
Cyber insurance requirements have moved from a one-page form to a detailed security questionnaire. Carriers now ask small and mid-size businesses specific questions about multi-factor authentication, endpoint detection, backups, patching and incident planning before they quote, and again at every renewal. The answers you sign become part of the contract.
This guide explains the controls underwriters commonly ask about, why an optimistic answer can put a claim at risk, and how to prepare an accurate application. If you want help verifying controls and producing evidence, our managed cyber security and MSSP services are built to show insurers and auditors that the controls are real.
This article is general information, not legal advice. Policy wording and state law vary, so confirm specifics with your broker and counsel.
Key takeaways
- There is no single national standard. Each carrier sets its own cyber insurance requirements, but the core list is consistent: MFA, EDR, tested offline or immutable backups, patching, email security, privileged access, an IR plan and training.
- Underwriters often ask about MFA in detail: email, remote access, and administrative access to directory services, backups, network gear and servers.
- Application answers are representations the insurer relies on. A 2022 federal case ended with a policy rescinded after the carrier alleged MFA was misrepresented.
- Answer what is enforced today, not what is planned. Disclose gaps and the date they will be closed.
- Keep evidence for every answer: screenshots, policy exports, restore test results and training records.
Where this guidance comes from. We drew on the FBI Internet Crime Complaint Center 2025 annual report, CISA’s #StopRansomware Guide and Cross-Sector Cybersecurity Performance Goals, the NAIC’s report on the cybersecurity insurance market (2024 data), two GAO reports on cyber insurance, NIST SP 800-61 Rev. 3, FTC small business guidance, the State of Indiana’s published list of underwriting control questions, a publicly posted Travelers MFA attestation form and broker analysis from Marsh and Lockton. We added what our security and forensics team sees when helping organizations answer security questionnaires and respond to incidents.
What cyber insurance requirements actually mean
When people say cyber insurance requirements, they usually mean three different things. First, the application questions an underwriter uses to decide whether to offer coverage and at what price. Second, supplemental forms or attestations, such as a separate MFA or ransomware questionnaire. Third, conditions written into the policy itself, such as how quickly you must report an incident.
Requirements differ by carrier, industry, revenue and the limits you buy, and they change from year to year. As of October 2026, the same security topics repeat across carriers because they track how losses actually happen.
The FTC’s small business guidance splits a typical policy into first-party coverage for your own costs, such as forensics, notification and business interruption, and third-party coverage for claims others bring against you. Security controls shape both.
Why underwriters ask more security questions now
A 2021 GAO report cited broker data showing that the share of clients buying cyber coverage rose from 26 percent in 2016 to 47 percent in 2020. It also reported that more than half of brokers surveyed saw clients’ prices rise 10 to 30 percent in late 2020, and that underwriters were more carefully scrutinizing risks from all entities, regardless of size or sector.
The market is now large. The NAIC’s report on the cybersecurity insurance market puts 2024 U.S. cyber direct written premiums at about $9.14 billion, down 7 percent from 2023, across roughly 4.37 million policies. Reported claims rose to nearly 50,000.
Losses explain the scrutiny. The FBI’s 2025 Internet Crime Report counted more than 1 million complaints and $20.877 billion in reported losses. Business email compromise alone accounted for 24,768 complaints and more than $3.04 billion in losses. Ransomware complaints totaled 3,611, and the FBI notes that reported ransomware losses usually exclude lost business, time and remediation costs, so the real figure is higher.
The security controls underwriters commonly ask about
This list reflects Indiana’s published underwriting questions, FBI and CISA guidance and broker research.
1. Multi-factor authentication (MFA)
MFA is the question most likely to be asked in detail. A publicly posted Travelers MFA form asks whether MFA is required for all employees using web or cloud email, for all remote network access by employees, contractors and third-party providers, and for administrative access to directory services, network backup environments, network infrastructure and endpoints or servers. It also asks that the signer complete the form with the person in charge of IT security.
CISA recommends phishing-resistant MFA, such as FIDO/WebAuthn security keys or PKI-based methods, where possible. Our identity and access security service covers phishing-resistant MFA, conditional access and privileged access.
2. Endpoint detection and response (EDR)
Underwriters commonly ask whether EDR runs on all endpoints and servers, not just antivirus. The Indiana question set also asks whether a SIEM is monitored 24×7 by a security operations center. The FBI’s 2025 report notes that EDR tools are particularly useful for spotting lateral movement during a ransomware attack.
3. Offline, immutable and tested backups
The FBI recommends off-site or offline backups that are encrypted, immutable and cover the entire organization’s data. CISA’s #StopRansomware Guide (September 2023) warns that many ransomware variants try to find and delete or encrypt accessible backups, and says to test backups regularly. Underwriters ask whether backups are separated from the main network, whether MFA protects the backup console and how often you test a restore.
4. Patching and end-of-life systems
The Indiana question set asks whether critical and high-severity patches are applied within 30 days of release and whether end-of-life software is avoided or segmented. Marsh reported in May 2024 that insurers had focused on patch management over the prior year. CISA’s goals call for patching known exploited vulnerabilities in internet-facing systems, which you can track against the CISA Known Exploited Vulnerabilities catalog.
5. Email security and payment verification
Given business email compromise losses, expect questions about email filtering, tagging external messages, web filtering and how you verify changes to vendor bank details. The FTC recommends SPF, DKIM and DMARC so criminals cannot easily send mail that appears to come from your domain. A call-back rule for payment changes, using a number already on file, is a simple, effective control.
6. Privileged access management
Marsh notes that insurers consistently scrutinize privileged account management, because compromised admin accounts make major harm much more likely. Questions cover separate admin accounts, MFA on every admin login, limits on who holds domain admin rights and how service accounts are controlled.
7. Incident response and recovery plans
Applications commonly ask for a written incident response plan, a data breach response plan and a disaster recovery plan tested at least annually. NIST SP 800-61 Rev. 3 (April 2025) ties incident response to the NIST Cybersecurity Framework 2.0. A plan should name who calls the insurer, who preserves evidence and who can authorize containment.
8. Security awareness training and phishing simulations
Underwriters usually ask whether staff receive regular training on social engineering and whether you run phishing simulations. Keep completion records and simulation results.
Not sure where you stand? Request a cyber insurance readiness review online and our team will check your controls against a typical application before you sign it. You can also book a consultation online to walk through your renewal form with an analyst.
Why misrepresenting controls can jeopardize coverage
Most applications end with a signed statement that the answers are true and complete and that the insurer may rely on them. The Travelers MFA form, for example, states that the answers may be relied upon as the basis for providing insurance and asks the applicant to report material changes.
Travelers v. International Control Services shows what can follow. In July 2022, Travelers asked a federal court in Illinois to rescind a policy, alleging the insured had stated it used MFA for administrative access but only protected its firewall with MFA. The insured had suffered a ransomware attack. According to Lockton, judgment was entered for Travelers on August 26, 2022, after the insured agreed to a judgment rescinding the policy.
Rescission treats the policy as if it never existed. Short of that, an inaccurate answer can lead to a disputed claim or nonrenewal, depending on policy language and state law.
The fix is simple in principle. Answer each question based on what is enforced today, across every system the question covers. If a control is partial, say so and give the remediation date.
How to prepare for a cyber insurance application or renewal
Treat the application as a small audit, whether it is a first policy or a renewal.
- Get the actual forms early. Ask your broker for the full application and every supplemental questionnaire at least a quarter before renewal.
- Assign an owner for each answer. The person who signs should not guess. Pair the signer with whoever runs IT or security, as the Travelers form expects.
- Verify, do not assume. Pull MFA enrollment reports, EDR device counts, patch compliance reports and backup job histories.
- Test a restore. Restore a real system or data set from your offline or immutable copy and record how long it took.
- Fix quick gaps first. MFA on admin, backup and remote access accounts is often fast to close and heavily weighted.
- Document everything. Save screenshots, configuration exports, policies, training logs and test results in one folder dated to the application.
- Review the draft with your broker. Disclose partial controls with dates. Read the notice and panel vendor terms.
- Keep it current. If a control changes mid-term, ask your broker whether the insurer must be told.
For a quick baseline, try our free ransomware readiness scorecard, which covers many of the same controls.
Cyber insurance requirements readiness checklist
Use this table to check each common question against the evidence an underwriter or claims adjuster may ask for. Your carrier’s form controls.
| Control | What underwriters commonly ask | Evidence to keep | Common gap |
|---|---|---|---|
| MFA | Email, remote access (incl. vendors), admin access to directory, backups, network devices, servers | MFA enrollment and conditional access reports; list of excluded accounts | Service accounts, legacy protocols or vendor VPN logins without MFA |
| EDR and monitoring | EDR on all endpoints and servers; 24×7 monitoring | Device count vs. asset inventory; SOC contract or on-call roster | Servers or Macs left off; alerts emailed but not worked overnight |
| Backups | Offline or immutable copies; MFA on backup console; restore testing | Backup architecture diagram; dated restore test results | Backups reachable with domain admin credentials; no recent restore test |
| Patching | Critical and high patches within a set window; end-of-life systems | Patch compliance reports; KEV tracking; EOL list with segmentation | Internet-facing devices and firewalls patched late |
| Email security | Filtering, external tags, SPF/DKIM/DMARC, payment verification | DMARC record and reports; written call-back procedure | DMARC left at monitor-only; payment changes approved by email |
| Privileged access | Separate admin accounts; limited domain admins; PAM | Admin group membership export; access review sign-off | Daily-use accounts with admin rights |
| IR and DR plans | Written IR, breach and DR plans; annual testing | Plans with dates; tabletop exercise notes; insurer notice contacts | Plan never exercised; insurer hotline not listed |
| Training | Regular awareness training; phishing simulations | Completion records; simulation results | New hires not enrolled; no simulations |
What affects cyber insurance cost and terms
We do not quote premiums, because they vary widely by carrier, limit and year. GAO identified company size, industry and the strength of cyber controls as factors in pricing. Limits, deductible, claims history and the sensitive data you hold also matter.
Coverage terms change too. GAO’s 2022 report noted insurers excluding coverage for losses from cyber warfare and infrastructure outages to limit systemic risk. Read exclusions, sublimits for ransomware or funds transfer fraud, and any waiting period for business interruption.
After a loss, the claim depends on evidence. Our guide to the forensic evidence insurers need for cyber insurance claims explains what adjusters typically request and how to preserve it.
How Honeybadger helps you meet cyber insurance requirements
Honeybadger Solutions is a veteran-owned SDVOSB that delivers cyber, vCISO and forensic services nationwide. For cyber insurance requirements, we help you answer accurately and back each answer with evidence.
- Control verification. Our vCISO service reviews renewal questionnaires and attestations on MFA, backup immutability, endpoint detection and privileged access, then builds a prioritized plan for gaps.
- Monitoring that answers the 24×7 question. Threat mitigation and SOC monitoring provides hardening plus around-the-clock detection, triage and escalation on a path agreed in writing.
- Backups you can prove. Managed backup and disaster recovery uses immutable and air-gapped copies and scheduled restore tests with documented results you can show an insurer.
- Incident support. If something happens, we help contain it and build the documented timeline counsel and insurers ask for.
We do not make coverage decisions; your insurer does. Our role is to make sure your answers are accurate and supported. Submit a service request online to start a readiness review, or book a consultation online to talk through your renewal timeline.
Why the online intake is faster than a phone call: it takes about two minutes, and your answers are routed straight to the specialist team that handles your kind of matter, whether that is cyber and forensics, investigations or field security. That team sees the full picture before it replies, so you skip phone tag and get a real answer and next steps sooner. If it cannot wait for business hours, use the urgent intake form, which is read seven days a week.
Frequently asked questions
What are the most common cyber insurance requirements for small businesses?
Questions vary by carrier, but most cover MFA, endpoint detection and response, tested offline or immutable backups, patching, email security, privileged access, a written incident response plan and security awareness training.
Can an insurer deny a claim or rescind a policy if my application answers were wrong?
It can happen. Application answers are typically signed representations the insurer relies on. In Travelers v. International Control Services, a 2022 federal case, the policy was rescinded by stipulated judgment after the insurer alleged MFA was misrepresented. Ask your broker and counsel how your policy and state law treat misstatements.
Is MFA on email enough to satisfy an underwriter?
Usually not. Forms such as the Travelers MFA attestation ask separately about web email, all remote network access including vendors, and administrative access to directory services, backups, network devices and servers. Answer each line based on what is actually enforced today.
Do I need a 24/7 SOC to get cyber insurance?
Not always, but some underwriting question sets ask whether endpoint detection tools and logs are monitored around the clock. If no one watches alerts overnight, say so accurately. A managed SOC is one way to close that gap and document it.
When should I start preparing for a cyber insurance renewal?
Ideally a full quarter ahead. That leaves time to verify each control, collect evidence, fix gaps such as missing MFA on admin or backup accounts, and review the draft with your broker before anyone signs.
Does cyber insurance replace an incident response provider?
No. A policy helps pay for covered losses, and many require prompt notice and may require insurer-approved vendors. You still need a tested plan, people who can act fast and evidence that supports the claim.
Sources and further reading
- FBI IC3, 2025 Internet Crime Report — complaint and loss totals, BEC and ransomware figures, FBI ransomware mitigations.
- CISA, #StopRansomware Guide (September 2023) — offline, encrypted and immutable backups, phishing-resistant MFA, IR planning.
- CISA, Cross-Sector Cybersecurity Performance Goals — phishing-resistant MFA, KEV patching and IR plan goals.
- NAIC, Report on the Cybersecurity Insurance Market (2024 data) — U.S. premium, policy and claim counts.
- GAO-21-477, Cyber Insurance: Insurers and Policyholders Face Challenges in an Evolving Market (2021) — take-up rates, price increases and underwriting scrutiny.
- GAO-22-104256, Cyber Insurance: Action Needed to Assess Potential Federal Response to Catastrophic Attacks (2022) — exclusions for cyber warfare and infrastructure outages.
- Indiana Cybersecurity Hub, Underwriting Security Controls Questions — state-published list of common underwriting control questions.
- Travelers, Cyber MFA attestation form (CYB-14306) — example of detailed MFA questions and reliance language.
- Lockton, Travelers v. ICS underscores need to respond carefully (2022) — case outcome and advice on accurate answers.
- Carrier Management, Travelers seeks rescission over MFA (2022) — allegations in the Travelers v. ICS filing.
- Marsh, CISO’s guide to cyber risk: make cyber more insurable (2024) — insurer focus on patching, PAM, EPP and EDR.
- NIST SP 800-61 Rev. 3 (April 2025) — incident response recommendations aligned to CSF 2.0.
- FTC, Cybersecurity for Small Business: Cyber Insurance — first-party and third-party coverage basics.
- FTC, Cybersecurity for small business: Email authentication — SPF, DKIM and DMARC.
Written and reviewed by the Honeybadger Solutions security and investigations team, a veteran-led Arizona firm (Arizona DPS private investigation agency license No. 1759795). Facts checked against the cited sources on October 2, 2026. This article is general information, not legal advice.
Browse by topic
Security guard services  · Private investigations  · Cybersecurity  · Digital forensics  · Financial fraud investigation  · Executive protection  · All articles