What are the requirements for cyber insurance?
- Brandon Alsup

- May 23, 2022
- 8 min read
Updated: Aug 18

Updated August 18, 2026
Kosh regularly gets asked what businesses need to have in place to qualify for cyber insurance.
Our customers often lean on us to work alongside their insurance broker and help determine whether their technology actually meets the requirements described on a cyber insurance application.
The short answer is:
Cyber insurance companies want to understand how well your organization protects its systems and sensitive information—and how prepared you are to respond and recover if something goes wrong.
There is no single checklist that every cyber insurance company uses. Requirements vary by carrier, industry, company size, revenue, data exposure, coverage limits, and other factors.
However, the applications we see tend to examine the same broad areas.
This article walks through five of them and shows the kinds of questions your company should be prepared to answer.
Related Articles
Start With the Application
There are a lot of potential requirements below. Don't assume your business needs to implement every one of them before talking to an insurance broker.
Nickie Tran, President of IQ Risk Insurance Services, gave us good advice when we first developed this guide: the best place to start is often the cyber liability application itself.
The application gives you something concrete to work from.
Get it from your broker early. Then have the people who understand your technology help answer the technical portions.
The process can quickly show you:
Which safeguards you already have
Which controls need to be verified
Where you may have gaps
What the particular insurer actually wants
Most importantly, don't guess at technical answers.
If you say a cybersecurity control is in place, make sure it really is.
To get Kosh Solutions' printable cybersecurity checklist, visit our Cybersecurity Assessment.
1. Cybersecurity Management
This is the high-level view of your cyber defenses.
Insurance companies aren't only interested in which security products you purchased. They may also want to understand how cybersecurity is managed inside the organization.
Examples of cybersecurity management controls include:
Security risk assessments
Written security policies
An incident response plan
Employee cybersecurity training
Restricting sensitive information based on job role
Assigning responsibility for cybersecurity
Reviewing access when employees join, change roles, or leave
Procedures for evaluating cybersecurity risks
One common question is simply:
Who is responsible for information security?
For a large organization, that may be a Chief Information Security Officer.
For a smaller business, it might be an IT director, executive, managed IT provider, or another designated person.
You don't necessarily need a full-time security executive. The insurer may simply want to understand who owns the responsibility and how cybersecurity is managed.
2. Contingency Management for Cyber Insurance
This section is about what happens if an incident actually occurs.
Can the business continue operating?
Can critical systems be recovered?
Does everyone know what to do?
Examples of contingency planning include:
Documented business continuity plan
Disaster recovery plan
Incident response plan
Documented backup procedures
Identification of critical systems
Defined recovery priorities
Alternative processes when important technology is unavailable
Contact information for key internal and external responders
Cyber insurance applications have historically asked businesses whether they maintain things such as backup systems, business continuity plans, disaster recovery plans and incident response plans.
Those questions are still highly relevant.
Travelers' publicly available CyberRisk application, for example, includes a section devoted specifically to business continuity, disaster recovery and incident response, including whether those plans are regularly tested and how long it takes to restore critical business operations.
Having a plan on paper is useful.
Knowing whether the plan actually works is better.
3. Information Records for Cyber Insurance
This section is about the information your organization collects, processes and stores.
Cyber insurers care because different types and quantities of information can create very different exposures following a breach.
Virtually every modern business holds some sensitive information.
An insurance application may ask whether you handle:
Credit or debit card information
Medical or health information
Social Security numbers
Employee and HR records
Bank account information
Customer personal information
Confidential business information
Intellectual property
It may also ask approximately how many individuals' records you maintain.
Businesses subject to requirements such as HIPAA or PCI DSS may receive additional questions about compliance.
Other information-related questions may include:
Is sensitive data encrypted while stored?
Is it encrypted while being transmitted?
Are laptops and mobile devices encrypted?
Who is allowed to access sensitive information?
Do you have data-retention and destruction procedures?
Do outside vendors store or process information for you?
These aren't theoretical questions. Data inventory, encryption, access restrictions and retention procedures all appear in cyber-insurance underwriting materials.
Travelers' publicly posted CyberRisk application, for example, asks about the types and volume of information handled, encryption, data-retention practices and access based on job function.
Understanding what information you actually have and where it lives is an important part of both cybersecurity and cyber insurance.
4. Information and Infrastructure Security Controls
This is usually the most technical part of the application. The insurer wants to understand what is standing between an attacker and your systems.
Common controls you may be asked about include:
Multi-Factor Authentication (MFA) Particularly for email, remote access, administrator accounts and privileged accounts.
Endpoint Detection and Response (EDR) Modern endpoint security that can detect and respond to suspicious behavior on computers and servers.
Patch and Vulnerability Management A process for finding vulnerabilities and keeping operating systems, applications, network equipment and other technology appropriately updated.
Firewalls and Network Security Controls designed to restrict and monitor traffic entering and leaving your environment.
Email Security and Filtering Protection against phishing, malicious links, dangerous attachments and other email-based threats.
Data Encryption Protection for sensitive data stored on devices or transmitted electronically.
Remote Access Security Controls governing VPNs, remote desktop services and other methods used to access company systems remotely.
Logging and Monitoring The ability to collect and monitor security activity so suspicious behavior can be identified.
Privileged Access Controls Additional protection around administrator and other highly powerful accounts.
Employee Security Awareness Training Ongoing training intended to reduce phishing, social engineering and other human-driven risks.
Current Travelers material identifies MFA, EDR, backup strategy, email security, encryption and remote-access controls among areas that may need to be addressed before certain cyber policies are bound. Marsh's cyber-resilience guidance also identifies patch and vulnerability management, privileged access, incident response, security awareness, logging and monitoring among important controls.
This is where the cyber-insurance application has evolved the most since this article was originally written.
A few years ago, an application might simply have asked whether you had "antivirus."
Today, the conversation is much more likely to include questions about MFA, EDR, vulnerabilities, privileged accounts, backup protection and whether security controls are actually implemented throughout the environment.
For the short version, see our Top 5 IT Requirements for Cyber Insurance Coverage.
5. Information and Infrastructure Continuity Controls
This section is related to contingency planning, but it gets more specific:
How well can your technology actually recover?
An incident response plan may tell everyone what to do. Continuity controls determine whether the systems themselves can be restored.
Questions to be prepared for include:
What systems and data are backed up?
How often are backups performed?
Are backups encrypted?
Are backup systems protected from unauthorized access?
Is at least one backup copy isolated or immutable?
Have you successfully restored data from backup?
How long would it take to restore essential functions?
Which systems have to be recovered first?
What happens if a critical cloud or technology provider becomes unavailable?
Backups deserve particular attention. Simply answering "yes, we have backups" does not tell the whole story.
A company may technically have backups while still discovering during an attack that:
The backups were also encrypted by the attacker
An administrator account gave the attacker access to the backup platform
Important systems weren't included
The backups had been failing
Nobody had tested a full restoration
That's why insurers increasingly care about both backup protection and recovery testing.
Travelers' current cyber-risk guidance specifically emphasizes protected backups and testing the ability to restore them, while its underwriting materials also ask about backup procedures and recovery testing.
What Else Might a Cyber Insurer Ask About?
The five categories above cover most of the fundamentals, but underwriting can go further.
Depending on the business and policy, you may also encounter questions about:
Vendors and third-party technology providers
Previous cyber incidents or claims
Penetration testing
External vulnerability scanning
End-of-life or unsupported systems
Wire-transfer procedures
Social engineering controls
Payment-card processing
Cloud services
Privileged access management
Security logging and monitoring
Third-party risk deserves more attention today than it did when we originally wrote this article.
Travelers' application materials include questions about vendors that have access to systems or confidential information, monitoring vendor access, revoking access when it is no longer required, and what happens if outsourced technology providers become unavailable.
You Don't Need Every Control to Apply for Cyber Insurance
There's a lot of information here, and it can feel daunting.
Remember: your company does not necessarily have to check every box on this page to receive cyber insurance coverage.
Different insurance companies have different appetites and requirements. The size and nature of your organization matter. A small professional-services company and a large healthcare organization aren't going to present exactly the same risk.
A missing control might:
Generate additional questions
Need to be addressed before coverage is bound
Affect which carriers will quote the risk
Affect pricing or terms
Affect a particular portion of coverage
Or it may not be required by your insurer at all.
That's why this article should be used as an overview and readiness checklist—not a substitute for the actual application.
Don't Guess on the Application
This may be the most important takeaway from this entire article.
Some application questions sound very simple:
Do you use MFA?
Do you have backups?
Do you use EDR?
Do you train employees?
A business owner might reasonably answer "yes" to all four.
But your IT team could discover:
MFA protects employees but not a legacy administrator account.
Backups are running, but nobody has recently tested a restoration.
EDR is deployed to workstations but missing from several servers.
Security training is available, but not every employee has completed it.
Those distinctions matter.
Don't answer technical insurance questions based on what you think is happening. Verify them.
Your insurance broker should help you understand the policy, coverage, limits, exclusions and the insurer's requirements.
Your IT provider should help you determine whether your technology actually matches the answers on the application.
Nickie Tran, President of IQ Risk Insurance Services, described that relationship well when we originally developed this guide:
"The coverage modules of cyber insurance are standardized but we tailor the policies and coverage options to the individual needs of our clients."
That principle still applies.
Is Your Company Ready?
The easiest way to find out is to start with the real application.
Ask your insurance broker for it early, then have your IT provider review the technical portions with you.
You may find that your organization is already in good shape.
Or the application may uncover several gaps worth fixing before renewal.
Either way, you will know considerably more about your actual cybersecurity posture than you did before.
To make the process easier, Kosh has put together a printable cybersecurity checklist based on the types of questions businesses encounter during cyber insurance applications.
You can also learn more about Kosh's Cybersecurity Services.
Disclaimer
The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.




Comments