Cyber Insurance Requirements: The Checklist Insurers Actually Ask For

If your cyber insurance renewal just landed with a supplemental questionnaire attached, you have probably noticed it looks nothing like the one-page form you signed a few years ago. Now there are pages of yes or no questions about MFA, endpoint detection, backup testing, and employee training, and somewhere near the signature line, a note that your answers are material to the policy.

The change was not random. Insurers spent years paying ransomware claims that dwarfed the premiums coming in, and they responded the way insurers always do. They raised prices, shrank coverage, and started demanding proof that you are a reasonable risk. The application is now a security audit in disguise, and getting it right matters twice: once for your premium, and again on the day you file a claim.

Here is the checklist that shows up on nearly every application, what a no answer actually costs, how to close each gap without a big budget, and why the same work counts toward HIPAA or SOC 2 readiness if that is anywhere in your future.

Why cyber insurance applications got strict

A few years ago, cyber coverage was cheap and the application took ten minutes. Then ransomware turned into an industry. Carriers paid out enormous claims for ransom negotiations, downtime, forensics, and lawsuits, and for a stretch many of them were losing money on cyber policies altogether.

The correction came fast. Premiums jumped, ransomware payouts got capped with sublimits, and underwriters started requiring specific controls instead of taking your word for it. Many carriers now scan your public internet footprint before quoting, so an exposed remote desktop port can raise your price before a human ever reads your application. The questionnaire stopped being paperwork and became the underwriting itself.

The checklist that shows up on almost every application

Every carrier words it differently, but the same handful of controls appears on nearly every small business application. If you can honestly answer yes to these seven, you are in good shape with most underwriters:

Notice what is not on the list: expensive consultants, a full-time security hire, or enterprise tooling. Every item here is achievable for a ten-person company.

  • MFA on email, remote access (VPN and remote desktop), and every admin account
  • EDR on servers and workstations, not just traditional antivirus
  • Backups that are encrypted, tested regularly, and kept separate from your network (offline or immutable)
  • A defined patching cadence, with critical fixes applied quickly
  • Recurring security awareness training for everyone, often with phishing simulations
  • A written incident response plan that names who does what
  • A documented offboarding process that cuts access on an employee’s last day

What a no answer actually costs you

A no does not always mean a denial. Sometimes it means a higher premium, a bigger deductible, or a lower limit on ransomware coverage. But some controls have become deal breakers, and plenty of carriers will simply not quote a business without MFA on email and remote access.

The bigger danger is answering yes when the honest answer is mostly. Your application becomes part of the insurance contract, and carriers investigate after a breach. At least one insurer has gone to court to rescind a policy, arguing the customer claimed MFA was in place when it only covered some systems. An honest no costs you money at renewal. An inaccurate yes can void the policy on the worst day of your business life. If you are not sure whether a control is fully deployed, find out before you sign.

Close the identity gaps first: MFA and EDR

Start with MFA because it is the control carriers weigh most heavily. If you run Microsoft 365, turn on security defaults (or Conditional Access policies if you have Business Premium) and roll out the Microsoft Authenticator app to everyone. Then cover the spots people forget: VPN logins, remote desktop, your firewall’s admin page, and the backup console. A password manager such as 1Password or Bitwarden closes the related question about how credentials are stored.

EDR means replacing traditional antivirus with software that watches for attacker behavior and can isolate an infected machine on its own. Microsoft Defender for Business (included with Microsoft 365 Business Premium), CrowdStrike, and SentinelOne are the names underwriters recognize. Small teams usually pair the tool with a monitoring service or an IT partner, because an alert nobody reads at 2 a.m. does not stop anything.

Backups and patching that hold up under questioning

The backup question usually has three parts: do you back up, is at least one copy separated from your network, and when did you last test a restore. The separation part matters because ransomware crews hunt down backups before they encrypt anything else, so a copy sitting on a network share does not count. Use immutable cloud storage or media that is physically disconnected, and remember that Microsoft 365 and Google Workspace are not backups by themselves; add a dedicated backup for email and files.

Then test a restore on a schedule and write down the date. Saying we back up daily is a weak answer. Saying we restored a server from backup in April and it took two hours is a strong one. For patching, turn on automatic updates wherever you can and set a defined window for critical fixes, measured in days, not months. Do not forget firewalls, switches, and anything else with a login page.

The paperwork controls: training, response plan, offboarding

Security awareness training does not need to be a production. Short sessions a few times a year plus occasional phishing simulations satisfy most carriers, and the topic earns its slot because phishing emails remain one of the most common ways attackers get in. CISA publishes free awareness materials if you want a starting point, and our free 30-minute remote security awareness session (available in English, Spanish, or Portuguese) is an easy way to check the box for your whole team.

An incident response plan can begin as a single page: who you call first, your carrier’s breach hotline number, who has authority to take systems offline, and how you reach staff if email is down. Print copies, because the plan stored on the encrypted server helps nobody.

Offboarding is the item everyone forgets. Write a checklist: disable the account the same day, revoke active sessions and MFA tokens, rotate any shared passwords, collect the laptop. Former employee accounts with live credentials are a favorite way in, and carriers know it.

The same work counts toward HIPAA and SOC 2

If compliance is anywhere on your horizon, none of this effort is wasted. The HIPAA Security Rule expects access controls, workforce training, contingency planning, and termination procedures. SOC 2 examines the same territory in its own language. The overlap with the insurance checklist is nearly total.

The habit that makes it pay off is keeping evidence: MFA enrollment reports, training attendance, restore test dates, the offboarding checklist with sign-offs. Do that and your insurance readiness folder quietly becomes the first draft of a compliance program, and next year’s renewal takes an afternoon instead of a scramble.

Key Takeaways

  • Cyber insurance applications are now security audits, and your signed answers become part of the contract.
  • MFA on email, remote access, and admin accounts is the single control most likely to make or break your quote.
  • An honest no raises your premium, but an inaccurate yes can get a claim denied after a breach.
  • Backups only count when a copy lives off the network and you can point to a recent, documented test restore.
  • Every control on the insurer’s checklist doubles as groundwork for HIPAA or SOC 2 readiness, so keep the evidence.

Before your renewal lands, take our free 12-question cyber risk assessment at /cyber-risk-assessment/ to see exactly which of these gaps you need to close first.


LogicSystemIQ is an IT managed services and SaaS studio based in Peabody, Massachusetts. We build DaycarePro (daycarepro.cloud), a trilingual SaaS for licensed home daycare providers. Reach us at (978) 815-1047 or Support@LogicSystemiq.com.

Scroll to Top