Cyber insurance was once straightforward to obtain with minimal scrutiny. Following sustained ransomware losses, underwriting tightened substantially. Insurers now ask detailed technical questions, and increasingly verify the answers. For security teams this has an unexpected upside: it created budget conversations that had previously stalled.
What insurers consistently ask about
- Multi-factor authentication — on remote access, email, privileged accounts and administrative interfaces. Frequently a precondition rather than a discount item, with phishing-resistant methods increasingly favoured.
- Backups — whether they are offline or immutable, how frequently restoration is tested, and whether backup systems are segregated from the production domain.
- Endpoint detection and response — coverage across the estate, and whether anyone monitors it.
- Privileged access management — how administrative accounts are controlled and reviewed.
- Email security — filtering, authentication and phishing defences.
- Patch and vulnerability management — particularly for internet-facing systems, with stated timelines.
- Network segmentation — whether a single compromise reaches everything.
- Incident response planning — whether a plan exists and whether it has been exercised.
- Security awareness training — coverage and frequency.
- End-of-life systems — unsupported software is a common exclusion trigger.
Accuracy on the application is critical
This deserves emphasis beyond the technical detail. The application form is not a survey — the answers form part of the basis on which cover is offered, and material inaccuracy can affect a claim.
A well-intentioned "yes, we have MFA everywhere" that turns out to mean "everywhere except the legacy VPN the attacker used" is precisely the scenario that produces a disputed claim at the worst possible moment. If a control is partially implemented, say so and describe the gap. Insurers are accustomed to partial coverage; they are much less accommodating about discovering it after a loss.
Practically, this means the person completing the form must be someone who genuinely knows the environment, and the answers should be verifiable from evidence rather than assumption.
What policies typically cover — and exclude
Cover commonly includes incident response costs, forensic investigation, legal and regulatory support, notification costs, business interruption, data restoration and sometimes extortion payments subject to conditions and legal constraints.
Exclusions deserve careful reading. Common ones include unsupported end-of-life software, failure to maintain the controls described in the application, certain nation-state or war-related acts, and losses arising from known unpatched vulnerabilities. The war and hostile-act exclusions in particular have been the subject of significant litigation and revised wording, so the specific language in your policy matters more than general expectations.
Using the process productively
- Treat the questionnaire as a gap assessment — it is a reasonable proxy for the controls that most reduce loss.
- Where a control is missing, price it against the premium difference; the business case is frequently easier to make in insurance terms than in abstract risk terms.
- Read the exclusions before the cover summary, since exclusions determine what you actually have.
- Confirm which incident response provider you are required or permitted to use, and whether you may use your own — this is easier to resolve before an incident.
- Check the notification obligations, which are often tighter than expected and can affect cover if missed.
- Revisit answers at renewal, since environments change and previously accurate statements may no longer hold.
Insurance is not a control
It is worth stating plainly: insurance transfers financial consequence, not responsibility. It does not prevent an incident, does not restore customer trust, and does not satisfy a regulator.
It is a legitimate part of a risk strategy alongside prevention, detection and response — not a substitute for any of them. An organisation that buys cover instead of controls has changed who pays, not whether the incident happens.
Related from TechBiz Security
Sources & further reading
- CISA — Cyber Essentials
- NIST — Cybersecurity Framework
- CIS Critical Security Controls
- CISA — StopRansomware
0 comments
Leave a comment