Skip to main content
Cyber Insurance Underwriting Field GuideSecurity Governance
5 min readFor vCISO Practitioners

Cyber Insurance Underwriting Field Guide

Scope of This Guide

This guide decodes the security controls that cyber insurers evaluate during underwriting and renewal. It's designed for security engineers managing infrastructure to meet carrier requirements, whether you're applying for the first time or defending a renewal after a claims event.

You'll discover the baseline control set most carriers expect, the documentation formats underwriters require, and the gaps that can lead to premium surcharges or declined applications. This isn't about gaming the system; it's about translating your existing security efforts into the evidence language underwriting teams understand.

Key Concepts and Definitions

Underwriting Controls: These are the specific security measures carriers evaluate to determine insurability and premium. They are conditions of coverage, not suggestions.

Baseline vs. Differentiated Posture: Baseline controls get you through the door. A differentiated posture, such as tested disaster recovery plans and mature identity governance, can lower your premium in a soft market.

Claims-Driven Requirements: Underwriting requirements often trace directly to claims data. For instance, business email compromise accounted for 31% of claims in Coalition's 2026 report. Expect questions on multi-factor authentication (MFA) and payment verification to align with such exposures.

Control Attestation: Carriers demand proof, not promises. Screenshots, policy exports, test logs, and third-party assessments are valuable. Self-reported checkboxes are not.

Requirements Breakdown

While each carrier's application varies, the core control set has converged around four domains:

Identity and Access

  • Enforce MFA on all remote access, privileged accounts, and email.
  • Implement conditional access policies to block legacy authentication protocols.
  • Use privileged access management with session recording for admin accounts.
  • Conduct regular access reviews with documented removal of stale accounts.

Endpoint Protection

  • Deploy endpoint detection and response (EDR) across all managed devices.
  • Maintain patch management with documented cycles; critical patches should be applied within 30 days.
  • Use mobile device management for BYOD environments accessing corporate data.
  • Provide inventory showing coverage percentage; carriers flag gaps below 95%.

Backup and Recovery

  • Maintain immutable or air-gapped backups tested within the last 90 days.
  • Document and validate recovery time objectives.
  • Ensure backup scope covers critical systems and data repositories.
  • Provide restoration test logs, not just backup success logs.

Incident Response

  • Keep a written incident response plan updated within the last 12 months.
  • Define roles with contact information for decision-makers.
  • Conduct and document tabletop exercises.
  • Have a breach counsel and forensics retainer or a clear procurement path.

The FBI reported $3 billion in business email compromise losses in 2025, highlighting the importance of email security in underwriting. Expect detailed questions about DMARC enforcement, payment verification workflows, and executive account protections.

Implementation Guidance

For First-Time Applications

Start documentation 90 days before your target bind date. Underwriters work from evidence you can produce during the application window, not controls you plan to implement after binding.

Build a controls evidence folder with:

  • MFA enrollment reports showing coverage percentage and enforcement status.
  • EDR dashboard exports showing deployment and detection posture.
  • Backup restoration test results with timestamps and scope.
  • An incident response plan with version date and leadership sign-off.
  • Vulnerability scan results showing critical/high remediation rates.

If you're missing a baseline control, document the remediation plan with specific timelines. A 60-day MFA rollout plan with executive buy-in is more credible than a checkbox claiming coverage you can't prove.

For Renewals After Claims

Claims trigger heightened scrutiny but also create opportunities for security investment. Use the renewal cycle to close gaps your prior budget couldn't address.

Document changes since the incident:

  • New controls implemented, with deployment dates and coverage metrics.
  • Process changes addressing the incident's root cause.
  • Training delivered to affected user populations.
  • Third-party assessments validating the remediation.

Carriers price the forward-looking risk, not the past event. A well-documented response to a business email compromise incident, MFA enforced, payment workflows revised, training delivered, can result in flat renewal pricing even after a claim.

For Manufacturing and Healthcare

These sectors face specific scrutiny. Manufacturing applications probe OT/IT segmentation and data theft controls; healthcare underwriters focus on VPN security and breach notification preparedness.

In healthcare, Tokio Marine HCC found 50-60% of ransomware incidents trace to VPN accounts without properly enforced MFA. If you manage healthcare infrastructure, expect the underwriter to ask for VPN MFA evidence explicitly.

Common Pitfalls

Self-Reported Coverage That Doesn't Match Reality: Claiming 100% MFA enforcement when guest WiFi bypasses it, or stating "all endpoints protected" when field devices run unmanaged, leads to declined applications when underwriters audit.

Backup Tests That Only Verify Backup Success: Running backups isn't the same as proving you can restore. Underwriters want restoration test logs showing successful recovery from backup media.

Incident Response Plans That Haven't Been Updated: A three-year-old incident response plan with departed employees listed as contacts signals neglect. Update it annually and document the review.

Missing Documentation for Controls You Actually Have: You've enforced MFA everywhere, but you can't export the enrollment report because you've never needed to. Build the evidence library before the application opens.

Confusing Compliance Frameworks with Insurance Requirements: SOC 2 or ISO 27001 certification helps, but carriers still want control-specific evidence. Don't assume certification answers every underwriting question.

Quick Reference Table

Control Domain Underwriter Expects to See Common Documentation Format
MFA Enforcement Enrollment percentage, enforcement policy, excluded accounts with justification Identity provider dashboard export, conditional access policy screenshots
EDR Deployment Coverage percentage, detection/response capability, update status EDR console report, agent deployment inventory
Backup Testing Restoration test results, test frequency, recovery time objectives Test logs with timestamps, restored system validation
Patch Management Patch cycle, critical patch SLA, current vulnerability posture Vulnerability scan results, patch deployment reports
Incident Response Current IR plan, tabletop exercise, defined escalation path IR plan document with version date, tabletop summary
Email Security DMARC/DKIM/SPF status, payment verification workflow, executive account protections DNS records, documented payment approval process
Access Governance Privileged account inventory, access review cadence, deprovisioning process Access review logs, privileged account management reports

The market is moving toward demonstrated controls rather than promised ones. As reported cybercrime losses jumped 26% to $20.9 billion in 2025, underwriting discipline became structural. Your documentation proves you're on the favorable side of that line.

You Might Also Like