Cyber insurance requirements: the controls underwriters expect
Cyber underwriting changed after the ransomware losses of the early 2020s. A set of security controls that were once discounts are now, in many markets, conditions of getting terms at all. Knowing which ones before you apply is the difference between a competitive quote and a declination.
Why this became an underwriting gate
Insurers found that a small number of controls correlated strongly with whether an intrusion turned into a total loss. Multi-factor authentication stops most credential-based entry. A tested offline backup means a business can refuse a ransom demand and restore instead. Endpoint detection shortens the time an attacker sits inside the network before anyone notices.
Because those controls change the size of the loss and not just the odds of one, underwriters treat them as structural rather than cosmetic.
The controls most commonly required
| Control | Why underwriters ask | What good evidence looks like |
|---|---|---|
| Multi-factor authentication | Removes the most common route in, which is a valid stolen credential. | Enforced on email, remote access and administrative accounts, not just offered. |
| Tested offline backups | Determines whether a ransom demand can be refused. | Backups separated from the production network, with a documented restore test, not just a backup job that reports success. |
| Endpoint detection and response | Shortens attacker dwell time inside the network. | Deployed across endpoints and servers with someone actually monitoring alerts. |
| Email filtering and user training | Most incidents still begin with a message someone acted on. | Filtering in place plus a training cadence you can describe and evidence. |
| Privileged access management | Limits how far an intrusion spreads once inside. | Administrative rights separated from daily-use accounts. |
| Patching cadence | Unpatched internet-facing systems are actively scanned for. | A stated timeframe for critical patches and a record of meeting it. |
How to prepare an application that gets good terms
The application is an underwriting document and a representation. Two things follow from that.
First, accuracy matters more than optimism. A control described as fully deployed when it covers part of the estate can become an issue at claim time, and it is one of the more common sources of dispute.
Second, partial deployment is worth explaining rather than rounding up. An underwriter reading that multi-factor authentication covers email and remote access today with servers scheduled next quarter can price that. An underwriter who later discovers it was aspirational is in a different conversation.
If a control is not fully in place, say so and say what the plan is. Underwriters price known gaps. They react badly to discovered ones.
If you cannot meet a requirement yet
Options usually exist. A higher retention, a ransomware sublimit, a shorter policy period, or a market with different appetite can all keep coverage in place while the control is deployed. The worst outcome is going unquoted because the submission was incomplete rather than because the risk was unacceptable.
What cyber insurance costs explains how these controls flow through to premium, and the cyber liability glossary defines the terms an application uses.
Have someone read the policy with you
If you are heading into a cyber renewal and are not sure how your controls will read to an underwriter, it is worth reviewing the submission before it goes to market. 4J prepares and reviews cyber submissions for Texas businesses.
Talk to a broker or call (469) 756-8776.
Educational content prepared from policy forms, carrier materials and regulatory sources. It is not a binder, a policy interpretation, or a guarantee of coverage. Coverage, availability and pricing depend on underwriting and the terms of the policy actually issued.
Common questions
Is multi-factor authentication mandatory for cyber insurance?
It is not a legal requirement, but many markets now treat it as a condition of offering terms rather than a discount, particularly on email and remote access. Absence of it commonly results in restricted terms or a declination.
What happens if we say a control is in place and it is not?
The application is a representation relied on in underwriting. A material inaccuracy can affect the claim and, depending on the facts and the policy language, the policy itself. Accuracy is the safer position.
Do underwriters verify the controls we describe?
Practices vary. Some carriers scan externally facing systems, some ask for evidence at bind, and some rely on the application until a claim occurs. Assume it will be examined when it matters most.
We are a small business. Do the same requirements apply?
Broadly yes, though expectations scale. Smaller businesses are often asked about the same core controls, because attackers select on opportunity rather than size.
Can we get cyber insurance without endpoint detection?
Often yes, but it may come with a higher retention, a ransomware sublimit or a reduced limit. Appetite varies meaningfully between carriers.
.png?width=500&height=136&name=4J%20commercial%20insurance%20broker%5B1%5D%20(1).png)