Endpoint securityChecklist3 min readUpdated September 2026

Getting Cyber Insurance: Security Controls Insurers Ask About

Cyber insurers commonly ask whether you use multi-factor authentication, endpoint detection and response (EDR), tested backups, timely patching, email filtering and a written incident plan. Requirements vary by insurer and change year to year, so treat this list as a way to prepare, not as a guarantee of coverage.

Answer every question accurately. A wrong answer on an application can cause a claim to be disputed, so ask your broker or attorney how your policy handles misstatements before you sign.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Which controls do insurers most often ask about?

The application questions cluster around a small set of controls. Expect to be asked about:

  • Multi-factor authentication: on email, remote access and VPN, cloud admin consoles and privileged accounts.
  • Endpoint detection and response: on laptops and servers, and whether someone monitors it. See whether a small business needs EDR.
  • Backups: frequency, whether one copy is offline or immutable, and whether you've tested a restore.
  • Patching: how quickly critical vulnerabilities are fixed, and whether you run unsupported software.
  • Email security: filtering for phishing and malware, and protection against spoofed domains.
  • Privileged access: who has admin rights and how they're protected.
  • Incident response: a written plan, contacts and whether it has been exercised.
  • Training: security awareness for staff, including phishing simulations.

Insurers differ in wording and depth, so read your actual questionnaire line by line.

How to collect evidence for each answer

Don't answer from memory. For every control, gather proof you could show a claims adjuster, and note who owns it:

  1. MFA: a screenshot of the enforcement policy and a report of users without it. Any exceptions should be listed and justified.
  2. EDR: a device inventory matched against the agent console, showing coverage.
  3. Backups: the schedule, where copies live, whether one is offline or immutable, and the date of your last successful restore test.
  4. Patching: your written target and recent patch reports. As a reference point, CISA's federal directive BOD 19-02 sets 15 days for critical vulnerabilities on internet-accessible systems1.
  5. Incident plan: the document, the contact list and the date you last rehearsed it.
  6. Training: completion records for each employee.

Store these in one folder. The same evidence answers customer security questionnaires and audits.

What if you don't meet a requirement yet?

Be honest and find the fastest fix. Common gaps and a practical response:

  • MFA missing on some accounts: enforce it through your identity provider, then re-run the user report. This is usually days of work, not months.
  • No EDR: deploy a pilot and get coverage on every laptop and server before you apply. A vendor such as CrowdStrike or SentinelOne can be a fit, and confirm managed monitoring if no one can watch alerts.
  • Untested backups: run a restore test this week and record the result. A backup you've never restored is an assumption.
  • No incident plan: write a first version. The ransomware response plan outline is a good starting point.

Tell your broker about gaps early. They can sometimes suggest a compensating control or a different insurer, and some policies offer coverage with conditions.

How do you avoid overstating your controls?

The most common mistake is a confident "yes" for something that's only partly true. Say MFA is on for staff email but not for the admin portal of a payment system. The honest answer isn't "yes". Use these habits:

  • Have the person who actually runs each control answer that question.
  • Answer with the narrowest true statement, and add notes for exceptions.
  • Keep a copy of the completed application with the date and signer.
  • Re-check answers before renewal, since your environment has changed since last year.

If a claim happens, your application answers will be compared with reality. Accuracy protects you far more than a clean-looking form.

How do you keep the controls in place all year?

Insurers can ask about controls again at renewal, and a lapse discovered after an incident is the worst time. Set a quarterly review: MFA exceptions, EDR coverage, a restore test, patch status, a look at admin accounts and any new tools that hold data. Log the results next to your evidence folder. Related work, such as security awareness training and Microsoft's own tiers covered in the Defender comparison, often serves your insurance answers and customer audits at the same time.

Executive Capability Standard

What Good Looks Like

For each control an insurer asks about, you can show current evidence, a named owner and a quarterly check that it still holds.

Building The Capability (5-Stage Skill Ladder)

1. Learn:Read the application questionnaire line by line and list each control it asks about.
2. Do Manually:Gather evidence for MFA, EDR coverage, backups, patching and your incident plan in one folder.
3. Delegate:Assign an owner for each control and the person who completes and signs the application.
4. Automate:Enforce MFA and endpoint coverage through policy, and schedule backup restore tests and patch reports.
5. Buy:Add managed endpoint monitoring or a backup service to close gaps you can't staff yourself.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

Frequently Asked Questions

What security controls does cyber insurance require?

It varies by insurer, but common asks are multi-factor authentication, EDR, tested backups, timely patching, email filtering, an incident plan and staff training. Read your actual application, since wording and thresholds differ.

Is MFA mandatory for cyber insurance?

Many insurers require it on email, remote access and admin accounts, and some decline applicants without it. Requirements differ, so confirm with your broker and the questionnaire for your specific policy.

Can a claim be denied for inaccurate application answers?

It can be disputed. Misstatements on an application may affect coverage, depending on the policy and jurisdiction. Answer accurately, keep evidence, and ask your broker or attorney how your policy treats errors.

How often should we test backups?

Regularly enough that you trust a restore, and at least after major changes. Record the date and result. An untested backup is an assumption, and insurers often ask when you last tested.

Sources

Where we quote a benchmark, we show its source. Other figures in this guide are estimates or general guidance, so check them against your own numbers.

  1. Security patch remediation SLAs (CISA federal mandates, used as industry norm). CISA Binding Operational Directives 19-02 and 22-01 (CISA briefing hosted at NIST CSRC), 2022.

Related Guides