SecOps Digest

Cyber Insurance: What Underwriters Ask For Before They'll Cover You

6 min readCustomer Trust & Compliance

Here is a shortcut most founders miss.

If you want a prioritised list of the security controls that actually reduce loss — not a vendor's list, not a framework's list of hundreds — read a cyber insurance application. It is written by an industry that pays cash when the controls are absent, and it is refined continuously against claims data. There is no better-incentivised prioritisation available to you, and you can get one for free by asking a broker for a quote.

Read it that way even if you never buy the policy.

Why the application got harder

Cyber insurance was once easy to buy: a one-page form, generous limits, low premiums. Then ransomware claims arrived at a scale the market had not priced for, and insurers responded the way insurers do — by tightening.

The result is that the application became a control checklist with teeth. Certain controls moved from "nice to have" to preconditions: without them, you are declined, sub-limited, or quoted a premium designed to make you go away. That is not a formality. An underwriter refusing to cover something is the most direct market signal you will get about what actually causes losses.

The controls underwriters ask about

Expect these, in roughly this order of emphasis. Recognise the list — it is close to identical to what a well-run small company should do anyway.

Multi-factor authentication, and specifically on three things: email, remote access (VPN, any remote desktop), and privileged or administrator accounts. This is the most common hard requirement, and applications increasingly ask whether it is enforced for all users rather than merely available. "Enabled for most people" is not the answer the form is asking for. (how to do this properly)

Backups, with specifics. Frequency, retention, whether at least one copy is offline or immutable, whether backups are segregated from the production domain, and when you last tested a restore. Insurers ask about immutability because backup destruction is the standard prelude to a ransomware demand. (backups)

Endpoint detection and response (EDR). Increasingly a requirement rather than a bonus, and it means a modern detection product with monitoring — not the antivirus that shipped with the laptop. Some insurers name acceptable products; some offer premium credits for specific ones.

Email security controls. Filtering, and often whether you have implemented SPF, DKIM and DMARC on your domain — the records that make it harder to spoof your company to other people.

Patching discipline. How quickly critical vulnerabilities are patched, particularly on internet-facing systems, and whether you have unsupported end-of-life software still in service.

Access management. How privileged accounts are controlled, whether administrator rights are widespread, and how access is removed when someone leaves. (offboarding)

Network segmentation and remote access. Whether remote desktop is exposed directly to the internet — a question that is close to disqualifying if answered wrongly — and whether a compromise of one machine reaches everything.

Incident response and continuity planning. Whether a written plan exists, and whether anyone has rehearsed it.

Payment controls. Whether you verify changes to bank details out of band, and whether payments above a threshold require dual authorisation. This maps exactly to the payment verification rule, and it is the control that governs funds-transfer fraud coverage.

Security training. Whether staff receive it, and whether phishing simulation is used.

If that list looks familiar, it should: it is the founder's security guide with prices attached.

Get the 31-point security checklist

The checklist, then one email a week on what changed and what a company your size should do about it.

Weekly. Unsubscribe in one click. See the checklist first.

Answering accurately is not optional

This is the part that matters most, and it is regularly underestimated.

The application is a formal representation to the insurer, usually signed by an officer of the company. Insurance law across most jurisdictions gives an insurer remedies when a material misrepresentation induced them to write the policy — remedies that can include reducing a claim payment or voiding the policy from inception. Disputes over the accuracy of application answers, particularly about MFA, are a known and live feature of this market.

The failure mode is rarely deliberate fraud. It is the founder who ticks "MFA enforced on all email accounts" because it was rolled out last year, without knowing that three executives were granted exemptions and the shared billing mailbox was never enrolled. Then the claim arrives, the forensic report reconstructs exactly how the attacker logged in, and the answer on the form turns out not to have been true.

So, before you sign:

  • Verify each answer instead of recalling it. Open the admin console and look. "I believe so" is not a basis for a signature.
  • Have the person who actually administers the systems review the answers, even if a founder signs.
  • Where an answer is partial, say so on the form. "Enforced for all users except two service accounts, documented and compensated by X" is an answerable statement an underwriter can price. A tick box that is 95% true is a problem waiting to surface.
  • Keep evidence of what was true on the date you signed — a screenshot of the enforcement policy, the backup test log. It costs nothing now and is decisive later.
  • Tell your broker when something material changes mid-term.

What the policy does and does not cover

Coverage varies enormously, and the label on the policy tells you very little. Read for these, and ask your broker to point at the specific clause rather than reassure you.

Usually included: incident response costs — the forensic investigators, legal counsel and breach coaches, which is genuinely the most valuable part for a small company because you cannot assemble that team at speed on your own; notification and credit monitoring; legal defence and liability to third parties; regulatory defence and, where insurable, fines; ransom payment and negotiation, subject to conditions and sanctions law.

Often included but frequently under-scoped: business interruption — your own lost income while systems are down. Check the waiting period before it begins and how "loss" is calculated. Also check whether dependent business interruption is included: if your critical SaaS provider is the one taken down, are you covered?

Very often excluded or sub-limited, and the one to look at hardest: funds transfer fraud. The invoice and CEO fraud scenario — money you were tricked into sending — is frequently a separate add-on, sometimes carrying a limit an order of magnitude below the headline policy limit. For most small companies this is the single most likely large loss. Ask specifically. Ask for the limit, not just whether it is included.

Commonly excluded: losses arising from unsupported end-of-life software; failure to maintain the controls you declared on the application; war and state-sponsored attack exclusions, whose wording has been actively revised in recent years and is worth reading rather than assuming; prior known incidents.

Conditions that will catch you out: most policies require you to use the insurer's panel of incident responders and to notify within a short window. Calling your own consultant first, before notifying, can reduce or invalidate the claim. Put the insurer's hotline number in your recovery plan — that is where you will need it.

Getting a better renewal

Premiums respond to demonstrated controls more than to promises, and the gap between a good and bad renewal is worth real money.

Through the year, keep a small evidence file: the MFA enforcement policy screenshot, backup test results with dates, EDR deployment coverage, your written incident response plan, training completion records, and any penetration test summary. Start the renewal conversation early with a broker who specialises in cyber, and tell them what improved since last year — improvements that are not communicated are not priced.

Then compare quotes on coverage rather than premium. A cheap policy with a low funds-transfer sub-limit and a long business-interruption waiting period is not cheaper; it is smaller.

The takeaway

Buy the policy or do not — that depends on your balance sheet, your customer contracts, and what a bad month would do to you.

But get the application form regardless, and work through it honestly. It will take an afternoon, it will produce a specific and ranked list of your gaps, and it is written by the only party in the security industry that pays money when the answer is wrong.

Get the 31-point security checklist

One email a week: what changed in security, what it means for a company your size, and the one thing worth doing about it. No vendor pitches, no fear.

Weekly. Unsubscribe in one click. See the checklist first.

More on Customer Trust & Compliance, or browse every article.