What Security Controls Do Cyber Insurance Carriers Expect?
Insurance agencies applying for or renewing cyber insurance should be prepared to demonstrate at least 8 core cybersecurity controls: multi-factor authentication, endpoint detection and response, email security, security awareness training, vulnerability and patch management, protected backups, access controls, and an incident response plan.
Cyber insurance requirements vary by carrier, policy, coverage limit, business size, technology environment, and claims history. No single checklist guarantees approval. However, agencies that cannot document basic protections may face higher premiums, reduced coverage, added exclusions, lower limits, or difficulty obtaining a policy.
For an insurance agency with 25-50 employees, the strongest approach is to assess security before the renewal application arrives, correct the highest-risk gaps, and retain evidence showing that each control is active and regularly managed.
The 8 Core Cybersecurity Controls for Cyber Insurance Readiness
- Multi-factor authentication
- Endpoint detection and response
- Email security and anti-phishing protection
- Employee security awareness training
- Vulnerability scanning and patch management
- Protected, tested backups
- Access control and account management
- Incident response planning and monitoring
These controls should operate together. Multi-factor authentication cannot replace backups. Antivirus cannot replace employee training. A written incident response plan cannot replace active monitoring. Cyber insurance readiness requires a layered security program rather than one product.
1. Multi-Factor Authentication
Multi-factor authentication, commonly called MFA, requires a user to provide more than a password before accessing an account. The second factor may be an authenticator application, hardware security key, device prompt, biometric check, or temporary code.
MFA should be considered for systems such as:
- Microsoft 365
- Remote access and virtual private networks
- Agency-management platforms
- Accounting and payment systems
- Cloud storage
- Administrative accounts
- Backup platforms
- Firewall and network-management portals
- Remote monitoring and management tools
- Carrier and vendor portals where supported
A password can be stolen through phishing, malware, reuse, social engineering, or an unrelated data breach. MFA adds another barrier that may prevent a stolen password from becoming a successful account takeover.
MFA Should Cover More Than Administrators
Some organizations enable MFA only for owners, managers, or IT administrators. That leaves ordinary employee accounts exposed even though those accounts may contain client communications, attachments, policy information, and access to shared files.
Agencies should identify every system that supports MFA, document any exceptions, and avoid relying on less secure verification methods when stronger options are practical.
Questions to Ask About MFA
- Is MFA enabled for every Microsoft 365 user?
- Are administrative accounts protected with stronger controls?
- Is MFA required for remote network access?
- Which agency and carrier applications support MFA?
- How are lost or replaced authentication devices handled?
- Are emergency access accounts documented and monitored?
- Can older authentication methods bypass MFA?
2. Endpoint Detection and Response
Endpoint detection and response, or EDR, monitors computers and servers for suspicious behavior. Unlike traditional antivirus, EDR is designed to identify activities such as ransomware behavior, credential theft, malicious scripts, unauthorized persistence, and unusual system changes.
An effective endpoint security program should address:
- Agency-owned desktops and laptops
- Remote employee computers
- Servers
- Supported virtual systems
- Devices that access sensitive client information
The security platform should be actively managed. Installing software is not enough if no one reviews alerts, isolates affected devices, investigates suspicious behavior, or confirms that every required computer remains protected.
What to Document
For cyber insurance applications, an agency may need to know:
- The endpoint security product in use
- The percentage of covered devices
- Whether protection is centrally managed
- Whether alerts are monitored
- Who investigates security events
- Whether devices can be isolated remotely
- How missing or inactive security agents are identified
911 IT provides layered endpoint, network, identity, email, and threat-monitoring services through its cybersecurity services.
3. Email Security and Anti-Phishing Protection
Email remains one of the most common ways criminals attempt to steal passwords, distribute malware, redirect payments, and impersonate executives, clients, carriers, or vendors.
An insurance agency's email security strategy should include:
- Spam and malware filtering
- Phishing and impersonation detection
- Protection against malicious links and attachments
- Domain authentication and anti-spoofing controls
- Multi-factor authentication
- Suspicious forwarding-rule monitoring
- External sender identification where appropriate
- A simple process for employees to report suspicious messages
Business Email Compromise
Business email compromise occurs when a criminal impersonates or takes control of a trusted account. The attacker may request a payment, change banking details, redirect a commission, obtain sensitive documents, or send additional phishing messages from a legitimate mailbox.
Agencies should establish an independent verification process for:
- Changes to banking information
- Urgent payment requests
- Requests for confidential client records
- Password or multi-factor authentication reset requests
- Unexpected changes in vendor instructions
- Requests that bypass normal approval procedures
Email filtering reduces risk, but employees still need procedures for verifying unusual requests through a known phone number or another trusted communication method.
4. Employee Security Awareness Training
Employees make security decisions throughout the workday. They open attachments, approve login prompts, handle client records, share files, answer calls, and respond to payment requests. Recurring training helps employees recognize threats and report them before a small mistake becomes a major incident.
Training should cover:
- Phishing emails
- Malicious links and attachments
- Unexpected multi-factor authentication prompts
- Password safety
- Payment and invoice fraud
- Social engineering by phone or text
- Safe handling of client information
- Remote-work security
- Lost or stolen devices
- How to report a suspected incident
Training Should Be Recurring and Measurable
A single annual presentation is easy to forget. A stronger program uses short recurring lessons, simulated phishing exercises, targeted coaching, and documented completion.
Useful measurements may include:
- Training completion rate
- Simulated phishing failure rate
- Simulated phishing reporting rate
- Repeat failures
- Time required to report a suspicious message
- Completion of additional coaching
The goal is not to embarrass employees. It is to build habits that help the agency identify threats earlier.
5. Vulnerability Scanning and Patch Management
Cybercriminals frequently exploit known weaknesses in operating systems, applications, firewalls, remote-access tools, and network devices. Vulnerability management helps the agency identify weaknesses, prioritize them, apply corrections, and verify that the risk has been reduced.
A complete process includes:
- Maintain an accurate inventory of devices and software.
- Scan for known vulnerabilities.
- Prioritize findings by severity and business exposure.
- Apply patches or other corrective controls.
- Confirm that remediation succeeded.
- Document approved exceptions and replacement plans.
Patch Management
Patch management should cover supported operating systems and, where practical, commonly used third-party applications. The MSP should monitor installation failures and identify computers that are offline, unmanaged, or unable to receive updates.
Critical vulnerabilities may require urgent action, while other updates may need testing to reduce the risk of interrupting agency applications.
Unsupported Technology
Unsupported operating systems, applications, servers, and network equipment may no longer receive security updates. Cyber insurance applications may ask whether the organization uses end-of-life technology.
The agency should maintain a replacement schedule and document any temporary exception, compensating protection, and target replacement date.
6. Protected and Tested Backups
Backups provide a recovery path after ransomware, accidental deletion, hardware failure, malicious activity, or a cloud-service problem. Cyber insurance applications may ask how frequently data is backed up, whether copies are isolated, and whether recovery is tested.
A defensible backup strategy should define:
- Which systems and data are protected
- How frequently backups occur
- Where copies are stored
- How long backups are retained
- Whether backup data is encrypted
- How backups are protected from ransomware
- Who receives and investigates failure alerts
- How often restoration is tested
- How quickly critical systems can be recovered
- How much recent data the agency could afford to lose
Separate Backup Credentials
Backup systems should not depend entirely on the same accounts and credentials used for everyday operations. If a criminal gains administrative access to the agency's network, separate protections may prevent the attacker from deleting or encrypting recovery copies.
Microsoft 365 Backup
Agencies should confirm how Microsoft 365 email, SharePoint, OneDrive, and Teams data are retained and restored. Cloud availability is not the same as a complete backup and recovery strategy.
Review backup, recovery, and continuity options through 911 IT's business continuity services.
Test Recovery Before an Emergency
A backup report showing successful jobs does not prove that the agency can restore a mailbox, file, server, or application within the required timeframe. Recovery testing should be performed before an actual incident and should produce documented results.
7. Access Control and Account Management
Employees should have access to the information and applications required for their roles, but they should not automatically receive broad administrative privileges or access to every client file.
An access-control program should address:
- Unique accounts for each employee
- Role-based access
- Least-privilege permissions
- Administrative account separation
- Shared-account reduction
- Regular access reviews
- Prompt employee offboarding
- Vendor and contractor access
- Remote-access restrictions
- Logging of important administrative activity
Administrative Privileges
Employees generally should not use administrative accounts for routine email, browsing, or document work. Separate privileged accounts reduce the opportunity for malware or stolen credentials to gain broad control.
Employee Offboarding
When an employee leaves, the agency should have a documented process to:
- Disable accounts at the approved time.
- Revoke active sessions.
- Remove remote access.
- Recover agency-owned devices.
- Preserve required business records.
- Transfer ownership of files and mailboxes.
- Remove application and carrier-system access.
- Change shared credentials known by the employee.
- Recover reusable licenses.
- Confirm and document completion.
Delays in offboarding can leave former employees or compromised accounts with unnecessary access to sensitive systems.
8. Incident Response Planning and Security Monitoring
An incident response plan defines what the agency will do when it suspects ransomware, account compromise, data exposure, payment fraud, lost equipment, unauthorized access, or another security event.
The plan should identify:
- How employees report a suspected incident
- Who has authority to declare an incident
- Who coordinates technical containment
- Who contacts the cyber insurance carrier
- Who contacts legal counsel and the insurance broker
- How evidence and system logs are preserved
- How affected accounts and devices are isolated
- Who approves external communication
- How recovery decisions are made
- How the agency reviews lessons after the event
Do Not Wait Until an Incident to Find Contact Information
The plan should include current contact details for:
- Agency leadership
- The managed IT and cybersecurity provider
- The cyber insurance carrier or breach hotline
- Insurance broker
- Legal counsel
- Digital forensics resources
- Critical software vendors
- Internet and communication providers
- Public relations or client communication support where appropriate
Copies of the plan should remain available even if the agency's normal email, server, or document system is unavailable.
Practice the Plan
A tabletop exercise allows decision-makers to walk through a realistic scenario without causing an actual outage. For example, the agency may practice responding to a compromised Microsoft 365 administrator, ransomware on a shared server, or fraudulent payment instructions sent from an employee mailbox.
The exercise should identify unclear responsibilities, unavailable contact information, recovery gaps, and decisions that require leadership approval.
Additional Controls That May Appear on a Cyber Insurance Application
Depending on the carrier, business, coverage, and technology environment, an application may also ask about:
- Network segmentation
- Managed firewalls
- Secure remote access
- Mobile device management
- Device encryption
- Data encryption
- Penetration testing
- Security risk assessments
- Privileged access management
- Domain protection
- Data retention and disposal
- Vendor risk management
- Logging and security event retention
- Security operations monitoring
- Written security policies
- Business continuity planning
The agency should answer every application question accurately. The MSP can provide technical evidence and explanations, but the agency, broker, insurer, and legal counsel remain responsible for interpreting the application and policy.
A 7-Step Cyber Insurance Readiness Process
Step 1: Obtain the Application Early
Ask the broker or carrier for the current application and supplemental security questions well before renewal. Requirements can change, and an older questionnaire may not reflect the next policy period.
Step 2: Inventory Systems, Accounts, and Data
Document employees, computers, servers, cloud platforms, remote-access tools, agency applications, vendors, and locations. The agency cannot verify protection for systems it has not identified.
Step 3: Perform a Security Assessment
Compare current protections against the application, recognized security practices, business risks, and the agency's contractual responsibilities.
The assessment should identify:
- Missing controls
- Partially implemented controls
- Unsupported technology
- Unprotected devices
- Weak administrative practices
- Backup and recovery gaps
- Missing documentation
One client in 911 IT's testimonial collection reported that a security audit identified and corrected previously unknown risks and described the information as worth significantly more than the audit cost.
Step 4: Prioritize the Highest-Risk Gaps
Correct the issues most likely to create a serious loss or affect coverage first. Common priorities include missing MFA, unmanaged endpoints, exposed remote access, unsupported systems, weak backups, and excessive administrative privileges.
Step 5: Implement and Verify Controls
After deploying a control, verify that it covers the required users, devices, accounts, and locations. A policy stating that MFA is required is not enough if several accounts can still sign in without it.
Step 6: Collect Evidence
Maintain documents that support application answers, such as:
- MFA coverage reports
- Endpoint security inventory
- Patch and vulnerability reports
- Backup and recovery-test records
- Training completion records
- Security policies
- Incident response plan
- Access-review records
- Network and system inventory
- Risk assessment and remediation plan
Step 7: Review Before Every Renewal
Cyber insurance readiness is not a one-time project. Review controls, documentation, claims questions, and technology changes before each renewal and after major business changes.
Common Reasons Cyber Insurance Applications Create Problems
| Security Gap | Why It Matters |
|---|---|
| MFA is not enabled for every applicable user | A stolen password may provide direct access to email, files, or remote systems. |
| Endpoint protection is installed but not monitored | Security alerts may remain uninvestigated while an attacker continues operating. |
| Backups use the same credentials as production systems | An attacker may be able to damage both live data and recovery copies. |
| Backups have never been restored | The agency does not know whether recovery will work during an actual emergency. |
| Unsupported systems remain in use | Known weaknesses may remain unpatched. |
| Employees share accounts | Activity cannot be attributed reliably, and access is harder to remove. |
| Former employee accounts remain active | Unused credentials may provide unauthorized access. |
| No incident response plan exists | Critical decisions and notifications may be delayed during an emergency. |
| Application answers are based on assumptions | The agency may unintentionally provide inaccurate information. |
| No evidence supports security claims | The agency may struggle to demonstrate that controls were active and maintained. |
How to Answer Cyber Insurance Questions Accurately
Cyber insurance questions are often written in technical language. Avoid answering "yes" merely because a related product is installed.
For every question, determine:
- What systems, users, or locations the question covers.
- Whether the control is fully or partially implemented.
- Whether any exceptions exist.
- Whether the control is actively monitored or reviewed.
- What evidence supports the answer.
- Who has confirmed the technical details.
Example: Multi-Factor Authentication
An agency should not answer that MFA is universally enabled when it protects Microsoft 365 but not remote access, administrative tools, or another system included in the question.
Example: Backups
An agency should not describe backups as isolated or immutable unless the configuration has been confirmed. Separate cloud storage does not automatically mean the backups cannot be changed or deleted.
Example: Security Monitoring
Installing endpoint security is different from providing 24/7 security monitoring. Confirm who reviews alerts, when coverage is available, and what actions the monitoring team can take.
When a question remains unclear, ask the broker or carrier for clarification and obtain guidance from qualified legal or insurance professionals.
Cyber Insurance Does Not Replace Cybersecurity
A cyber insurance policy may help the agency respond financially and operationally to a covered incident. It does not prevent the incident, restore trust automatically, or eliminate the agency's responsibility to maintain appropriate protections.
Even when a claim is covered, an agency may still experience:
- Business interruption
- Employee downtime
- Client concern
- Lost opportunities
- Legal and regulatory work
- System rebuilding
- Vendor disruption
- Reputational damage
- Policy deductibles and uncovered expenses
The best strategy combines risk reduction, incident preparation, reliable recovery, and suitable insurance coverage.
How Managed IT Services Support Cyber Insurance Readiness
A managed IT provider can help maintain the technical foundation required for ongoing security and reliable application answers.
Relevant services may include:
- Microsoft 365 security administration
- Multi-factor authentication deployment
- Endpoint security management
- Email protection
- Patch management
- Vulnerability scanning
- Firewall and network management
- Backup monitoring and recovery testing
- Employee onboarding and offboarding
- Security awareness training
- Documentation and reporting
- Incident response planning
- Coordination with brokers and carriers
911 IT combines managed IT services, cybersecurity, business continuity, and cloud services to help businesses maintain security controls and reliable technology operations.
A Practical Cyber Insurance Readiness Scenario
Consider a 40-person independent insurance agency preparing for renewal. The application asks about MFA, endpoint security, employee training, backups, vulnerability management, administrative access, and incident response.
The initial assessment finds:
- MFA is enabled for most Microsoft 365 users but not every administrator.
- Several remote computers are missing active endpoint protection.
- Security training was completed once more than a year ago.
- Server backups are running, but Microsoft 365 data is not covered by a separate recovery plan.
- No recent restoration test has been documented.
- Two former employee accounts remain active.
- The incident response plan does not contain current broker and carrier contact details.
The agency creates a 45-day remediation plan:
- Require MFA for all supported accounts.
- Bring every business device under centralized endpoint management.
- Launch recurring security awareness training.
- Add appropriate Microsoft 365 data protection.
- Perform and document restoration tests.
- Disable unused accounts and review permissions.
- Update and exercise the incident response plan.
- Collect evidence for each completed control.
By starting before renewal, the agency has time to make accurate application statements instead of rushing to deploy controls after the insurer requests additional information.
Cyber Insurance Readiness Checklist
Use this checklist to prepare for an application or renewal:
- Obtain the current application from the broker or carrier.
- Confirm MFA coverage for email, remote access, administrators, and critical cloud services.
- Verify that every business computer has active, managed endpoint protection.
- Review email security and anti-phishing controls.
- Complete recurring employee security training.
- Run vulnerability scans and remediate critical findings.
- Confirm that operating systems and applications remain supported.
- Document patch-management procedures.
- Review administrative privileges and shared accounts.
- Disable former employee and unused accounts.
- Confirm which servers, cloud services, and applications are backed up.
- Verify that backup copies are protected from production-system compromise.
- Perform and document recovery tests.
- Update the incident response plan.
- Conduct a tabletop exercise.
- Maintain a current device, account, software, and vendor inventory.
- Collect reports and evidence supporting application answers.
- Ask the broker or carrier to clarify ambiguous questions.
- Have qualified professionals review legal and insurance interpretations.
- Repeat the review before every renewal.
Questions to Ask an MSP About Cyber Insurance Readiness
- Can you assess our controls against the current application?
- Can you verify MFA coverage across all applicable systems?
- Which endpoint security platform do you manage?
- Who monitors and responds to security alerts?
- How do you identify unprotected or inactive devices?
- How frequently do you scan for vulnerabilities?
- How quickly are critical security updates addressed?
- How are Microsoft 365 identities and data protected?
- How are backups isolated from ransomware?
- How often do you test recovery?
- Do you provide recurring security awareness training?
- Can you help us create and test an incident response plan?
- What documentation can you provide for our application?
- Can you coordinate technical questions with our broker or carrier?
- How do you handle employee onboarding and offboarding?
- How do you review administrative access?
- Which services are included in our monthly agreement?
- Which readiness projects would require separate pricing?
Frequently Asked Questions
Is multi-factor authentication required for cyber insurance?
Many cyber insurance applications ask whether MFA protects email, remote access, administrative accounts, and other important systems. Requirements vary by carrier and policy, so the agency should review the current application and confirm the exact scope.
Is antivirus enough to qualify for cyber insurance?
Basic antivirus alone is generally not a complete security program. Applications may ask about centrally managed endpoint detection and response, alert monitoring, email protection, backups, MFA, training, vulnerability management, and incident response.
Do small insurance agencies need endpoint detection and response?
Small agencies still handle valuable client information and rely heavily on email and cloud systems. Managed endpoint protection can help identify ransomware, malicious scripts, credential theft, and other suspicious behavior that traditional antivirus may miss.
How often should employees receive security training?
Training should be recurring rather than limited to a one-time event. The appropriate schedule depends on risk and policy requirements, but many organizations use short lessons and phishing simulations throughout the year.
Does Microsoft 365 include everything needed for backup?
Microsoft provides availability and retention features, but agencies should confirm whether those capabilities meet their recovery needs. A separate Microsoft 365 backup service may be appropriate for email, SharePoint, OneDrive, and Teams data.
How often should backups be tested?
Recovery testing should occur on a recurring schedule based on the importance of each system. The agency should document the test, the data or system restored, the time required, and any corrective action.
What is an immutable backup?
An immutable backup is designed so that stored recovery data cannot be altered or deleted during a defined retention period. The exact technical implementation varies, so agencies should verify the configuration rather than relying only on a product label.
Can an MSP complete the cyber insurance application?
An MSP can provide technical facts, reports, and explanations. Agency leadership should review the answers and work with the broker, insurer, legal counsel, and other qualified advisors before submitting the application.
What happens if an application answer is inaccurate?
Inaccurate statements may create serious coverage and claim issues. The agency should answer carefully, document supporting evidence, disclose exceptions where required, and obtain professional guidance when a question is unclear.
How early should an agency prepare for renewal?
Begin several months before renewal whenever possible. Early preparation gives the agency time to obtain the current application, assess controls, correct gaps, test recovery, and gather documentation.
Does cyber insurance cover every cyber incident?
No. Coverage depends on the policy's terms, limits, deductibles, exclusions, conditions, and facts surrounding the incident. The agency should review coverage questions with its broker, carrier, and legal counsel.
What is the most important first step?
Obtain the current insurance application and complete a documented security assessment. That establishes which protections are already in place, which answers require verification, and which gaps should be corrected first.
Prepare Before the Renewal Deadline
Cyber insurance readiness is easier when the agency treats it as a year-round security program rather than a last-minute application exercise.
Focus first on the eight core controls:
- Multi-factor authentication
- Endpoint detection and response
- Email security
- Employee training
- Vulnerability and patch management
- Protected and tested backups
- Access control
- Incident response and monitoring
Then verify that each control covers the correct users, devices, accounts, applications, and locations. Keep evidence current and review the program whenever the agency changes technology, adds employees, opens an office, acquires another business, or approaches policy renewal.
911 IT has served businesses since 2004 and provides 24/7 access to support, managed cybersecurity, proactive monitoring, backup and continuity planning, and security awareness services. Its cybersecurity approach includes threat monitoring, firewall and network protection, phishing prevention, employee training, encryption, and secure backup solutions.
Need to identify security gaps before your next cyber insurance application? Schedule a discovery call with 911 IT to review your MFA coverage, endpoint protection, Microsoft 365 security, backups, vulnerability management, and incident response readiness.
