Skip to content

Cyber Insurance Security Requirements, What Insurers Now Ask For

The renewal used to be a short form and a signature. Now it is a questionnaire several pages long, full of technical terms, and the broker has made it clear that some answers will decide whether cover is offered at all. Cyber insurance security requirements have tightened because insurers have paid for a great many incidents and have a clear picture of which controls would have prevented them. That makes the questionnaire useful in its own right: it is a list of what actually works, written by people who pay when it does not.

What the questionnaire is really asking

The exact wording varies by insurer, but the underlying controls are remarkably consistent, because the same handful of failures sit behind most claims. Each question maps to one of them.

Multi-factor authentication everywhere that matters

Insurers ask whether MFA is enforced on email, on remote access such as VPN and remote desktop, on administrative accounts, and increasingly on cloud applications and backup consoles. “Available to users” is not the same as “enforced for all users”, and the questionnaire usually asks the second. The reasoning is simple: a stolen or guessed password is the beginning of most intrusions, and MFA is the control that stops it being enough.

Endpoint detection and response

Traditional antivirus is no longer regarded as sufficient. Insurers want endpoint detection and response on servers and workstations, and many now ask whether it is monitored by a security team around the clock. The question behind the question is how quickly an intrusion would be noticed and contained.

Backups that are tested and out of reach

Expect questions about how often backups run, whether at least one copy is offline or immutable so ransomware cannot encrypt it, whether backups are encrypted, and whether restores have been tested. “Yes, we back up” earns little credit without the offline copy and the test. Insurers have seen too many claims where the backups were encrypted alongside the data.

Patching, email filtering, training and a plan

The remaining questions cover how quickly critical security updates are applied, whether email is filtered for phishing and malicious attachments, whether staff receive security awareness training and phishing simulations, whether privileged accounts are separated from everyday ones, and whether a written incident response plan exists and has been exercised. Some ask about end-of-life systems still in use, and about how remote access is secured beyond MFA.

Answering honestly, and why it matters

The instinct under time pressure is to answer optimistically: MFA is “mostly” on, backups are “regularly” tested, patching is “prompt”. That instinct is dangerous. The answers on the questionnaire become part of the contract, and if a claim is later investigated and a control declared present turns out to have been absent, the insurer may reduce the payout, dispute the claim or, in serious cases, treat the policy as void because it was issued on the basis of inaccurate information. That is a worse position than having declared the gap in the first place.

The better approach is to treat the questionnaire as an audit. Go through it with whoever runs your IT, answer each item with evidence, and where the honest answer is no, decide whether to fix it before submission or declare it and accept the terms that follow. Many gaps, such as enforcing MFA on remaining accounts or adding an immutable backup copy, can be closed in weeks. Some insurers will offer cover conditional on a fix being completed by a date. Our cyber security consulting work is often exactly this exercise: turning a questionnaire into a short list of actions and the evidence to back each answer.

Turning requirements into a programme rather than a scramble

The controls insurers ask about are not arbitrary. They are the same layered measures any organization should have regardless of insurance: MFA to stop credential theft being enough, endpoint detection with someone watching it, tested and isolated backups so ransomware becomes recoverable, filtered email and trained staff to reduce what gets through, timely patching to close known holes, and a rehearsed plan for the day something still goes wrong. Put in place as a programme, they make the questionnaire a formality each year rather than a scramble, and they make the business less likely to need the policy at all.

Common questions

What security controls do cyber insurers require?

Most ask for multi-factor authentication on email, remote access and administrative accounts, endpoint detection and response on servers and workstations, backups with an offline or immutable copy that have been test-restored, timely patching of critical updates, email filtering, security awareness training, and a written incident response plan. The exact list varies by insurer and by the size and sector of the business.

What happens if our questionnaire answers were wrong?

Answers form part of the basis on which the policy is issued. If a claim is investigated and a control declared present was actually absent, the insurer may reduce or dispute the payout, or in serious cases treat the policy as void. Honest answers, including declared gaps, are safer than optimistic ones. Speak to your broker about how a specific insurer treats misstatements.

Can we get cyber insurance without EDR or MFA?

Some insurers may decline, others may offer restricted cover, higher deductibles or exclusions for ransomware. Because MFA and endpoint detection and response can usually be deployed within weeks, it is generally more sensible to close those gaps before renewal than to accept restricted terms. Ask your broker whether the insurer will accept a commitment to complete the fix by a stated date.

Does an insurance questionnaire replace a security assessment?

No. It covers the controls most associated with claims, which makes it a useful checklist, but it does not test whether the controls actually work in your environment. A proper assessment looks at configuration, coverage gaps and the specific risks of your business, and provides the evidence behind each questionnaire answer. Doing both gives you honest answers and a stronger position on the day of a claim.

If a renewal questionnaire has landed and you would like the answers checked against what is actually deployed, our cyber security consulting, endpoint detection and response and managed backup pages describe the controls insurers most often ask about, and you can contact us to work through the form with evidence rather than guesswork.

← All articles

Ready to Get Started?

Talk to our experts about your needs by calling +1 (647) 725-9693 or book a free 30-minute consultation.

Book a Meeting

Our Partners

Microsoft
Azure
Aws
Google cloud
Cisco
Dell
Lenovo
Hp aruba
Fortinet
Crowdstrike
Checkpoint
Veeam
Microsoft
Azure
Aws
Google cloud
Cisco
Dell
Lenovo
Hp aruba
Fortinet
Crowdstrike
Checkpoint
Veeam