Blog

Cyber Insurance Requirements: What insurers are asking for

Cyber Insurance Requirements

A cyber insurance policy pays a claim based on what an underwriter can verify was actually in place at the time of a breach, not on what a business believed it had configured. That distinction has become the center of cyber insurance requirements over the last two years, and it is costing companies real money at the exact moment they most need coverage to work.

Insurers spent years asking simple yes-or-no questions on applications and taking the answers at face value. Ransomware losses changed that math. Carriers now write specific technical controls directly into policy language, verify those controls after an incident rather than before, and deny or void claims when what investigators find doesn’t match what the application described. For a CFO or COO, understanding these requirements determines whether a policy paid for faithfully every year actually functions when called on.

Why underwriters stopped trusting the application form

For years, cyber insurance applications worked like most commercial insurance products: a company answered a set of questions about its security posture, signed the form, and paid the quoted premium. Insurers rarely verified the answers. The assumption was that businesses understood their own environments and reported them honestly.

That assumption broke down under the weight of ransomware losses. Ransomware accounted for the large majority of cyber insurance losses in the first half of 2025, and a significant share of claims traced back to a control the applicant had reported as present but that wasn’t actually enforced. Coalition’s 2024 Cyber Threat Index found that 82% of claims involved organizations without multi-factor authentication fully in place, despite MFA appearing on nearly every underwriting questionnaire since 2022.

Insurers responded by rewriting the terms of the relationship. Multi-factor authentication, endpoint detection and response, and tested backups moved from recommended practices to conditions of coverage, written directly into policy language. Marsh McLennan’s 2024 report found that 41% of cyber insurance applications were denied on first submission, with missing MFA and inadequate endpoint protection as the leading reasons.

Underwriting a policy today resembles underwriting a mortgage more than underwriting a general liability line: the paperwork alone no longer closes the deal.

When “we have MFA” meets a courtroom

The clearest signal of how far this shift has gone came from a courtroom rather than a renewal notice. In 2022, Travelers filed suit against a policyholder, International Control Services, seeking to void a cyber policy after a breach. The company had stated on its application that multi-factor authentication protected privileged access across its systems. The investigation that followed the breach found MFA had only been applied to the firewall, not to the servers, workstations, or remote access tools the application implied were covered.

Travelers argued the misrepresentation was material enough to void the policy entirely, not simply reduce the payout. The case set a template other insurers have since followed: an application answer functions as a specific factual claim, checked against what investigators find after an incident, rather than a general impression of security posture.

What an $18 million claim denial revealed

The City of Hamilton, Ontario, offers the most public example of what this looks like in practice. A ransomware attack in February 2024 disabled roughly 80% of the city’s network, taking down licensing, property tax processing, and transit systems. The city refused to pay the ransom and instead absorbed the cost of rebuilding its systems. When Hamilton turned to its cyber insurer for the resulting recovery bill, estimated at $18.3 million, the claim was denied because multi-factor authentication had not been fully implemented across the network at the time of the attack, even though MFA had been identified as a requirement years earlier.

A rollout that reached some departments and not others, with nobody tracking which accounts remained exposed, left the requirement enforced on paper years before it was enforced in practice. That kind of partial implementation satisfies a security checklist during a routine quarter and fails an underwriting review the moment a claim gets filed.

For a CFO or finance director, the real lesson concerns partial deployment: a control covering most of the organization functions as no control at all, from an insurer’s perspective, when the one unprotected account happens to be the one an attacker finds.

The cyber insurance requirements insurers verify

The specific list of required controls varies by carrier and policy size, but a consistent baseline has emerged across the market. Multi-factor authentication is now expected on every account touching business systems: email, VPN and remote access, cloud administrator consoles, and any privileged login, not only the accounts that were easiest to configure first. SMS-based MFA is increasingly rejected for privileged accounts in favor of authenticator apps or hardware keys.

Endpoint detection and response has replaced traditional antivirus as the expected standard, deployed across every workstation and server rather than a subset. Roughly two-thirds of insurers now require it. Backups need to be immutable, isolated from the production network, and restore-tested on a documented schedule. A backup that has never been tested to actually restore data carries the same risk profile as no backup at all once an underwriter asks for proof.

A written incident response plan, patch management with defined timeframes, and documented security awareness training round out what most carriers now expect before issuing or renewing a policy. The list of required controls has stayed fairly stable; the burden of proof behind it has escalated sharply. Attestation used to be sufficient. Carriers now request configuration exports, sign-in logs, and screenshots demonstrating each control was active, and some ask for a signed letter from an IT provider confirming the environment matches what the application describes.

What this means for the CFO signing the renewal

This is fundamentally a financial exposure question, even though it routes through the IT department. If what you reported on your application doesn’t match what’s actually running, that mismatch defines if your claim gets paid or your policy gets rescinded. That makes it a finance and operations problem as much as an IT one, because it decides who eats the cost of a breach: the insurer or the business.

Before the next renewal comes due, a few questions deserve direct answers, ideally from whoever manages your IT: Is multi-factor authentication enforced on every account with access to business systems, including accounts added since the last audit? Has endpoint detection been deployed to every device, including exceptions and shadow systems that never made it onto an official inventory? Has backup restoration actually been tested in the last quarter, with the date documented somewhere other than someone’s memory?

The premium increases that follow a failed audit or a coverage lapse are frequently larger than the cost of closing these gaps in the first place. Insurers are pricing what you can prove, not what your actual risk looks like. A business that can’t produce documentation pays a penalty right alongside one that’s genuinely exposed.

Meeting cyber insurance requirements without the scramble

Syntech Group works with finance and operations leaders across Southern California who are staring down a renewal questionnaire that looks nothing like the one from three years ago. Enforcing multi-factor authentication across every account, deploying and monitoring endpoint detection on every device, and testing backup restoration on a documented schedule are standard components of our managed IT services.

Treating cyber insurance requirements as an ongoing operational standard, changes the negotiation with an underwriter from an application into a formality. With a renewal coming up, now’s the time to check whether your controls would hold up under a post-breach audit, not after a real claim is riding on it.