What cyber insurers check before they write your policy

September 21, 2026 · Cybersecurity & Defense · Tech Parachute

Futuristic workspace featuring a glowing computer screen with coding displayed, ideal for technology and programming concepts.

Before a cyber insurer writes your policy, they want proof that a handful of specific security controls are already in place: multi-factor authentication, backups an attacker cannot reach, protection on every computer, current software updates, filtered email, and trained staff. Most of this arrives as an application questionnaire, and the answers decide whether you get coverage, what it costs, and whether a claim gets paid later. Here is what they ask about, and why each item matters.

Multi-factor authentication, almost everywhere

This is the question most applications lead with. Insurers want to see multi-factor authentication (a code or app prompt on top of the password) on email, on any way into your network from outside the office, and on every administrator account. A stolen password is the most common way attackers get in, and a second factor stops most of those attempts cold.

"Mostly" is the answer that causes trouble. If the owner's mailbox has it but the shared front-desk account does not, or remote access works with a password alone, say so on the form and fix it before you sign.

Backups that ransomware cannot touch

Insurers pay for ransomware recovery, so they care a great deal about whether you could recover without paying the ransom. Expect questions about how often you back up, whether at least one copy is kept offline or in storage that cannot be changed or deleted for a set period, and when you last tested a restore.

A backup drive plugged into the same server it protects does not count for much here, because ransomware encrypts whatever it can reach. If you want a plain-English refresher on how many copies to keep and where, our post on the 3-2-1 backup rule covers it.

Protection on every computer, not just antivirus

Many applications now ask specifically about endpoint detection and response, often shortened to EDR. Traditional antivirus looks for known bad files. EDR watches for suspicious behavior, like a program suddenly encrypting hundreds of documents, and can stop it and isolate the machine. Insurers also want to know that someone is actually watching those alerts, not just that the software is installed.

Software updates and unsupported systems

Expect a question about how quickly you install security updates, and another about whether anything in the office runs software the manufacturer no longer supports. That old Windows PC running one piece of equipment in the back room is exactly what the question is looking for. It does not always mean a denial, but it needs to be disclosed, and ideally isolated from the rest of the network.

Email filtering and staff training

Most attacks start with an email. Insurers ask whether incoming mail is filtered for phishing and malicious attachments, and whether employees get regular security awareness training. Some also ask whether you run practice phishing emails to see who clicks. Training records are worth keeping, because they are easy evidence to hand over.

Who has administrator rights

If everyone in the office logs in as an administrator, one bad click can do far more damage. Insurers want to know that admin rights are limited to the people who need them, and that those accounts are separate from the ones used for everyday email and browsing.

A plan for the bad day

Some applications ask whether you have a written incident response plan: who you call, who makes decisions, and how you keep the business running while systems are down. It does not need to be long. It needs to exist before you need it, with phone numbers that work when email does not.

Why honest answers matter more than good ones

The application is not a formality. If you tick "yes" to a control that turns out not to be in place, the insurer may refuse to pay the claim that control would have prevented, which is the worst possible time to find out. It is far better to answer accurately, close the gaps, and update the insurer, than to discover the difference after an incident.

How to get ready before renewal

Start by pulling up last year's application, or a blank one from your agent, and go through it line by line with whoever manages your IT. For each question, write down whether the answer is truly yes, and what evidence you could show: a screenshot of the multi-factor settings, a backup report, a restore test date, a training log. Anything that is a "no" or a "sort of" becomes your to-do list, and fixing those items before the renewal date usually costs less than the premium difference.

If you would like a second pair of eyes on your insurance questionnaire, that fits naturally alongside our managed IT and security services. Get in touch and we will walk through it with you.