Yes, carriers now require specific security controls before they’ll write or renew a policy, and four matter most: multi-factor authentication, endpoint detection and response (EDR), immutable backups, and a tested incident response plan. Insurers no longer take your word for it either. Underwriting has shifted toward evidence, guided by frameworks like the NIST Cybersecurity Framework and questionnaires that mirror the CIS Controls.
Start here:
- Turn on MFA for email, VPN, and every admin account.
- Deploy EDR across all endpoints, not just servers.
- Test your backup restores and write down what happened.
- These four controls carry more underwriting weight than almost anything else on the application.
- Skipping even one often means a higher premium, a coverage exclusion, or a flat decline.
Key Takeaways
Cyber insurance eligibility now hinges on four verifiable controls, MFA, EDR, immutable backups, and a tested incident response plan, more than any other factor in underwriting.
| Point | Details |
|---|---|
| MFA is non-negotiable | Enforce it on email, VPN/RDP, and every admin console, with phishing-resistant options for admins. |
| Proof beats promises | Carriers want screenshots, scan reports, and restore test logs, not self-attestation. |
| Backups need testing | Immutable or air-gapped backups with documented restore tests reduce ransomware exclusions. |
| Renewal is not automatic | Lapsed controls or undisclosed incidents can trigger non-renewal or claim denial. |
| Mavericks Office Solutions builds the evidence | Managed cybersecurity, MDR, and fractional CISO services map directly to what underwriters check. |
Table of Contents
- How Do Insurers Evaluate Cyber Risk?
- What Security Controls Do Insurers Require?
- What Does a Cyber Policy Actually Cover?
- What Drives Your Cyber Insurance Premium?
- How Do You Prepare a Cyber Insurance Application?
- How Do You Keep Cyber Coverage Valid at Renewal?
- Get Insurer-Ready With Mavericks Office Solutions
- Sources
How Do Insurers Evaluate Cyber Risk?
Underwriting runs on a predictable sequence: a written questionnaire, then automated scans or document requests, then a manual review, then a decision on binding, sublimits, and exclusions. Carriers tightened this process after years of rising ransomware losses. The FBI’s Internet Crime Complaint Center logged hundreds of thousands of complaints and billions in potential losses during the peak ransomware years, which is exactly why underwriters stopped trusting self-attestation and started demanding proof.
What gets weighted most heavily are the controls that blunt ransomware and business email compromise, the two claim categories driving most payouts. Underwriters commonly ask for:
- Screenshots of MFA enforcement policies and conditional access rules
- Network topology diagrams showing segmentation
- Vulnerability scan results from the last 90 days
- Logs proving EDR or MDR coverage across endpoints
Pro Tip: Build an evidence folder before you ever open an application. Screenshot your MFA settings, export your backup configuration, and save your last tabletop exercise report. Carriers move faster on applicants who arrive with proof instead of promises.
What Security Controls Do Insurers Require?
Every control below maps to something an underwriter will actually ask to see, not just a checkbox on a form.
Multi-factor authentication. MFA needs to cover email, VPN or RDP access, and every admin console. NIST SP 800-63B recommends phishing-resistant authenticators like FIDO2 keys for high-value accounts, and carriers increasingly ask specifically about that tier of protection. Proof looks like conditional access screenshots or FIDO2 enrollment logs, not a verbal confirmation on a call.
EDR and managed detection. Coverage needs to reach every endpoint, running in active detection mode with alerts routed somewhere a human actually watches. An MDR provider or SOC contract, plus an agent inventory export, satisfies this line on most questionnaires.
Backups and recovery. Immutable or air-gapped backups, tested restores, and documented recovery time objectives are now close to universal requirements. A Microsoft 365 backup strategy with a restore test report attached carries more weight than a vendor’s marketing claim about “military-grade” backup.

Identity and privileged access. Admin accounts need to be separate from daily-use accounts, with least-privilege enforced and a documented process for granting elevated access. An inventory of privileged accounts is standard proof.
Patch and vulnerability management. Critical vulnerabilities patched within 14 to 30 days, backed by scan reports and patch logs, aligns with NIST’s patch management guidance.
Email security. DMARC, SPF, and DKIM records, plus phishing simulation results, show up on nearly every questionnaire.
Logging and monitoring. Retention policies and SIEM or MDR coverage screenshots round out the technical evidence.
Incident response. A written plan with named roles, a recent tabletop exercise date, and an IR retainer if you have one.
Vendor risk. A vendor inventory and contracts with security service-level agreements, especially for any connected devices like IP cameras, which carry their own cybersecurity exposure.
What Does a Cyber Policy Actually Cover?
First-party coverage pays for your own losses: forensic investigation, legal counsel, breach notification costs, and business interruption income. Third-party coverage pays claims brought against you, like a customer lawsuit after their data leaked. The FTC’s guidance on cyber insurance walks through both categories and urges businesses to read the fine print before assuming either is unlimited.
Exclusions are where policies get complicated:
- Ransomware sublimits that cap payouts far below the policy’s headline limit
- Co-insurance clauses requiring you to cover a percentage of the loss
- War or state-sponsored attack exclusions, a growing gray area after several high-profile disputes
- Betterment exclusions, meaning the insurer won’t pay to upgrade your security beyond restoring what existed
- Denial triggers tied to pre-existing, unpatched vulnerabilities you knew about
Missing MFA or an untested backup isn’t just an underwriting problem. It can void coverage entirely if a claim traces back to that exact gap.
What Drives Your Cyber Insurance Premium?
Revenue, industry exposure, data volume, claims history, and control posture set your price, in roughly that order of weight. A healthcare practice or law firm pays more than a retail shop with the same revenue because regulatory exposure and data sensitivity raise the stakes.
- Verified MFA and EDR can lower quoted premiums or remove exclusions entirely
- A documented IR plan often shortens underwriting review time
- Claims history from the past three years affects pricing more than almost any single control
Most small businesses budget a few thousand dollars a year for coverage, according to SMB-focused cost guidance, and every dollar spent on prevention tends to buy more premium reduction than the same dollar spent negotiating with a broker after the fact.
How Do You Prepare a Cyber Insurance Application?
Gather these before you start:
- MFA and conditional access screenshots
- EDR agent inventory and MDR contract
- Backup configuration and restore test report
- Written IR plan and tabletop exercise summary
- Vendor contracts with security clauses
The timeline usually runs 60 to 90 days from self-attestation to binding:
- Complete the questionnaire and self-attestation
- Undergo external scans and respond to evidence requests
- Receive a quote with proposed sublimits and exclusions
- Negotiate terms and bind coverage
Ask your broker what triggers a pre-binding technical assessment and whether your industry faces extra scrutiny. A 90-day cybersecurity action plan gives you a realistic runway to close gaps before that first questionnaire goes out.
How Do You Keep Cyber Coverage Valid at Renewal?
Renewal isn’t a rubber stamp. Carriers expect fresh evidence: patched internet-facing systems, a recent tabletop test, and a current backup restore report.
- EDR and MDR alerts should show continuous monitoring, not a one-time install
- Retain documentation for at least as long as your policy period, often longer
- Undisclosed incidents, lapsed MFA, or ignored remediation deadlines are the fastest routes to non-renewal or a denied claim
A control that passed underwriting last year but quietly lapsed this year is worse than never having it, because it can look like misrepresentation on the file.
A Practical Order of Operations for Getting Insurable
If your budget and staff are limited, sequence matters. MFA everywhere comes first because it’s cheap and closes the most common attack path. EDR with monitored alerting comes second. Immutable, tested backups and a written IR plan come third, because insurers treat “we tested our recovery” as more credible than “we have backups.”
Most SMBs can’t staff a 24/7 security operation internally, which is exactly when a managed detection provider or a fractional CISO earns its cost. Start with evidence, not marketing claims. Carriers reward screenshots and test reports over polished pitch decks every time.
Get Insurer-Ready With Mavericks Office Solutions
Meeting cyber insurance requirements without an IT department dedicated to it usually means scrambling for evidence the week before renewal. Mavericks Office Solutions closes that gap by running the exact controls carriers ask about as ongoing managed services, not one-time projects.

Our managed cybersecurity services cover MFA enforcement, EDR deployment, and monitored alerting, while our backup and recovery work includes documented restore tests, the kind of proof underwriters actually request instead of a verbal assurance. We facilitate tabletop exercises and build the incident response documentation carriers want to see before binding, and our fractional CISO services give smaller teams board-level governance answers without a full-time hire. Every engagement produces an evidence package you can hand straight to your broker.
If your renewal is within 90 days or you’re applying for coverage for the first time, request a readiness review through our managed IT services page and find out exactly which controls need attention before an underwriter finds the gap for you.

Sources
For deeper reading, the FTC’s cyber insurance overview explains policy scope in plain language, while NIST SP 800-63B is the technical standard behind MFA expectations. The CIS Controls list is the closest thing to a universal underwriting checklist, and the CyberReadiness Institute’s FAQ covers costs and application basics for smaller organizations. Treat the first two as evidence standards and the last two as background reading.
- Cyber Insurance | Federal Trade Commission
- NIST Special Publication 800-63B: Digital Identity Guidelines — Authentication and Lifecycle
- CIS Controls®
- Cyber Insurance Requirements Checklist 2026: Insurers
Recommended
- Small Business Cybersecurity: A Michigan Owner’s Playbook – Mavericks Office Solutions
- Why Every Ohio Small Business Needs a Cybersecurity Plan in 2026 – Mavericks Office Solutions
- Best Business Password Manager for SMBs: 2026 Guide – Mavericks Office Solutions
- Cybersecurity – Mavericks Office Solutions