Knowing which cyber insurance controls underwriters prioritize can help you close gaps before your next application or renewal.
1. Multi-factor authentication (MFA)
MFA requirements for cyber insurance have become the most consistently enforced item on carrier questionnaires and the most commonly cited reason for application denial when it's missing. Carriers want to see it enforced across email, remote access, and privileged accounts. Cybersecurity insurance MFA requirements are increasingly verified and not self-reported.
2. Endpoint detection and response (EDR)
Insurers want to know you have active monitoring on endpoints, with the ability to detect and respond to threats in real-time. Managed EDR solutions are particularly attractive because they provide 24/7 coverage without requiring a full in-house security team.
3. Immutable backups
Backups that ransomware can encrypt are essentially useless. Carriers want off-site, immutable backups with tested recovery procedures.
4. Incident response plan
You should have a written incident response plan that identifies who does what and how you’ll communicate during an incident. Carriers may ask to see it. Give yourself extra points if you’ve conducted a tabletop exercise.
5. Patch management
Unpatched systems are a known attack vector—CISA's Known Exploited Vulnerabilities catalog documents hundreds of actively weaponized CVEs, many tied directly to ransomware group activity. Expect insurers to ask about your patch cadence and vulnerability backlog.
Restricting who holds admin-level privileges and monitoring what they do with those privileges limits the blast radius when credentials are stolen.
7. Email security
According to IBM's 2025 Cost of a Data Breach Report, phishing overtook stolen credentials as the most common initial attack vector, responsible for 16% of breaches. Carriers look for email filtering, anti-spoofing controls (SPF, DKIM, DMARC), and some form of protection against malicious attachments and links.
8. SIEM / log management
Centralized logging allows you to detect threats throughout your environment and "replay" what occurred if something goes wrong. Cyber insurance underwriting requirements increasingly focus on whether you can demonstrate active monitoring. For carriers, that means you have to be able to explain how attackers got in if the worst should occur.
The 2025 Verizon DBIR found the human element present in the majority of breaches, making training one of the highest-leverage controls an organization can implement.
10. Vulnerability management
Carriers want to know that you’re proactively scanning vulnerabilities and prioritizing remediation efforts. An asset inventory that is three years old won’t satisfy underwriters.