Quick Answer: Prepare Evidence for 12 Core Cybersecurity Controls
A 25–50 employee financial firm should prepare evidence for at least 12 cybersecurity controls before applying for or renewing cyber insurance: multi-factor authentication, endpoint detection and response, email security, security awareness training, patch management, protected backups, recovery testing, privileged-access controls, employee offboarding, incident response, vendor-risk management, and continuous security monitoring.
Insurance applications vary by carrier, policy, coverage amount, and risk profile. A control requested by one insurer may not be required by another. However, incomplete safeguards, inaccurate application answers, or weak documentation can delay underwriting, restrict coverage, increase premiums, or create problems during a claim.
The safest approach is to begin preparing 60–90 days before renewal. Coordinate the application with your insurance broker, leadership team, legal counsel, and cybersecurity provider. Do not answer technical questions from memory. Verify each response and preserve evidence supporting it.
The 12-Control Cyber Insurance Readiness Framework
| Control | What it helps address | Evidence to prepare |
|---|---|---|
| 1. Multi-factor authentication | Unauthorized access caused by stolen passwords | Coverage report, policies, screenshots, and exception list |
| 2. Endpoint detection and response | Malware, ransomware, and suspicious device activity | Protected-device inventory and monitoring reports |
| 3. Email security | Phishing, impersonation, malicious links, and attachments | Email-security configuration and incident reports |
| 4. Security awareness training | Employee mistakes and social engineering | Training completion and phishing-test results |
| 5. Patch management | Exploitation of known vulnerabilities | Patch reports, vulnerability findings, and exception records |
| 6. Protected backups | Data loss, ransomware, and system failure | Backup coverage, retention, security, and monitoring reports |
| 7. Recovery testing | Backup failure and extended downtime | Documented restore-test results |
| 8. Privileged-access controls | Misuse or compromise of administrator accounts | Administrator inventory and access-review records |
| 9. Onboarding and offboarding | Excessive access and former-employee accounts | Completed checklists and account-review reports |
| 10. Incident-response planning | Delayed, inconsistent, or unauthorized response actions | Written plan, contact list, and exercise results |
| 11. Vendor-risk management | Third-party and supply-chain incidents | Vendor inventory, assessments, and contracts |
| 12. Security monitoring | Threats that occur outside normal working hours | Alert-handling procedures and monitoring reports |
1. Enforce Multi-Factor Authentication
Multi-factor authentication, or MFA, requires a second form of verification in addition to a password. It is one of the first controls a financial firm should assess before completing a cyber insurance application.
MFA should be considered for:
- Microsoft 365 and company email
- Remote-access and virtual private network services
- Cloud financial applications
- Administrator accounts
- Backup-management portals
- Remote monitoring and management tools
- Accounting and tax platforms when supported
- Vendor-management portals
- Payment and banking systems
- Other systems containing sensitive information
The firm should determine whether MFA is merely available, enabled for some users, or technically enforced for all applicable accounts. Those answers are not interchangeable.
Evidence to collect
- A list of systems protected by MFA
- The percentage of active users covered
- A list of exempt accounts and the reason for each exception
- The authentication methods permitted
- Policies blocking older authentication methods
- Administrator-account protection
- The process for resetting MFA
Financial firms using Microsoft 365 should verify that MFA and identity policies are configured rather than assuming the license provides protection automatically. Review 911 IT’s cloud services for help managing Microsoft 365 security.
2. Deploy Endpoint Detection and Response
Endpoint detection and response, or EDR, monitors workstations and servers for suspicious behavior. It can help identify malware, ransomware, credential theft, unauthorized scripts, and other activity that traditional antivirus may not stop.
EDR coverage should include:
- Employee desktops
- Laptops
- Servers
- Remote-worker devices
- Privileged administrator systems
- Company-owned devices used outside the office
Installing an EDR agent is only one part of the control. The firm should also know:
- Who monitors alerts
- Whether alerts are reviewed outside normal business hours
- Who can isolate a compromised device
- How quickly serious alerts are investigated
- What happens when an agent stops reporting
- How unsupported devices are handled
Evidence to collect
- An inventory of protected endpoints
- A report showing active and inactive agents
- Recent alert summaries
- The escalation and containment procedure
- Documentation of unresolved coverage gaps
3. Strengthen Email and Impersonation Protection
Financial organizations are frequent targets for phishing, credential theft, fake invoice requests, payroll changes, wire fraud, and executive impersonation. A cyber insurance readiness review should evaluate both technical email protection and internal approval procedures.
Email controls may include:
- Phishing and malware filtering
- Malicious-link analysis
- Attachment scanning
- Executive impersonation protection
- Domain-spoofing protection
- External-sender notices
- Email authentication settings
- Mailbox-forwarding alerts
- A phishing-reporting button
- Automated investigation and quarantine
Protect financial transactions with process controls
Email security cannot determine whether every request is legitimate. Financial firms should require independent verification for:
- New payment instructions
- Bank-account changes
- Wire transfers
- Payroll changes
- Vendor-payment updates
- Requests for tax or identity information
- Unusual access requests
Use a known telephone number or approved workflow rather than replying to the original message. Consider requiring two-person approval for high-risk financial transactions.
4. Provide Recurring Security Awareness Training
Employees should receive cybersecurity training when hired and at least annually afterward. Financial firms may benefit from shorter recurring lessons and phishing simulations throughout the year.
Training should address:
- Phishing
- Business email compromise
- Password and MFA security
- Payment fraud
- Safe handling of client information
- Remote-work risks
- Malicious attachments and links
- Secure file sharing
- Lost or stolen devices
- How to report suspicious activity
Evidence to collect
- Training completion records
- Dates and topics covered
- Phishing-simulation results
- Follow-up training for employees who need assistance
- New-hire training procedures
- Copies of reporting instructions
A training program should improve behavior rather than punish employees for mistakes. The objective is to create rapid reporting and reduce the time an attacker remains undetected.
5. Maintain a Documented Patch and Vulnerability Program
Cybercriminals regularly target known vulnerabilities in operating systems, applications, firewalls, remote-access services, and other internet-facing technology. A financial firm should know what it owns, which systems are supported, and how quickly important updates are installed.
The patch-management program should cover:
- Employee computers
- Servers
- Microsoft applications
- Web browsers
- PDF and document software
- Firewalls
- Network equipment
- Remote-access tools
- Financial applications
- Common third-party software
Define remediation targets
The firm should establish risk-based targets for correcting vulnerabilities. For example:
| Risk level | Example internal target |
|---|---|
| Critical, actively exploited, internet-facing | As soon as safely possible, often within 24–72 hours |
| High risk | Within 7–14 days |
| Moderate risk | Within 30 days |
| Low risk | During the normal maintenance cycle |
These are example internal targets, not universal insurance or regulatory requirements. The appropriate schedule depends on the vulnerability, system, available mitigation, operational risk, and the firm’s policies.
Evidence to collect
- Current patch-compliance reports
- Recent vulnerability-scan results
- A list of unsupported systems
- Documented exceptions and compensating controls
- Remediation tickets and completion records
6. Maintain Protected and Segregated Backups
A backup strategy should prevent one compromised account, server, or network from destroying every recovery copy. The firm should be able to explain what is backed up, how frequently backups run, where copies are stored, and how they are protected.
Backup coverage may include:
- Servers and virtual machines
- Shared files
- Application databases
- Microsoft 365 email
- OneDrive, SharePoint, and Teams data
- Critical cloud applications
- Network-device configurations
- Important employee workstations
Protection may include:
- Separate backup administrator accounts
- Multi-factor authentication
- Encrypted data
- Immutable or deletion-protected copies
- Restricted network access
- Unique credentials
- Monitoring for failed jobs and configuration changes
- A copy isolated from the production environment
Learn more about secure backups through 911 IT’s business continuity services.
7. Prove That Data and Systems Can Be Recovered
Insurance applications may ask whether backups are tested. A successful backup notification does not prove that files, email, databases, or servers can be restored.
A practical testing schedule is:
- Daily: Investigate backup failures
- Monthly: Review protected systems and storage capacity
- Quarterly: Restore representative files, email, and application data
- Quarterly or semiannually: Test recovery of critical servers or applications
- Annually: Conduct a broader disaster-recovery exercise
Evidence to collect
- The date of each recovery test
- The system or data restored
- The requested recovery point
- The time required
- Whether the restored information was usable
- Problems discovered
- Corrective actions and retest dates
Documented recovery tests are stronger evidence than a verbal statement that the provider “checks the backups.”
8. Control Administrator and Privileged Access
Administrator accounts can change security policies, disable protections, access sensitive information, and delete data. A compromised privileged account may allow an attacker to expand a small incident into a major loss.
A financial firm should:
- Maintain an inventory of administrator accounts
- Use named accounts rather than shared credentials
- Separate daily email accounts from administrator accounts
- Enforce MFA
- Grant only the permissions required
- Review privileges quarterly
- Remove unnecessary access promptly
- Monitor administrator activity
- Protect emergency-access credentials
- Restrict vendor and MSP privileges
Evidence to collect
- A current privileged-account list
- The most recent access review
- MFA coverage for administrators
- Role assignments
- Former-provider and former-employee access-removal records
9. Standardize Employee Onboarding and Offboarding
Inactive and former-employee accounts create avoidable risk. Every employee change should trigger a documented workflow covering identity, applications, devices, permissions, and company data.
Onboarding should include
- A unique user account
- Minimum required permissions
- MFA enrollment
- A secured company device
- Approved software and application access
- Security awareness training
- Equipment and access documentation
Offboarding should include
- Disabling sign-in at the approved time
- Revoking active sessions
- Removing administrator privileges
- Preserving business records
- Removing cloud and application access
- Securing or wiping company devices
- Reviewing shared passwords
- Transferring necessary files and email
- Documenting completion
Evidence to collect
- Completed onboarding and offboarding checklists
- A current active-user inventory
- A list of inactive accounts
- Recent access-review reports
- Documentation for terminated employees
10. Maintain and Exercise an Incident-Response Plan
A written incident-response plan should explain what the organization will do after ransomware, account compromise, data exposure, payment fraud, lost equipment, or another serious event.
The plan should define:
- How employees report incidents
- Who leads the response
- Who can isolate devices or disable accounts
- Who contacts the insurer or broker
- When approved legal counsel is involved
- How evidence is preserved
- Who communicates with clients and employees
- How vendors and law enforcement are contacted
- How business operations continue
- How decisions are documented
Coordinate the plan with the insurance policy
Some policies may provide access to approved legal counsel, forensic investigators, notification vendors, negotiators, public relations specialists, or other response resources. The plan should identify the correct insurance contact and any notification or consent requirements.
Do not automatically hire outside vendors, negotiate with attackers, restore systems, or send breach notifications without coordinating with qualified incident-response, legal, insurance, and cybersecurity professionals. Unapproved actions may increase risk or complicate coverage.
Test the plan annually
Conduct a tabletop exercise using a realistic scenario. Measure whether participants know:
- Whom to call
- Who has decision authority
- Where policies and credentials are stored
- Which systems must be restored first
- How the insurer will be notified
- How client and regulatory concerns will be evaluated
11. Review Technology Vendors and Service Providers
A financial firm may depend on cloud platforms, managed IT providers, software vendors, payment processors, data providers, document portals, phone systems, and other third parties. A disruption or breach at one provider can affect the firm’s operations and clients.
A vendor-risk process should include:
- An inventory of critical vendors
- The type of information each vendor can access
- The business service each vendor supports
- Security and privacy requirements
- Contractual notification responsibilities
- Available security reports or certifications
- Backup and recovery responsibilities
- Subcontractor or supply-chain dependencies
- Access-removal procedures
- Alternative providers or continuity plans
Ask how dependent-business losses are addressed
Ask your broker how the policy treats an outage or incident affecting a technology provider rather than your own systems. Coverage definitions, waiting periods, sublimits, and exclusions can differ substantially.
12. Monitor Security Events and Define After-Hours Response
Technology may generate alerts 24 hours a day. The firm should know which events are monitored, who receives them, and what happens when a serious threat occurs at night, on a weekend, or during a holiday.
Monitoring may include:
- Endpoint security alerts
- Microsoft 365 sign-in risk
- Suspicious email activity
- Firewall and network alerts
- Backup failures
- Administrator changes
- Vulnerability findings
- Unusual file activity
- Offline or unprotected devices
A managed IT provider should clearly distinguish between automated monitoring, human investigation, and incident response. Those are related but different services.
What Information Is Commonly Requested on a Cyber Insurance Application?
Application questions vary, but a financial firm may be asked about:
- Annual revenue and number of employees
- Types and quantities of sensitive records
- Past incidents and insurance claims
- Multi-factor authentication
- Endpoint protection
- Email security
- Backups and recovery testing
- Patch and vulnerability management
- Security awareness training
- Remote-access security
- Administrator-account controls
- Incident-response planning
- Payment verification procedures
- Vendor-risk management
- Regulatory or contractual obligations
Never interpret a question more broadly or narrowly merely to produce a preferred answer. Ask the broker or carrier to clarify ambiguous terms, then document the interpretation used.
The 7-Part Application Verification Process
- Assign one business owner. Select an executive responsible for coordinating the application.
- Route technical questions to IT. Do not ask an office manager or executive to estimate security settings.
- Clarify ambiguous language. Confirm what the carrier means by terms such as “all users,” “encrypted,” “offline,” or “24/7 monitoring.”
- Collect evidence. Obtain reports, policies, screenshots, contracts, and test results.
- Document exceptions. Record systems or users not covered and the reason.
- Review the complete application. Leadership, IT, the broker, and appropriate legal or compliance advisors should review answers before submission.
- Preserve the final copy. Save the application, policy, endorsements, evidence, and related correspondence together.
Cyber Insurance Application Evidence Checklist
| Requested evidence | Available | Missing | Owner |
|---|---|---|---|
| Current user and device inventory | |||
| MFA coverage report | |||
| Administrator-account inventory | |||
| Endpoint protection report | |||
| Patch and vulnerability report | |||
| Email-security configuration | |||
| Security training completion report | |||
| Backup coverage report | |||
| Recent recovery-test results | |||
| Incident-response plan | |||
| Incident-response exercise results | |||
| Employee offboarding checklist | |||
| Critical-vendor inventory | |||
| Security-monitoring procedure |
What Cyber Insurance May Cover
Coverage depends on the specific policy, endorsements, exclusions, limits, sublimits, deductibles, and facts of the event. Depending on the contract, a policy may address certain costs related to:
- Legal and breach-response services
- Digital forensics
- Data restoration
- Business interruption
- Notification and credit-monitoring services
- Public relations support
- Cyber extortion response
- Privacy claims
- Regulatory investigations or penalties where insurable
- Third-party claims
- Incidents involving certain technology providers
This list is not a representation that any particular loss will be covered. Review the actual policy with a qualified cyber insurance broker and legal counsel.
What May Require Separate or Additional Coverage?
Some losses may be excluded, restricted, or addressed through separate endorsements or policies. Ask specifically about:
- Fraudulent transfer of funds
- Social engineering and invoice manipulation
- Telecommunications fraud
- Hardware replacement
- Reputational harm
- Losses caused by unapproved vendors
- Incidents involving unsupported systems
- Extended cloud-provider outages
- Prior known incidents
- Contractual liabilities
- War, infrastructure, or systemic-event exclusions
- Events occurring before the policy period
A cyber policy should not be assumed to cover every form of technology failure, crime, theft, fraud, or business interruption. Ask the broker how cyber, crime, professional liability, property, and other policies interact.
10 Policy Terms Financial Firms Should Review
1. Coverage limit
Determine the maximum amount available and whether one limit applies to all losses.
2. Sublimits
Some categories may have lower limits than the primary policy limit.
3. Deductible or retention
Confirm the amount the firm must absorb before coverage applies.
4. Waiting period
Business-interruption coverage may begin only after a defined period of downtime.
5. Retroactive date
Review whether incidents beginning before a certain date are excluded.
6. Approved vendors
Understand whether the firm must use designated legal, forensic, notification, or recovery providers.
7. Consent requirements
Determine which expenses or actions require insurer approval.
8. Dependent-business coverage
Review protection for incidents affecting important vendors or cloud providers.
9. Security-control representations
Confirm that statements about MFA, backups, monitoring, encryption, and other safeguards are accurate.
10. Notification deadlines
Document whom to contact and how quickly suspected incidents must be reported.
How Much Cyber Insurance Does a Financial Firm Need?
There is no universal coverage amount for every 25–50 employee financial firm. The decision should consider:
- The quantity and sensitivity of client records
- Annual revenue
- Estimated daily cost of downtime
- Contractual requirements
- Potential legal and notification costs
- Dependence on cloud applications
- Payment and funds-transfer exposure
- Regulatory responsibilities
- Business-continuity capabilities
- Worst-case recovery scenarios
Leadership should work with the broker, legal counsel, finance professionals, and technical advisors to estimate realistic losses. The lowest premium should not be the only selection factor.
A Practical Cyber Loss Estimate
Consider a 35-employee financial firm that depends on Microsoft 365, cloud financial applications, shared client documents, and remote access.
A serious cyber incident could create costs across several categories:
| Cost category | Questions to estimate |
|---|---|
| Business interruption | How much revenue and employee productivity could be lost each day? |
| Technical recovery | What would forensic investigation, containment, and restoration cost? |
| Legal response | What advice, notification analysis, and contractual review may be required? |
| Client response | What communication, support, or monitoring services may be needed? |
| Third-party claims | Could clients or vendors allege financial or privacy harm? |
| Fraud | Could payment instructions or banking information be manipulated? |
| Vendor outage | What happens if a critical cloud provider is unavailable? |
This exercise helps leadership evaluate whether the proposed limit, deductible, waiting period, and sublimits align with the firm’s actual exposure.
Common Cyber Insurance Mistakes
- Waiting until the week before renewal. Important security gaps may require weeks to correct and document.
- Answering technical questions from memory. Verify every response with reports and configuration evidence.
- Confusing “enabled” with “enforced.” A feature available to users may not protect every account.
- Assuming an MSP handles everything. Confirm the provider’s contractual scope and identify client responsibilities.
- Failing to document exceptions. One unprotected server or administrator account can make a broad answer inaccurate.
- Not preserving the application. Keep the submitted answers and supporting evidence with the policy.
- Buying a policy based only on price. Review exclusions, sublimits, waiting periods, vendors, and incident procedures.
- Assuming cyber insurance covers fraud. Funds-transfer and social-engineering losses may require specific language or separate coverage.
- Never testing the incident plan. Employees may not know whom to contact during an emergency.
- Treating insurance as a substitute for security. Insurance transfers a portion of financial risk; it does not prevent attacks or restore operations by itself.
Red Flags to Correct Before Renewal
- Some employees do not use MFA
- Administrators share accounts
- Remote access is protected only by a password
- Endpoint protection is missing from devices
- No one monitors security alerts after hours
- Former employees still have active accounts
- Backups use the same credentials as production systems
- No recent recovery test exists
- Unsupported software remains in use
- Critical vulnerabilities remain unresolved
- No written incident-response plan exists
- The firm cannot produce a complete asset or vendor inventory
These findings do not automatically determine whether coverage will be available. They should be treated as business risks requiring documented decisions and remediation.
A 90-Day Cyber Insurance Readiness Plan
Days 1–30: Assess and Verify
- Request the renewal application early
- Assign an executive application owner
- Inventory users, devices, administrators, applications, and vendors
- Verify MFA coverage
- Review endpoint and email protection
- Examine patch and vulnerability reports
- Confirm backup scope and ownership
- Review the current insurance policy and endorsements
Days 31–60: Correct High-Risk Gaps
- Enforce MFA where supported
- Protect remote and administrator access
- Deploy missing endpoint-security agents
- Correct critical patching gaps
- Remove former-employee access
- Strengthen backup security
- Update employee security training
- Document payment-verification procedures
Days 61–90: Test and Submit
- Conduct a backup recovery test
- Run an incident-response exercise
- Complete a privileged-access review
- Collect final security evidence
- Review application answers with technical personnel
- Clarify ambiguous questions with the broker
- Obtain appropriate legal or compliance review
- Preserve the completed application and evidence
Cyber Insurance Readiness Scorecard
| Requirement | Complete | Incomplete | Evidence available |
|---|---|---|---|
| MFA is enforced for applicable accounts | |||
| Remote access requires MFA | |||
| Endpoint detection covers supported devices | |||
| Email and impersonation protections are active | |||
| Employees receive recurring security training | |||
| Critical vulnerabilities are remediated promptly | |||
| Backups are isolated or deletion-protected | |||
| Recovery tests are documented | |||
| Administrator access is reviewed quarterly | |||
| Employee offboarding is documented | |||
| An incident-response plan exists | |||
| The incident plan has been exercised | |||
| Critical vendors are assessed | |||
| Security alerts receive a defined response |
15 Questions to Ask Your Insurance Broker
- Which cybersecurity controls does the carrier expect?
- How does the policy define multi-factor authentication?
- Are any coverage sections subject to lower sublimits?
- How are ransomware and cyber extortion addressed?
- How are fraudulent transfers and social engineering addressed?
- Does the policy cover business interruption?
- What waiting period applies?
- How are incidents involving cloud providers or vendors addressed?
- Which legal, forensic, and response vendors may be used?
- Which expenses require advance approval?
- How quickly must a suspected incident be reported?
- What exclusions deserve special attention?
- How do the cyber and crime policies interact?
- What evidence should we preserve with the application?
- What changes must be reported during the policy period?
15 Questions to Ask Your IT Provider
- Is MFA enforced for every applicable employee?
- Does MFA protect remote and administrator access?
- Are all supported computers and servers covered by EDR?
- Who monitors security alerts after hours?
- Which email and impersonation controls are enabled?
- When was the most recent vulnerability assessment?
- How quickly are critical vulnerabilities corrected?
- Which systems and cloud services are backed up?
- Can one administrator delete every backup copy?
- When was the last documented restore test?
- How many administrator accounts exist?
- Are former-employee accounts removed promptly?
- Do we have a written incident-response plan?
- When was the plan last exercised?
- Can you provide evidence supporting every technical insurance answer?
How 911 IT Helps Financial Firms Prepare for Cyber Insurance
911 IT helps financial organizations evaluate and document the technical safeguards commonly reviewed during cyber insurance applications and renewals. Services include:
- Multi-factor authentication
- Microsoft 365 identity and security management
- Endpoint detection and response
- Email and phishing protection
- 24/7 threat monitoring
- Patch and vulnerability management
- Security awareness training
- Protected backups
- Recovery testing and business continuity
- Administrator and user-access reviews
- Incident-response planning
- Technology documentation and reporting
Explore 911 IT’s cybersecurity services, business continuity services, and specialized IT support for financial firms.
Take One Action This Week
Request a copy of your current cyber insurance application and ask your IT provider to verify every technical answer. For each “Yes” response, require one supporting report, policy, screenshot, test result, or contract provision.
Create a remediation list for any response that cannot be verified. Assign an owner and deadline, then begin corrections at least 60–90 days before the next renewal.
Schedule a Cyber Insurance Readiness Assessment
A useful readiness assessment should verify security controls, identify unsupported application answers, document exceptions, and produce a prioritized improvement plan. It should not guarantee insurance eligibility, pricing, coverage, or claim payment.
Schedule a discovery call with 911 IT to review your MFA coverage, endpoint protection, email security, backups, recovery testing, incident-response plan, administrator access, and insurance documentation.
