A cybersecurity firm’s workers’ comp premium is driven less by the “low-risk office employer” label than by how each role is classified, which states your people work in, and how the PEO structures its policy. A quote that looks cheap on a blended basis can hide a code that doesn’t match your job descriptions, a policy that doesn’t list every state you employ people in, or a pricing bundle you can’t compare line by line.
That matters because your headcount is rarely uniform. Analysts and GRC consultants sit at desks, while penetration testers, red teamers, and incident responders travel, work at client sites, or handle hardware.
This article explains how a cybersecurity PEO workers’ compensation program works, where classification and pricing go wrong, and which documents to request before you sign. It is informational, not legal, tax, or insurance advice, and state rules change, so confirm specifics with your state agency or rating bureau.
Why Security Firms Don’t Fit the Typical Tech Employer Mold
Most software companies have a fairly uniform workforce: people at laptops. Security firms are more mixed. Analysts, security engineers, and GRC consultants are generally office or professional roles. Penetration testers may spend time on client premises, run physical security assessments, or handle devices in a lab. On-site incident responders can be dispatched on short notice, carry equipment, and work long hours in unfamiliar facilities. Those differences change both the exposure and, potentially, how a carrier or rating bureau views the role.
Workers’ compensation is regulated state by state, which shapes everything that follows. Each state sets its own coverage requirements, and rates are filed and approved under state rules. Four states, Ohio, North Dakota, Washington, and Wyoming, have historically been monopolistic: employers generally must buy coverage from the state fund rather than from private carriers. As of 2026, confirm the current list and how each state treats PEOs and co-employment with the state agency, since this affects which PEO options even exist for employees based there. Some PEOs handle monopolistic-state employees through the state fund separately, and some don’t cover them at all.
The most common misconception in this industry is “we’re all remote, so we have no workers’ comp risk.” Remote employees can still suffer compensable injuries, and whether a particular home-based injury qualifies depends on state law and the facts. A fully remote team also tends to be a multi-state team. Each state where someone works can carry its own obligations, so scattered hiring creates more compliance surface, not less.
The practical takeaway is that “low-risk” is a starting assumption, not a conclusion. What counts is the role-by-role and state-by-state picture of your actual workforce.
How a PEO Delivers Workers’ Comp: Master Policy, Carrier Programs, and Co-Employment
A PEO can provide workers’ comp in a few different ways, and which one you get is vendor-specific. Confirm it in writing rather than assuming. For a fuller walkthrough of the mechanics, see how the PEO workers’ compensation insurance program works.
- Master (pooled) policy: the PEO holds a policy covering its client companies as worksite employees. Pricing is set by the PEO and its carrier, and your own claims history may be blended with the pool or considered only partly.
- Client-specific or guaranteed-cost policy placed through the PEO: the PEO arranges a policy tied more closely to your company, so your own loss experience carries more weight.
- Captive or large-deductible structures: some PEOs use these, which can shift part of the claims risk to the PEO or to participating clients. They introduce questions about collateral, retained losses, and what happens when results are poor.
What co-employment changes
Under a typical PEO arrangement, the PEO is the employer of record for workers’ comp purposes. In practice, that means the PEO’s carrier relationship, claims experience, and underwriting appetite affect your coverage, not just your own history. That can help a young firm with no loss record. It can also mean a PEO-wide change at renewal reaches you regardless of how few claims you’ve had, which is one of the risks of a PEO master workers’ comp policy.
PEO versus the alternatives
A certified PEO (CPEO) is an IRS-certified designation relating to payroll tax responsibilities, and it doesn’t by itself tell you how the workers’ comp is structured. An employer of record (EOR) typically employs workers on your behalf, often in a specific location, which is a different model. An ASO usually provides HR and payroll services without co-employment and generally leaves the workers’ comp policy with you, so you’d compare it to a standalone policy. A payroll-only provider usually has no role in coverage. Matching like to like matters when comparing quotes.
For illustration, imagine a 40-person security consultancy with 28 desk-based staff and 12 consultants who regularly work at client sites. It could buy a standalone policy and have its own claims history and class codes rated, or join a PEO master policy priced under the PEO’s blended arrangement. The standalone route offers more transparency on how your roles are rated. The PEO route may offer simpler administration and access to a larger pool. Neither is automatically cheaper, and the answer depends on how each is coded and priced.
Classification Codes: Where Cybersecurity Companies Get Overcharged or Misclassified
Every employee’s pay is assigned to a class code that reflects the work they do, and each code has its own rate. In most states, the National Council on Compensation Insurance (NCCI) maintains the classification system. Some states run their own independent bureaus, including California, New York, and Pennsylvania, among others. Verify the current bureau for each of your states, as of 2026, before relying on any code mapping.
Code 8810, clerical office employees, is the usual reference for desk-based staff in NCCI states. How a security company’s technical staff are classified varies. Some states and carriers apply software or IT consulting codes, and others have different treatment. Confirm exact codes and their state applicability with the PEO and the bureau rather than assuming 8810 covers everyone. Firms in other professional-services fields face a similar issue, as covered in this look at architecture PEO workers’ compensation programs.
The role-split test
Before you request quotes, split your payroll into three groups: office or remote staff, field or client-site staff, and anyone doing hardware or lab work. Then ask each PEO which code applies to each group and why. Their answers tell you whether the quote reflects your business or a template.
Warning signs
- A single blended code for the whole company, with no role breakdown.
- A code that seems chosen for the PEO’s administrative convenience rather than your job descriptions.
- A mismatch between the quote and what your roles actually do, in either direction.
Misclassification cuts both ways. Coding field staff too cheaply may look good in a quote but can lead to reclassification and a bill later. Coding desk staff too expensively means you overpay all year.
What to verify
Ask how audits work, how reclassification is handled at renewal, and who pays a premium true-up if an audit changes the picture. Get the answers in the contract or a written addendum, not on a sales call.
Pricing Mechanics: Rate Per $100 of Payroll, Experience Mod, and What Gets Bundled
The basic workers’ comp formula is straightforward: payroll for a class code, divided by 100, multiplied by that code’s rate. Sum the results across codes. On a standalone policy, an experience modification factor (the experience mod) then adjusts the total up or down based on your own claims history compared with similar employers. PEO pooled policies may blend or replace the mod, so ask directly how your claims history is treated and whether a clean record earns you anything. If you’re weighing a move off a standalone or assigned-risk policy, this guide to modeling the cost of moving to a PEO master policy shows how to structure the comparison.
Presentation matters as much as the math. Some PEOs show workers’ comp as its own line item with a rate by code. Others fold it into a single administrative fee or a per-employee price. Bundled pricing is not inherently bad, but it makes side-by-side comparison much harder, because you can’t see how much of the price is insurance and how much is service. If a PEO won’t break the number out, you can’t tell whether a low headline reflects efficiency or a thinly priced policy with adjustments later. For a related look at how PEO fees are structured for technology employers, see PEO pricing for tech startups.
Why high salaries change the picture
Because premium is payroll-based, a firm with high average salaries pays more per head than a lower-paid workforce in the same code. Rules that limit how much payroll counts, including payroll caps for certain positions, treatment of executive officers, and state-specific limits, can materially change cost. These rules differ by state, so check each state you operate in rather than assuming a general answer. Ask whether the PEO applies these provisions and where they’re documented.
Adjustments after the quote
Premiums are typically estimated up front and reconciled later. Premium audits and mid-year payroll changes, such as a hiring surge or a big bonus cycle, can produce adjustments. A PEO’s pricing structure may also differ from the underlying carrier’s filed rate, so the number you see isn’t always a pass-through of the carrier’s filing. Ask whether the PEO bills estimated premium each pay period and how, and when, it reconciles against actual payroll.
Coverage Gaps a Cybersecurity Firm Should Check Beyond the Standard Policy
A policy can be correctly coded and fairly priced and still leave holes that matter to a security firm.
Multi-state and remote workers. Confirm the policy lists every state where employees work, not just your headquarters. Ask how “other states” coverage is handled, what triggers a need to add a state, and who is responsible for notifying the PEO when someone relocates or a new remote hire starts.
Travel and international assignments. Workers’ comp generally doesn’t automatically extend to every foreign assignment. If your consultants fly overseas for engagements or incident response, ask about foreign voluntary or endemic coverage and verify the terms with the carrier itself, in writing.
Client contract requirements. Enterprise and government clients often require certificates of insurance, and some contracts specify minimum limits or waivers of subrogation. Confirm the PEO can issue the certificates you need, whether it can accommodate those endorsements, and how fast it can turn requests around. A slow certificate process can hold up a signed statement of work.
Exposures workers’ comp doesn’t address. This is where confusion is common in the industry. Workers’ comp covers employee work injuries and illnesses. It does not cover professional liability (tech errors and omissions), cyber liability, or employment practices liability. These are separate products, and a PEO does not necessarily include them. Some PEOs offer or broker certain liability coverages, but you shouldn’t assume it. If a client contract requires E&O or cyber coverage, ask what the PEO provides and what you’d need to buy elsewhere.
It’s worth keeping a list of every contractual insurance requirement across your active client agreements. Compare that list against what each PEO says it can deliver, and treat any “we can probably do that” as unconfirmed until it’s in writing. Firms that also field physical security staff can compare notes with this overview of a security guard PEO workers’ compensation program.
What Better Looks Like: Questions and Documents to Request Before You Choose a PEO
A good program is one you can examine. Ask each PEO to put the following in writing:
- The policy structure: master policy, client-specific policy, or captive/large-deductible arrangement.
- The carrier name and its financial strength rating. If you cite an AM Best rating, check it directly and note the date of your lookup, since ratings change.
- Class codes assigned by role, and the rate for each code.
- The audit process and the terms for any premium true-up.
Then ask about claims. Who files the claim, who manages return-to-work, and how are claims data and loss runs shared with you? Can you get them during the contract and after you leave? Your own loss history is a negotiating asset with future carriers, so you want access to it.
Exit and renewal terms deserve equal attention. Ask what happens to your coverage and experience if you leave mid-term, how quickly you’d need replacement coverage in place, and how rates can change at renewal. A PEO-wide rate increase can reach you even with a clean record, so ask what limits, if any, the contract places on renewal changes.
Finally, compare at least two or three providers using the same payroll, the same role mix, and the same state list. Quotes built on different assumptions can’t be compared, and a low number often reflects a more favorable assumption rather than a better program. A PEO workers’ comp program evaluation checklist can help you hold every provider to the same inputs so the differences you see are real.
Compare on Coding and Structure, Not the Headline Rate
The right workers’ comp program for a cybersecurity firm depends on how your roles are coded and how the policy is priced and structured, not on the lowest advertised number. A desk-heavy team with a few field consultants needs a PEO that can explain its codes, its audit terms, and its coverage across your states.