top of page

What are the requirements for cyber insurance?

Updated: Aug 18

Desk scene with laptop, padlock and clipboard beside text reading What are the requirements for cyber insurance?

Updated August 18, 2026


Kosh regularly gets asked what businesses need to have in place to qualify for cyber insurance.


Our customers often lean on us to work alongside their insurance broker and help determine whether their technology actually meets the requirements described on a cyber insurance application.


The short answer is:

Cyber insurance companies want to understand how well your organization protects its systems and sensitive information—and how prepared you are to respond and recover if something goes wrong.

There is no single checklist that every cyber insurance company uses. Requirements vary by carrier, industry, company size, revenue, data exposure, coverage limits, and other factors.


However, the applications we see tend to examine the same broad areas.

This article walks through five of them and shows the kinds of questions your company should be prepared to answer.


Related Articles


Start With the Application

There are a lot of potential requirements below. Don't assume your business needs to implement every one of them before talking to an insurance broker.

Nickie Tran, President of IQ Risk Insurance Services, gave us good advice when we first developed this guide: the best place to start is often the cyber liability application itself.


The application gives you something concrete to work from.

Get it from your broker early. Then have the people who understand your technology help answer the technical portions.


The process can quickly show you:

  • Which safeguards you already have

  • Which controls need to be verified

  • Where you may have gaps

  • What the particular insurer actually wants


Most importantly, don't guess at technical answers.

If you say a cybersecurity control is in place, make sure it really is.

To get Kosh Solutions' printable cybersecurity checklist, visit our Cybersecurity Assessment.


1. Cybersecurity Management

This is the high-level view of your cyber defenses.

Insurance companies aren't only interested in which security products you purchased. They may also want to understand how cybersecurity is managed inside the organization.


Examples of cybersecurity management controls include:

  • Security risk assessments

  • Written security policies

  • An incident response plan

  • Employee cybersecurity training

  • Restricting sensitive information based on job role

  • Assigning responsibility for cybersecurity

  • Reviewing access when employees join, change roles, or leave

  • Procedures for evaluating cybersecurity risks


One common question is simply:

Who is responsible for information security?

For a large organization, that may be a Chief Information Security Officer.

For a smaller business, it might be an IT director, executive, managed IT provider, or another designated person.


You don't necessarily need a full-time security executive. The insurer may simply want to understand who owns the responsibility and how cybersecurity is managed.


2. Contingency Management for Cyber Insurance

This section is about what happens if an incident actually occurs.

  • Can the business continue operating?

  • Can critical systems be recovered?

  • Does everyone know what to do?


Examples of contingency planning include:

  • Documented business continuity plan

  • Disaster recovery plan

  • Incident response plan

  • Documented backup procedures

  • Identification of critical systems

  • Defined recovery priorities

  • Alternative processes when important technology is unavailable

  • Contact information for key internal and external responders


Cyber insurance applications have historically asked businesses whether they maintain things such as backup systems, business continuity plans, disaster recovery plans and incident response plans.

Those questions are still highly relevant.


Travelers' publicly available CyberRisk application, for example, includes a section devoted specifically to business continuity, disaster recovery and incident response, including whether those plans are regularly tested and how long it takes to restore critical business operations.


Having a plan on paper is useful.


Knowing whether the plan actually works is better.


3. Information Records for Cyber Insurance

This section is about the information your organization collects, processes and stores.


Cyber insurers care because different types and quantities of information can create very different exposures following a breach.


Virtually every modern business holds some sensitive information.


An insurance application may ask whether you handle:

  • Credit or debit card information

  • Medical or health information

  • Social Security numbers

  • Employee and HR records

  • Bank account information

  • Customer personal information

  • Confidential business information

  • Intellectual property


It may also ask approximately how many individuals' records you maintain.

Businesses subject to requirements such as HIPAA or PCI DSS may receive additional questions about compliance.


Other information-related questions may include:

  • Is sensitive data encrypted while stored?

  • Is it encrypted while being transmitted?

  • Are laptops and mobile devices encrypted?

  • Who is allowed to access sensitive information?

  • Do you have data-retention and destruction procedures?

  • Do outside vendors store or process information for you?


These aren't theoretical questions. Data inventory, encryption, access restrictions and retention procedures all appear in cyber-insurance underwriting materials.

Travelers' publicly posted CyberRisk application, for example, asks about the types and volume of information handled, encryption, data-retention practices and access based on job function.


Understanding what information you actually have and where it lives is an important part of both cybersecurity and cyber insurance.


4. Information and Infrastructure Security Controls

This is usually the most technical part of the application. The insurer wants to understand what is standing between an attacker and your systems.


Common controls you may be asked about include:

  • Multi-Factor Authentication (MFA) Particularly for email, remote access, administrator accounts and privileged accounts.

  • Endpoint Detection and Response (EDR) Modern endpoint security that can detect and respond to suspicious behavior on computers and servers.

  • Patch and Vulnerability Management A process for finding vulnerabilities and keeping operating systems, applications, network equipment and other technology appropriately updated.

  • Firewalls and Network Security Controls designed to restrict and monitor traffic entering and leaving your environment.

  • Email Security and Filtering Protection against phishing, malicious links, dangerous attachments and other email-based threats.

  • Data Encryption Protection for sensitive data stored on devices or transmitted electronically.

  • Remote Access Security Controls governing VPNs, remote desktop services and other methods used to access company systems remotely.

  • Logging and Monitoring The ability to collect and monitor security activity so suspicious behavior can be identified.

  • Privileged Access Controls Additional protection around administrator and other highly powerful accounts.

  • Employee Security Awareness Training Ongoing training intended to reduce phishing, social engineering and other human-driven risks.


Current Travelers material identifies MFA, EDR, backup strategy, email security, encryption and remote-access controls among areas that may need to be addressed before certain cyber policies are bound. Marsh's cyber-resilience guidance also identifies patch and vulnerability management, privileged access, incident response, security awareness, logging and monitoring among important controls.


This is where the cyber-insurance application has evolved the most since this article was originally written.


A few years ago, an application might simply have asked whether you had "antivirus."


Today, the conversation is much more likely to include questions about MFA, EDR, vulnerabilities, privileged accounts, backup protection and whether security controls are actually implemented throughout the environment.


5. Information and Infrastructure Continuity Controls

This section is related to contingency planning, but it gets more specific:

How well can your technology actually recover?

An incident response plan may tell everyone what to do. Continuity controls determine whether the systems themselves can be restored.


Questions to be prepared for include:

  • What systems and data are backed up?

  • How often are backups performed?

  • Are backups encrypted?

  • Are backup systems protected from unauthorized access?

  • Is at least one backup copy isolated or immutable?

  • Have you successfully restored data from backup?

  • How long would it take to restore essential functions?

  • Which systems have to be recovered first?

  • What happens if a critical cloud or technology provider becomes unavailable?


Backups deserve particular attention. Simply answering "yes, we have backups" does not tell the whole story.


A company may technically have backups while still discovering during an attack that:

  • The backups were also encrypted by the attacker

  • An administrator account gave the attacker access to the backup platform

  • Important systems weren't included

  • The backups had been failing

  • Nobody had tested a full restoration


That's why insurers increasingly care about both backup protection and recovery testing.


Travelers' current cyber-risk guidance specifically emphasizes protected backups and testing the ability to restore them, while its underwriting materials also ask about backup procedures and recovery testing.


What Else Might a Cyber Insurer Ask About?

The five categories above cover most of the fundamentals, but underwriting can go further.


Depending on the business and policy, you may also encounter questions about:

  • Vendors and third-party technology providers

  • Previous cyber incidents or claims

  • Penetration testing

  • External vulnerability scanning

  • End-of-life or unsupported systems

  • Wire-transfer procedures

  • Social engineering controls

  • Payment-card processing

  • Cloud services

  • Privileged access management

  • Security logging and monitoring


Third-party risk deserves more attention today than it did when we originally wrote this article.


Travelers' application materials include questions about vendors that have access to systems or confidential information, monitoring vendor access, revoking access when it is no longer required, and what happens if outsourced technology providers become unavailable.


You Don't Need Every Control to Apply for Cyber Insurance

There's a lot of information here, and it can feel daunting.

Remember: your company does not necessarily have to check every box on this page to receive cyber insurance coverage.


Different insurance companies have different appetites and requirements. The size and nature of your organization matter. A small professional-services company and a large healthcare organization aren't going to present exactly the same risk.


A missing control might:

  • Generate additional questions

  • Need to be addressed before coverage is bound

  • Affect which carriers will quote the risk

  • Affect pricing or terms

  • Affect a particular portion of coverage


Or it may not be required by your insurer at all.

That's why this article should be used as an overview and readiness checklist—not a substitute for the actual application.


Don't Guess on the Application

This may be the most important takeaway from this entire article.

Some application questions sound very simple:

  • Do you use MFA?

  • Do you have backups?

  • Do you use EDR?

  • Do you train employees?


A business owner might reasonably answer "yes" to all four.

But your IT team could discover:

  • MFA protects employees but not a legacy administrator account.

  • Backups are running, but nobody has recently tested a restoration.

  • EDR is deployed to workstations but missing from several servers.

  • Security training is available, but not every employee has completed it.


Those distinctions matter.


Don't answer technical insurance questions based on what you think is happening. Verify them.

Your insurance broker should help you understand the policy, coverage, limits, exclusions and the insurer's requirements.


Your IT provider should help you determine whether your technology actually matches the answers on the application.


Nickie Tran, President of IQ Risk Insurance Services, described that relationship well when we originally developed this guide:

"The coverage modules of cyber insurance are standardized but we tailor the policies and coverage options to the individual needs of our clients."

That principle still applies.


Is Your Company Ready?

The easiest way to find out is to start with the real application.

Ask your insurance broker for it early, then have your IT provider review the technical portions with you.


You may find that your organization is already in good shape.


Or the application may uncover several gaps worth fixing before renewal.

Either way, you will know considerably more about your actual cybersecurity posture than you did before.


To make the process easier, Kosh has put together a printable cybersecurity checklist based on the types of questions businesses encounter during cyber insurance applications.




Disclaimer

The information contained in this communication is intended for limited use for informational purposes only. It is not considered professional advice, and instead, is general information that may or may not apply to specific situations. Each case is unique and should be evaluated on its own by a professional qualified to provide advice specifically intended to protect your individual situation. Kosh is not liable for improper use of this information.


Comments


Commenting on this post isn't available anymore. Contact the site owner for more info.
bottom of page