Cyber insurance used to be straightforward to obtain. A short application, a modest premium, broad coverage. That market is gone. After several years of severe ransomware losses, carriers restructured underwriting, and the application became a technical audit.
The practical consequence: your ability to obtain coverage, and the premium you pay, now depends directly on specific controls being in place and demonstrable. And the application is a warranty, which makes accuracy a legal matter rather than an administrative one.
The controls carriers now require
These appear on virtually every application. Several are now conditions of coverage rather than rating factors — answer no, and the application is declined rather than priced higher.
Multi-factor authentication
The single most heavily weighted control. Carriers ask about it separately for email, for remote access, and for administrative accounts, and they increasingly ask whether it covers all users rather than most. Partial deployment is frequently treated as no deployment.
Endpoint detection and response
Traditional antivirus no longer satisfies most carriers. They are asking specifically for EDR, and often whether it is monitored — by your team, a provider, or a security operations centre. Deployed-but-unmonitored is a weaker answer than many businesses realise.
Backups that survive an attack
The questions have become specific: are backups offline, immutable, or otherwise isolated from the production network; how frequently are they tested; what is the retention period. Modern ransomware deliberately targets accessible backups, so a backup reachable with domain credentials is treated as no backup at all.
Patch management
Cadence for critical patches, and whether any end-of-life software remains in the environment. Unsupported operating systems are close to a disqualifier with several carriers.
Email security
Filtering, anti-phishing, and increasingly whether SPF, DKIM and DMARC are correctly configured — a question that catches out a lot of businesses whose domain authentication was never completed properly.
Security awareness training
Delivered, documented, and often with simulated phishing. Carriers want evidence of a programme, not a single session.
Privileged access management
How many administrative accounts exist, whether they are separated from day-to-day accounts, and how they are protected.
An incident response plan
Written, and ideally tested. Some carriers ask when it was last exercised.
| Control | What carriers ask | Answer that hurts you |
|---|---|---|
| Multi-factor authentication | Email, remote access and admin accounts, separately; all users or most | Partial deployment |
| Endpoint detection and response | EDR rather than antivirus, and who monitors it | Deployed but unmonitored |
| Backups | Offline, immutable or isolated; test frequency; retention | Reachable with domain credentials |
| Patch management | Critical patch cadence; any end-of-life software | Unsupported operating systems |
| Email security | Filtering, anti-phishing, SPF, DKIM and DMARC | Domain authentication never completed |
| Security awareness training | Documented programme, often with simulated phishing | A single session |
| Privileged access | How many admin accounts; separated from daily accounts | Admin rights on everyday accounts |
| Incident response plan | Written, tested, and when last exercised | No written plan |
The part that should worry you most
The application is a warranty. Your answers become part of the contract, and material misrepresentation gives the carrier grounds to deny a claim or rescind the policy.
This is not a hypothetical risk. Claims have been contested on precisely this basis — a business attested to MFA across all users, suffered a compromise through an account that did not have it, and found coverage disputed at the point of loss.
The scenario that produces this is rarely deliberate. Someone in the business completes the form, answers what they believe to be true, and nobody verifies it technically. A year later the gap emerges.
The rule to work by: no answer goes on a cyber application without technical verification. "We think so" is not a basis for a warranty.
Coverage terms worth reading
Beyond eligibility, several structural terms materially affect what you actually recover:
- Ransomware sublimits. The policy may carry a headline limit with a much lower cap specifically for ransomware — often the exposure you were buying it for.
- Waiting periods. Business interruption typically only begins after a waiting period, commonly 8 to 12 hours. An outage shorter than that recovers nothing.
- Coinsurance on ransomware, requiring you to bear a percentage of the loss.
- Dependent business interruption — whether outages at your vendors are covered. Increasingly relevant as more of the stack is outsourced.
- Panel requirements. Many policies require you to use the carrier's approved incident response vendors. Engaging your own first can jeopardise coverage, which is worth knowing before an incident rather than during one.
That last point deserves emphasis. In the first hours of an incident the instinct is to call your IT provider and start fixing. If the policy requires carrier notification and panel counsel first, acting on instinct can cost you the claim.
| Policy term | What to check |
|---|---|
| Ransomware sublimit | How far below the headline limit the ransomware cap sits |
| Waiting period | Hours before business interruption cover starts (commonly 8 to 12) |
| Ransomware coinsurance | The percentage of the loss you bear |
| Dependent business interruption | Whether outages at your vendors are covered |
| Panel requirements | Whether you must notify the carrier and use its approved responders first |
Carriers now verify independently
Several carriers run external scans of applicants before binding — checking for exposed remote desktop, unpatched internet-facing services, expired certificates, leaked credentials in breach databases, and domain authentication configuration.
This means the application is no longer purely self-reported. A discrepancy between what you attest and what they observe from outside is a problem at underwriting rather than at claim time, which is at least the better of the two.
It also means an external vulnerability scan before you apply is worth doing. You want to know what they will see.
Preparing for renewal
- Start 90 days out. Remediation takes longer than the renewal window allows if you begin when the forms arrive.
- Get the application to your IT provider early and have them answer the technical sections with evidence, not recollection.
- Close gaps before applying rather than attesting and intending to fix. The attestation is what binds.
- Document everything — training records, patch reports, backup test results, the incident response plan. Some carriers request evidence, and having it ready improves terms.
- Compare more than premium. Sublimits, waiting periods and panel requirements vary enormously between carriers at similar prices.
There is a genuine upside here worth naming. The controls carriers demand are, almost without exception, the controls that reduce the chance of a serious incident. Businesses often find that preparing for renewal is the thing that finally funds security work they had deferred for years — and the insurance becomes the secondary benefit.


