top of page

Top 5 IT Requirements for Cyber Insurance Coverage

May 11, 2023
4 min read

Updated: Aug 18

Updated August 17, 2026


Infographic titled 5 Things Cyber Insurance Companies Look For shows a checklist, laptop alerts, backups, and incident response.

You may already know the reasons why your business needs cyber insurance, but figuring out what insurers expect from your IT environment can be less straightforward.


There is no universal checklist that every cyber insurer uses. Requirements vary based on the insurer, your industry, company size, coverage limits, and risk profile.


However, cyber insurance applications consistently ask about a core group of cybersecurity controls. In 2026, these are five of the most important areas businesses should be prepared to address.


What do cyber insurance companies look for?


1. Multi-Factor Authentication (MFA)

MFA remains one of the most important cybersecurity controls.

At a minimum, businesses should expect questions about MFA protecting:

  • Email

  • Remote access

  • Administrator and privileged accounts

  • Critical cloud applications


The important distinction is where MFA is actually enabled. Answering "yes" to an application question about MFA when it only protects some users or systems can create problems later.


2. Endpoint Detection and Response (EDR)

Traditional commercial antivirus is no longer the best way to describe modern endpoint protection.


Insurers increasingly want to know whether computers and servers are protected by Endpoint Detection and Response (EDR) or comparable security technology capable of detecting suspicious behavior and responding to threats.


EDR does more than scan for known viruses. It helps identify potentially malicious activity occurring on an endpoint and gives your IT or security team greater visibility when something goes wrong.


3. Vulnerability and Patch Management

Keeping software current has become increasingly important as attackers target vulnerabilities in internet-facing systems, firewalls, VPN appliances, applications, and other technology.


Businesses should have a process for:

  • Identifying vulnerabilities

  • Prioritizing critical security updates

  • Patching operating systems and applications

  • Updating network and security devices

  • Addressing unsupported or end-of-life technology

Simply turning on automatic Windows updates is not the same thing as having a vulnerability-management process.


4. Protected and Tested Backups

Most businesses have some form of backup. The more important question is:

Can those backups actually help you recover from a cyberattack?

Insurers may ask whether critical systems and data are backed up, whether backups are separated or protected from the production environment, and whether recovery has been tested.


A backup that has never been tested is still an assumption. This has become especially important with ransomware because attackers frequently try to compromise backups as part of an attack.


5. An Incident Response Plan

Cybersecurity is not only about preventing an attack. Businesses also need a plan for what happens when something gets through.


An incident response plan should establish basics such as:

  • Who needs to be contacted

  • Who has authority to make decisions

  • How IT systems will be isolated or investigated

  • When the insurance carrier and broker should be contacted

  • How outside legal, forensic, or security resources will be engaged

  • How the business will continue operating during the incident


The middle of a ransomware attack is not the ideal time to decide who is responsible for doing what.


What about employee cybersecurity training?

Security awareness training is still important and is frequently evaluated by insurers. So are email security, privileged-access controls, logging and monitoring, remote-access security, and other safeguards.


We have limited this article to five controls because these provide a useful starting point—not because they are the only things an insurer may ask about.

For a more comprehensive look, see our guide: What Are the Requirements for Cyber Insurance?


You can also read our broader overview: Cyber Insurance in 2026: What Businesses Need to Know.


Don't Just Check the Box

This may be the most important part of the cyber insurance application process.

Don't guess at the technical answers.


Applications may ask whether you use MFA, EDR, backups, vulnerability management, employee training, security monitoring, or other controls. A business owner or office manager may reasonably believe a safeguard is in place without knowing exactly how it is configured.


Have your IT or cybersecurity provider review the technical portions of the application.


For example, your organization might use MFA for Microsoft 365 users but have a legacy administrator account that is not protected. Or you may have backups running every night without anyone regularly testing whether critical systems can actually be restored.


Inaccurate information on an insurance application can create coverage issues if an incident later occurs. The specific outcome depends on the policy, the facts of the claim, and applicable law, so businesses should work with their insurance broker or carrier on insurance questions.


Your IT team has a different job:

Make sure the technical answers accurately describe your environment.

Cyber Insurance Requirements Are Really Cybersecurity Fundamentals

One positive change in cyber insurance over the past several years is that many of the controls insurers ask about are simply good cybersecurity practices.


MFA, EDR, patch management, tested backups, and incident response planning do not only help with an insurance application. They make it harder for an attacker to get in and give your organization a better chance of recovering when something does happen.


Before your next cyber insurance renewal, ask your broker for the application early and have your IT provider review the technical questions with you.

Kosh also offers a Free Cybersecurity Checklist that can help you identify areas that may need attention before your next renewal.


Disclaimer


The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.



Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page