Your cyber insurance application is almost done but your broker just flagged that you can't confirm MFA on privileged accounts, and now the underwriter wants a third-party attestation you've never heard of. Insurers denied or restricted coverage for more than 1 in 5 applicants in recent renewal cycles for failing basic security controls, here are the 9 they check first.
In This Article
- Why Cyber Insurance Applications Fail Before They're Reviewed
- The 9 Cyber Insurance Security Controls and How to Document Each One
- Having the Controls Isn't Enough. Documentation Kills Claims
- Which Controls to Prioritize If You're Starting from Zero
- Frequently Asked Questions
- Not Sure If Your Business Passes the Insurer's Checklist? Get a Pre-Application Security Audit
Why Cyber Insurance Applications Fail Before They're Reviewed
Most cyber insurance application denials aren't close calls, they're automatic. Underwriters use structured questionnaires with threshold controls that trigger an instant decline or a blanket exclusion before a human underwriter scores the rest of your submission.
Three controls function as hard gates: Multi-Factor Authentication (MFA) on privileged and remote accounts, Endpoint Detection and Response (EDR) on all managed devices, and tested, offline data backups. If your application shows any of these as absent or unverified, many insurers will decline outright or exclude ransomware coverage; the single event most SMBs are buying coverage for. The remaining six controls affect your premium and coverage limits, but these three determine whether you get a policy at all.
The 9 Cyber Insurance Security Controls and How to Document Each One
Underwriters don't just want to know that a control exists; they want evidence it was active and enforced on the date you signed the application. For each control below, the documentation column is what you need to produce, not just implement.
| Control | What It Is | Insurer Questionnaire Language | Documentation You Must Provide | Gate or Scored? |
|---|---|---|---|---|
| 1. MFA on Privileged & Remote Accounts | Multi-Factor Authentication (MFA) requires a second verification step beyond a password before granting account access. | "Is MFA enforced for all administrative, email, and remote access accounts?" | Screenshot of MFA policy enforcement in your identity provider (e.g., Azure AD Conditional Access); list of accounts in scope; last-audit date. | Hard Gate |
| 2. Endpoint Detection and Response (EDR) | EDR is security software that monitors endpoints in real time, detects threats, and enables rapid response, distinct from traditional antivirus. | "Do all endpoints have EDR or next-gen antivirus deployed and actively monitored?" | Vendor name and version; device coverage report showing 100% enrollment; evidence of active monitoring (SOC or managed alerts). | Hard Gate |
| 3. Tested, Offline/Air-Gapped Data Backups | Air-gapped backups are copies of data stored on systems with no persistent network connection to the production environment, preventing ransomware from encrypting them. | "Are backups stored offline or immutably, and have they been tested for restoration in the past 12 months?" | Last restore-test date and result; backup job logs; confirmation backups are isolated from production network. Vieth Consulting LLC's tested, managed data backup and recovery service generates these records automatically. | Hard Gate |
| 4. Documented Incident Response Plan (IRP) | An Incident Response Plan (IRP) is a written procedure defining roles, escalation steps, and communication protocols when a security event occurs. | "Do you have a documented and tested incident response plan?" | Signed, dated IRP document; evidence of at least one tabletop exercise; owner name and review date. Vieth Consulting LLC can build your documented incident response and disaster recovery plan. | Scored |
| 5. Privileged Access Management (PAM) | Privileged Access Management (PAM) controls, monitors, and audits access for accounts with elevated system permissions, preventing lateral movement after a breach. | "Do you limit and log administrative access using a PAM solution?" | PAM tool name; privilege audit log showing least-privilege enforcement; list of admin accounts and their access scope. | Scored |
| 6. Email Filtering and Anti-Phishing | Email filtering tools block malicious messages, spoofed senders, and phishing links before they reach employee inboxes. | "Do you use email security filtering beyond default provider settings, including anti-phishing and attachment scanning?" | Filter vendor and configuration; evidence of DMARC/DKIM/SPF records; quarantine report showing active filtering. | Scored |
| 7. Security Awareness Training with Completion Records | Security awareness training is a formal, recurring program that educates employees on phishing, password hygiene, and social engineering with tracked completion. | "Is security awareness training conducted at least annually, with records of employee completion?" | Training platform name; completion report by employee; date of most recent session; phishing simulation results if available. | Scored |
| 8. Patch Management and Vulnerability Scanning | Patch management is the process of identifying and applying software updates to close known security vulnerabilities across all systems on a defined schedule. | "Do you have a formal patch management process and conduct regular vulnerability scans?" | Patch cadence policy; last vulnerability scan report with remediation notes; evidence of critical patch SLAs being met. | Scored |
| 9. Secure Remote Access (ZTNA or Managed VPN) | Zero Trust Network Access (ZTNA) and managed VPNs restrict remote connections to verified users and devices, replacing open or legacy remote desktop protocols. | "Do remote employees access company systems through a secure, authenticated gateway rather than direct RDP or unmanaged VPN?" | Remote access solution name; policy requiring use for all remote sessions; confirmation RDP is not exposed to the internet. | Hard Gate |
Vieth Consulting LLC delivers Controls 1, 2, 3, and 9 as part of its managed cybersecurity stack for Madison and Milwaukee SMBs with the documentation trail built in, not assembled at renewal time.
Having the Controls Isn't Enough. Documentation Kills Claims
The most common post-breach claims dispute isn't fraud, it's a mismatch between what you checked on the application and what the insurer's forensic team finds. Insurers can void a claim when your documented controls don't match your actual environment at the time of the incident.
What Is the Attestation Trap?
The attestation trap occurs when you check "yes" to a control on the cyber insurance application checklist, but your insurer's forensic investigation finds the control wasn't enforced at the time of the breach. A common example: MFA was deployed for cloud email but not for the VPN, and the attacker entered through the VPN. In a ransomware incident, a scenario cyber insurance is supposed to cover, that gap can become grounds for partial or full claim denial.
What Proper Documentation Looks Like
Acceptable documentation is not a written policy alone. Insurers want three things for each control: the written policy, screenshot or log evidence showing the control was active, and the last-tested or last-reviewed date. Vieth Consulting LLC's Quarterly Business Reviews (QBRs) and Hardware Lifecycle Reports create this paper trail continuously, not in a scramble before your renewal deadline.
Which Controls to Prioritize If You're Starting from Zero
For a first-time cyber insurance application, MFA and EDR must be in place before anything else. Without those two, most applications won't advance past the initial questionnaire screen regardless of how strong your other controls are.
Construction firms, nonprofits, and professional services organizations in the Madison and Milwaukee area rarely have the IT capacity to implement all nine controls simultaneously, and trying to do so is the fastest way to implement none of them correctly. A phased approach is more realistic and more defensible to an underwriter.
- Week 1-2: MFA on all admin, email, and remote access accounts; EDR deployed to all endpoints with active monitoring confirmed.
- Week 2-4: Backup restore test completed and documented; IRP drafted, assigned an owner, and dated.
- Days 30-90: PAM policy enforced; ZTNA or managed VPN replacing any open RDP; email filtering hardened beyond default settings.
- Ongoing: Security awareness training scheduled with tracked completion; patch management cadence formalized; vulnerability scans added to QBR review cycle.
Vieth Consulting LLC's Madison and Milwaukee cybersecurity services follow exactly this phased sequence, so SMBs apply with a defensible, documented control set rather than a rushed checklist. Unlike national MSPs who hand you a generic cyber insurance checklist, Vieth Consulting LLC audits your actual environment against current insurer questionnaire criteria, serving Madison, Milwaukee, and surrounding Wisconsin communities.
Frequently Asked Questions
What security controls do cyber insurance companies require?
Most cyber insurers require nine controls: MFA on privileged and remote accounts, EDR on all endpoints, tested air-gapped backups, a documented incident response plan, privileged access management, email filtering, security awareness training, patch management, and secure remote access. MFA, EDR, and tested backups are the three most likely to cause an automatic decline if absent.
Can you get cyber insurance without MFA?
Some insurers will issue a policy without MFA but will exclude ransomware coverage, the event most SMBs are buying protection for. Many insurers now treat MFA on privileged and remote accounts as a hard requirement and will decline applications that cannot document it. Applying without MFA in place significantly limits your coverage options.
What happens if I lie on a cyber insurance application?
Misrepresenting controls on a cyber insurance application, even unintentionally, can void your policy at the time of a claim. Insurers conduct forensic investigations after breaches and compare findings against your application answers. A mismatch, such as checking "yes" to MFA when it wasn't enforced on all required accounts, is sufficient grounds for claim denial.
How long does it take to meet cyber insurance requirements?
The three hard-gate controls (MFA, EDR, and tested backups) can typically be deployed and documented within two to four weeks for most SMBs. The remaining scored controls, including a formal incident response plan, privileged access management, and ZTNA, realistically take 30 to 90 days to implement correctly with supporting documentation.
Not Sure If Your Business Passes the Insurer's Checklist? Get a Pre-Application Security Audit
Vieth Consulting's security assessment maps your current controls directly against the questions on today's cyber insurance applications, so you apply knowing exactly where you stand, not hoping for the best.
Schedule Your Free Security Assessment
