Cyber Insurance Requirements: What Underwriters Demand in 2024
Cyber insurance requirements are the security controls an underwriter demands before they'll issue or renew a policy. In practice, insurers commonly require five baseline controls: multi-factor authentication (MFA), endpoint detection and response (EDR), immutable backups, email security, and a documented incident response (IR) plan. Fail to demonstrate any of these and you'll face higher premiums, coverage exclusions, or outright declination.
The five baseline controls insurers actually check
Underwriting has tightened dramatically since ransomware losses spiked. Insurers no longer take your word for it — they ask for evidence on the application, and misrepresentation can void a claim. Here's what each control means in concrete terms:
- MFA — Required on all remote access, VPNs, email (especially Microsoft 365 / Google Workspace), and privileged/admin accounts. "MFA on email only" is increasingly insufficient; expect questions about MFA on your identity provider and any internet-facing management interfaces.
- EDR — A named product (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, etc.) deployed across endpoints and servers, ideally with 24/7 monitoring. Legacy signature-only antivirus won't clear the bar.
- Immutable backups — Backups that cannot be altered or deleted by an attacker, tested for restore, and stored offline or in a separate security domain. This is the single biggest factor in ransomware recovery, so insurers scrutinise it.
- Email security — Anti-phishing and filtering controls, plus SPF, DKIM and DMARC to reduce spoofing. Email remains the primary ransomware and business email compromise entry point.
- Documented IR plan — A written, tested plan with defined roles, contact trees, and playbooks. Bonus points for tabletop exercises in the last 12 months.
These five are the confirmed baseline underwriting conditions insurers commonly require. Larger policies add controls like privileged access management, network segmentation, vulnerability patching SLAs, and end-of-life software inventories.
What cyber insurance does not cover
Buying a policy is not a substitute for security, and the exclusions matter more than most buyers realise. Cyber insurance typically does not cover:
- Pre-existing breaches — Incidents that began before the policy started, even if discovered later.
- Known, unpatched vulnerabilities — If you knew about a critical flaw and didn't remediate it, claims can be denied.
- Failure to maintain required controls — If you attested to MFA on your application but it wasn't actually enforced, the insurer can rescind coverage.
- Acts of war / nation-state attacks — Many policies now include war exclusions that can apply to state-sponsored attacks (a contested area since the NotPetya litigation).
- Loss of future revenue and reputational harm beyond defined business interruption limits.
- Fines that are legally uninsurable in your jurisdiction (some regulatory penalties cannot be insured).
The practical lesson: your application answers become contractual warranties. Answer them accurately, and keep evidence that your controls were operating throughout the policy period.
Do you really need it, and is it mandatory?
Cyber insurance is not legally mandatory for most organisations — but it's increasingly required by contract. Enterprise customers, government agencies, and prime contractors routinely demand proof of a cyber policy (often $1M–$5M in limits) as a condition of doing business. So while no law forces you to buy it, your sales pipeline may.
On the "do I need it" question: any organisation that holds sensitive data, processes payments, or would suffer material downtime from an outage benefits. The controls you implement to qualify for coverage — MFA, EDR, tested backups — are exactly the controls that reduce your actual breach risk. In other words, meeting the requirements is worthwhile even if you never file a claim.
How to prepare before you apply
Treat the application like an audit. Work in this order to close the highest-impact gaps first:
- Enforce MFA everywhere — email, VPN, admin accounts, and your identity provider. This is the fastest premium-mover.
- Deploy and monitor EDR across all endpoints and servers; document the product and coverage percentage.
- Prove immutable, tested backups — run a restore and keep the evidence dated.
- Configure SPF, DKIM, DMARC and turn on advanced email filtering.
- Write and tabletop your IR plan — even a two-hour exercise gives you something to attest to.
Document each control with screenshots, config exports, and dates. This evidence both speeds underwriting and protects you if you ever need to claim.
Want to estimate what your premium might look like before you talk to a broker? Try PlayCISO
Ready to practise the decisions these articles describe?
Run a free War Room →