Cybersecurity & Compliance

Cyber Insurance Requirements: What Insurers Expect From Your IT

MSP Worx · 5 min read · Updated Oct 10, 2026

Cyber insurance used to be straightforward to obtain. A short application, a modest premium, broad coverage. That market is gone. After several years of severe ransomware losses, carriers restructured underwriting, and the application became a technical audit.

The practical consequence: your ability to obtain coverage, and the premium you pay, now depends directly on specific controls being in place and demonstrable. And the application is a warranty, which makes accuracy a legal matter rather than an administrative one.

The controls carriers now require

These appear on virtually every application. Several are now conditions of coverage rather than rating factors — answer no, and the application is declined rather than priced higher.

Multi-factor authentication

The single most heavily weighted control. Carriers ask about it separately for email, for remote access, and for administrative accounts, and they increasingly ask whether it covers all users rather than most. Partial deployment is frequently treated as no deployment.

Endpoint detection and response

Traditional antivirus no longer satisfies most carriers. They are asking specifically for EDR, and often whether it is monitored — by your team, a provider, or a security operations centre. Deployed-but-unmonitored is a weaker answer than many businesses realise.

Backups that survive an attack

The questions have become specific: are backups offline, immutable, or otherwise isolated from the production network; how frequently are they tested; what is the retention period. Modern ransomware deliberately targets accessible backups, so a backup reachable with domain credentials is treated as no backup at all.

Patch management

Cadence for critical patches, and whether any end-of-life software remains in the environment. Unsupported operating systems are close to a disqualifier with several carriers.

Email security

Filtering, anti-phishing, and increasingly whether SPF, DKIM and DMARC are correctly configured — a question that catches out a lot of businesses whose domain authentication was never completed properly.

Security awareness training

Delivered, documented, and often with simulated phishing. Carriers want evidence of a programme, not a single session.

Privileged access management

How many administrative accounts exist, whether they are separated from day-to-day accounts, and how they are protected.

An incident response plan

Written, and ideally tested. Some carriers ask when it was last exercised.

ControlWhat carriers askAnswer that hurts you
Multi-factor authenticationEmail, remote access and admin accounts, separately; all users or mostPartial deployment
Endpoint detection and responseEDR rather than antivirus, and who monitors itDeployed but unmonitored
BackupsOffline, immutable or isolated; test frequency; retentionReachable with domain credentials
Patch managementCritical patch cadence; any end-of-life softwareUnsupported operating systems
Email securityFiltering, anti-phishing, SPF, DKIM and DMARCDomain authentication never completed
Security awareness trainingDocumented programme, often with simulated phishingA single session
Privileged accessHow many admin accounts; separated from daily accountsAdmin rights on everyday accounts
Incident response planWritten, tested, and when last exercisedNo written plan

The part that should worry you most

The application is a warranty. Your answers become part of the contract, and material misrepresentation gives the carrier grounds to deny a claim or rescind the policy.

This is not a hypothetical risk. Claims have been contested on precisely this basis — a business attested to MFA across all users, suffered a compromise through an account that did not have it, and found coverage disputed at the point of loss.

The scenario that produces this is rarely deliberate. Someone in the business completes the form, answers what they believe to be true, and nobody verifies it technically. A year later the gap emerges.

The rule to work by: no answer goes on a cyber application without technical verification. "We think so" is not a basis for a warranty.

Coverage terms worth reading

Beyond eligibility, several structural terms materially affect what you actually recover:

  • Ransomware sublimits. The policy may carry a headline limit with a much lower cap specifically for ransomware — often the exposure you were buying it for.
  • Waiting periods. Business interruption typically only begins after a waiting period, commonly 8 to 12 hours. An outage shorter than that recovers nothing.
  • Coinsurance on ransomware, requiring you to bear a percentage of the loss.
  • Dependent business interruption — whether outages at your vendors are covered. Increasingly relevant as more of the stack is outsourced.
  • Panel requirements. Many policies require you to use the carrier's approved incident response vendors. Engaging your own first can jeopardise coverage, which is worth knowing before an incident rather than during one.

That last point deserves emphasis. In the first hours of an incident the instinct is to call your IT provider and start fixing. If the policy requires carrier notification and panel counsel first, acting on instinct can cost you the claim.

Policy termWhat to check
Ransomware sublimitHow far below the headline limit the ransomware cap sits
Waiting periodHours before business interruption cover starts (commonly 8 to 12)
Ransomware coinsuranceThe percentage of the loss you bear
Dependent business interruptionWhether outages at your vendors are covered
Panel requirementsWhether you must notify the carrier and use its approved responders first

Carriers now verify independently

Several carriers run external scans of applicants before binding — checking for exposed remote desktop, unpatched internet-facing services, expired certificates, leaked credentials in breach databases, and domain authentication configuration.

This means the application is no longer purely self-reported. A discrepancy between what you attest and what they observe from outside is a problem at underwriting rather than at claim time, which is at least the better of the two.

It also means an external vulnerability scan before you apply is worth doing. You want to know what they will see.

Preparing for renewal

  1. Start 90 days out. Remediation takes longer than the renewal window allows if you begin when the forms arrive.
  2. Get the application to your IT provider early and have them answer the technical sections with evidence, not recollection.
  3. Close gaps before applying rather than attesting and intending to fix. The attestation is what binds.
  4. Document everything — training records, patch reports, backup test results, the incident response plan. Some carriers request evidence, and having it ready improves terms.
  5. Compare more than premium. Sublimits, waiting periods and panel requirements vary enormously between carriers at similar prices.

There is a genuine upside here worth naming. The controls carriers demand are, almost without exception, the controls that reduce the chance of a serious incident. Businesses often find that preparing for renewal is the thing that finally funds security work they had deferred for years — and the insurance becomes the secondary benefit.

Sources

  1. New York State Department of Financial Services — Insurance Circular Letter No. 2 (2021): Cyber Insurance Risk Framework
  2. CISA — #StopRansomware Guide
  3. CISA — Bad Practices
  4. CISA, FBI, NSA and international partners — Weak Security Controls and Practices Routinely Exploited for Initial Access (AA22-137A)

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.