Cyber Insurance: 12 Critical Controls Underwriters Check
A cyber insurance application is the most honest security audit most businesses will ever sit through, and almost nobody treats it that way. It arrives as an admin task, gets forwarded to whoever handles IT, and comes back with a row of ticks. Then a claim happens, and the ticks turn out to have been a contract.
This is what those forms actually ask, why underwriters ask it, and what a “no” costs you.
What a cyber insurance application is really doing
It is not a questionnaire. It is the basis on which the contract is priced and, in most jurisdictions, the basis on which it can later be undone.
The wording is unusually blunt about this. Beazley’s published application form declares that the statements in it “are the basis of the contract should a policy be issued, and have been relied upon by the insurer in issuing any policy”. That sentence is doing an enormous amount of work, and it sits above a signature line.
So the useful reframing is this: every question on a cyber insurance form is a control the insurer has data to suggest changes your loss profile. They are not asking to be thorough. They are asking because their claims file says it matters.
The 12 controls a cyber insurance underwriter checks
The list below follows the actual structure of a live cyber insurance application — Beazley publishes both of its cyber applications openly, one for applicants under $250M in revenue and a longer one above it. The shorter form is the realistic reference point for a small or mid-sized business; the longer one shows where the market is heading, because this year’s large-account question is next year’s small-account question.
1. MFA on remote access
Asked as: do you require multi-factor authentication for remote access to your network, both cloud-hosted and on-premises, including via VPNs?
Note the scope. Not “do you have MFA”, but whether it is required, and whether it covers the VPN. Coalition’s threat research found that 58% of its ransomware claims in 2024 began with a compromised perimeter appliance such as a VPN or firewall. This question is the single most direct line between a claims file and a form field.
2. MFA on web-based email
A separate question, deliberately. Email is where business email compromise starts, and BEC together with funds transfer fraud made up 58% of all claims in Coalition’s 2026 Cyber Claims Report, covering the 2025 year across more than 100,000 policyholders. The average funds transfer fraud loss was $112,000.
3. Privileged and domain administrator accounts
The larger form breaks this out on its own: MFA enforced for privileged directory accounts, domain administrators restricted to domain controllers rather than browsing the web and reading email, and administrator passwords over 25 characters.
That is a very specific picture of a well-run estate, and it is the question most small businesses fail without realising it.
4. Incoming email controls
Screening for malicious attachments, screening for malicious links, and tagging external email. Multiple-choice, choose all that apply — which means a partial answer is visible as a partial answer.
5. Endpoint protection, and which kind
The small form asks whether all company devices are protected by anti-virus, anti-malware or endpoint protection. The larger form abandons the yes/no entirely and asks you to name the vendor for three separate rows: Endpoint Protection Platform, Endpoint Detection and Response, and Managed Detection and Response.
Naming a vendor is much harder to fudge than ticking a box. That shift — from claim to evidence — is the direction every question on these forms is travelling.
6. Backups: frequency, location, and the syncing trap
Three questions in a row. How often you back up. Where the backups live — corporate network, cloud service, offline. And then the one that catches people: if you rely on a cloud-based backup service, is it a “syncing service”? The form names DropBox, OneDrive, SharePoint and Google Drive explicitly.
A sync target is not a backup. It faithfully replicates the encryption. Underwriters have seen enough claims to ask about it by name.
7. Restore testing
Asked as a frequency, not a yes/no: never, annually, two to three times a year, or quarterly or more often. There is no option for “we assume it works”.
That single question is the most useful thing on the cyber insurance form, because it is the one control you can prove or disprove in an afternoon. What a defensible answer actually requires is set out in our piece on the 7 failures a restore drill exposes.
8. Patching internet-facing systems
Whether you, or an outsourced provider on your behalf, actively manage and install critical patches across internet-facing systems. The scope is narrow on purpose: the internet-facing edge is where the claims come from.
9. End-of-life software
Do you have any end-of-life or end-of-support software on your network, and if so, is it segregated? The available answers include don’t know, which is worth noticing. Underwriters would rather have an honest “don’t know” than a confident wrong answer, because the confident wrong answer is the one that voids the policy.
10. Local administrator rights and hardened baselines
Do ordinary users have local administrator rights on their laptops, and do you run a hardened baseline configuration across substantially all devices? Both are free to fix and both materially change how far an intrusion travels.
11. Remote desktop exposed to the internet
Named products — Microsoft Remote Desktop, TeamViewer, VNC, AnyDesk — and whether any of them are exposed directly to the internet. In Coalition’s data, remote desktop products were the second most common ransomware entry point at 18%.
12. A written incident response plan
Do you have an incident response plan for network intrusions and malware incidents? A binary question with a lot hiding behind it, and the one control on this list that costs nothing but attention.
The two questions that have nothing to do with hacking
Near the end of both forms sits a section headed Money Transfer Controls, and it asks two things that no firewall will ever help with.
First, whether staff who disburse or transmit funds get anti-fraud training at least annually. Second, whether a vendor’s request to change its bank account details is confirmed out of band — the form spells it out, so that an emailed request gets a phone call back.
Those two questions defend against the single largest category in the claims data. Coalition found that 71% of funds transfer fraud claims came from social engineering, and that 52% of them started as business email compromise. A callback procedure written on one side of A4 addresses more insured loss than most security products.
What a cyber insurance “no” actually costs you
There are four distinct outcomes, and they are worth separating because they are often collapsed into “you pay more”.
Declined outright. Some controls are eligibility gates rather than pricing inputs. No MFA on remote access and email is the common one.
Covered, but not for the thing you were worried about. Ransomware and extortion get excluded or written down to a sublimit well below the policy limit, so the headline number on the schedule is not the number available for the loss you actually have.
Covered with you sharing the loss. Coinsurance on ransomware claims, where you carry an agreed percentage alongside the insurer, plus a higher retention.
Priced worse. This is the one everybody expects and it is the least interesting of the four, because a premium is an annual cost and an exclusion is a one-off catastrophe.
We are not going to publish a premium range, and you should distrust anyone who does. Cyber insurance pricing depends on revenue, sector, records held, limit, retention and your control set. A figure quoted without knowing the estate is marketing rather than information. Ask a broker who has seen your answers. What we will say is that the market is currently soft — Marsh recorded cyber rates falling 4% globally in Q2 2026, the twelfth consecutive quarter of decline — which makes this an unusually good moment to have good answers.
What a wrong “yes” costs you, which is worse
The failure mode that should frighten you is not the honest no. It is the optimistic yes.
In 2022 Travelers moved to rescind a cyber insurance policy issued to a US electronics manufacturer, International Control Services, after a ransomware attack. The application, signed by the company president, stated that MFA protected administrative and privileged access. Travelers alleged the company in fact used MFA only to protect its firewall, and not the server that was attacked.
The case did not go to trial. The insured agreed to a judgment, and in August 2022 the court declared the policy void from inception — no coverage for past, present or future claims, each side paying its own costs. They had paid a premium for a policy that legally never existed, and they found out after the incident.
Nobody in that story set out to commit fraud. Somebody answered a question about MFA the way they believed the estate worked. That is the ordinary failure here, and it is why the person who signs should not be the person guessing.
Two practical consequences. Answer from evidence rather than memory — export the conditional access policy, pull the EDR deployment report, look at the backup job. And watch for “failure to maintain” conditions, which require the controls you described at underwriting to still be running at the time of loss. A control switched off for a migration and never switched back on is a live coverage problem.
When cyber insurance is the wrong purchase
The unprofitable thing to say, so we will say it.
If you have no MFA, no tested backup and no idea what end-of-life software is on the network, buying cyber insurance first is the wrong order. You will either be declined, or issued a policy whose most useful sections are excluded, or — worst — issued a policy you believe protects you and which will not survive contact with a claim. The money is better spent closing the gaps and applying in three months from a stronger position.
Cyber insurance is also the wrong tool for a problem you can simply remove. It does not restore a reputation, it does not un-notify a regulator, and it does not give back the fortnight your business spends not trading. It transfers financial consequence. It transfers nothing else.
And it is worth reading the exclusions with the same care as the controls list. Retroactive dates, business interruption waiting periods, defence costs eroding the limit, and requirements to use the insurer’s own breach counsel and forensics vendors all shape what you actually receive.
Why the cyber insurance controls are worth having anyway
This is the same argument our POPIA compliance checklist makes about regulation, and it holds here for the same reason: the control does the work, the paperwork just makes you schedule it.
Marsh McLennan’s Cyber Risk Intelligence Center has been matching organisations’ self-assessed controls against their actual claims since 2023. Its August 2025 findings ranked network hardening, EDR, logging and monitoring, awareness training and incident response planning as the five controls most associated with a reduced chance of a breach-based claim.
Three of the measured effects are worth quoting. Every 25% increase in EDR deployment across workstations correlated with a further 10% decrease in breach likelihood. Phishing-resistant MFA correlated with a 9% lower breach likelihood than MFA that is not. Organisations running regular tabletop exercises were 13% less likely to suffer a material cyber event.
Read the first of those again. It is not a switch, it is a gradient — the estate you left uncovered is the part that is still exposed. This is the same finding that runs through our piece on why identity attacks beat exploits: deployment is not coverage, and the gap between them is where the loss happens.
If you want a framework rather than an insurer’s form, the CIS Controls Implementation Group 1 is a good fit for a business of this size — 56 safeguards described as essential cyber hygiene and aimed explicitly at organisations with limited security expertise. The overlap with the application form is close to total, which is not a coincidence.
The South African cyber insurance wrinkle
Two things are specific to this market and worth knowing.
The first is that the controls on an insurer’s form and the safeguards expected under POPIA’s section 19 are largely the same controls. Doing the work once produces evidence for both, plus the client security questionnaire that arrives with every enterprise contract.
The second applies if you are a regulated financial institution. The FSCA and Prudential Authority’s Joint Standard 2 of 2024 on Cybersecurity and Cyber Resilience Requirements commenced on 1 June 2025, with a twelve-month window to reach full compliance, and it covers banks, insurers, retirement funds, discretionary and administrative FSPs and more. Its requirements — asset inventories, access control, MFA, backup strategy, control testing, material incident reporting — read like the same list again. If that describes you, the cyber insurance application is not additional work; it is a subset of work you already owe a regulator.
How to prepare for a cyber insurance renewal in four weeks
A realistic sequence for a business without dedicated security staff, in the order that changes the answers fastest:
- Week one. MFA on remote access, web email and every administrative account, with any exemption written down and owned by a named person. This is the eligibility gate; nothing else matters as much.
- Week two. Backups. Confirm at least one copy is offline or immutable rather than a sync target, then run a real restore and record the date and the result.
- Week three. The edge. Find internet-exposed remote desktop and remove it, inventory end-of-life software, and confirm someone is genuinely patching the internet-facing systems.
- Week four. Paper. An incident response plan naming people rather than roles, an out-of-band callback rule for bank detail changes, and a folder holding the evidence for every answer you are about to give.
That last item is the one most people skip and the one that pays repeatedly. The same evidence file answers the insurer, the regulator and the enterprise client who wants a security questionnaire completed by Friday.
The summary worth keeping
Treat the cyber insurance form as a free gap analysis written by people who see the claims. Answer it from evidence rather than optimism, and if the honest answer is no, fix it rather than rounding it up.
The controls are not the price of the policy. They are the reason you may never need it, and every one of them still pays for itself on the day you decide not to renew. If you want the strategic version of this conversation — what to fix, in what order, against a budget — that is the work we describe under the virtual CIO role.
Most of the twelve are configuration rather than purchase, and an honest gap list is a week’s work to produce. That list, costed and prioritised, is the deliverable of our cybersecurity risk management assessment.
One thing a cyber insurance application will not ask about, and increasingly should: if you build and sell software, the Cyber Resilience Act obliges you to notify a national CSIRT and ENISA within 24 hours of learning that a vulnerability in your product is being exploited — a clock that starts well before your insurer hears anything.