Cyber insurance underwriting has become more technical because the loss exposure is technical. An application may ask not only whether a control exists, but where it is deployed, how it is enforced and how often it is tested.
The NAIC notes that cyber policies are highly customized and that many traditional commercial property and general liability policies do not cover cyber risks. Security controls therefore matter both as risk management and as part of presenting an accurate cyber-insurance application.
1. Multi-factor authentication: protect the accounts that matter most
CISA recommends requiring MFA wherever possible, especially for remote access and privileged or administrative accounts, and encourages phishing-resistant methods when available. For cyber underwriting, a “yes” answer can be incomplete if MFA protects only a small subset of users.
Be prepared to explain MFA coverage for email, VPN/remote access, cloud applications, administrators and other high-value systems. Also document any exceptions and compensating controls.
2. Backups: the question is whether you can actually restore
A ransomware-resilient backup strategy is more than copying files. Insurers may ask about backup frequency, isolation, offline or immutable copies, retention, administrative separation and restoration tests. If an attacker can encrypt production systems and the backups with the same credentials, the backup may not provide the recovery option the business expected.
Keep evidence of restore tests and know the recovery time for critical systems.
3. Patching and vulnerability management
CISA repeatedly recommends timely updates and prioritizing known exploited vulnerabilities. Underwriters may ask how quickly critical internet-facing systems are patched, whether the organization scans for vulnerabilities and how unsupported software is handled.
A written patch policy is useful only when the organization can show that it is followed. Asset inventory is the foundation: a company cannot patch a system it does not know exists.
4. Endpoint security and detection
Endpoints include laptops, desktops and servers where ransomware or credential theft can begin. Cyber applications may ask about endpoint protection, endpoint detection and response (EDR), centralized logging and whether alerts are monitored.
Technology names change, but the underwriting question is stable: can the organization detect suspicious activity early enough to contain it?
| Control area | Evidence to prepare | Common gap |
|---|---|---|
| MFA | Systems covered, method used, exception list | MFA enabled for email but not admins or remote access |
| Backups | Backup schedule, isolation, restore-test records | Backups reachable with the same compromised credentials |
| Patching | Asset inventory, vulnerability scans, remediation targets | Unknown or unsupported internet-facing systems |
| Endpoint security | Deployment coverage, alert monitoring, response process | Tool installed but not centrally monitored |
| Incident response | Plan, contacts, tabletop exercises | No decision process for a real event |
5. Employee training and phishing resistance
Technical controls cannot eliminate human-targeted attacks. Security awareness training, phishing exercises and a simple process for reporting suspicious messages can reduce exposure. NAIC committee materials discussing cyber underwriting have identified MFA, employee training, patch cadence and backup hygiene among key controls evaluated by at least some cyber insurers.
6. Privileged access and identity management
Separate ordinary user accounts from privileged administration, limit permissions to what is needed, remove unused accounts and monitor high-risk access. Shared administrator credentials make investigation and containment harder.
7. Incident response and outside dependencies
A cyber policy can include breach response, forensic, legal, notification, business interruption and other coverages, but the organization still needs an operational plan. Know who has authority to isolate systems, call the insurer, engage approved vendors and preserve evidence.
Also map critical service providers. A cloud, managed-service or software outage can affect operations even when the insured’s own network was not directly compromised.
Do not overstate controls on an insurance application
Cyber applications are part of the underwriting record. Answer based on the actual environment, not an aspirational security roadmap. If a question is ambiguous, ask the broker or insurer how it should be interpreted and document the answer.
- Confirm phishing-resistant MFA for privileged and remote access where feasible.
- Maintain current asset and software inventories.
- Prioritize patching of known exploited and internet-facing vulnerabilities.
- Keep isolated or otherwise ransomware-resilient backups and test restoration.
- Deploy monitored endpoint protection appropriate to the environment.
- Train employees and provide a simple phishing-reporting process.
- Use least privilege and remove stale accounts.
- Test the incident-response plan and insurer-notification process.
- Review third-party and cloud dependencies.
Frequently asked questions
Does MFA guarantee a company can buy cyber insurance?
No. MFA is an important control, but underwriting considers many factors and insurer appetites differ.
Are backups enough to stop ransomware?
No. Backups improve recovery options but do not prevent credential theft, data exfiltration or operational disruption. They should be part of a layered security program.
What is phishing-resistant MFA?
CISA describes methods such as FIDO/WebAuthn security keys as stronger against phishing than codes that can be relayed or stolen.
Does a general liability policy automatically cover a cyber event?
No. The NAIC says most commercial property and general liability policies do not cover cyber risks, and cyber policies are highly customized.
Sources & further reading
Reviewed against CISA and NAIC guidance in September 2026. Cyber underwriting requirements change quickly and vary by insurer, industry, revenue, controls and loss history.
