What Cyber Insurers Actually Look for Before Writing a Policy
Why cyber insurance applications get rejected, the 5 core controls underwriters verify, and how SMEs can qualify for better rates.
- Cyber insurance is no longer a rubber-stamp purchase; underwriters now scrutinize actual technical controls.
- Multi-Factor Authentication (MFA) on email and remote access is an absolute prerequisite for coverage.
- Immutable, air-gapped backups are required to protect against ransomware claim exclusions.
- Demonstrating baseline hygiene directly lowers policy premiums and deductible limits.
Five years ago, getting a business cyber insurance policy often meant answering a half-dozen check-the-box questions and paying a modest annual premium.
Those days are gone.
Following waves of catastrophic ransomware payouts and supply chain breaches, insurers and underwriting syndicates (MGAs) have tightened their criteria drastically. Today, insurers evaluate your business using rigorous risk assessments. If your fundamentals are missing, applications are rejected, coverage is restricted, or premiums could jump by double-digit percentages.
Understanding how underwriters think helps you fix the right gaps before you submit an application.
The 5 Non-Negotiable Controls Underwriters Look For
While questionnaire formats vary across providers (such as Allianz, Hiscox, Chubb, or Beazley), underwriters consistently examine five foundational control areas:
1. Universal Multi-Factor Authentication (MFA)
This is the single most common reason applications get denied. Insurers want to see MFA enforced on: - All business email accounts (Microsoft 365, Google Workspace). - Every remote access tool (VPNs, RDP connections, remote desktop software). - Administrative and cloud management consoles.If an attacker can compromise a single user password and log in without a second factor, underwriters consider the risk unacceptable.
2. Isolated, Air-Gapped Backups
When ransomware hits, insurers want assurance you can restore operations without paying a ransom. They will ask: - Are backups created on an automated schedule? - Is at least one complete copy stored offline, immutable, or completely isolated from the main network? - Has your team tested a full data restoration within the last 12 months?If your backups are connected directly to the primary network, ransomware can encrypt both your live data and your backups simultaneously.
3. Endpoint Detection & Response (EDR)
Standard signature-based antivirus software from ten years ago is no longer considered adequate defense against modern malware. Insurers expect modern endpoint protection (like Microsoft Defender for Business, CrowdStrike, or SentinelOne) deployed on every workstation, laptop, and server—especially devices used by remote workers.4. Enforced Patch Management Windows
Underwriters know that attackers scan for public vulnerabilities (CVEs) within hours of disclosure. They look for written policies or automated tooling ensuring critical and high-severity operating system and software patches are deployed within a clear window (typically 14 to 30 days).5. Basic Incident Response Preparedness
If a breach occurs at 2:00 AM on a Saturday, who gets called? Underwriters look for a simple, documented incident response plan that includes: - Named internal and external IT contacts. - Designated legal and PR notification channels. - Your insurer’s emergency incident hotline number.Why Preparing Early Saves Money
Businesses that approach cyber insurance reactively often end up in a stressful rush trying to implement complex tools while renewals loom.
Taking proactive steps delivers tangible business benefits: - Avoiding Policy Exclusions: Insurers frequently attach strict warranties; if an un-MFA'd account causes a breach, coverage may be disputed. - Lower Deductibles: Demonstrating solid hygiene gives brokers leverage to negotiate lower self-insured retention limits. - Faster Approval: Transparent documentation speeds underwriting and prevents last-minute coverage gaps.