Cyber Insurance Checklist
The technical requirements every business must meet to obtain and maintain coverage
Cyber insurers are tightening requirements faster than most businesses can keep up. This checklist covers the security controls most commonly required to qualify for coverage and to ensure your claims are honored.
Multi-Factor Authentication (MFA)
MFA is now the single most universally required control across all major cyber insurers. You must have MFA enabled on: all email accounts (Microsoft 365, Google Workspace), all remote access solutions (VPN, Remote Desktop, Citrix), all privileged/admin accounts, all cloud-based applications containing sensitive data, and all financial systems. Failure to have MFA enabled, especially on email and remote access, is the most common reason claims are denied after an incident.
Endpoint Detection & Response (EDR)
Traditional antivirus is no longer sufficient. Insurers require Endpoint Detection and Response (EDR) software on all managed endpoints: workstations, laptops, and servers. EDR provides behavioral-based detection that can identify threats antivirus misses, particularly fileless malware and ransomware in its early stages. You must be able to demonstrate that EDR is deployed and actively monitored on 100% of your endpoints.
Privileged Access Management
Admin and privileged accounts represent the highest-value targets for attackers. Insurers require that: privileged accounts are separate from standard user accounts, admin credentials are not used for day-to-day computing tasks, local administrator rights are removed from standard user accounts where possible, and all privileged account access is logged and monitored. This is a technical control that requires proper configuration, not just a policy statement.
Backup & Disaster Recovery
You must be able to demonstrate a working, tested backup strategy. Insurer requirements typically include: automated daily backups of all critical systems and data, off-site or cloud backup storage (not just local backup), immutable or air-gapped backup copies that ransomware cannot encrypt, documented recovery procedures with defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), and evidence of regular backup restoration testing. A backup that has never been tested is not a backup from an insurer's perspective.
Patch Management
Insurers require a documented, regular patch management process covering: operating system patches applied within 30 days of release (critical patches within 14 days), third-party software patches (browsers, Java, Adobe, etc.) applied promptly, firmware updates for network equipment, servers, and other infrastructure, and a process for identifying end-of-life systems that no longer receive security updates. Unpatched systems are the leading vector for ransomware attacks, and insurers know it.
Security Awareness Training
Human error remains the leading cause of breaches. Insurers increasingly require: regular (at minimum annual, preferably quarterly) security awareness training for all employees, phishing simulation exercises to test and reinforce training, documented training completion records, and training coverage of specific topics including phishing, social engineering, password hygiene, and data handling. Annual training checkboxes are being replaced by requirements for ongoing, measurable programs.
Email Security Controls
Email is the primary attack vector for phishing and business email compromise (BEC). Required controls typically include: email filtering (anti-spam, anti-malware, sandboxing), DMARC, DKIM, and SPF records configured correctly on your domain, advanced threat protection that can identify malicious links and attachments, and email encryption for messages containing sensitive data. BEC attacks, where attackers impersonate executives or vendors to redirect payments, have caused billions in losses and are a focus area for insurers.
Incident Response Plan
You must have a documented, tested incident response plan that covers: defined roles and responsibilities during a security incident, contact information for your IT provider, legal counsel, and insurance carrier, documented steps for isolating compromised systems, communication procedures for notifying affected parties, and evidence that the plan has been reviewed and updated within the past 12 months. Insurers want to know that if something goes wrong, you know what to do and won't make it worse.
Network Security
Basic network security controls required by most insurers include: a next-generation firewall (NGFW) configured and maintained by a qualified professional, network segmentation to limit lateral movement in the event of a breach, remote access via VPN with MFA (no open RDP to the internet), wireless network segmentation (guest networks separated from corporate networks), and logging and monitoring of network traffic for anomalous activity.
Vendor & Third-Party Risk
Insurers are increasingly focused on supply chain risk. You should be able to demonstrate: a documented inventory of all vendors with access to your systems or data, contractual requirements for security practices in vendor agreements, a process for vetting new vendors before granting access, and regular review of vendor security posture. Third-party breaches, where an attacker compromises your vendor to reach you, are increasingly common and a growing underwriting focus.
Not Sure If You Meet These Requirements?
A cyber insurance readiness assessment from SimplifIT will evaluate your current security posture against insurer requirements and give you a prioritized action plan. We work with organizations to close the gaps before renewal, not after a claim is denied.
