Cyber insurance used to be a form you filled in. That changed. After several years of heavy losses, insurers started verifying controls before writing a policy, and verifying them again before paying a claim. Businesses that answered a questionnaire optimistically are discovering the second check is the one that counts.
Here is what carriers are actually asking for, and where claims get denied.
The controls almost every carrier now requires
Multi-factor authentication
This is the non-negotiable one. Carriers want MFA on email, on remote access, and on administrative accounts at minimum. Many now want it everywhere.
The trap is partial deployment. “We have MFA” usually means it is on for most people, with exceptions for a few executives who found it annoying and a service account nobody wants to touch. Those exceptions are exactly where attackers get in, and an insurer reviewing a claim will find them.
Endpoint detection and response
Traditional antivirus is no longer sufficient in the eyes of most carriers. They want EDR, which watches for the behavior of an attack rather than matching known signatures. If your questionnaire asks about EDR and you are running a consumer antivirus product, answering yes is a problem you have created for your future self.
Tested, offline backups
Note the word tested. Carriers increasingly ask when you last performed a restore, not whether backups exist. They also want at least one copy that ransomware cannot reach, which means immutable or genuinely offline. A backup drive plugged into the server it protects does not qualify, and modern ransomware specifically looks for it.
Documented patching
Not just that you patch, but that you can show a process and a record. “We update when we remember” is a finding.
Email security and staff training
Filtering for phishing and business email compromise, plus documented security awareness training. Business email compromise is one of the most common claim categories, and carriers price for it.
Where claims actually get denied
Three patterns come up repeatedly.
The application did not match reality. You stated MFA was deployed everywhere. The forensic investigation finds the compromised account did not have it. That is a material misrepresentation, and it can void the policy rather than just reduce the payout.
The incident response process was not followed. Most policies require immediate notification and frequently require using the carrier’s approved response vendors. Businesses that spend three days trying to fix it themselves, then call the insurer, often find that decision expensive. Call the carrier first.
A known vulnerability went unpatched. If the entry point had a patch available for months, some policies exclude the loss entirely.
Manufacturing and logistics: the newer questions
If you run production equipment, carriers have started asking whether your operational technology network is separated from your business network. This is a reasonable question with expensive consequences. A ransomware event that reaches production is not a data loss claim, it is a business interruption claim, and those are far larger.
Most owners believe their production network is isolated. In practice, a vendor remote support tool or a single convenience uplink usually connects it. Verifying that before an insurer asks is worth doing. Our OT security assessments answer that question without touching the production line.
Treat the questionnaire as a gap analysis
The most useful thing about a cyber insurance application is that it is a free list of what a well-informed third party considers minimum competence. Rather than answering it optimistically, answer it honestly, then treat every no as a project.
The controls carriers ask about are the ones that actually reduce risk. That is why they ask. A business that can answer the whole questionnaire truthfully is meaningfully harder to breach, and it will pay less for coverage.
If you are filling one out and not certain your answers are accurate, a security assessment will establish what is really true before you sign something. Being wrong on that form is worse than being uninsured, because you will have paid premiums for coverage that does not respond.