consistently enforced across every login point. The company had cyber insurance. It just didn’t have the controls the policy assumed were already in place.
That gap between “has a policy” and “has the controls the policy requires” is common enough that insurers have changed the rules. If you’re a small business owner weighing whether Zero Trust Network Access (ZTNA) is worth the money, the insurance angle is real. It’s just not the part of the story most vendors lead with.
Why Insurers Now Ask About Your Network Architecture

Cyber insurance used to be a short questionnaire and a check. That’s changed. Insurers absorbed years of claims tied to preventable breaches, and underwriters now ask pointed technical questions before they’ll quote a policy at all.
Marsh McLennan’s 2025 Cyber Insurance Data found that 96% of cyber policies now require multi-factor authentication as a baseline condition of coverage. MFA is just the floor. Many carriers also want evidence of network segmentation, endpoint detection, and controls over how remote employees and vendors reach internal systems.
That last item is what ZTNA is built for. It verifies each user and device before granting access to a specific application, rather than handing out broad network access once someone logs in.
What ZTNA Actually Brings to an Underwriting Conversation
When an underwriter reviews your application, they’re really asking one question: if an attacker gets a foothold, how far can they move before someone notices? A flat network where one compromised laptop can reach the accounting system, the file server, and the customer database is a different risk profile than one where access is segmented and continuously checked.
ZTNA touches several items on the modern underwriting checklist at once: identity verification, device posture checks, and segmented access by design. That doesn’t make it a magic checkbox. But it does mean it maps directly onto controls insurers are already asking about, instead of being an extra feature you have to explain from scratch.
The Premium Discount: What’s Documented and What Isn’t
The numbers floating around online range widely, and not all of them mean what they seem to.
The 15–30% range
TechCompass’s 2026 analysis of cyber insurance requirements found that organizations implementing a fuller set of controls, including multi-factor authentication, endpoint detection and response, tested backups, and access segmentation, saw premium reductions in the 15% to 30% range. ZTNA sits inside that broader control stack. It isn’t a line item insurers price separately from everything else.
Dollar figures tied specifically to ZTNA’s slice of that discount aren’t published anywhere reliable enough to cite here. What is documented, from Meriplex’s 2026 ROI analysis of ZTNA deployments, is the cost side: a mid-sized rollout runs roughly $75,000 to $150,000 depending on scale and existing infrastructure. Treat any specific dollar savings figure you see quoted alongside that number with some skepticism unless it names its source and shows its math.
The 31% figure you’ll see cited
You may also come across a claim that Zero Trust architecture can reduce cyber losses by up to 31%. That number comes from a Zscaler analysis of data held by Marsh McLennan’s Cyber Risk Intelligence Center. Read it carefully. Zscaler sells Zero Trust products, so the analysis has a commercial interest in the finding, and the 31% figure is a retrospective modeling exercise, estimating what past losses might have looked like had Zero Trust controls been in place, rather than a measured result from businesses currently running ZTNA. It’s directional data worth knowing about. It isn’t proof of what will happen to your own claims history.
The Bigger Money Question: Claim Denials
Premium discounts get the headlines. They may not be the biggest financial argument for ZTNA.
CyberProtect LLC’s citation of 2025 market data puts the cyber insurance claim denial rate at around 21%. That figure is drawn from aggregated industry reporting rather than CyberProtect’s own primary research, so treat it as a rough industry benchmark rather than a fixed number. Even at the low end of what’s being reported, a denied claim after a real breach can cost a small business far more than any premium discount saves, because you’re left covering incident response, legal fees, and downtime out of pocket while still holding a policy you paid for.
Coalition’s 2024 Cyber Threat Index found that 82% of the denials in its dataset traced back to problems with multi-factor authentication, specifically cases where MFA was enabled somewhere in the environment but not enforced across every access point insurers expected it to cover. The absence of MFA wasn’t usually the issue. Partial, inconsistent enforcement was. That distinction matters, because it’s exactly the gap identity-based access tools are designed to close by verifying at every connection point rather than assuming protection exists somewhere upstream.
Where a Platform Like NordLayer Fits Into the Underwriting Picture
Not every ZTNA product documents its controls the same way, and that documentation matters when you’re building a case to an underwriter or defending a claim later. Platforms like NordLayer are built with small and mid-sized business deployments in mind, offering identity-based access controls and device posture checks that map onto the kinds of requirements insurers are now asking about. If you sign up through some of the links in this article, EdgeTrustNetwork may earn a commission at no extra cost to you.
Whichever platform you evaluate, ask specifically whether it produces audit logs and access reports you can hand to a broker or an insurer during a claims review. That paper trail is often what separates a smooth claims process from a denied one.
Running the Actual Math
Before treating insurance savings as the reason to adopt ZTNA, look at the full picture rather than one line of it.
Meriplex’s 2026 ROI analysis put ZTNA implementation costs at $75,000 to $150,000 for a mid-sized deployment. Set that against a 15% to 30% premium reduction on a typical mid-market policy, and the insurance savings alone probably won’t cover the investment in year one, and maybe not in year two either. That doesn’t mean the math fails. It means insurance should be one line in the business case, not the headline.
The stronger case combines three things: a reduced chance that a breach reaches sensitive systems, avoidance of the kind of claim denial tied to incomplete access controls, and a premium discount that chips away at the ongoing cost of coverage over time. Compliance requirements in your industry may add a fourth reason on top of that.
What to Do Before Your Next Renewal
A few steps make this concrete rather than theoretical.
- Ask your broker directly what control set they’re pricing against. Get the actual checklist, not a general description, so you know whether ZTNA closes a documented gap for your policy.
- Get architecture documentation, not just a vendor’s marketing sheet. Underwriters increasingly want to see how access is segmented and verified, and a clear diagram helps that conversation move faster.
- Don’t treat MFA and ZTNA as separate line items on your own checklist. Insurers usually evaluate them together, and a partial rollout of either one may not move your risk profile much in an underwriter’s eyes.
- Revisit your policy language around “reasonable security measures.” That phrase is where a lot of denials originate, according to Coalition’s own claims analysis. Know exactly what your insurer considers reasonable before a claim happens, not after.
The Real Takeaway
ZTNA can lower your premium, somewhere in the range other businesses have documented, though nothing here is guaranteed for every policy or carrier. The bigger financial exposure isn’t the premium line at all. It’s the roughly one in five claims that industry data suggests get denied, most often over a control that existed in name but wasn’t fully enforced, the kind of gap ZTNA is specifically designed to close.
Go back to that manufacturer from the opening. Whether it’s one company or a pattern that shows up across insurer claims data, the lesson holds either way: the real loss wasn’t a slightly higher premium the year before. It was a claim that never got paid, because the control the insurer assumed was in place wasn’t actually enforced. That’s the number worth building your security case around.