To get approved for cyber insurance today, you need more than a willingness to pay premiums. Insurers now require proof of active security controls, not just policies on paper. The 9 must-have controls are: Multi-Factor Authentication (MFA), Endpoint Detection and Response (EDR), Encrypted & Tested Backups, Incident Response Plan, Privileged Access Management (PAM), Email Security (with DMARC/DKIM/SPF), Security Awareness Training, Patch Management, and Network Segmentation. Miss even one of these and your application may be denied or your claim rejected after a breach.
Why Cyber Insurance Requirements Have Gotten So Tough
A few years ago, getting a cyber insurance policy was relatively easy. You filled out a short questionnaire, checked a few boxes, and coverage was approved. That era is over.
Insurers have paid out billions in ransomware claims, data breach settlements, and business interruption losses. They responded by raising the bar significantly. Today, underwriters don’t just ask what security tools you have. They ask for screenshots, configuration reports, enrollment logs, and dated proof that your controls actually work.
The stakes are real. One mid-market manufacturer suffered a ransomware attack and filed a $2.3 million claim, which was denied because a single VPN account lacked MFA. The insured attested in the application that MFA was enforced for all remote access. One missed account was enough to void the claim.
This is the new reality of cyber insurance. And if you’re applying for coverage or heading into renewal, you need to know exactly what insurers expect.
What Is Cyber Insurance and Who Needs It?
Cyber insurance (also called cybersecurity insurance or cyber liability insurance) is a policy that helps organizations recover financially from cyberattacks, data breaches, ransomware, and other digital threats. It typically covers costs like:
- Forensic investigation and incident response
- Legal fees and regulatory fines
- Data breach notification and credit monitoring
- Business interruption losses
- Ransom payments (in some policies)
- Third-party liability from affected customers
Who needs it?
Any business that stores customer data, relies on digital systems, or operates in a regulated industry. Healthcare, finance, retail, and legal firms face the strictest scrutiny, but small businesses are targeted just as often as large enterprises.
Read more: 12 Essential SOC Tools for Threat Detection
The 9 Must-Have Cyber Insurance Security Controls

1. Multi-Factor Authentication (MFA)
Multi-factor authentication (MFA) is one of the most critical requirements in modern cybersecurity and is also a major factor in cyber insurance approvals and claims. In many cases, the absence of properly enforced MFA is the primary reason insurance applications are denied or claims are rejected. Insurers now expect MFA to be enabled across all critical access points, including email accounts such as Microsoft 365 and Google Workspace, VPN and remote desktop access, cloud admin consoles, SaaS platforms, and all privileged or administrative accounts.
Traditional SMS-based MFA is increasingly considered insufficient because of risks such as SIM-swapping attacks. As a result, insurers and security professionals now prefer stronger authentication methods, including number-matching authenticator apps and hardware security keys, especially for users with elevated privileges.
2. Endpoint Detection and Response (EDR)
Traditional antivirus software is no longer considered sufficient for modern cybersecurity protection. Insurance providers now commonly require Endpoint Detection and Response (EDR), or the more advanced Managed Detection and Response (MDR), to be deployed on every device connected to a company’s network. Unlike traditional antivirus tools that rely mainly on signature-based detection, EDR uses behavior-based threat analysis, real-time monitoring, and automated isolation of compromised devices to detect and contain attacks more effectively.
Cyber insurance carriers typically expect EDR coverage across all servers, workstations, and laptops, including remote and personal devices used for work purposes. They also look for active response capabilities rather than passive detection alone, and larger organizations are often expected to maintain 24/7 monitoring or work with a managed Security Operations Center (SOC) to ensure continuous threat oversight.
Read more: Cybersecurity Checklist for Gaming Companies
3. Encrypted and Tested Backups
Ransomware attacks have made strong backup practices a non-negotiable requirement for cyber insurance coverage. However, insurers no longer accept just any backup system. They expect backups to be encrypted both in transit and at rest to protect sensitive data from unauthorized access. Backups must also be isolated or immutable, meaning they are stored offsite or in a write-once format that prevents ransomware from encrypting or altering them.
In addition, insurance carriers want proof that backups are regularly tested through restore exercises, typically at least once per year, to confirm that recovery processes actually work during an incident. They also require backup environments to use separate credentials from production systems so that attackers who compromise the main network cannot easily access or destroy backup data.

4. Documented Incident Response Plan (IRP)
Beyond documentation, carriers now require tabletop exercises and annual simulated incident walkthroughs to test whether your team can execute the plan under pressure. A cyber incident is not the time to figure out who does what. Insurers want a written, tested incident response plan in place before a breach occurs. Your IRP should clearly define:
- Who leads the incident response effort?
- Who contacts the insurance carrier (and when)
- Who coordinates with legal counsel?
- Who communicates externally with customers or regulators?
- Escalation paths and out-of-hours contact procedures.
5. Privileged Access Management (PAM)
Privileged Access Management (PAM) is designed to control who can access an organization’s most sensitive systems and under what conditions. Cyber insurers now expect businesses to separate administrative accounts from everyday user accounts, as permanently elevated privileges are considered a major security risk.
Standing admin access, where IT staff remain continuously logged in with high-level permissions, has become a significant red flag in modern underwriting assessments. To meet current security expectations, organizations should provide individual credentials for every privileged user rather than shared admin accounts, implement time-limited or just-in-time access for sensitive systems, and maintain full logging and auditing of privileged activity.
Automated offboarding processes are also essential to ensure that access is revoked immediately upon employees’ departure from the organization. For companies working with Managed Service Providers (MSPs), insurers examine PAM controls even more closely because a compromised MSP account can affect hundreds of connected client environments, making strong credential management and access hygiene critically important.
Read more: Cybersecurity Checklist for IT Support Teams
6. Email Security (with DMARC, DKIM, and SPF)
Beyond the technical protocols, carriers want advanced phishing protection with attachment sandboxing, impersonation defenses, and AI-aware detection for social engineering attacks. Email remains the number one attack vector for phishing, business email compromise (BEC), and credential theft. Basic spam filtering is no longer sufficient. Insurers expect a layered email security approach:
- SPF (Sender Policy Framework): Specifies which mail servers are authorized to send email for your domain
- DKIM (DomainKeys Identified Mail): Adds a cryptographic signature to outgoing emails to prevent spoofing
- DMARC (Domain-based Message Authentication, Reporting, and Conformance): Tells receiving servers what to do with emails that fail SPF or DKIM checks and reports back on abuse

7. Security Awareness Training and Phishing Simulations
The human element remains one of the weakest points in any cybersecurity strategy, which is why insurers place strong emphasis on employee training and awareness. Organizations are expected not only to educate staff about security threats but also to actively test their ability to recognize and respond to them. Common carrier requirements include annual security awareness training for all employees, quarterly phishing simulation campaigns, security onboarding for new hires within the first 30 days, and targeted education on threats such as business email compromise and social engineering.
These practices do more than improve security posture; they can also directly influence cyber insurance premiums. Research from Marsh McLennan indicates that regular security awareness training and phishing simulations are among the controls most strongly associated with a lower likelihood of cyber insurance claims.
8. Patch Management
Unpatched software remains one of the most common and heavily exploited attack vectors in cybersecurity, which is why insurers now require organizations to maintain a structured and consistent patch management program rather than relying on occasional manual updates.
Cyber insurance carriers expect businesses to define clear service-level agreements (SLAs) for patching critical vulnerabilities, often requiring high-severity CVEs to be addressed within 24 to 72 hours. They also expect organizations to have processes in place to identify and replace end-of-life software that no longer receives security updates. In addition, insurers commonly require restrictions on risky features such as Microsoft Office macros, which are frequently used in phishing and malware attacks.
Businesses are also expected to implement mobile device management (MDM) solutions to ensure remote and mobile devices receive timely patches and remain compliant with security policies. Together, these controls help reduce exposure to preventable attacks and demonstrate a mature cybersecurity posture.
9. Network Segmentation
Network segmentation limits how far an attacker can move inside your environment after gaining initial access. Without it, a single compromised device can become a full network takeover. Insurers look for:
- Logical or physical separation of critical systems (finance, HR, customer data) from general user networks
- Firewall configurations with IPS (Intrusion Prevention System) capabilities
- DNS or web filtering at the network edge
- Restrictions on lateral movement between segments
Read more: 12 Essential Steps to Secure Your Remote Workspace
Cyber Insurance Requirements by Business Size
Healthcare, finance, and legal firms face additional requirements tied to their regulatory environments. Insurers evaluate encryption practices, access controls, and data-handling procedures for client information, tailored to each industry’s compliance standards. Not every business faces the same requirements. Here’s how expectations scale by organization size:
| Business Size | Core Requirements | Advanced Requirements |
| Small (1–50 employees) | MFA, EDR, backups, IRP | Email security, training |
| Mid-market (51–500) | All above + PAM, patching | Network segmentation, SIEM |
| Enterprise (500+) | All of the above | 24/7 SOC, penetration testing, vendor risk program |
| Regulated industries | All of the above | Compliance-specific controls (HIPAA, PCI-DSS, SOX) |
Cyber Insurance Requirements by Industry

Healthcare
Healthcare organizations must demonstrate HIPAA-aligned controls, including data encryption, access logging, and a formal breach notification process. Ransomware has devastated healthcare networks in recent years, making backup isolation and incident response planning critical for eligibility.
Finance and Accounting
Financial firms face heightened scrutiny around privileged access management, client data segregation, and transaction fraud prevention. Carriers evaluate controls around wire transfer verification and BEC prevention separately from general cybersecurity.
Legal and Professional Services
Law firms are prime targets due to client confidentiality and the value of legal documents. Carriers assess encryption of client files, access controls, and procedures for responding to data subject requests.
Retail and eCommerce
PCI-DSS compliance is often a prerequisite for retail cyber insurance. Carriers assess cardholder data environments, payment system segmentation, and third-party processor security.
Read more: Cybersecurity Framework
What Happens If You Don’t Meet the Requirements?
There are three possible outcomes when you apply without meeting requirements:
- Application denied. Carriers will decline to issue a policy. You’ll be pushed toward surplus lines markets where premiums can be three times standard rates.
- Coverage with exclusions. You may get a policy, but specific risks (like ransomware) may be excluded entirely, meaning the coverage doesn’t protect you from the most common threat.
- Claim denied after a breach. This is the worst outcome. If you misrepresent your security posture on the application, even unintentionally, the carrier can deny your claim and potentially rescind the policy. A single missed MFA account was enough to void a $2.3M claim.
How to Prove Your Controls to Insurers
Checking a box that said we had MFA enabled used to be enough. In 2025 and beyond, underwriters want evidence. The businesses getting the best terms are the ones that can show their work. Proof, not promises. Here’s what constitutes acceptable proof for each control:
- MFA: Conditional Access policy screenshots, MFA enrollment reports with coverage percentages
- EDR: Agent deployment coverage report, active policy configuration, vendor SLA
- Backups: Backup policy document, offsite configuration, dated restore test results
- IRP: Written plan with version date, tabletop exercise records
- PAM: Privileged account inventory, access log samples, and offboarding procedures
- Email security: DMARC policy enforcement reports, DKIM/SPF DNS records
- Training: Training completion records, phishing simulation reports
- Patching: Vulnerability scan reports, patch SLA documentation
- Segmentation: Network architecture diagram, firewall configuration
How Cyber Insurance Controls Affect Your Premium
There’s a direct financial incentive to meeting these requirements beyond just getting approved. A 75-person company without strong controls may pay $15,000–$25,000 per year for a policy riddled with sublimits and exclusions. The same company with documented security controls may pay $5,000–$10,000 for comprehensive coverage, a savings that often exceeds the cost of implementing those controls. Organizations that cannot demonstrate compliance with baseline controls at renewal are seeing premium increases of 40–100%. Some are losing coverage entirely.
Read more: GRC Cybersecurity
Final Thoughts
Cyber insurance is no longer a simple financial safety net you purchase and forget. It has become a gatekeeper for minimum security standards, and the businesses that treat it seriously will be protected when it counts. The good news is that moving from a weak security posture to one that meets insurer requirements does not require a massive budget overhaul. It requires structure, documentation, and consistent follow-through.
Start with MFA. Add EDR. Test your backups. Write your incident response plan. Document everything. Do that, and you will not only qualify for coverage, but you will be genuinely more resilient against the attacks that make cyber insurance necessary in the first place.
Frequently Asked Questions (FAQs)
What are the most common reasons cyber insurance applications are denied?
Missing or incomplete MFA is the single most common reason. Carriers also deny applications due to a lack of EDR coverage, untested backups, and missing incident response documentation. If you answer ‘no’ to MFA for any access category, expect a denial or significant exclusion.
Does cyber insurance cover ransomware?
Most policies include ransomware coverage, but it is often subject to sublimits and conditions. If your organization lacks the required security controls, especially MFA, EDR, and tested backups, the carrier may exclude ransomware from your policy or deny ransomware-related claims.
How long does the cyber insurance application process take?
For small businesses, the application and approval process typically takes 1–2 weeks. Larger organizations or those in regulated industries may undergo a more intensive underwriting review lasting 4–8 weeks, which may include third-party security assessments.
Can a cyber insurance claim be denied after a breach?
Yes. If the carrier determines that your actual security posture did not match what was disclosed on the application, they can deny the claim entirely and potentially rescind the policy. Accurate documentation of your controls is the most important protection against this outcome.
What is the average cost of cyber insurance for a small business?
Small business cyber insurance premiums typically range from $1,000 to $7,500 annually for $1 million in coverage. The actual cost depends on industry, revenue, data volume, and documented security controls. Businesses with strong, documented security programs qualify for lower premiums.
Do small businesses really need cyber insurance?
Yes. Small businesses are increasingly targeted precisely because attackers know they often have weaker defenses and fewer resources to recover. The average cost of a data breach for a small business far exceeds what most can absorb without insurance.
What is tail coverage in a cyber insurance policy?
Tail coverage (also called extended reporting coverage) extends your reporting period beyond your policy’s expiration. This matters because breaches are sometimes discovered weeks or months after they occur. Without tail coverage, a breach discovered after policy expiration may not be covered.














