Cyber Insurance Requirements: What Your Policy Expects

What Is Cyber Insurance, and What Does Your Policy Actually Require?

Cyber insurance helps cover the cost of a security incident, but only if your IT environment matches what you told the insurer. Carriers now expect specific controls like MFA, EDR and tested backups before they write a policy, and they check for them when you file a claim.

Most business owners think of cyber insurance like any other policy: pay the premium, file a claim if something goes wrong. After several years of heavy ransomware losses, underwriters have become much more specific about what they require up front and much more careful when a claim comes in. In practice, your policy works like a compliance framework with its own checklist. Here's what's usually on it, why claims get reduced or denied, and how to keep your coverage solid.

What carriers usually require to write a policy

Requirements vary by carrier and coverage level, but these controls appear on nearly every underwriting questionnaire.

Multi-factor authentication (MFA)

The most commonly required control. Carriers want MFA on email, remote access (VPN and remote desktop), cloud applications and administrator accounts, and some require it everywhere. Missing MFA can raise your premium, limit coverage for attacks that start with stolen passwords, or prevent a policy from being written. See our MFA dictionary entry.

Endpoint detection and response (EDR)

Many underwriters no longer accept traditional antivirus on its own. They want endpoint detection and response, which watches for suspicious behavior instead of only matching known malware signatures. Some policies limit ransomware coverage when EDR is missing. Our EDR article explains the difference.

Tested, isolated backups

"We have backups" isn't enough. Carriers want backups that are separated from your production network, protected from tampering (for example with immutable or WORM storage), and restored on a test basis so you know they work.

A written incident response plan

A documented process for who does what, in what order, when something happens. A general security policy doesn't count. See What is a cybersecurity incident response plan?

Security awareness training

Recurring training with completion records, and often phishing simulations. Security awareness training is a standard part of NerdSquad cybersecurity plans.

Patch management

Evidence that operating systems and software are kept current, and that unsupported systems (Windows 10 reached end of support in October 2025, for example) have been replaced or isolated.

Privileged access and logging

Controls on who has administrator rights, separate admin accounts, and logs that show when those accounts were used. Some carriers ask specifically about shared and service accounts.

Vendor oversight

Underwriters increasingly ask how you evaluate the security of your technology vendors. A simple, documented review process is usually enough to answer the question.

Why claims get reduced or denied

Claim problems tend to follow the same few patterns.

  • Inaccurate questionnaire answers. The application is part of the policy. If it says MFA is enforced on remote access and the investigation finds it was switched off during a software change and never turned back on, the carrier may argue misrepresentation and contest the whole claim. Every answer should be something you can prove today, not something that was true when the system was set up.
  • MFA gaps. Partial MFA is common: email is covered, but the VPN, an old admin account or a cloud app isn't. Attackers find the uncovered door, and investigators find it too.
  • Unpatched systems. Some policies limit coverage when an attacker used a vulnerability that had a patch available for a long time. The policy wording matters, and so does a patch record showing updates were being applied.
  • Untested or reachable backups. If backups sit on the same network with the same credentials, ransomware can encrypt them along with everything else. If they were never tested, you may learn they don't restore at the worst moment.
  • Missing logs. Without logs, investigators can't establish what was accessed or when. That makes the investigation slower and costlier, and it can make it harder to show what was and wasn't affected.
  • Late notice. Most policies require prompt notice of a potential claim, and many provide a breach hotline to call right away. Trying to handle an incident quietly before calling the carrier can create coverage disputes. Read your policy's notice terms now, before you need them.

What the carrier's investigators look for

After a claim, the carrier usually assigns a forensic team. Their job is to understand the incident and confirm that policy conditions were met. Expect them to check whether the controls on your application were actually in place, whether backups were isolated and working, your patch history, your access logs, your incident timeline and when you notified the carrier. The firms that fare best are the ones whose day-to-day IT already matches the application, so the evidence is there without a scramble.

One environment, three jobs

The controls carriers ask for are the same ones that make your business harder to attack and that frameworks like HIPAA, GLBA, PCI DSS and SOC 2 expect. You don't need separate programs for security, compliance and insurance. You need one well-run environment that satisfies all three and records that prove it.

How NerdSquad helps

Requirements vary by carrier, so no IT provider can promise you'll qualify for a particular policy. What we do:

  • Put the controls insurers commonly require in place and keep them running: MFA, EDR, patching, backup and disaster recovery, training and logging.
  • Help you answer the security questionnaire accurately at application and renewal, and gather the documentation your broker or carrier asks for.
  • Offer cyber insurance through a licensed insurance partner, so coverage and the security work behind it line up.

For the wider picture, see How do you help businesses protect against cyber threats?


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: Cybersecurity services for businesses