Cyber insurance IT checklist: what insurers ask for and how to prove it
The short answer. Insurers now decline or surcharge businesses that cannot show eight controls: multi-factor authentication everywhere, managed endpoint security, tested offline backups, patching on a schedule, email filtering, security awareness training, an incident response plan and privileged-account control. Each one below explains what the question means, what the insurer wants to see, and how a business of 10 to 100 people gets there.
Why the questionnaire got hard
Ransomware losses forced insurers to underwrite like banks. The application used to be a checkbox; today it is a control audit, and a wrong answer is worse than a missing one. If you attest that you have multi-factor authentication and a claim shows you did not, the insurer can deny the claim. Treat the questionnaire as a statement you will be held to.
The eight controls, in the order insurers weight them
1. Multi-factor authentication (MFA) on everything that matters. Email, remote access, administrator accounts, cloud consoles and backups. "We have MFA" means every account, not most. What to show: your Microsoft 365 or Google Workspace report of MFA enrollment, and the VPN or remote-desktop policy that refuses logins without it.
2. Managed endpoint detection and response (EDR), not antivirus. Insurers ask for EDR by name. It means a security agent on every computer and server that detects behavior, not just known files, watched by people who respond. What to show: the vendor's name, the device count covered against your total, and who monitors alerts after hours. IT Shield is our version of this control, from $10 per device per month; 24/7 human monitoring is on the Premium tier.
3. Backups that are offline or immutable, and tested. A backup that ransomware can encrypt is not a backup. Insurers want copies the attacker cannot reach, with a restore test on record. What to show: the backup product, what is covered (servers, Microsoft 365, workstations), the immutability setting, and the date and result of the last restore test.
4. Patching on a schedule. Operating systems, browsers, and the applications people use every day, updated within a defined window. What to show: the patch policy, the last month's report, and how failed patches are followed up.
5. Email security beyond the built-in filter. Advanced phishing protection, attachment sandboxing, and DMARC, DKIM and SPF on your domain so nobody can send email as you. What to show: the email security product and a DMARC record at "p=reject".
6. Security awareness training with phishing tests. At least annually, with proof of completion per employee and periodic simulated phishing. What to show: the training platform's completion report and the last simulation's results.
7. A written incident response plan. Who to call, in what order, what to shut down, how to preserve evidence, and when to notify the insurer (usually within 24 to 72 hours, or the claim is at risk). What to show: the plan, dated, with the insurer's hotline in it.
8. Privileged account control. No one uses an administrator account for daily work; local administrator rights removed; service accounts inventoried; departed employees disabled the same day. What to show: the list of administrator accounts and the offboarding procedure.
What happens at claim time
The adjuster asks for the same evidence the application asked for, plus logs from the incident. If the logs do not exist because nobody was collecting them, the claim gets harder. Managed endpoint security and a managed help desk exist partly so the record exists when you need it.
How to get through the questionnaire in two weeks
Week one: send us the questionnaire; we map every question to a control and mark it green, amber or red for your environment. Week two: we close the amber and red items, most of which are configuration, not purchases, and produce the evidence pack. You answer every question with a document behind it.
Questions
Can you fill in the cyber insurance questionnaire for us?
We map each question to a control in your environment, close the gaps, and give you the evidence; you sign the attestation with documents behind every answer, which is what protects a claim.
Is antivirus enough for cyber insurance?
No. Insurers ask for endpoint detection and response (EDR), not antivirus, and many want it monitored around the clock. IT Shield provides managed EDR from $10 per device per month with a three-device minimum; Premium adds 24/7 human threat monitoring.
What if we already got declined?
A decline usually names the missing controls. We close them, document the change, and you apply again with evidence behind every answer.
Do you help after an incident?
Yes. On Standard and Premium managed plans and IT Shield Premium we respond to P1 incidents 24/7, preserve the evidence your insurer needs, and work with your insurer's incident response firm.