Cyber Insurance Readiness: What Underwriters Actually Require Now

Armorstack SENTRY — Cyber Insurance Readiness

Cyber Insurance Readiness: What Underwriters Actually Require Now

Underwriting has shifted from a questionnaire to a technical audit. Carriers now verify MFA, EDR, backup testing, and incident response capability before they bind or renew — and a documentation gap on any one of them can mean a denied claim, not just a higher premium. Here is what underwriters check, how gaps surface after a breach, and how to get audit-ready before renewal.

Direct Answer

Why Underwriting Changed

Cyber insurance used to be priced largely off a self-attestation questionnaire. Ransomware loss ratios changed that. Carriers now treat specific controls — phishing-resistant multi-factor authentication, endpoint detection and response with active containment, tested and immutable backups, a documented and exercised incident response plan, and security awareness training with phishing simulation — as conditions of coverage, not best practices. Roughly three in four carriers now run independent external attack surface scans during underwriting, so what an applicant claims and what the carrier can observe from outside the network are increasingly the same dataset.

The practical consequence for mid-market organizations is that “we have a cyber policy” is no longer a sufficient answer to a board or an auditor. The policy is conditioned on maintaining specific controls continuously, not on having them in place the day the application was signed. A gap that opens six months into the policy term — an admin account MFA was never extended to, a backup job that silently stopped verifying — is a gap the carrier can point to after a breach, whether or not it caused the incident.

What Underwriters Check

The Five Controls That Drive Binding and Renewal Decisions

Every major carrier’s supplemental ransomware application asks some version of these five questions. The honest answer to each requires documentation, not a checkbox.

1. MFA Everywhere — Not Just Email

Carriers now ask specifically about MFA coverage on remote access (VPN, RDP), all cloud administrator consoles, all privileged and service accounts, and email — and increasingly require phishing-resistant methods (FIDO2/WebAuthn or certificate-based) for administrators and executives rather than SMS or push-only factors. A single unenrolled admin account is enough to create a coverage dispute, because policy language typically ties the MFA warranty to the environment, not to a percentage.

2. EDR With Active Response — Not Legacy Antivirus

Signature-based antivirus no longer satisfies the endpoint question on most applications. Carriers ask whether endpoint detection and response is deployed fleet-wide, whether it is centrally monitored 24/7, and whether it can automatically contain a compromised host — isolate it from the network — rather than only alert a human who may not see the alert for hours. “We have an antivirus product” and “we have monitored EDR with automated containment” are different answers to the same question, and only one of them is what current applications are asking for.

3. Backups That Have Actually Been Tested

Carriers ask whether backups are immutable or air-gapped, and — increasingly — whether recovery has been tested, not merely whether backups exist. An untested backup is a hypothesis. Applications that ask “when was your last successful recovery test” are asking because insurers have paid claims for organizations whose backups turned out to be unrestorable when the incident actually happened. (Our companion article, Disaster Recovery in the Age of Ransomware, covers the 3-2-1-1-0 backup architecture and testing cadence underwriters are asking about in detail.)

4. A Documented, Tested Incident Response Plan

Insurers want a written IR plan with named owners and an escalation path, and evidence the plan has been exercised — a tabletop exercise is generally acceptable evidence. A plan that exists as a document nobody has walked through is difficult to defend as an operational capability if a claims adjuster asks about it after an incident. Organizations that hold an incident response retainer with a qualified provider are able to answer this question with a contract and a tested plan rather than an intention.

5. Security Awareness Training With Phishing Simulation

Business email compromise and phishing-initiated ransomware remain leading causes of loss in insurer claims data, and underwriting applications increasingly ask about the cadence of security awareness training and whether phishing simulation is run and measured — not just whether an annual compliance video was assigned. Carriers associate documented training and simulation programs with reduced claim frequency, which is reflected in both binding decisions and pricing.

Where This Goes Wrong

How Control Gaps Turn Into Claim Denials

These are not hypothetical risks. Documented cases show carriers denying or rescinding coverage specifically because a control the applicant attested to was not actually in place.

City of Hamilton, Ontario — $18.3M Denied Over Inconsistent MFA

A February 2024 ransomware attack took down roughly 80 percent of Hamilton’s municipal systems. In July 2025, the city disclosed that its insurer denied the claim after a forensic and legal review found the absence of MFA across several departments was the “root cause” the policy excluded — leaving the city to cover the full CAD $18.3 million recovery cost. The city’s own solicitor confirmed staff knew about the MFA requirement in the policy as early as fall 2022 and had only partially rolled it out when the attack occurred (CBC News).

Travelers v. International Control Services — Coverage Rescinded Over One Server

In a 2022 federal case (No. 22-cv-2145, C.D. Ill.), Travelers sought to rescind a policy after a ransomware claim when forensics showed the insured had certified MFA on all administrative access but had, in fact, left one server without it. The case illustrates that underwriting attestations are treated as material representations — a single unenrolled system is enough grounds for an insurer to contest the entire policy, independent of whether that system was the actual point of entry.

Getting Audit-Ready

From Attestation to Evidence

Being audit-ready means every “yes” on the application can be backed with evidence a claims investigator would accept — not just a policy document.

Underwriter AsksA Weak “Yes”An Audit-Ready “Yes”
Is MFA enforced?“Yes, on email and VPN”A current identity-provider report showing 100% MFA coverage across email, remote access, admin consoles, and privileged accounts
Is EDR deployed?“Yes, we have antivirus”A monitored EDR deployment report with fleet coverage percentage and 24/7 SOC eyes-on-glass
Are backups tested?“Yes, we run nightly backups”Dated recovery-test logs with pass/fail results and immutability configuration screenshots
Is there an IR plan?“Yes, it’s in the policy binder”A named-owner plan plus a dated tabletop exercise report and, ideally, an active IR retainer contract
Is staff trained?“Yes, annual training is assigned”Completion and phishing-simulation click-rate trend reports by quarter

SENTRY’s monitoring and reporting layer is built to produce this evidence continuously, rather than assembled by hand the week before renewal. The 90-Day Proof includes a baseline readiness review as part of the trial, so you know exactly where the gaps are before your next renewal — not after a denial.

FAQ

Frequently Asked Questions About Cyber Insurance Readiness

Will good controls actually lower our premium, or just get us bound?
Both. Carriers price ransomware coverage in part on the same control set discussed here, and organizations that can produce evidence of phishing-resistant MFA, monitored EDR, tested backups, and a documented IR program typically qualify for standard or preferred pricing tiers rather than the surcharged or excluded terms applied to unverified applicants. Ask your broker specifically which controls affect your premium tier — it varies by carrier and industry.
Does having SENTRY replace the need for a broker or an insurance application review?
No. SENTRY builds and documents the technical controls carriers ask about; your broker remains the right party to interpret specific policy language, warranty clauses, and panel-firm requirements. We recommend having your broker review the underwriting application alongside your SENTRY readiness report before you submit.
We already have a policy. Do we need to worry about this before renewal?
Yes. Most policies condition ongoing coverage on maintaining the attested controls for the full policy term, not just at signing — the Hamilton case turned on a gap that opened after the policy was in force. A mid-term control gap (an MFA rollout that stalls, an EDR agent that silently stops reporting) is exactly the kind of thing that surfaces during a post-incident forensic review.
What is a phishing-resistant MFA method, specifically?
FIDO2/WebAuthn security keys and platform passkeys, and certificate-based authentication, are considered phishing-resistant because the credential is cryptographically bound to the legitimate site and cannot be relayed by an attacker-controlled proxy. SMS codes and simple push approval are better than nothing but are increasingly excluded from what carriers count as compliant MFA for privileged and administrative accounts specifically because both have been defeated at scale by real-time phishing kits.
How long does a readiness review take?
A baseline SENTRY readiness review — mapping your current MFA, EDR, backup testing, IR plan, and training posture against a standard carrier supplemental application — typically takes one to two weeks depending on environment size. Request a readiness review to get a specific timeline for your organization.

Don’t Find Out You’re Uninsured at Claim Time.

SENTRY builds and documents the exact control set carriers underwrite against — phishing-resistant MFA, monitored EDR with active response, tested immutable backups, a rehearsed IR plan, and measured security awareness training — so your next renewal is a formality, not a gamble.

Serving regulated organizations nationally.
877-890-5508  |  [email protected]