Cyber insurance is becoming harder to qualify for because cyberattacks have become more expensive, disruptive, and difficult to predict. Insurers are responding by examining how well businesses actually protect their systems before offering coverage.
Completing a questionnaire is no longer always enough. Businesses may need to prove that important security controls, like multi-factor authentication, endpoint protection, backups, and employee training, are active and genuinely working. The exact requirements vary by insurer, policy, industry, company size, and risk level, but the overall direction is clear: insurers want evidence of real, ongoing cybersecurity, not promises about tools a business intends to implement later.
Why cyber insurance standards have become stricter
Cyber insurance was once available with relatively limited technical scrutiny, and many businesses qualified by completing a basic questionnaire about their cybersecurity practices. That's changed as cyber incidents have grown more costly. According to the National Association of Insurance Commissioners, the US cyber insurance market reached $11.2 billion in direct written premiums in 2024, and that scale of exposure has pushed insurers toward far more rigorous underwriting.
Ransomware attacks can cause prolonged downtime, data loss, legal expenses, customer notifications, and reputational damage, and even when a business refuses to pay a ransom, it may still face major recovery expenses if attackers steal sensitive information. Business email compromise is another growing concern, where an attacker gains access to an employee's email account, impersonates a manager or vendor, and convinces someone to transfer money, bypassing traditional antivirus tools entirely because it relies on stolen credentials and human trust rather than malware.
Insurers also have to weigh supply-chain risk, since one attack or outage affecting a major technology provider can disrupt thousands of insured businesses simultaneously. These compounding risks have made it harder for insurers to predict and limit their losses, which is exactly why they're now asking more detailed questions and setting higher security expectations before issuing or renewing policies.
Insurers want proof, not just promises
The biggest change is the shift from self-reported security to evidence-based underwriting. An insurer may request documentation showing that a business's security controls are properly implemented, potentially including multi-factor authentication enrollment reports, endpoint protection status reports, backup and restoration test results, employee training records, patch and vulnerability reports, and written security and incident-response policies. Some insurers also scan internet-facing systems for outdated software, exposed services, or other visible weaknesses.
This means businesses shouldn't guess when answering technical questions. A "yes" on an application may be interpreted as confirmation that a control covers all required users, devices, or systems. A company might use multi-factor authentication for employee email but not for an administrator account, and answering that MFA is fully implemented could create a real mismatch between the application and the company's actual security posture. That gap has already cost real businesses their coverage. In one widely reported case, Travelers moved to rescind a policy and deny a ransomware claim against International Control Services after discovering the business had attested to full MFA deployment when it wasn't actually enabled on every server, and the misrepresentation alone was enough to trigger the denial, independent of whether the gap caused the breach. The safest approach is having the person completing the application review technical answers with the company's IT or cybersecurity provider before anything gets submitted.
The security controls businesses are commonly expected to have
Requirements differ among insurers, but several controls appear frequently across cyber insurance applications.
Multi-factor authentication adds another verification step beyond a password, helping stop an attacker from accessing an account even after stealing the credentials. Insurers may expect it to protect business email, remote network access, cloud platforms, administrative accounts, and any other system containing sensitive data, and partial implementation may not be enough. Confirm which accounts and systems are actually covered rather than assuming MFA is active everywhere. The Change Healthcare ransomware attack, one of the most disruptive healthcare cyberattacks in recent memory, has been widely reported as tracing back to exactly this kind of gap, a system that reportedly lacked MFA.
Modern endpoint protection matters because employee laptops, workstations, and servers are common entry points for attackers, and insurers increasingly expect capable endpoint protection that can detect suspicious activity and help contain an infected device. Installing the software is only the first step. Someone must also monitor alerts, address inactive devices, and ensure new equipment gets enrolled, and larger or higher-risk organizations may face stronger monitoring expectations than a smaller business with a simpler environment.
Protected and tested backups can help a business restore operations after ransomware, data loss, or system failure, but only if attackers can't delete them and the business can successfully restore its data. Insurers may want to know how frequently critical data is backed up, whether backups sit separated from the main network, who can access or modify them, and when the business last completed a successful restoration test. A report showing that a backup job completed does not necessarily prove the data can actually be recovered. Regular restoration testing provides far stronger evidence.
Regular patching matters because attackers frequently target known weaknesses in outdated software, and a consistent process for identifying and updating operating systems, business applications, servers, firewalls, remote-access tools, and internet-facing systems reduces the window those vulnerabilities stay open. Insurers may pay particular attention to critical vulnerabilities and unsupported software, and exact patching deadlines vary, so avoid treating any single timeline as a universal requirement.
Email security and employee training matter because many cyber incidents begin with a phishing email, fraudulent invoice, or stolen password. Technical email filters reduce the number of dangerous messages that reach employees, but they can't stop every attempt, so regular security-awareness training helps employees recognize suspicious links, unexpected password-reset requests, fake invoices, impersonation attempts, and unusual payment instructions. Businesses should also maintain a separate verification process for significant financial transfers or changes to vendor payment details.
Incident-response planning means having a written plan telling employees what to do after discovering a possible cyberattack, identifying who must be contacted, who has authority to make decisions, how affected systems will be contained, when the insurer and other advisors must be notified, and how the business will continue or restore operations. That plan should be reviewed and tested periodically, since discovering outdated contact details or procedures during an active incident only increases delays and losses.
Why owning security tools is not enough
A common mistake is assuming that purchasing security technology automatically satisfies an insurer's requirements. A control only provides real protection when it's properly configured, monitored, and maintained, and problems can develop quietly over the course of a policy year. MFA may be active for most employees but missing from one important account. Endpoint protection may be installed but no one is reviewing the alerts. A new laptop connects without being added to the security system. Backups run automatically but fail to capture critical data. A security control gets disabled temporarily during a system change and is never restored.
This gradual weakening is sometimes called security drift, and a company can look fully prepared when it applies for coverage while carrying serious gaps just a few months later. That's exactly why cyber insurance readiness should be treated as an ongoing responsibility rather than an annual form to complete once and forget.
How stricter requirements affect small and midsize businesses
Small and midsize businesses can find these requirements especially difficult, often relying on a small internal IT team or an outsourced provider rather than dedicated security and compliance departments. They may have appropriate tools but lack the documentation needed to prove those tools are actually working, or discover that security protections cover only part of the organization.
When a business doesn't meet an insurer's expectations, it may face a denied application, higher premiums or deductibles, lower coverage limits, additional exclusions, reduced coverage for certain types of losses, or requirements to complete improvements before coverage even begins. The solution isn't necessarily purchasing every available security product. Smaller businesses should focus first on the controls most relevant to their actual risks and the insurer's specific requirements, and starting early matters, since waiting until the renewal deadline leaves too little time to deploy protections, correct configuration problems, test backups, and gather evidence.
Application mistakes that can put coverage at risk
Cyber insurance applications often ask detailed technical questions, and incorrect answers can affect both eligibility and how a future claim is handled. Common mistakes include guessing instead of verifying a technical answer, saying a control covers the entire business when exceptions exist, reporting a planned improvement as already completed, assuming a security tool is working without checking it, failing to document training, testing, or security reviews, allowing required controls to lapse after the policy begins, and delaying notification to the insurer after discovering an incident.
Businesses should answer every question based on their current security environment, and known exceptions should be discussed with the broker rather than hidden or overlooked. Before submission, the application should be reviewed by the business, its broker, and the people actually responsible for its technology.
What to review beyond basic eligibility
Qualifying for a cyber insurance policy does not mean every cyber-related loss will be fully covered. Policyholders should understand their coverage limits, deductibles, ransomware and extortion coverage, fraudulent-transfer and social-engineering sublimits, third-party service interruption coverage, incident-notification requirements, and cyberwar and widespread-event exclusions. A policy may provide broad overall coverage but place a much lower limit on losses caused by fraudulent wire transfers, or may not cover lost income from an outage at a third-party technology provider unless that protection is specifically included. Policy language varies considerably, so a broker should explain unclear limitations before the business purchases or renews coverage.
How to prepare for an application or renewal
Businesses can reduce last-minute problems by preparing before the insurer sends a renewal deadline. Start by asking the broker for the latest application and expected security controls, then have the IT or cybersecurity provider assess the current environment. Confirm that MFA protects all required accounts and systems, verify that endpoint protection covers all company devices and servers, and test whether critical data can actually be restored from backups.
From there, address critical software updates and known vulnerabilities, review employee security training and payment-verification procedures, update and test the incident-response plan, gather security reports, policies, and test records, and review every application answer for accuracy before submission. Continue monitoring required controls after the policy begins, since readiness at application time doesn't guarantee readiness six months later.
Frequently asked questions
Does every insurer have the same cybersecurity requirements?
No. Requirements vary by insurer, policy, company size, industry, data exposure, claims history, and requested coverage limit, so ask your broker for the specific expectations that apply to your business.
Can a business get cyber insurance without MFA?
It may be difficult, especially when MFA is missing from email, remote access, cloud platforms, or administrative accounts. The final decision depends on the insurer and the business's overall risk profile.
Will stronger cybersecurity lower the premium?
It may improve pricing or policy terms, but some controls are simply required to qualify at all. Implementing stronger security doesn't guarantee a specific discount.
Can a claim be denied if a security control stops working?
A missing or inactive control can create coverage problems if it contradicts the application or policy conditions, particularly when that gap contributed to the incident. The outcome depends on the specific policy language and circumstances.
When should a business begin preparing for renewal?
Preparation should begin several weeks or months in advance, giving the business time to assess its security, fix important gaps, test its systems, and collect supporting documentation.
