The gap between these two columns is where uninsured losses live. A firm like Bloc Cyber reviews coverage at the insuring-agreement level precisely because a bundled checkbox does not reveal these gaps until a claim is filed.
Five years ago, a cyber insurance application was a two-page form with a handful of yes-or-no questions. Today, that same application runs ten pages or more, and the answers you provide directly determine whether you receive a quote, what your premium looks like, and how much coverage you can actually secure. For small and mid-market companies, the shift has been jarring. Underwriters now ask pointed questions about MFA deployment, backup architecture, EDR coverage, privileged access controls, and incident response planning, and a weak answer on any single control can result in a declination. The gap between "we have antivirus" and "we are insurable" has widened dramatically. This guide walks through each category of underwriting question, explains what carriers are actually looking for, and shows you how to position your organization for favorable terms at your next renewal. If you are an owner, CFO, IT lead, or risk manager at a company with 10 to 500 employees, these are the controls that will define your insurability through 2026 and beyond.
Why Cyber Underwriting Has Shifted to Strict Security Controls
The underwriting process for cyber liability has undergone a structural overhaul since 2021. Carriers absorbed record losses from ransomware and business email compromise claims, and their response was not simply to raise premiums. They rebuilt their applications around specific technical controls, turning the underwriting questionnaire into a de facto security audit.
This shift means your application is no longer a formality. It is the primary risk-selection tool, and your answers carry binding authority. Misrepresenting a control, whether intentionally or through ignorance, can void coverage at the moment you file a claim.
The Link Between Ransomware Claims and Underwriting Standards
Ransomware drove the change. Between 2020 and 2024, ransomware claims accounted for the majority of cyber insurance losses, with average ransom demands climbing past $1.5 million for mid-market targets. Carriers traced the root cause of most successful attacks to a short list of failures: missing MFA on remote access, no endpoint detection, and backups that were connected to the same network as production systems.
That pattern is why underwriting questions now focus on a specific set of controls. Carriers are not asking about your firewall brand or how many IT staff you employ. They want to know whether you have implemented the controls that correlate most directly with ransomware resilience.
Minimum Security Requirements vs. Preferred Risk Profiles
There is a meaningful difference between meeting the minimum threshold for a quote and qualifying for preferred pricing. Minimum requirements typically include MFA on remote access, some form of endpoint protection, and regular backups. Preferred profiles go further: phishing-resistant MFA across all applications, 24/7 managed detection and response, immutable backups with tested restoration, and a documented incident response plan that has been exercised within the past twelve months.
Companies that meet only the minimum often face higher retentions, lower sublimits on ransomware, and coinsurance provisions. Those that demonstrate a mature security posture receive broader coverage with more favorable terms.
Critical MFA and Access Control Requirements
MFA is the single most scrutinized control on any cyber insurance application. Nearly 99% of cyber insurance applications now include specific questions about MFA implementation, and the questions have grown far more granular than "Do you use MFA?"
MFA for Remote Access, Administrative Accounts, and Email
Underwriters want to know exactly where MFA is enforced. The three non-negotiable categories are remote access (VPN, RDP, remote desktop gateways), administrative and privileged accounts (domain admins, cloud admins, database admins), and email (Microsoft 365, Google Workspace, or any cloud-hosted email platform).
A common mistake among smaller organizations is deploying MFA on email but leaving RDP or VPN access protected by passwords alone. Underwriters treat that gap as a material deficiency. If your application states that MFA is in place but you cannot demonstrate enforcement across all three categories, you risk a coverage dispute if a breach exploits the unprotected entry point.
Implementing Privileged Access Management (PAM) for High-Risk Users
Privileged access management goes beyond MFA. Carriers increasingly ask whether administrative credentials are stored in a PAM vault, whether sessions are logged and monitored, and whether standing privileges have been reduced through just-in-time access provisioning. For companies with 50 or more employees, PAM controls are becoming a baseline expectation rather than a differentiator.
If you do not have a formal PAM solution, document the compensating controls you use: separate admin accounts, time-limited access, mandatory approval workflows, and session recording. Underwriters want evidence that privileged credentials are not a single point of failure.
Defending the Perimeter with EDR and Incident Response Plans
Endpoint protection and incident response readiness are evaluated together because they represent two sides of the same coin: your ability to detect an attack and your ability to respond before it becomes a claim.
Endpoint Detection and Response (EDR) vs. Traditional Antivirus
Traditional signature-based antivirus is no longer sufficient for most cyber insurance applications. Underwriters specifically ask whether you deploy EDR, which provides behavioral analysis, threat hunting, and automated containment capabilities that antivirus cannot match.
The distinction matters because modern attacks rarely rely on known malware signatures. They use living-off-the-land techniques, fileless attacks, and legitimate administrative tools. EDR platforms detect these behaviors in real time. Many carriers now require EDR with a managed detection and response (MDR) service that provides 24/7 monitoring, particularly for organizations without an in-house security operations center.
Testing Your Incident Response Plan with Tabletop Exercises
Having an incident response plan on paper is not enough. Underwriters ask whether the plan has been tested, when it was last updated, and who participates in the exercises. A tabletop exercise, where key stakeholders walk through a simulated breach scenario, demonstrates that your organization can execute the plan under pressure.
Run at least one tabletop exercise per year. Include your executive team, IT staff, legal counsel, and your insurance broker. At Bloc Cyber, we encourage clients to review their policy's notice provisions during these exercises so the team knows exactly when and how to trigger coverage. A 72-hour delay in notifying your carrier can jeopardize your claim.
Securing Backup Architecture Against Ransomware
Backup questions on cyber insurance applications have evolved from "Do you back up your data?" to detailed inquiries about architecture, segmentation, and recovery testing.
The Importance of Air-Gapped and Immutable Backups
Ransomware operators specifically target backup systems. If your backups reside on the same network as your production environment, an attacker with domain admin credentials can encrypt or delete them alongside everything else. That is why underwriters now ask whether your backups are air-gapped (physically or logically isolated from the production network) or immutable (stored in a format that cannot be altered or deleted for a defined retention period).
Cloud-based immutable storage has become a practical option for small and mid-market companies that cannot maintain physical air-gapped tape infrastructure. The key is that the backup cannot be reached or modified by an attacker who has compromised your primary environment.
Verification and Restoration Testing Frequencies
Backups that have never been tested are backups you cannot rely on. Underwriters ask how often you verify backup integrity and whether you have performed a full restoration test. Quarterly testing is the emerging standard, though monthly testing will strengthen your application.
Document the results of each test, including time-to-restore metrics. If your recovery time objective is 48 hours but your last test showed a 96-hour restore, that gap is a material risk that underwriters will probe.
Comparison: Basic Security vs. Insurable Security Posture
Understanding the gap between a minimal security setup and what carriers expect helps you prioritize investments that directly affect your insurability and premium.
Table: Control Implementation and Impact on Premiums
| Attack Method | Primary Pressure | Data Breach Involved? | Typical Demand Range (Mid-Market) | Key Insurance Response |
|---|---|---|---|---|
| Encryption Only | Operational shutdown | Not necessarily | $50K - $500K | Business interruption, forensics, ransom reimbursement (if covered) |
| Data Leak Threat | Regulatory and reputational exposure | Yes | $100K - $1M+ | Notification costs, regulatory defense, crisis PR |
| DDoS Extortion | Revenue loss from downtime | No | $10K - $250K | Business interruption, DDoS mitigation costs |
| Double Extortion | Shutdown + leak threat combined | Yes | $100K - $2M+ | All first-party and third-party coverages may apply |
| Triple Extortion | Shutdown + leak + third-party pressure | Yes | $250K - $5M+ | Full policy activation including liability defense |
These ranges are approximate and vary by carrier, industry, and revenue size. The cumulative effect of implementing all five controls can be substantial, both in premium savings and in the breadth of coverage available to you.
Common Questions About Cyber Insurance Applications
FAQ: What if we don't have MFA on every application?
Partial MFA deployment does not automatically disqualify you, but it limits your options. Most carriers require MFA on remote access, admin accounts, and email as a minimum. Missing any of those three will likely result in a declination or a restrictive endorsement.
FAQ: Does having a backup mean I don't need cyber insurance?
No. Backups protect your data, but they do not cover forensic investigation costs, legal defense, regulatory fines, notification expenses, or business interruption losses. A policy form may respond to all of those exposures depending on how it is written.
FAQ: Why does the insurer care about my employee training?
Phishing remains the most common initial attack vector. Carriers ask about security awareness training because organizations with regular training programs file fewer claims. Annual training with simulated phishing tests is the standard expectation.
FAQ: Can I get coverage if I use a personal device for work?
You can, but your application will need to describe the controls applied to those devices: MDM enrollment, MFA enforcement, endpoint protection, and data segregation. Unmanaged personal devices are a red flag for underwriters.
FAQ: How often should I update my incident response plan?
Review and update it at least annually, or immediately after any organizational change such as a new IT vendor, office location, or leadership transition. Carriers want to see a plan that reflects your current environment and contact information.
Preparing Your Business for the Next Renewal
Your renewal is not just a billing event. It is the moment when your security posture is reassessed and your coverage terms are reset. Start preparing 90 days before your renewal date by auditing your MFA deployment, confirming your backup architecture meets current standards, verifying EDR coverage across all endpoints, reviewing privileged access controls, and scheduling a tabletop exercise for your incident response plan.
Each of these controls maps directly to questions on your application. Gaps that existed at your last renewal may now result in exclusions, higher retentions, or non-renewal. The underwriting questions around MFA, backups, EDR, privileged access, and incident response are not going to get simpler: they will only grow more detailed as carriers refine their risk models.
If you are unsure whether your current controls align with what carriers expect, Bloc Cyber works through the actual policy form with you, identifying where coverage grants stop and where gaps exist before a claim surfaces. Request a coverage review to have a specialist walk through your application and policy language, so you know exactly what you are buying and what you are not.
ABOUT THE AUTHOR
Caden Braly
— Founder, Bloc Cyber
I'm Caden Braly, founder of Bloc Cyber, the specialty cyber insurance arm of Braly Insurance. I built Bloc Cyber around one idea: businesses deserve coverage that actually responds when a cyberattack happens. I work closely with clients to understand their exposure, place the right policy through specialty carriers, and stand with them through the claim. My goal is simple — give every business straight answers and protection they can trust.
Full profile → caden@bloccyber.com LinkedIn




