Services /  GRC

Cyber Insurance Readiness

Answer the insurer's questions truthfully, and be able to prove the answers.

The problem

The cyber insurance application asks whether you enforce MFA everywhere, whether backups are offline and tested, and whether EDR covers every endpoint. Someone is about to tick yes to all three. If a claim ever follows, those ticks are the first thing the insurer will examine.

The method.

01

Test the warranties before you sign them

Insurer applications turn on a small number of controls: MFA on email, remote access and privileged accounts; EDR coverage; immutable or offline backups with tested restores; patch cadence on internet-facing systems; email filtering; and privileged access separation. We verify each against the systems, not against a recollection: MFA enforcement policy in the IdP, agent coverage against the asset inventory, last successful restore test date.

02

Report the honest coverage number

Coverage is a percentage, not a yes. "EDR on 87% of endpoints, 14 machines uncovered, all contractor laptops" is an answer you can defend and remediate. "Yes" is an answer that can void a claim.

03

Close the cheap gaps first

Most applications fail on a handful of items that take days, not quarters: MFA on the last legacy protocol, an EDR agent on the machines the MDM never enrolled, a restore test that has never been performed. Fixing these usually moves both the premium and the coverage terms.

04

Assemble the evidence file

For each declared control, keep the artifact that supports it: the IdP conditional-access policy export, the agent coverage report, the restore test record with timestamps, the patch SLA report, the incident response plan and the date of the last exercise. Filed together, dated, and refreshed at renewal.

05

Align the policy with the incident plan

Read the notification clause: most policies require notification within a fixed window and require the insurer's panel counsel and forensic firm to be used. Those contacts and that deadline belong inside your incident response plan, or the first hours of a real incident will quietly breach the policy.

Insurance warranties are annual declarations about a system that changes daily. The ROC keeps testing the declared controls through the policy period, so at claim time, and at renewal, the answer you gave is still the answer that is true.

What controls do cyber insurers require?

Most underwriters converge on the same set: multi-factor authentication on email, VPN and privileged accounts; endpoint detection and response deployed across the estate; immutable or offline backups with tested restores; a patching cadence for internet-facing systems; email filtering; separation of privileged accounts; and a documented, exercised incident response plan. Coverage and premium both turn on these.

Can a cyber insurance claim be denied because of an inaccurate application?

Yes. Answers on the proposal form are typically warranties. If you declared universal MFA and the breach entered through an account without it, the insurer can dispute or deny the claim on that basis. The safe approach is to answer with verified coverage figures and named exceptions rather than with a yes.

How do you evidence backup and restore controls to an insurer?

With a dated restore test record: what was restored, from which backup, how long it took, whether the data was verified as complete, and who performed it. Backups that exist but have never been restored are the most common gap found during insurance readiness, and they are also the most common reason a ransomware recovery fails.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.