Cyber insurance used to be straightforward. You answered a short questionnaire, paid a modest premium, and filed the policy away. Underwriters were competing for business and asking relatively little in return.

That era is over. After years of heavy ransomware losses, carriers rebuilt their underwriting from the ground up. The application is now a detailed technical audit, the controls it asks about are effectively mandatory, and, in the part that catches businesses out, your answers become part of the contract.

Here is what carriers now expect, and how to get your environment into a state where renewal is a formality rather than a scramble.

The Controls Carriers Now Expect

Requirements vary between carriers, but a common core has emerged. If you are missing several of these, expect either a declination, a sharply loaded premium, or coverage with ransomware carved out.

Multi-factor authentication, everywhere

This is the single most consistent requirement, and the one most often answered too optimistically. Carriers generally want MFA on email, on remote access and VPN, on cloud administration consoles, and on any remote access to servers. Increasingly they ask specifically about privileged and administrative accounts.

The common failure is partial coverage: MFA on email, but a legacy VPN without it, or a handful of service accounts exempted years ago for convenience. Those exceptions are exactly what an underwriter is asking about.

Endpoint detection and response

Traditional signature-based antivirus is no longer sufficient in most applications. Carriers want EDR: tooling that watches behaviour, can isolate a compromised machine, and retains enough telemetry to reconstruct what happened. Many now ask whether it is monitored around the clock, and by whom.

Backups that survive the attack

Backups are the difference between an expensive week and an existential event, and modern ransomware deliberately targets them. Carriers have caught up, and now ask about specifics:

  • Offline, immutable or otherwise out of reach of an attacker who has domain administrator rights.
  • Separated credentials backup systems that do not authenticate against the same directory as everything else.
  • Tested restores, with a date. "We have backups" is not the question. "When did you last restore from them" is.
  • A documented recovery time you have actually measured rather than estimated.

Email security and user training

Since most incidents still begin with email, carriers ask about filtering, about protections against impersonation and spoofing, and about whether staff receive regular phishing awareness training with simulations. Some now ask for completion rates.

Patch management with evidence

Expect to be asked how quickly critical vulnerabilities are remediated, and to substantiate it. Related: whether any unsupported operating systems remain in service, a question that became considerably sharper once Windows 10 went end of support.

Privileged access controls

Carriers increasingly ask how many users hold administrative rights, whether staff use separate accounts for administrative work, and whether privileged access is reviewed. Environments where everyone is a local administrator attract attention immediately.

The part businesses underestimate

Your application answers are representations that form part of the insurance contract. If you attest to MFA on all remote access, suffer an intrusion through a remote access path that did not have it, and the carrier establishes that during claims investigation, you have handed them a coverage defence at the exact moment you need the policy to work. The application is not paperwork. It is the policy.

Why Accuracy Matters More Than Optimism

There is a strong temptation to answer applications aspirationally, describing the environment as you intend it to be rather than as it is. It is rarely deliberate dishonesty. Someone in finance completes the form, asks IT a question, receives a broadly reassuring answer, and ticks the box.

The problem surfaces months later, during a claim, when a forensic investigator reconstructs precisely how the attacker got in. That process routinely surfaces the exceptions: the contractor account without MFA, the server excluded from patching because a fragile application ran on it, the backup job that had been failing silently since spring.

An honest application that results in a higher premium is vastly better business than an optimistic one that results in a denied claim.

If you cannot answer a question confidently, the right move is to find out before submitting, not to assume the reassuring answer.

Getting Ready for Renewal

Start ninety days out

Most of these controls cannot be implemented in the week before renewal. Deploying EDR across an estate, closing MFA gaps on legacy systems, or rebuilding a backup architecture to be genuinely immutable are projects measured in weeks. Beginning a quarter ahead turns renewal into an administrative task.

Get the application early and treat it as a checklist

Ask your broker for the questionnaire well before it is due. Go through it with whoever runs your IT and mark every question in three categories: confidently yes, confidently no, and not sure. The third category is the actual work.

Verify rather than assume

For each control, find the evidence. Pull the list of accounts without MFA enforced. Check when a restore was last tested, and from which backup. Look at actual patch compliance numbers rather than the policy that says patching happens monthly. Discrepancies between policy and practice are common and entirely fixable, provided you find them yourself.

Document what you find

Keep the evidence: configuration screenshots, restore test results, training completion reports, patch compliance figures. It shortens the application process, supports a better premium, and becomes genuinely valuable if you ever need to demonstrate your posture during a claim.

Write down your exceptions

Almost every environment has something that cannot meet the standard: a legacy system, a vendor-mandated configuration, a machine tied to production equipment. Document each one: what it is, why it exists, what compensating controls surround it, and who accepted the risk. Disclosing a known, contained exception is a far stronger position than having a claims investigator discover it.

The Useful Side Effect

It is worth naming the obvious: the controls carriers demand are, almost without exception, the controls that prevent incidents in the first place. MFA, EDR, tested and isolated backups, prompt patching and constrained administrative rights are not insurance paperwork. They are the short list of measures that actually stop the attacks carriers have spent years paying for.

Approached that way, insurance readiness stops being a compliance exercise imposed from outside. It becomes an externally imposed deadline for work that was worth doing regardless, with a premium reduction as the immediate reward and a materially lower chance of ever filing a claim as the real one.

Renewal Coming Up?

We can walk your environment against your carrier's questionnaire, close the gaps, and assemble the evidence, so you can answer every question accurately.

Book a Readiness Review