Skip to content

Resource

Cyber insurance IT requirements, in plain language.

What insurers are actually asking, what they verify, and how to answer with evidence instead of a guess.

The application changed. Most businesses haven't caught up.

Cyber insurance used to be a short questionnaire. A few broad questions about backups and antivirus. Most businesses checked the boxes, paid the premium, and moved on.

That's not what the application looks like now.

Carriers paid out heavily on ransomware and business email compromise claims over the last several years. They learned something from those payouts: the businesses that got hit hardest almost always had the same gaps. No MFA on critical accounts. Backups that were never tested. No incident response plan. Controls that were assumed to exist rather than verified.

So underwriters stopped taking your word for it. The application got longer. The questions got more specific. And the verification got more serious. Carriers now ask for screenshots, policy exports, backup test logs, and documented evidence of controls. Not just a yes or no answer. The most important shift in cyber insurance underwriting is this: carriers no longer ask whether you have these controls. They ask whether you can prove the controls were fully enforced at the time of the incident. Those are not the same question. The gap between them is where most claims get denied.

Meeting cyber insurance and compliance requirements

What carriers are actually asking about.

Each item below maps to a specific question on most applications. The plain-language explanation is what the question is actually getting at.

Multi-factor authentication. Enforced, not just available

MFA is the first question on almost every application and the most common source of claim denial. Carriers want MFA enforced on email, remote access, VPN, cloud platforms, and every administrative account. Not turned on as an option that employees choose to use. MFA that can be bypassed because conditional access wasn't configured doesn't satisfy what the carrier is asking. Partial enforcement, email but not VPN, users but not admins, creates the gaps that attackers exploit and that carriers flag at claim time.

Endpoint detection and response

Traditional antivirus matches files against known signatures. Endpoint detection and response monitors behavior in real time and can isolate a compromised device before an attacker moves laterally through the network. Most carriers have moved past asking about antivirus and are now asking specifically about EDR, whether it's actively monitored, and how quickly alerts get investigated. Owning the tool and managing it well are two different things. A carrier reviewing a claim will look at whether alerts were acted on, not just whether the software was installed.

Backups. Immutable, tested, and documented

Carriers ask whether backups are immutable, whether they're stored separately from the systems they protect, and how recently a restore was tested. A backup connected to the same network as the systems it protects can be encrypted in the same ransomware attack. Immutable backups, copies that can't be altered or deleted once written, survive the attack. The testing question matters equally. A backup that has never been restored is treated by carriers the same way it performs in a real incident: as an unknown. Documented restore tests with dates and results are what a carrier wants to see, not a confirmation that the backup job completed.

Email security and domain protection

Business email compromise drives significant carrier losses. Applications ask about spam filtering, phishing protection, attachment scanning, and whether DMARC, SPF, and DKIM are configured for the domain. These records prevent other senders from spoofing your domain. Sending email that appears to come from your organization to deceive clients or employees. Most businesses have some email filtering. Fewer have all three domain records configured correctly. Carriers are specifically asking about all three.

Patch management with documented cadence

Unpatched systems are one of the most consistent breach entry points. Carriers want to know that operating systems, applications, and firmware are updated on a regular schedule. And that there's documentation of the process. An environment where patches are applied when someone remembers to check is different from one where patching happens on a defined schedule with compliance reporting. The application is asking about the latter.

Privileged access controls and admin separation

How many administrator accounts exist, who holds them, and are they separated from standard user accounts. Shared admin credentials, global admin accounts belonging to former employees, and admin accounts used for daily work are all conditions carriers flag. Privileged access management means the right people have the right access and nothing more. And that it gets reviewed.

Security awareness training and phishing simulations

Human error is present in the majority of incidents. Carriers want documented training programs and evidence of phishing simulations. Not a one-time onboarding video. The question is whether employees are regularly tested and whether the results show improvement over time.

A written, tested incident response plan

Who gets called in the first hour of an incident. Who contacts the carrier. Who contacts legal counsel. How the business communicates with clients and staff while the incident is being managed. Carriers want a document, not a conversation. And increasingly they want evidence it's been tested. A tabletop exercise in the past twelve months. A plan that exists in someone's head doesn't satisfy the application.

Logging and alert monitoring

Whether audit logging is configured, how long logs are retained, and whether alerts are actively monitored and responded to. This is how carriers determine whether the business would even know if something was happening. An environment without logging has no record to investigate and no way to demonstrate that controls were working at the time of an incident.

Third-party and vendor access controls

Whether vendors and contractors who connect to the environment have been evaluated, whether their access is limited to what they need, and whether it gets reviewed. Supply chain attacks frequently enter through vendor access that was set up once and never revisited.

Why most businesses struggle to answer honestly.

The application isn't asking trick questions. It's asking about controls that should exist in any well-managed IT environment. The problem is that most businesses have IT that was built reactively. Controls added when something forced the issue, settings configured at setup and never revisited, access managed by whoever was available.

When the application asks about MFA, the honest answer for most businesses isn't yes or no. It's partially. On some accounts, for some users, configured some time ago and never verified since. When it asks about backup testing, the honest answer is often that the backup runs but nobody has tested a restore. When it asks about the incident response plan, the honest answer is that there isn't one in writing.

Checking yes when the honest answer is partially or no isn't fraud in most cases. It's a business that doesn't know its own environment well enough to answer accurately. But it creates a serious problem when a claim gets filed and the carrier reviews what was actually in place.

The framework behind the controls.

The controls carriers ask about didn't come from nowhere. They reflect what the security industry has established as the baseline for reducing risk in business environments. CIS Controls, the framework we align to, maps directly to what underwriters are asking about. MFA, endpoint protection, backup and recovery, access management, logging, incident response. These are CIS implementation group controls that apply to businesses in the 25 to 250 employee range.

This matters for two reasons.

First, a business managed to CIS Controls isn't retrofitting security to pass an application. It already has the controls in place because they're the right controls regardless of what a carrier asks. The application becomes a documentation exercise, not a gap-closing scramble.

Second, carriers price risk based on demonstrated controls. A business that can show documented, maintained controls, with test logs, configuration reports, access reviews, and an incident response plan, is a demonstrably lower risk than one that can only attest verbally. That difference shows up at renewal in rates, coverage limits, and exclusions. Managing IT to a recognized framework and meeting cyber insurance requirements are the same conversation. The controls overlap because they're solving the same problem.

The questions worth asking before you fill out the application.

These are the questions your IT provider should be able to answer specifically. If the answers are vague, that's meaningful information about what you'll be able to demonstrate to a carrier.

Can you show me evidence that MFA is enforced, not just enabled, on every administrative account, every remote access path, and every cloud platform we use?

When was the last backup restore test performed, and is there documentation of the results?

Are our backups immutable? Can they be reached and encrypted by a ransomware attack that hits the main environment?

Is DMARC configured for our domain, and is it in enforcement mode?

How many global admin accounts exist in our Microsoft 365 tenant, and when were they last reviewed?

Is audit logging configured and retained, and for how long?

Do we have a written incident response plan? Has it been tested in the last twelve months?

What changes when the environment is managed to a standard.

The renewal conversation is different. The application gets answered from documentation, not memory. Every question about MFA has a policy export behind it. Every question about backup testing has a log with dates and results. Every question about admin accounts has a reviewed and current list. The incident response plan exists in writing and has been tested.

That documentation doesn't just satisfy the application. It's the difference between a claim that gets paid and one that gets denied on the grounds that the control wasn't actually in place when the incident happened.

When IT is managed to a recognized framework, cyber insurance readiness isn't a separate project. It's a byproduct of how the environment is already being run. The controls exist. The documentation exists. The evidence exists. The application reflects reality instead of what someone hopes is true.

If you're not confident your answers to the application are accurate, that's exactly what an IT Environment Review is for. We look at what's actually in place, compare it against what carriers are asking, and tell you where the gaps are before the application. Not after the claim.

Schedule an IT Environment Review

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.