Resources

Cyber Insurance Readiness Guide

Prepare for cyber insurance applications and renewals with accurate security documentation, MFA, endpoint protection, backups, identity controls and incident planning.

Cyber insurance applications have become technical enough that the person signing one should know exactly what each answer means. A yes to MFA, EDR or backups needs to match what is actually deployed and operating.

Cyber insurance can transfer part of the financial risk associated with certain cyber incidents, subject to policy terms, limits and exclusions.

Insurance does not replace cybersecurity.

Organizations should build a security program first and ensure insurance applications accurately describe the controls actually in place.

Why Accuracy Matters

A cyber-insurance application may ask whether the organization uses specific controls.

Answers should reflect the actual environment.

If a question is unclear, ask the broker or carrier for clarification rather than assuming what the question means.

Common Security Topics on Applications

Applications often ask about:

  • Multi-factor authentication
  • Endpoint detection and response
  • Antivirus
  • Backups
  • Backup isolation
  • Email security
  • Administrative access
  • Remote access
  • Patch management
  • Security training
  • Incident response
  • Data encryption
  • Network segmentation
  • Security monitoring
  • Vendor management

Requirements differ by carrier and policy.

Document MFA Coverage

Do not answer simply that "MFA is enabled" without understanding where it applies.

Document whether MFA protects:

  • Microsoft 365
  • Remote access
  • VPN
  • Administrative accounts
  • Cloud applications
  • Backup administration
  • Remote monitoring tools
  • Privileged access

Document Backup Protection

Know:

  • What is backed up
  • Frequency
  • Retention
  • Offsite copies
  • Administrative access
  • Isolation
  • Restoration testing
  • Recovery objectives

Maintain Security Evidence

Useful evidence can include:

  • Asset inventories
  • Security policies
  • MFA reports
  • Endpoint protection reports
  • Patch reports
  • Backup test results
  • Security awareness records
  • Incident response plan
  • Risk assessments
  • Vulnerability reports

Review Before Renewal

Security environments change during the policy period.

Before renewal, compare the insurance application against current technical reality.

Coordinate IT, Management and Insurance

Cyber insurance should not be completed by a single department in isolation.

Management, IT/security, the insurance broker and legal counsel may each have information required to answer the application accurately.

Common questions

Does cyber insurance require MFA?

Many carriers request MFA for specific systems, but requirements vary by policy.

Does an MSP decide whether coverage applies?

No. Coverage decisions are made according to the insurance contract and carrier. An MSP can document technical controls but should not interpret insurance coverage unless qualified to do so.

Can an MSP help with the application?

An MSP can provide factual information about technical controls and configurations. Policy interpretation should be handled by the broker, carrier or legal counsel.

Sources and further reading

This guide references current primary-source material. Requirements and product capabilities can change, so verify current source guidance before implementation.

Ready to move forward?

Want help applying this to your business?

We can look at your current environment and tell you which parts of this guide matter most for you.

Talk With Huff Data