What security controls do I need to get cyber insurance?
There is no single cyber insurance standard, and each insurer sets its own application questions. Expect to be asked about controls that CISA treats as baseline: multifactor authentication, endpoint detection and response, offline and tested backups, prompt patching, security awareness training and an exercised incident response plan. GAO has reported that underwriters scrutinize risk more closely and that cyber controls affect premiums.
Why controls now drive coverage
In its 2021 review of the cyber insurance market, GAO reported that underwriters had been scrutinizing the risks posed by all entities more carefully, regardless of size or sector, and that insurers had tightened terms and become more selective. GAO also noted that premium changes depend partly on how strong a company's cyber controls are.
States regulate cyber insurance, and GAO found they generally do not set minimum coverage standards. So the controls you need are defined by your insurer's application and policy wording, not by a public rulebook. Read both before you sign.
Renewal is also a natural checkpoint. Compare this year's application questions with last year's to see where your insurer's attention has moved, and budget for the controls it now asks about.
The controls to have in place
Each item below is something CISA recommends for small and mid-size businesses or ransomware defense. Expect your application to ask how you implement controls like these, and treat your broker's actual questionnaire as the authoritative list.
- Multifactor authentication: CISA calls for phishing-resistant MFA on all services, especially email, VPNs and accounts that reach critical systems.
- Endpoint detection and response or application allowlisting on all assets.
- Backups: offline, encrypted, and tested for availability and integrity in a recovery scenario.
- Patching: regular updates, prioritizing internet-facing systems and known exploited vulnerabilities.
- Training: teaching staff to recognize and report phishing.
- Incident response: a written plan and communications plan that you exercise.
Answer the application accurately
An application is a set of statements your company makes about itself. If it says MFA protects all remote access and one VPN or admin account turns out to lack it, that gap is the kind of discrepancy a claim review can surface. Have IT verify every answer, list exceptions instead of rounding them away, and keep screenshots or reports as evidence. If a control is still being rolled out, say so and give a completion date rather than answering yes.
Ask your broker what the policy requires you to do during an incident, such as using the insurer's breach coach, forensic firm or panel counsel, and put those contacts into your incident response plan.
Keep evidence ready for renewal
- MFA coverage report for all users, admins and remote access
- EDR deployment status across laptops and servers
- Most recent backup restore test, with date and result
- Patch compliance and vulnerability scan summaries
- Training completion and phishing-test records
- Date of the last incident response tabletop exercise
Common follow-up questions
Will insurers deny coverage without MFA?
It depends on the insurer and policy, and no public rule sets it. MFA is one of the most basic controls CISA recommends, so expect it to be asked about. Check your application and policy wording for any condition that ties coverage to specific controls.
Does cyber insurance replace security spending?
No. Insurance transfers part of the financial loss after an incident. It does not prevent downtime, data loss or reputational harm, and the controls insurers ask about are the same ones that reduce the chance of a claim in the first place.
Who should fill in the insurance application?
Finance or the broker usually owns the form, but IT, or your managed IT provider, should verify every technical answer and supply the evidence behind it. A senior leader should review it before signing, since it is your company's representation to the insurer.
LAN Service Group implements and documents the security controls insurers ask about, including MFA, endpoint protection, backups and patching, for small and mid-size businesses, and helps IT verify application answers with evidence.
Talk to LAN Service Group (888) 281-7243