Why Underwriting Changed
Cyber insurance used to be priced largely off a self-attestation questionnaire. Ransomware loss ratios changed that. Carriers now treat specific controls — phishing-resistant multi-factor authentication, endpoint detection and response with active containment, tested and immutable backups, a documented and exercised incident response plan, and security awareness training with phishing simulation — as conditions of coverage, not best practices. Roughly three in four carriers now run independent external attack surface scans during underwriting, so what an applicant claims and what the carrier can observe from outside the network are increasingly the same dataset.
The practical consequence for mid-market organizations is that “we have a cyber policy” is no longer a sufficient answer to a board or an auditor. The policy is conditioned on maintaining specific controls continuously, not on having them in place the day the application was signed. A gap that opens six months into the policy term — an admin account MFA was never extended to, a backup job that silently stopped verifying — is a gap the carrier can point to after a breach, whether or not it caused the incident.
The Five Controls That Drive Binding and Renewal Decisions
Every major carrier’s supplemental ransomware application asks some version of these five questions. The honest answer to each requires documentation, not a checkbox.
1. MFA Everywhere — Not Just Email
Carriers now ask specifically about MFA coverage on remote access (VPN, RDP), all cloud administrator consoles, all privileged and service accounts, and email — and increasingly require phishing-resistant methods (FIDO2/WebAuthn or certificate-based) for administrators and executives rather than SMS or push-only factors. A single unenrolled admin account is enough to create a coverage dispute, because policy language typically ties the MFA warranty to the environment, not to a percentage.
2. EDR With Active Response — Not Legacy Antivirus
Signature-based antivirus no longer satisfies the endpoint question on most applications. Carriers ask whether endpoint detection and response is deployed fleet-wide, whether it is centrally monitored 24/7, and whether it can automatically contain a compromised host — isolate it from the network — rather than only alert a human who may not see the alert for hours. “We have an antivirus product” and “we have monitored EDR with automated containment” are different answers to the same question, and only one of them is what current applications are asking for.
3. Backups That Have Actually Been Tested
Carriers ask whether backups are immutable or air-gapped, and — increasingly — whether recovery has been tested, not merely whether backups exist. An untested backup is a hypothesis. Applications that ask “when was your last successful recovery test” are asking because insurers have paid claims for organizations whose backups turned out to be unrestorable when the incident actually happened. (Our companion article, Disaster Recovery in the Age of Ransomware, covers the 3-2-1-1-0 backup architecture and testing cadence underwriters are asking about in detail.)
4. A Documented, Tested Incident Response Plan
Insurers want a written IR plan with named owners and an escalation path, and evidence the plan has been exercised — a tabletop exercise is generally acceptable evidence. A plan that exists as a document nobody has walked through is difficult to defend as an operational capability if a claims adjuster asks about it after an incident. Organizations that hold an incident response retainer with a qualified provider are able to answer this question with a contract and a tested plan rather than an intention.
5. Security Awareness Training With Phishing Simulation
Business email compromise and phishing-initiated ransomware remain leading causes of loss in insurer claims data, and underwriting applications increasingly ask about the cadence of security awareness training and whether phishing simulation is run and measured — not just whether an annual compliance video was assigned. Carriers associate documented training and simulation programs with reduced claim frequency, which is reflected in both binding decisions and pricing.
How Control Gaps Turn Into Claim Denials
These are not hypothetical risks. Documented cases show carriers denying or rescinding coverage specifically because a control the applicant attested to was not actually in place.
City of Hamilton, Ontario — $18.3M Denied Over Inconsistent MFA
A February 2024 ransomware attack took down roughly 80 percent of Hamilton’s municipal systems. In July 2025, the city disclosed that its insurer denied the claim after a forensic and legal review found the absence of MFA across several departments was the “root cause” the policy excluded — leaving the city to cover the full CAD $18.3 million recovery cost. The city’s own solicitor confirmed staff knew about the MFA requirement in the policy as early as fall 2022 and had only partially rolled it out when the attack occurred (CBC News).
Travelers v. International Control Services — Coverage Rescinded Over One Server
In a 2022 federal case (No. 22-cv-2145, C.D. Ill.), Travelers sought to rescind a policy after a ransomware claim when forensics showed the insured had certified MFA on all administrative access but had, in fact, left one server without it. The case illustrates that underwriting attestations are treated as material representations — a single unenrolled system is enough grounds for an insurer to contest the entire policy, independent of whether that system was the actual point of entry.
From Attestation to Evidence
Being audit-ready means every “yes” on the application can be backed with evidence a claims investigator would accept — not just a policy document.
| Underwriter Asks | A Weak “Yes” | An Audit-Ready “Yes” |
|---|---|---|
| Is MFA enforced? | “Yes, on email and VPN” | A current identity-provider report showing 100% MFA coverage across email, remote access, admin consoles, and privileged accounts |
| Is EDR deployed? | “Yes, we have antivirus” | A monitored EDR deployment report with fleet coverage percentage and 24/7 SOC eyes-on-glass |
| Are backups tested? | “Yes, we run nightly backups” | Dated recovery-test logs with pass/fail results and immutability configuration screenshots |
| Is there an IR plan? | “Yes, it’s in the policy binder” | A named-owner plan plus a dated tabletop exercise report and, ideally, an active IR retainer contract |
| Is staff trained? | “Yes, annual training is assigned” | Completion and phishing-simulation click-rate trend reports by quarter |
SENTRY’s monitoring and reporting layer is built to produce this evidence continuously, rather than assembled by hand the week before renewal. The 90-Day Proof includes a baseline readiness review as part of the trial, so you know exactly where the gaps are before your next renewal — not after a denial.
Frequently Asked Questions About Cyber Insurance Readiness
Don’t Find Out You’re Uninsured at Claim Time.
SENTRY builds and documents the exact control set carriers underwrite against — phishing-resistant MFA, monitored EDR with active response, tested immutable backups, a rehearsed IR plan, and measured security awareness training — so your next renewal is a formality, not a gamble.
Serving regulated organizations nationally.
877-890-5508 | [email protected]