Skip to main content
Techx4u, Inc

Security Assessment

Cyber Insurance Controls Insurers Expec

Cyber insurers increasingly ask about practical security controls. Here is what businesses should have ready before applying, renewing or answering an insurer's questions.

· 8 min read

Cyber insurance starts with evidence, not a checkbox

Cyber insurance is not a replacement for security controls. An insurer is taking on part of the financial risk associated with a cyber incident, so it needs to understand how that risk is being managed before agreeing terms.

The exact questions and requirements vary between insurers, policies and industries. Some applications ask about multifactor authentication, endpoint protection, backups, patching and privileged access. Others go deeper into email security, remote access, incident response and security awareness.

The important point is that an application is not just paperwork. Your answers can become relevant when a claim is assessed. If the application says MFA protects privileged and remote access, you should be able to demonstrate that it is actually configured and enforced.

This is where many businesses struggle. They may own Microsoft 365, EDR, firewalls and backup software, but nobody has checked whether the controls are consistently configured or whether exceptions have accumulated. The tools exist. The operational ownership does not.

The controls insurers commonly ask about

There is no universal cyber insurance checklist, but several control areas appear regularly in underwriting questionnaires. The exact requirements should always be confirmed with the insurer or broker handling the policy.

Multifactor authentication

MFA is one of the first controls worth checking. Do not simply ask whether MFA is "enabled". Determine which accounts and services require it.

Review MFA for:

  • Microsoft 365 and other cloud applications.
  • Remote access services and VPNs.
  • Privileged administrator accounts.
  • Email access.
  • Other externally accessible systems.

The important distinction is between having MFA available and enforcing MFA. If users can bypass it, or important administrator accounts are excluded, the actual protection is different from what a simple questionnaire answer might suggest.

Microsoft Entra Conditional Access can also apply stronger controls based on users, applications, devices and risk. The configuration needs to match the statement made in the insurance application.

Endpoint protection

Insurers may ask whether company devices have antivirus, EDR or another endpoint protection platform. Again, installation is only the starting point.

Check whether devices are actually reporting into the platform. Look for machines that have stopped communicating, protection that has been disabled, outdated agents and policy exceptions.

The same applies to servers. A business may have strong endpoint protection on laptops while leaving critical servers outside the security platform. That may be intentional, but the gap needs to be understood.

Businesses that need someone to operate these controls rather than simply install them can consider managed endpoint security, where monitoring and operational handling are part of the service model.

Backups and recovery

Backup questions can be more detailed than "Do you have backups?" Insurers may want to understand what is backed up, how often it runs, how long data is retained and whether backups are separated from production systems.

A backup platform showing successful jobs is not enough by itself. You should know whether important data can actually be restored and who is responsible for carrying out recovery.

Consider Microsoft 365 separately as well. Exchange Online, SharePoint, OneDrive and Teams data may require their own recovery strategy depending on the organisation's requirements.

A review of backup and data protection controls should therefore look at both the technology and the recovery process.

Patching and vulnerability management

Insurance questionnaires commonly ask whether systems are patched and how vulnerabilities are managed. The sensible answer is not "we install updates automatically" unless you can demonstrate how the process works.

A practical patching process identifies assets, prioritises vulnerabilities, deploys updates, handles failures and records exceptions. Internet-facing systems and actively exploited vulnerabilities may need faster treatment than routine updates on less exposed systems.

If a device cannot be patched because of application compatibility or vendor restrictions, document the reason and consider compensating controls. An exception should be managed, not forgotten.

What people get wrong about cyber insurance controls

The biggest mistake is treating the insurer's questionnaire as a list of boxes to tick. If a business rushes to answer "yes" without checking the underlying configuration, it creates a gap between the documented security position and the real environment.

Another mistake is focusing only on the controls mentioned by the insurer. Security requirements can change, and a questionnaire cannot describe every risk in your environment. MFA may be required, for example, but that does not mean weak administrator permissions become acceptable elsewhere.

Businesses also sometimes buy a security product shortly before completing an insurance application and assume the requirement is now satisfied. Installing EDR, MFA or backup software does not prove that it is working correctly across the environment.

There is also confusion between policy requirements and good security practice. An insurer may specify particular conditions for coverage, but meeting those conditions does not mean the organisation has addressed every significant security weakness.

Finally, some companies leave the questionnaire entirely to an IT provider. Technical input is useful, but management should understand what is being declared. The organisation signing the application needs to know whether the answers accurately represent how its systems are operated.

Check the controls before the renewal deadline

The easiest time to discover a security gap is before the insurer asks about it. Start by obtaining the current questionnaire, policy wording and any specific control requirements from your broker or insurer.

Then map each requirement to an actual system or process. If the questionnaire asks whether MFA is enforced for remote access, identify the remote-access systems and verify the configuration. If it asks about backups, identify the protected workloads, retention and recovery process.

Evidence is useful here. Depending on the requirement, this might include Microsoft Entra configuration, endpoint management reports, backup reports, patch-management records, firewall settings or security policies.

Do not manufacture evidence simply to complete the application. If something is not implemented, record the gap and decide whether it needs remediation, risk acceptance or discussion with the broker or insurer.

A technical security assessment can also help identify weaknesses before they become an insurance or operational problem. The useful outcome is a prioritised list of issues that someone can actually fix.

What to actually do in order

First, get the current cyber insurance questionnaire and policy requirements. Do not work from an old application or a generic checklist found online.

Next, identify the controls being asked about. At minimum, review MFA, privileged access, endpoint protection, patching, backups, remote access and incident response where they appear in the insurer's requirements.

Then verify the controls technically. Check actual configurations and reports rather than relying on what someone remembers being deployed.

After that, document exceptions. Record devices without EDR, accounts without MFA, systems that cannot currently be patched, backup workloads that are excluded and other relevant gaps.

Prioritise remediation based on the insurer's requirements and the actual risk to the business. Do not make changes blindly just to produce a better questionnaire response. A rushed configuration change can introduce operational problems of its own.

Finally, keep the evidence and review it periodically. Security controls change as employees join and leave, systems are replaced, applications move to the cloud and policies are modified. The answer given to an insurer should describe the environment that actually exists, not the environment the business intended to have.

Common questions

What cybersecurity controls do cyber insurers require?
Requirements vary by insurer and policy, but questionnaires commonly cover controls such as multifactor authentication, endpoint protection, patching, backups, privileged access, remote access and incident response. Businesses should obtain the current requirements from their insurer or broker and verify that the stated controls are actually configured and operating across the relevant systems.
Does having MFA qualify for cyber insurance?
Having MFA available does not necessarily mean the insurance requirement is satisfied. Insurers may expect MFA to be enforced for particular accounts, remote access services or cloud applications. Businesses should check which systems and users are covered, identify exclusions and verify the actual configuration before declaring that MFA is fully implemented.
Do I need EDR for cyber insurance?
Some insurers may require or expect endpoint detection and response, while others may accept different endpoint protection controls. The answer depends on the policy and insurer. If EDR is deployed, businesses should also verify that endpoints are reporting correctly, policies are active and exceptions are understood rather than treating installation alone as proof of protection.
Will cyber insurance cover a ransomware incident if I have backups?
Backups can support recovery from ransomware, but having backups does not automatically determine whether a claim is covered. Coverage depends on the policy wording, exclusions and the circumstances of the incident. Businesses should understand the insurer's requirements, maintain appropriate backups and verify that important data can actually be restored when required.
Share

Let's talk about your environment

Tell us what you are running and what worries you. We will come back with a straight assessment and a costed plan — no obligation.