Book online or chat with usAnswered 24/7Licensed, insured & bondedSchedule a Consultation
Request serviceUrgentConsultation

Cyber Insurance Requirements: Controls Underwriters Check

Business owner reviewing cyber insurance requirements on an application with a hardware security key on the desk

Cyber insurance requirements have moved from a one-page form to a detailed security questionnaire. Carriers now ask small and mid-size businesses specific questions about multi-factor authentication, endpoint detection, backups, patching and incident planning before they quote, and again at every renewal. The answers you sign become part of the contract.

This guide explains the controls underwriters commonly ask about, why an optimistic answer can put a claim at risk, and how to prepare an accurate application. If you want help verifying controls and producing evidence, our managed cyber security and MSSP services are built to show insurers and auditors that the controls are real.

This article is general information, not legal advice. Policy wording and state law vary, so confirm specifics with your broker and counsel.

Key takeaways

  • There is no single national standard. Each carrier sets its own cyber insurance requirements, but the core list is consistent: MFA, EDR, tested offline or immutable backups, patching, email security, privileged access, an IR plan and training.
  • Underwriters often ask about MFA in detail: email, remote access, and administrative access to directory services, backups, network gear and servers.
  • Application answers are representations the insurer relies on. A 2022 federal case ended with a policy rescinded after the carrier alleged MFA was misrepresented.
  • Answer what is enforced today, not what is planned. Disclose gaps and the date they will be closed.
  • Keep evidence for every answer: screenshots, policy exports, restore test results and training records.

Where this guidance comes from. We drew on the FBI Internet Crime Complaint Center 2025 annual report, CISA’s #StopRansomware Guide and Cross-Sector Cybersecurity Performance Goals, the NAIC’s report on the cybersecurity insurance market (2024 data), two GAO reports on cyber insurance, NIST SP 800-61 Rev. 3, FTC small business guidance, the State of Indiana’s published list of underwriting control questions, a publicly posted Travelers MFA attestation form and broker analysis from Marsh and Lockton. We added what our security and forensics team sees when helping organizations answer security questionnaires and respond to incidents.

What cyber insurance requirements actually mean

When people say cyber insurance requirements, they usually mean three different things. First, the application questions an underwriter uses to decide whether to offer coverage and at what price. Second, supplemental forms or attestations, such as a separate MFA or ransomware questionnaire. Third, conditions written into the policy itself, such as how quickly you must report an incident.

Requirements differ by carrier, industry, revenue and the limits you buy, and they change from year to year. As of October 2026, the same security topics repeat across carriers because they track how losses actually happen.

The FTC’s small business guidance splits a typical policy into first-party coverage for your own costs, such as forensics, notification and business interruption, and third-party coverage for claims others bring against you. Security controls shape both.

Why underwriters ask more security questions now

A 2021 GAO report cited broker data showing that the share of clients buying cyber coverage rose from 26 percent in 2016 to 47 percent in 2020. It also reported that more than half of brokers surveyed saw clients’ prices rise 10 to 30 percent in late 2020, and that underwriters were more carefully scrutinizing risks from all entities, regardless of size or sector.

The market is now large. The NAIC’s report on the cybersecurity insurance market puts 2024 U.S. cyber direct written premiums at about $9.14 billion, down 7 percent from 2023, across roughly 4.37 million policies. Reported claims rose to nearly 50,000.

Losses explain the scrutiny. The FBI’s 2025 Internet Crime Report counted more than 1 million complaints and $20.877 billion in reported losses. Business email compromise alone accounted for 24,768 complaints and more than $3.04 billion in losses. Ransomware complaints totaled 3,611, and the FBI notes that reported ransomware losses usually exclude lost business, time and remediation costs, so the real figure is higher.

The security controls underwriters commonly ask about

This list reflects Indiana’s published underwriting questions, FBI and CISA guidance and broker research.

1. Multi-factor authentication (MFA)

MFA is the question most likely to be asked in detail. A publicly posted Travelers MFA form asks whether MFA is required for all employees using web or cloud email, for all remote network access by employees, contractors and third-party providers, and for administrative access to directory services, network backup environments, network infrastructure and endpoints or servers. It also asks that the signer complete the form with the person in charge of IT security.

CISA recommends phishing-resistant MFA, such as FIDO/WebAuthn security keys or PKI-based methods, where possible. Our identity and access security service covers phishing-resistant MFA, conditional access and privileged access.

2. Endpoint detection and response (EDR)

Underwriters commonly ask whether EDR runs on all endpoints and servers, not just antivirus. The Indiana question set also asks whether a SIEM is monitored 24×7 by a security operations center. The FBI’s 2025 report notes that EDR tools are particularly useful for spotting lateral movement during a ransomware attack.

3. Offline, immutable and tested backups

The FBI recommends off-site or offline backups that are encrypted, immutable and cover the entire organization’s data. CISA’s #StopRansomware Guide (September 2023) warns that many ransomware variants try to find and delete or encrypt accessible backups, and says to test backups regularly. Underwriters ask whether backups are separated from the main network, whether MFA protects the backup console and how often you test a restore.

4. Patching and end-of-life systems

The Indiana question set asks whether critical and high-severity patches are applied within 30 days of release and whether end-of-life software is avoided or segmented. Marsh reported in May 2024 that insurers had focused on patch management over the prior year. CISA’s goals call for patching known exploited vulnerabilities in internet-facing systems, which you can track against the CISA Known Exploited Vulnerabilities catalog.

5. Email security and payment verification

Given business email compromise losses, expect questions about email filtering, tagging external messages, web filtering and how you verify changes to vendor bank details. The FTC recommends SPF, DKIM and DMARC so criminals cannot easily send mail that appears to come from your domain. A call-back rule for payment changes, using a number already on file, is a simple, effective control.

6. Privileged access management

Marsh notes that insurers consistently scrutinize privileged account management, because compromised admin accounts make major harm much more likely. Questions cover separate admin accounts, MFA on every admin login, limits on who holds domain admin rights and how service accounts are controlled.

7. Incident response and recovery plans

Applications commonly ask for a written incident response plan, a data breach response plan and a disaster recovery plan tested at least annually. NIST SP 800-61 Rev. 3 (April 2025) ties incident response to the NIST Cybersecurity Framework 2.0. A plan should name who calls the insurer, who preserves evidence and who can authorize containment.

8. Security awareness training and phishing simulations

Underwriters usually ask whether staff receive regular training on social engineering and whether you run phishing simulations. Keep completion records and simulation results.

Not sure where you stand? Request a cyber insurance readiness review online and our team will check your controls against a typical application before you sign it. You can also book a consultation online to walk through your renewal form with an analyst.

Why misrepresenting controls can jeopardize coverage

Most applications end with a signed statement that the answers are true and complete and that the insurer may rely on them. The Travelers MFA form, for example, states that the answers may be relied upon as the basis for providing insurance and asks the applicant to report material changes.

Travelers v. International Control Services shows what can follow. In July 2022, Travelers asked a federal court in Illinois to rescind a policy, alleging the insured had stated it used MFA for administrative access but only protected its firewall with MFA. The insured had suffered a ransomware attack. According to Lockton, judgment was entered for Travelers on August 26, 2022, after the insured agreed to a judgment rescinding the policy.

Rescission treats the policy as if it never existed. Short of that, an inaccurate answer can lead to a disputed claim or nonrenewal, depending on policy language and state law.

The fix is simple in principle. Answer each question based on what is enforced today, across every system the question covers. If a control is partial, say so and give the remediation date.

How to prepare for a cyber insurance application or renewal

Treat the application as a small audit, whether it is a first policy or a renewal.

  1. Get the actual forms early. Ask your broker for the full application and every supplemental questionnaire at least a quarter before renewal.
  2. Assign an owner for each answer. The person who signs should not guess. Pair the signer with whoever runs IT or security, as the Travelers form expects.
  3. Verify, do not assume. Pull MFA enrollment reports, EDR device counts, patch compliance reports and backup job histories.
  4. Test a restore. Restore a real system or data set from your offline or immutable copy and record how long it took.
  5. Fix quick gaps first. MFA on admin, backup and remote access accounts is often fast to close and heavily weighted.
  6. Document everything. Save screenshots, configuration exports, policies, training logs and test results in one folder dated to the application.
  7. Review the draft with your broker. Disclose partial controls with dates. Read the notice and panel vendor terms.
  8. Keep it current. If a control changes mid-term, ask your broker whether the insurer must be told.

For a quick baseline, try our free ransomware readiness scorecard, which covers many of the same controls.

Cyber insurance requirements readiness checklist

Use this table to check each common question against the evidence an underwriter or claims adjuster may ask for. Your carrier’s form controls.

ControlWhat underwriters commonly askEvidence to keepCommon gap
MFAEmail, remote access (incl. vendors), admin access to directory, backups, network devices, serversMFA enrollment and conditional access reports; list of excluded accountsService accounts, legacy protocols or vendor VPN logins without MFA
EDR and monitoringEDR on all endpoints and servers; 24×7 monitoringDevice count vs. asset inventory; SOC contract or on-call rosterServers or Macs left off; alerts emailed but not worked overnight
BackupsOffline or immutable copies; MFA on backup console; restore testingBackup architecture diagram; dated restore test resultsBackups reachable with domain admin credentials; no recent restore test
PatchingCritical and high patches within a set window; end-of-life systemsPatch compliance reports; KEV tracking; EOL list with segmentationInternet-facing devices and firewalls patched late
Email securityFiltering, external tags, SPF/DKIM/DMARC, payment verificationDMARC record and reports; written call-back procedureDMARC left at monitor-only; payment changes approved by email
Privileged accessSeparate admin accounts; limited domain admins; PAMAdmin group membership export; access review sign-offDaily-use accounts with admin rights
IR and DR plansWritten IR, breach and DR plans; annual testingPlans with dates; tabletop exercise notes; insurer notice contactsPlan never exercised; insurer hotline not listed
TrainingRegular awareness training; phishing simulationsCompletion records; simulation resultsNew hires not enrolled; no simulations

What affects cyber insurance cost and terms

We do not quote premiums, because they vary widely by carrier, limit and year. GAO identified company size, industry and the strength of cyber controls as factors in pricing. Limits, deductible, claims history and the sensitive data you hold also matter.

Coverage terms change too. GAO’s 2022 report noted insurers excluding coverage for losses from cyber warfare and infrastructure outages to limit systemic risk. Read exclusions, sublimits for ransomware or funds transfer fraud, and any waiting period for business interruption.

After a loss, the claim depends on evidence. Our guide to the forensic evidence insurers need for cyber insurance claims explains what adjusters typically request and how to preserve it.

How Honeybadger helps you meet cyber insurance requirements

Honeybadger Solutions is a veteran-owned SDVOSB that delivers cyber, vCISO and forensic services nationwide. For cyber insurance requirements, we help you answer accurately and back each answer with evidence.

  • Control verification. Our vCISO service reviews renewal questionnaires and attestations on MFA, backup immutability, endpoint detection and privileged access, then builds a prioritized plan for gaps.
  • Monitoring that answers the 24×7 question. Threat mitigation and SOC monitoring provides hardening plus around-the-clock detection, triage and escalation on a path agreed in writing.
  • Backups you can prove. Managed backup and disaster recovery uses immutable and air-gapped copies and scheduled restore tests with documented results you can show an insurer.
  • Incident support. If something happens, we help contain it and build the documented timeline counsel and insurers ask for.

We do not make coverage decisions; your insurer does. Our role is to make sure your answers are accurate and supported. Submit a service request online to start a readiness review, or book a consultation online to talk through your renewal timeline.

Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.

Frequently asked questions

What are the most common cyber insurance requirements for small businesses?

Questions vary by carrier, but most cover MFA, endpoint detection and response, tested offline or immutable backups, patching, email security, privileged access, a written incident response plan and security awareness training.

Can an insurer deny a claim or rescind a policy if my application answers were wrong?

It can happen. Application answers are typically signed representations the insurer relies on. In Travelers v. International Control Services, a 2022 federal case, the policy was rescinded by stipulated judgment after the insurer alleged MFA was misrepresented. Ask your broker and counsel how your policy and state law treat misstatements.

Is MFA on email enough to satisfy an underwriter?

Usually not. Forms such as the Travelers MFA attestation ask separately about web email, all remote network access including vendors, and administrative access to directory services, backups, network devices and servers. Answer each line based on what is actually enforced today.

Do I need a 24/7 SOC to get cyber insurance?

Not always, but some underwriting question sets ask whether endpoint detection tools and logs are monitored around the clock. If no one watches alerts overnight, say so accurately. A managed SOC is one way to close that gap and document it.

When should I start preparing for a cyber insurance renewal?

Ideally a full quarter ahead. That leaves time to verify each control, collect evidence, fix gaps such as missing MFA on admin or backup accounts, and review the draft with your broker before anyone signs.

Does cyber insurance replace an incident response provider?

No. A policy helps pay for covered losses, and many require prompt notice and may require insurer-approved vendors. You still need a tested plan, people who can act fast and evidence that supports the claim.

Sources and further reading

Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.

Browse by topic

Security guard services  ·  Private investigations  ·  Cybersecurity  ·  Digital forensics  ·  Financial fraud investigation  ·  Executive protection  ·  All articles