Getting Cyber Insurance: Security Controls Insurers Ask About
Cyber insurers commonly ask whether you use multi-factor authentication, endpoint detection and response (EDR), tested backups, timely patching, email filtering and a written incident plan. Requirements vary by insurer and change year to year, so treat this list as a way to prepare, not as a guarantee of coverage.
Answer every question accurately. A wrong answer on an application can cause a claim to be disputed, so ask your broker or attorney how your policy handles misstatements before you sign.
Vendors Covered in this Article
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Which controls do insurers most often ask about?
The application questions cluster around a small set of controls. Expect to be asked about:
- Multi-factor authentication: on email, remote access and VPN, cloud admin consoles and privileged accounts.
- Endpoint detection and response: on laptops and servers, and whether someone monitors it. See whether a small business needs EDR.
- Backups: frequency, whether one copy is offline or immutable, and whether you've tested a restore.
- Patching: how quickly critical vulnerabilities are fixed, and whether you run unsupported software.
- Email security: filtering for phishing and malware, and protection against spoofed domains.
- Privileged access: who has admin rights and how they're protected.
- Incident response: a written plan, contacts and whether it has been exercised.
- Training: security awareness for staff, including phishing simulations.
Insurers differ in wording and depth, so read your actual questionnaire line by line.
How to collect evidence for each answer
Don't answer from memory. For every control, gather proof you could show a claims adjuster, and note who owns it:
- MFA: a screenshot of the enforcement policy and a report of users without it. Any exceptions should be listed and justified.
- EDR: a device inventory matched against the agent console, showing coverage.
- Backups: the schedule, where copies live, whether one is offline or immutable, and the date of your last successful restore test.
- Patching: your written target and recent patch reports. As a reference point, CISA's federal directive BOD 19-02 sets 15 days for critical vulnerabilities on internet-accessible systems1.
- Incident plan: the document, the contact list and the date you last rehearsed it.
- Training: completion records for each employee.
Store these in one folder. The same evidence answers customer security questionnaires and audits.
What if you don't meet a requirement yet?
Be honest and find the fastest fix. Common gaps and a practical response:
- MFA missing on some accounts: enforce it through your identity provider, then re-run the user report. This is usually days of work, not months.
- No EDR: deploy a pilot and get coverage on every laptop and server before you apply. A vendor such as CrowdStrike or SentinelOne can be a fit, and confirm managed monitoring if no one can watch alerts.
- Untested backups: run a restore test this week and record the result. A backup you've never restored is an assumption.
- No incident plan: write a first version. The ransomware response plan outline is a good starting point.
Tell your broker about gaps early. They can sometimes suggest a compensating control or a different insurer, and some policies offer coverage with conditions.
How do you avoid overstating your controls?
The most common mistake is a confident "yes" for something that's only partly true. Say MFA is on for staff email but not for the admin portal of a payment system. The honest answer isn't "yes". Use these habits:
- Have the person who actually runs each control answer that question.
- Answer with the narrowest true statement, and add notes for exceptions.
- Keep a copy of the completed application with the date and signer.
- Re-check answers before renewal, since your environment has changed since last year.
If a claim happens, your application answers will be compared with reality. Accuracy protects you far more than a clean-looking form.
How do you keep the controls in place all year?
Insurers can ask about controls again at renewal, and a lapse discovered after an incident is the worst time. Set a quarterly review: MFA exceptions, EDR coverage, a restore test, patch status, a look at admin accounts and any new tools that hold data. Log the results next to your evidence folder. Related work, such as security awareness training and Microsoft's own tiers covered in the Defender comparison, often serves your insurance answers and customer audits at the same time.
What Good Looks Like
For each control an insurer asks about, you can show current evidence, a named owner and a quarterly check that it still holds.
Building The Capability (5-Stage Skill Ladder)
How to Get Started
Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.
Frequently Asked Questions
What security controls does cyber insurance require?
It varies by insurer, but common asks are multi-factor authentication, EDR, tested backups, timely patching, email filtering, an incident plan and staff training. Read your actual application, since wording and thresholds differ.
Is MFA mandatory for cyber insurance?
Many insurers require it on email, remote access and admin accounts, and some decline applicants without it. Requirements differ, so confirm with your broker and the questionnaire for your specific policy.
Can a claim be denied for inaccurate application answers?
It can be disputed. Misstatements on an application may affect coverage, depending on the policy and jurisdiction. Answer accurately, keep evidence, and ask your broker or attorney how your policy treats errors.
How often should we test backups?
Regularly enough that you trust a restore, and at least after major changes. Record the date and result. An untested backup is an assumption, and insurers often ask when you last tested.
Sources
Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.
- Security patch remediation SLAs (CISA federal mandates, used as industry norm). CISA Binding Operational Directives 19-02 and 22-01 (CISA briefing hosted at NIST CSRC), 2022.
Related Guides
Do You Need EDR? A Small Business Decision Guide
Endpoint detection and response goes beyond antivirus. See when a small business needs it, what to compare in demos, and how to roll it out.
Ransomware Response Plan: Who Does What in the First 24 Hours
An outline for a ransomware response plan: roles, first-hour containment steps, the payment question, communications and how to recover safely.
What SOC 2 Auditors Expect From Security Awareness Training
What security awareness training satisfies a SOC 2 audit: content, timing, who must complete it and the evidence to keep for the auditor.
Microsoft Defender for Business or E5 Security? How to Choose
Compare Defender for Business and the E5 security tier by the capabilities you will actually use, who runs them and what to confirm with Microsoft.
SBOM Requirements for Software Vendors: What Buyers Ask For
What a software bill of materials is, who asks vendors for one, what it must contain and how to generate and share SBOMs from your build pipeline.