Cyber insurance readiness: what underwriters now require
Cyber insurance has changed. The questionnaires are longer, the required controls are more specific, and underwriters increasingly verify answers rather than accept them. Organizations that were insurable three years ago on the strength of a short application now face declined applications, significant exclusions, or claims denied after an incident because a stated control was not in place.
This guide covers how underwriting actually works now, the specific controls underwriters focus on, what happens when an answer is weak, and how to prepare the evidence that supports a strong application. It is not specific to one market or broker; it draws on patterns across the cyber insurance market as it currently operates in Europe and internationally, using EU framing for regulation: NIS2, DORA, and GDPR where relevant.
- Cyber insurance is now effectively a security controls audit. The application asks what controls you have; underwriters increasingly verify whether they actually work.
- The controls underwriters focus on are a short, consistent list: MFA, EDR, tested backups, access control, offboarding, email security, patching, incident response, awareness training, and network segmentation.
- A weak answer does not always mean a declined application. It may mean a higher premium, a sublimit, a specific exclusion, or a condition that requires control improvement within a defined window.
- Claims are denied when a stated control was not in place at the time of the incident. Answering untruthfully on an application is grounds for claim denial and, in the worst case, insurance fraud.
- An identity and access assessment directly addresses the questions underwriters ask most, producing the evidence needed for the access control and offboarding sections of the questionnaire.
- Self-insurance and funded reserves are valid complements to commercial cover, particularly when premiums are high or specific risks cannot be covered commercially.
why cyber insurance got harder to obtain and renew
Three dynamics drove the change, and they are structural, not temporary. First, claim costs rose. Ransomware became the dominant cause of cyber insurance claims, with incident costs increasing sharply as attackers became more sophisticated at setting ransom amounts proportional to what organizations are covered for. Insurers absorbed significant losses and tightened underwriting in response.
Second, underwriters realized they had been writing cover without properly understanding what controls were in place. Applications asked broad questions and accepted statements at face value. When claims came in, insurers discovered that stated controls did not exist, were partially deployed, or had not been tested.
Third, the coverage market professionalized. Insurers brought in security expertise. Questions became more specific. Some insurers now use external security ratings or technical assessments as part of underwriting, not just questionnaire responses. The result is a market where the application process is substantively different from what it was five years ago. The organizations that navigate this well treat the application as an assessment, not a form to complete.
how underwriting now works
The core mechanism is a security controls questionnaire. Insurers use different questionnaires, but the content overlaps significantly, and the direction of change is toward more specificity. The questionnaire asks whether specific controls exist, then for the most significant ones asks about scope (is MFA on all admin accounts or just some?), exceptions (are there accounts where MFA is not enforced, and why?), and testing (when was the backup last tested by restoring it?).
Controls fully in place, well-documented, and tested are a positive signal. Controls partially deployed trigger follow-up questions. Controls absent are either a red flag that affects coverage terms or a condition the insurer requires resolved before or shortly after binding. Some insurers use third-party security rating services that assess your external-facing posture; if your external posture and your questionnaire answers conflict, underwriters ask questions.
The truthfulness requirement is absolute. Answering that a control is in place when it is not is grounds for claim denial. An incident that reveals a material misrepresentation in the application exposes the organization to having coverage voided. The most useful orientation is to treat the questionnaire as a gap analysis: questions you cannot answer confidently point to areas where controls are absent or undocumented, and addressing those gaps before the application strengthens it.
the controls underwriters require
Multi-factor authentication (MFA). MFA is the single highest-weighted control in most questionnaires, covering email, VPN and remote access, admin accounts, and cloud infrastructure. Partial MFA coverage is now a common source of adverse outcomes. Admin accounts without MFA are the highest-risk gap. MFA blocks more than 99.2% of account-compromise attacks (Microsoft). Questions include whether MFA is required for all remote access, whether admin accounts have it enforced without exceptions, and whether legacy applications that bypass SSO are protected.
Endpoint detection and response (EDR). Underwriters ask whether EDR is deployed across endpoints and actively monitored, including coverage percentage and whether alerts are reviewed by a qualified person or team. Some distinguish basic antivirus from behavioral EDR and score them differently.
Tested backups and recovery capability. The detail added is around testing. Underwriters ask when the backup was last restored in a test, whether backups are stored offline or separated from production, and the recovery time objective for critical systems. Backups that exist but have never been tested are a weaker answer. Backups connected to production may be encrypted in a ransomware event along with primary data.
Access control and least privilege. This covers how access is managed, whether it is provisioned by role, and how long it takes to revoke. Questions include whether a formal access review process exists, how frequently it runs, and whether privileged access is separated from standard user access. The use of stolen credentials was involved in 36% of breaches (Verizon DBIR), so these questions correlate directly with the credential-based breach scenario that drives most claims.
Offboarding and joiner-mover-leaver (JML) process. Underwriters ask how quickly access is removed when someone leaves and whether the process covers all applications or only the primary directory. 83% of employees admit they still have access to at least one account from a previous employer (Beyond Identity, 2022, self-reported). Questions include whether offboarding is automated or manual, the target time window, and whether SaaS applications outside the main directory are covered.
Email security. Email is the primary vector for phishing, the most common initial access method in breach claims. Underwriters ask about email filtering, whether DMARC/DKIM/SPF records are configured, and whether users receive phishing simulation training. DMARC policy set to p=none is a weaker answer than p=quarantine or p=reject.
Vulnerability and patch management. Questions cover scanning frequency, patching cadence for critical patches, and whether internet-facing systems are prioritized. Underwriters focus on whether known exploited vulnerabilities are remediated promptly, and some ask about end-of-life software.
Incident response plan. Underwriters ask whether a documented plan exists, when it was last reviewed, and whether it has been tested through a tabletop exercise. A plan that exists only as a document and has never been exercised is scored differently. It should cover notification obligations under GDPR and NIS2.
Security awareness training. Questions cover whether training is provided, how frequently, and whether it includes phishing simulation. The evidence question is whether completion is tracked.
Network segmentation. Underwriters ask whether production systems, critical infrastructure, and sensitive data are segmented from general networks. The assessment scenario is ransomware lateral movement. Questions include whether backups are on a separate segment and whether there is any air-gapping.
what a weak answer costs you
A weak answer does not automatically result in declined cover. Underwriters have several levers.
Higher premium. The relationship between control quality and premium is direct. Organizations with strong controls across all domains pay less than those with gaps.
Sublimits. A sublimit caps coverage for a specific loss type below the overall limit. An organization with gaps in ransomware-relevant controls may receive a policy with a ransomware sublimit well below the headline amount. In a ransomware claim, the sublimit is what applies.
Exclusions. Underwriters may exclude specific risk categories entirely. An organization with no tested backups may receive a policy that excludes ransomware-related business interruption, discovered only when it files a claim.
Coverage conditions. Insurers can bind coverage on the condition that specified controls are improved within a defined window, typically three to six months. Missing the deadline is grounds for policy adjustment.
Declined application. For the most significant gaps, no MFA on admin accounts, no backups, no incident response plan, some insurers decline to write cover, more commonly in higher-risk industries or after a prior claim.
Claim denial after incident. This is the worst outcome. The investigation finds that a control stated as in place was not, and the insurer may deny the claim in part or in full. The answer to the questionnaire should be the current state, with qualifications where controls are partially deployed and compensating controls noted where full implementation is not yet in place.
how to prepare for renewal: what works
Starting at least three months before renewal gives time to close the most significant gaps. The preparation that produces a strong application works through the same domains the questionnaire covers, treating each as an internal assessment before submission.
It starts with the questionnaire itself. Working through the format the primary underwriter uses, as an internal assessment, turns every question you cannot answer confidently into a gap to address. Auditing MFA coverage means exporting enrollment status from the identity provider and identifying every account where MFA is not required or not enrolled, with admin accounts as the priority since any admin account without MFA is the most important gap to resolve before the application.
Verifying backup posture means confirming backups are running as documented and that at least one has been restored in a test in the last 12 months, with the result documented. Documenting the access control and offboarding process means pulling records of when the access review last ran, which systems it covered, and what the most recent offboardings looked like, including whether the process covers applications outside the main directory. An undocumented process is an absent process from an underwriting perspective.
Checking email security means verifying DMARC, DKIM, and SPF records, and upgrading a p=none policy to p=quarantine before the application as a direct improvement to the answer. Reviewing incident response documentation means confirming the plan exists, was reviewed in the last 12 months, and has been exercised through a tabletop. For gaps that cannot be closed before the application, documenting the current state, the compensating controls, and the remediation plan with timelines is preferable to an unqualified "yes" that does not reflect reality. The questionnaire is a legal document, so answering truthfully with qualifications produces a better outcome than an unqualified false positive discovered at claim time.
how an identity assessment produces the evidence underwriters need
A significant portion of the questionnaire covers identity and access: MFA coverage, privileged access hygiene, access control process, and offboarding completeness. These questions are answered best with current data, not estimates. A read-only connection to the identity provider surfaces every account in the directory, its MFA enrollment status, its privilege level, its activity, and any accounts that correspond to users no longer active. MFA coverage figures then come from actual directory data, former employee access is surfaced as specific accounts with documented remediation steps, and admin accounts without MFA appear as findings with priority classifications. A plain-language summary of the identity posture is usable for insurance applications, internal security reporting, and customer security questionnaires alike.
self-insurance and risk retention: the basics
For some organizations, commercial cyber insurance is too expensive, too limited, or both. Understanding the alternatives is part of a complete risk management picture.
What self-insurance means in practice. The organization retains the financial risk rather than transferring it. This is the default position for any risk that is not covered. Choosing it deliberately means preparing financially for the losses it implies.
Funded reserves. A dedicated financial pool set aside for potential cyber incident costs: incident response, recovery, legal fees, notification, and regulatory fines. The size should be calibrated to the potential loss scenario, not an arbitrary figure. A reserve works alongside commercial insurance, covering the retention and any losses within a self-insured layer, or in place of commercial cover where the premium is uneconomical.
The self-insured retention (SIR). A defined maximum the organization absorbs per incident, with commercial insurance covering losses above that threshold. This reduces premium costs by absorbing more of the lower-layer risk while transferring catastrophic exposure.
What self-insurance requires. A mature security program, a realistic loss model, dedicated and accessible funds, and the internal capability to manage incident response and claims. Without these, self-insurance is accepting risk without a plan.
When commercial cover is too expensive. The right response is not to go without cover but to understand which controls most affect the premium, address those first, and re-approach the market. MFA coverage, backup posture, and documented incident response carry the highest weight. The decision between commercial cover, self-insurance, or a combination involves the IT or security lead, the CFO, and legal.
how this maps to NIS2, DORA, and ISO 27001
The controls underwriters require and the controls these frameworks mandate are substantially the same list. Preparing for insurance renewal and preparing for framework compliance are complementary.
NIS2. Directive (EU) 2022/2555 requires covered entities to implement cybersecurity risk management measures including access control, MFA, incident response, business continuity, and supply chain security. The Article 21 measures map closely to the underwriting control list.
DORA. The Digital Operational Resilience Act applies to financial entities in the EU and their critical ICT service providers, with requirements for ICT risk management, incident response, resilience testing, and access control including periodic review of user access rights with particular attention to privileged accounts.
ISO 27001. ISO 27001:2022 includes access control, business continuity, incident management, and vulnerability management as required Annex A controls. Certification evidence can be attached to questionnaire responses.
GDPR. GDPR requires appropriate technical and organizational measures for personal data security. An incident involving personal data triggers notification obligations under Article 33 (72-hour authority notification) and Article 34 (affected individual notification in high-risk cases). The incident response plan should cover these.
let's start with a conversation
Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.
Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.
We'll take it from there

+48 783 762 997
julian@unshadowit.com

