Cyber insurance applications have become technical enough that the person signing one should know exactly what each answer means. A yes to MFA, EDR or backups needs to match what is actually deployed and operating.
Cyber insurance can transfer part of the financial risk associated with certain cyber incidents, subject to policy terms, limits and exclusions.
Insurance does not replace cybersecurity.
Organizations should build a security program first and ensure insurance applications accurately describe the controls actually in place.
Why Accuracy Matters
A cyber-insurance application may ask whether the organization uses specific controls.
Answers should reflect the actual environment.
If a question is unclear, ask the broker or carrier for clarification rather than assuming what the question means.
Common Security Topics on Applications
Applications often ask about:
- Multi-factor authentication
- Endpoint detection and response
- Antivirus
- Backups
- Backup isolation
- Email security
- Administrative access
- Remote access
- Patch management
- Security training
- Incident response
- Data encryption
- Network segmentation
- Security monitoring
- Vendor management
Requirements differ by carrier and policy.
Document MFA Coverage
Do not answer simply that "MFA is enabled" without understanding where it applies.
Document whether MFA protects:
- Microsoft 365
- Remote access
- VPN
- Administrative accounts
- Cloud applications
- Backup administration
- Remote monitoring tools
- Privileged access
Document Backup Protection
Know:
- What is backed up
- Frequency
- Retention
- Offsite copies
- Administrative access
- Isolation
- Restoration testing
- Recovery objectives
Maintain Security Evidence
Useful evidence can include:
- Asset inventories
- Security policies
- MFA reports
- Endpoint protection reports
- Patch reports
- Backup test results
- Security awareness records
- Incident response plan
- Risk assessments
- Vulnerability reports
Review Before Renewal
Security environments change during the policy period.
Before renewal, compare the insurance application against current technical reality.
Coordinate IT, Management and Insurance
Cyber insurance should not be completed by a single department in isolation.
Management, IT/security, the insurance broker and legal counsel may each have information required to answer the application accurately.
Common questions
Does cyber insurance require MFA?
Many carriers request MFA for specific systems, but requirements vary by policy.
Does an MSP decide whether coverage applies?
No. Coverage decisions are made according to the insurance contract and carrier. An MSP can document technical controls but should not interpret insurance coverage unless qualified to do so.
Can an MSP help with the application?
An MSP can provide factual information about technical controls and configurations. Policy interpretation should be handled by the broker, carrier or legal counsel.
Sources and further reading
This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.
