Your broker asks for an updated cyber insurance application. You expect a few questions about coverage. Instead, you need to explain which systems have multi-factor authentication, when you last tested a backup, and who can make decisions during an attack.
That is the shift behind today’s cyber insurance requirements. Insurers want a clearer view of whether your controls work across the business, not a list of products you’ve purchased. Before you answer, get clear on what you can prove and where the gaps sit.
Key Takeaways for Cyber Insurance Quotes
- Insurers commonly examine multi-factor authentication, endpoint protection, backups, patching, privileged access, and incident response. The exact requirements vary by carrier and risk profile.
- A written policy or installed tool isn’t proof that a control works. Know its scope, owner, exceptions, and most recent test.
- Incomplete answers can delay a quote or affect its terms. An honest gap with a remediation plan is better than an unsupported “yes.”
- Put one leader in charge of the application. IT, vendors, finance, legal, and your broker each hold part of the answer.
Why a signed questionnaire is no longer enough
A cyber quote is a decision about potential loss. A ransomware attack could interrupt orders, payroll, customer service, or production before anyone knows the full cost. Insurers ask about controls because they need to understand both the chance of an incident and your ability to recover.
That doesn’t mean every carrier uses the same checklist. Questions change with your industry, revenue, sensitive data, prior claims, requested limits, and the systems your business depends on. The security controls commonly reviewed by underwriters are a useful starting point, but your broker should confirm what a particular carrier expects.
A quote may still be possible with an open issue. It may also come with different pricing, conditions, or limits. You need to know which gaps are material before the application leaves your business.
If you can’t tell where a control applies, you can’t answer honestly whether it’s in place across the company.
Cyber insurance requirements start with access and detection

Multi-factor authentication must cover the exposed paths
Start with email, remote access, and administrator accounts. Then check cloud administration and access to backup systems. One forgotten privileged account can change the meaning of an otherwise confident answer.
Ask your team for the configuration and an account report, not a general assurance that MFA is “turned on.” Check exceptions, service accounts, contractors, and acquired business units. If a legacy system cannot support MFA, record who can reach it and what protection sits around it.
Specops’ explanation of insurer MFA questions shows why the scope of deployment matters. Describe partial coverage as partial coverage. Your broker can ask the carrier how it wants that exception presented.
Endpoint protection needs a coverage view
Endpoint detection and response, often called EDR, helps identify suspicious activity on workstations and servers. The useful question for underwriting is not whether you pay for EDR. It’s which devices have it installed, active, and reporting.
Compare the EDR report with your systems inventory. Look for servers, remote devices, newly acquired systems, and machines that stopped reporting. Confirm who reviews alerts and what happens outside business hours. Don’t invent a coverage percentage to sound complete. Show the actual report and explain the exceptions.
Backups and response plans need a real test

A successful backup job isn’t a successful recovery
Insurers commonly ask whether backups are protected from the same attack that could hit your primary systems. Offline or immutable copies can help. Access to the backup platform also needs protection.
Then comes the harder question: have you restored anything that matters? A backup log says data was copied. A restore test shows whether your team can bring back a critical system, how long it takes, and what gets lost.
Choose a business process, not only a convenient test file. If order processing depends on a database, an identity service, and a cloud application, recovery has to account for those connections. Keep dated test results, failures, owners, and follow-up work. The control evidence to prepare before renewal should reflect what happened, not what the plan predicted.
An incident plan must name decision-makers
Your response plan should answer practical questions. Who declares an incident? Who can shut down access? Who contacts the broker, insurer, counsel, customers, and critical vendors? Who can approve urgent spending?
Run a tabletop exercise against a plausible disruption. A ransomware event affecting a shared system is enough to expose unclear authority. Record what the team decided and what needs fixing. Check your policy’s notification, consent, and approved-provider provisions before an incident, since those terms vary.
Check patching, privileged access, and vendors
Identity and recovery attract attention, but they don’t stand alone. Underwriters may ask how you find vulnerabilities, apply security updates, limit administrator privileges, and separate sensitive systems.
Keep patch records for critical systems and a short list of overdue exceptions. Show who approved each exception and when it will be resolved. Review administrator accounts for people who changed roles or left. A documented cyber insurance renewal review can help you compare these records with last year’s answers.
Vendor access deserves the same attention. Your managed service provider may have remote access across much of the company. A payroll or hosting provider may hold data or support a process you cannot pause. Know which vendors have privileged access, how you review it, and what happens when the relationship ends.
This is where cyber insurance requirements expose a broader ownership problem. The risk may sit with a vendor, while your company remains responsible for explaining the control.
Build evidence before you answer “yes”
Map each question to a system and an owner
A sound application starts with a current systems inventory. Include major cloud services, remote access, servers, business units, and material vendor connections. Without that map, “all systems” is an assumption.
For each question, record the control owner, scope, evidence location, last review date, and exceptions. Identity settings, EDR reports, patch records, restore-test notes, and incident-exercise results give different parts of the picture. Keep them dated so you can tell whether they still describe the business.
Resolve contradictions before the broker sees them
Last year’s application may say MFA covers every remote user. Since then, you’ve bought a company, added a cloud service, or changed providers. Compare the old answer with today’s configuration.
Don’t ask five people to answer the same question separately. Bring IT, security, operations, legal, finance, and key vendors into one review. When answers conflict, establish the fact before submitting anything. If a control is incomplete, describe the gap, current protection, owner, and expected remediation date.
A 30-day renewal preparation plan can organize the evidence, but don’t wait until the final month to discover a failed restore test.
Give the application an executive owner
Your technical team can validate controls. Your broker can explain insurer questions and seek terms. Neither should have to guess what risk management is willing to accept.
Name one accountable executive to coordinate the response. That person should be able to settle ownership disputes, raise material gaps, and approve accurate disclosures. For a growing company, the exercise may reveal a technology leadership gap rather than a lack of effort. A fractional CTO or fractional CISO can help connect systems, vendors, recovery, and business decisions when no full-time leader owns that view.
Management should get a short summary: the controls that work, material exceptions, recovery-test results, decisions needed, and the likely business effect of an outage. The board needs cyber risk reporting it can govern, not a copy of the insurer’s questionnaire.
That reporting remains useful after you receive a quote. It tells you which risks you’ve reduced, which you’re asking insurance to absorb, and which remain with the business.
Read the quote as carefully as the application
Getting quoted isn’t the same as getting the protection you expected. Compare limits, retentions, sublimits, exclusions, and waiting periods alongside the premium. Ask how the policy handles ransomware, business interruption, and disruption at a dependent vendor.
Check notification deadlines, consent requirements, and any rules about using approved incident-response firms. A lower premium can leave you carrying more of a loss if a relevant coverage part is limited.
If you’re renewing, pull the prior application, policy, endorsements, claims history, and material-change notices. Confirm how the new terms apply to the business you operate now. Don’t assume last year’s coverage or answers still fit.
Frequently Asked Questions
Does every insurer require the same security controls?
No. Carriers assess different exposures and use different questionnaires. MFA, endpoint protection, protected backups, patching, and incident response are common areas of scrutiny, but your broker should confirm the carrier’s actual requirements.
Can you get a quote with an incomplete control?
Possibly. The answer depends on the gap, your risk profile, and the carrier. A missing control may affect eligibility, price, limits, or conditions. Disclose it accurately and ask how remediation would affect the quote.
Is a written incident response plan enough?
Not on its own. You should know whether the contacts are current, decision rights are clear, and the team has practiced a realistic scenario. A dated exercise record is more useful than an untouched document.
Make the quote a clearer business decision
The application isn’t the goal. You need a trustworthy picture of what protects your business, what remains exposed, and how quickly you could recover.
When your answers have evidence and an owner, you can speak to the insurer without guessing. You can also make a better decision about the risk your company will keep.