Cyber & Insurance Technology

Cyber Insurance Readiness: MFA, Backups, Patching and the Controls Underwriters Review

Cyber insurance is highly customized, and underwriters may ask detailed questions about security controls. Use this readiness checklist for MFA, backups, patching, endpoint security and incident response.

Padlock on a laptop with light trails, illustrating cyber insurance security controls
Photo: FlyD / Unsplash
Short answer: Cyber insurers can evaluate how an organization controls account access, ransomware exposure, software vulnerabilities, backups, endpoints, vendors and incident response. Multi-factor authentication (MFA), reliable backups, timely patching and security monitoring are common areas of scrutiny, but there is no universal checklist that guarantees a quote, a specific premium or claim coverage.

Cyber insurance underwriting has become more technical because the loss exposure is technical. An application may ask not only whether a control exists, but where it is deployed, how it is enforced and how often it is tested.

The NAIC notes that cyber policies are highly customized and that many traditional commercial property and general liability policies do not cover cyber risks. Security controls therefore matter both as risk management and as part of presenting an accurate cyber-insurance application.

1. Multi-factor authentication: protect the accounts that matter most

CISA recommends requiring MFA wherever possible, especially for remote access and privileged or administrative accounts, and encourages phishing-resistant methods when available. For cyber underwriting, a “yes” answer can be incomplete if MFA protects only a small subset of users.

Be prepared to explain MFA coverage for email, VPN/remote access, cloud applications, administrators and other high-value systems. Also document any exceptions and compensating controls.

2. Backups: the question is whether you can actually restore

A ransomware-resilient backup strategy is more than copying files. Insurers may ask about backup frequency, isolation, offline or immutable copies, retention, administrative separation and restoration tests. If an attacker can encrypt production systems and the backups with the same credentials, the backup may not provide the recovery option the business expected.

Keep evidence of restore tests and know the recovery time for critical systems.

3. Patching and vulnerability management

CISA repeatedly recommends timely updates and prioritizing known exploited vulnerabilities. Underwriters may ask how quickly critical internet-facing systems are patched, whether the organization scans for vulnerabilities and how unsupported software is handled.

A written patch policy is useful only when the organization can show that it is followed. Asset inventory is the foundation: a company cannot patch a system it does not know exists.

4. Endpoint security and detection

Endpoints include laptops, desktops and servers where ransomware or credential theft can begin. Cyber applications may ask about endpoint protection, endpoint detection and response (EDR), centralized logging and whether alerts are monitored.

Technology names change, but the underwriting question is stable: can the organization detect suspicious activity early enough to contain it?

Control area Evidence to prepare Common gap
MFA Systems covered, method used, exception list MFA enabled for email but not admins or remote access
Backups Backup schedule, isolation, restore-test records Backups reachable with the same compromised credentials
Patching Asset inventory, vulnerability scans, remediation targets Unknown or unsupported internet-facing systems
Endpoint security Deployment coverage, alert monitoring, response process Tool installed but not centrally monitored
Incident response Plan, contacts, tabletop exercises No decision process for a real event

5. Employee training and phishing resistance

Technical controls cannot eliminate human-targeted attacks. Security awareness training, phishing exercises and a simple process for reporting suspicious messages can reduce exposure. NAIC committee materials discussing cyber underwriting have identified MFA, employee training, patch cadence and backup hygiene among key controls evaluated by at least some cyber insurers.

6. Privileged access and identity management

Separate ordinary user accounts from privileged administration, limit permissions to what is needed, remove unused accounts and monitor high-risk access. Shared administrator credentials make investigation and containment harder.

7. Incident response and outside dependencies

A cyber policy can include breach response, forensic, legal, notification, business interruption and other coverages, but the organization still needs an operational plan. Know who has authority to isolate systems, call the insurer, engage approved vendors and preserve evidence.

Also map critical service providers. A cloud, managed-service or software outage can affect operations even when the insured’s own network was not directly compromised.

Do not overstate controls on an insurance application

Cyber applications are part of the underwriting record. Answer based on the actual environment, not an aspirational security roadmap. If a question is ambiguous, ask the broker or insurer how it should be interpreted and document the answer.

  • Confirm phishing-resistant MFA for privileged and remote access where feasible.
  • Maintain current asset and software inventories.
  • Prioritize patching of known exploited and internet-facing vulnerabilities.
  • Keep isolated or otherwise ransomware-resilient backups and test restoration.
  • Deploy monitored endpoint protection appropriate to the environment.
  • Train employees and provide a simple phishing-reporting process.
  • Use least privilege and remove stale accounts.
  • Test the incident-response plan and insurer-notification process.
  • Review third-party and cloud dependencies.

Frequently asked questions

Does MFA guarantee a company can buy cyber insurance?

No. MFA is an important control, but underwriting considers many factors and insurer appetites differ.

Are backups enough to stop ransomware?

No. Backups improve recovery options but do not prevent credential theft, data exfiltration or operational disruption. They should be part of a layered security program.

What is phishing-resistant MFA?

CISA describes methods such as FIDO/WebAuthn security keys as stronger against phishing than codes that can be relayed or stolen.

Does a general liability policy automatically cover a cyber event?

No. The NAIC says most commercial property and general liability policies do not cover cyber risks, and cyber policies are highly customized.

Reviewed against CISA and NAIC guidance in September 2026. Cyber underwriting requirements change quickly and vary by insurer, industry, revenue, controls and loss history.