Cyber insurers now expect a specific set of security controls before they'll quote. The usual list is multi-factor authentication on email, remote access and admin accounts, endpoint detection and response, segregated and tested backups, controlled privileged access, timely patching with no unsupported systems, centralized logging, a tested incident response plan, security awareness training and some form of vendor oversight. Missing one of these can mean exclusions, reduced limits, a higher retention or a declined application. This post covers what underwriters ask about each control, how to answer applications accurately and what evidence to prepare.

Why have cyber insurance requirements tightened?

A few years ago, many cyber policies were written on the strength of a short application with a handful of yes/no questions. After a period of heavy claims from account compromise, data breaches and prolonged system outages, insurers moved to detailed control questionnaires and supplemental applications.

The shift in mindset matters more than any single question. Underwriters now treat certain controls as conditions of coverage, not as points in your favor. They also read your answers closely, because the application becomes part of the basis on which the policy is issued.

Which security controls do cyber insurers require?

Every insurer's application is different, but the core controls are consistent. Here's a quick view before the detail.

Control What underwriters typically ask Evidence to have ready
MFA Is it enforced for email, remote access and privileged accounts? For all users? Policy settings, coverage report, list of exceptions
EDR What share of endpoints and servers are covered? Who responds to alerts? Deployment report, monitoring arrangement
Backups Are they segregated, immutable or offline? When were restores last tested? Architecture diagram, restore test records
Privileged access How many admin accounts exist? Are they separate from daily accounts? Admin account inventory, access review records
Patching How fast are critical patches applied? Any end-of-life systems? Patch compliance report, asset inventory
Logging Are logs centralized and retained? Who reviews them? Log source list, retention settings
Incident response Is there a written, tested plan? Plan document, tabletop exercise record
Training Do all staff complete security training? How often? Completion reports
Vendors How is third-party access controlled and reviewed? Vendor inventory, contract clauses

Multi-factor authentication

MFA usually draws the most detailed questions. Expect separate questions for email, remote access (VPN, remote desktop gateways, remote management tools), privileged and admin accounts, and often cloud consoles and backup systems.

The questions are usually absolute: "Is MFA enforced for all remote access?" If a service account, a shared mailbox or a single vendor connection is exempt, the honest answer is not a clean yes. Check for legacy authentication protocols that let users bypass MFA entirely, since these are easy to miss and can make a "yes" inaccurate.

Endpoint detection and response

Traditional signature-based antivirus is often no longer enough to satisfy the question. Insurers want endpoint detection and response on workstations and servers, and they want to know who acts on the alerts. A tool that nobody watches at night or over the weekend is weaker than it looks on paper, and some applications ask about that directly.

Know your coverage percentage. If EDR is on 94% of devices, find out what the other 6% are before you answer.

Backups that survive a bad day

Backup questions focus on whether your backups would still be usable after a serious incident. Underwriters ask whether copies are segregated from the production network, whether at least one copy is immutable or offline, whether backups are encrypted and when you last tested a full restore.

Segregation includes credentials. If the same administrator account can manage production servers and delete backups, one compromised account can take out both. Restore testing matters because business interruption losses depend on how long you are down, and an untested backup gives you no reliable recovery time.

Privileged access management

Insurers want to see that admin rights are limited and controlled. Common questions cover separate admin accounts for IT staff, removal of local admin rights from users, how service accounts are inventoried and managed, and whether privileged credentials are vaulted or issued only when needed.

Count your domain and cloud admin accounts before you fill in the form. The number is often higher than people expect once old project accounts and service accounts are included.

Patching and end-of-life systems

Expect questions about how quickly you apply critical security patches, with internet-facing systems often asked about separately. Some applications ask whether you track actively exploited vulnerabilities, such as those in CISA's Known Exploited Vulnerabilities catalog.

End-of-life systems draw their own questions. If you run an operating system or application that no longer receives security updates, list it, explain how it is isolated and give a retirement date. A vague answer here tends to invite exclusions.

Logging and monitoring

Underwriters ask whether security logs are collected centrally, how long they are kept and who reviews them. Logs matter to insurers after a claim too. Without them, it's hard to establish what data was accessed, which affects both notification obligations and the cost of investigation.

Incident response plan

A written incident response plan is now a standard expectation, and many applications ask whether it has been tested. A tabletop exercise with IT, leadership, legal and communications is the simplest way to show that.

Build the policy into the plan. Most cyber policies require prompt notice of a potential claim and specify how to engage the insurer's approved vendors for forensics, legal counsel and notification. Put the claims contact number and those conditions in the plan so nobody has to find the policy document during an incident.

Security awareness training

Insurers typically ask whether all employees complete security awareness training and how often. They are looking for a regular program with tracked completion, covering topics such as password practices, handling sensitive data and reporting suspicious activity. Keep the completion reports. "Everyone does it" is hard to prove without them.

Vendor management

Third parties with access to your network or data are part of your risk, and insurers increasingly ask about them. Typical questions: do you maintain an inventory of vendors with access to systems or data, do contracts include security requirements, and do vendors use MFA when connecting remotely?

Remote access by IT service providers deserves particular attention. If a provider connects to your environment, its access should meet the same MFA and logging standard as your own staff.

How should you answer a cyber insurance application?

Treat the application as a legal document, because it is one. Your answers are part of what the insurer relies on when issuing the policy, and they are often signed or attested by a senior officer. Material misstatements can give the insurer grounds to dispute a claim or, in some cases, to rescind the policy entirely.

A few practices keep you out of trouble:

  1. Have the right people answer. The broker or finance team can coordinate, but IT and security staff should answer technical questions, and someone should verify each answer against the actual configuration.
  2. Read absolute wording carefully. "All," "always" and "every" mean exactly that. If there is an exception, say so.
  3. Use the comments or supplemental fields. A "no" with a clear explanation and a remediation date is far better than an unqualified "yes" that turns out to be wrong.
  4. Keep a copy of what you submitted. Store it with the evidence that supported each answer at the time.
  5. Track changes during the policy period. If a control is removed or degraded, check your policy's requirements on notifying the insurer, and fix it before the next renewal questionnaire asks.

The most dangerous answers are the ones that were true for part of the environment. An MFA rollout that is "basically done" or EDR that is "on everything important" are the details that come out during a post-claim investigation.

What evidence should you prepare?

Underwriters increasingly ask for proof, and some scan your internet-facing systems from the outside before quoting. Assemble an evidence pack well before renewal:

  • MFA enforcement settings and a coverage report showing enrolled users and any exceptions
  • EDR deployment report compared against your asset inventory
  • Backup architecture diagram and the dates and results of recent restore tests
  • List of privileged accounts and the date of the last access review
  • Patch compliance reports and a list of any end-of-life systems with isolation details
  • Log sources, retention settings and monitoring arrangements
  • The current incident response plan and notes from the latest tabletop exercise
  • Training completion reports
  • Vendor inventory and standard contract security clauses

Much of this is the same evidence an auditor or a large customer would ask for. Collecting it once and refreshing it on a schedule saves effort across all three.

Frequently asked questions

What happens if we don't meet every requirement?

It depends on the insurer and the gap. Outcomes range from a higher retention or lower limit to specific exclusions or a declined application. A documented remediation plan with owners and target dates usually helps the conversation, especially for gaps you can close within weeks.

Do insurers check whether our answers are true?

Some verify before binding, through outside-in scans, evidence requests or interviews. All of them will learn the real state of your controls if you make a claim, because the forensic investigation will show it. Answer as if the claim investigation is the audit.

When should we start preparing for renewal?

Start several months before the renewal date. That leaves time to gather evidence, close small gaps and resolve questions with your broker without rushing the application.

Is the insurer's checklist a substitute for a security framework?

No. Insurance questionnaires focus on the controls most relevant to claims. A framework such as the CIS Critical Security Controls or the NIST Cybersecurity Framework gives you a fuller program, and most insurer requirements map neatly onto it.

Next steps

  • Get last year's application and the current insurer's questionnaire, and assign each question to a named owner.
  • Verify MFA, EDR and backup answers against real configuration data, not memory.
  • Close quick gaps now, and document a dated plan for the rest.
  • Build an evidence pack you can refresh each year.
  • Add the insurer's notification requirements and claims contacts to your incident response plan.