Direct answer: Cyber insurers price on a short list of controls, and the application is where they check for them. The ones that move the decision and the premium are enforced multi-factor authentication everywhere, endpoint detection and response on your devices, backups that are immutable and have been restore-tested, a tested incident response plan, and security awareness training with phishing simulation. Patching, email filtering, privileged access control and logging sit just behind them. An application fails, or a claim gets denied, when you attest to a control you do not actually have operating.
What the application actually asks
A cyber insurance application is a controls questionnaire wearing a different hat. It is not asking whether you care about security. It is asking whether specific, named controls are in place, because those controls are the ones that correlate with claims the underwriter would rather not pay. The questions are yes or no, the answers are warranties you are making to the insurer, and a yes you cannot evidence is the most expensive thing on the form. Treat each line as something you will have to prove after an incident, not as a box to clear before a renewal deadline.
Enforced MFA, and the word enforced
Multi-factor authentication is the control underwriters ask about first, and the word that matters is enforced. Having MFA available is not the same as requiring it. Underwriters want it mandatory on remote network access, on webmail, on your identity provider, and above all on privileged and administrator accounts. The gap that bites is the exception: the service account, the legacy VPN, the one admin who found MFA annoying and was quietly exempted. That exception is the path an attacker takes, and it is also the detail that turns an attested yes into a misrepresentation when the claim is investigated.
EDR on the endpoints
Underwriters now expect endpoint detection and response rather than traditional antivirus, deployed across servers and workstations, with someone or something watching the alerts. Coverage is the question behind the question. EDR on ninety per cent of endpoints with the other ten per cent being the unmanaged laptops and the forgotten server is the ten per cent that gets compromised. Be able to say what it is deployed on and what it is not, because the honest answer priced correctly beats the optimistic answer that voids the policy.
Free weekly email
Get The Compliance Brief every Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
Immutable backups that have been restore-tested
Backups are where ransomware economics are decided, so underwriters ask about them closely. Two properties matter. Immutability, meaning a copy an attacker who owns your network cannot encrypt or delete, whether that is offline, air-gapped or object-locked. And restore testing, meaning you have actually recovered from those backups and timed it, not merely confirmed the backup job reports success. A backup you have never restored is a hope, not a control, and it is the single most common gap between what an application claims and what exists when it is needed.
A tested incident response plan
Insurers ask whether you have an incident response plan, and increasingly whether you have exercised it. A plan that lives in a document nobody has opened is weak evidence. A plan that has been walked through a tabletop exercise, with the gaps it exposed written down and addressed, is a control. Some policies also require you to use a panel firm during a claim, which is worth checking against any incident response retainer you already hold before you buy either, so you are not paying twice or breaching a condition.
Security awareness training
Underwriters ask about awareness training and phishing simulation because most claims start with a person, not a zero-day. What they want is the same thing an auditor wants: evidence the training runs on a cadence and that phishing simulations happen and are acted on. This is a control you can stand up quickly and evidence cleanly, which makes it one of the easier lines on the application to turn from a no into a defensible yes.
What fails an application
The patterns that sink applications or premiums are consistent. MFA that is available but not enforced, with exceptions nobody mapped. Antivirus where the market now expects EDR. Backups that are neither immutable nor ever restore-tested. An incident response plan that exists on paper and has never been exercised. No awareness programme, or one with no records. Underneath all of them sits the real risk, which is misrepresentation. A cyber policy is built on the warranties in your application, and an insurer that finds a control was not operating as attested has grounds to reduce or deny the claim at the worst possible moment. The goal is not to answer yes to everything. It is to answer accurately and to close the gaps that make accurate answers weak.
How a readiness position answers it
A readiness position changes the conversation with an underwriter from assertion to evidence. Instead of ticking boxes and hoping, you map each question on the application to a control and a piece of proof: the MFA enforcement policy and the exception list, the EDR deployment coverage, the immutability setting and the dated restore test, the incident response plan and the tabletop record, the training completions and the phishing results. That pack does two things. It lets you answer the application honestly and specifically, which is what keeps a future claim payable. And where it surfaces a gap, you fix the gap before you attest rather than discovering it during a claim. Our cyber insurance readiness tool walks the same control list so you can see where you stand before the application lands on your desk.
Will readiness lower my premium?
Premiums are the underwriter decision, and they price on risk, so we do not promise a number. What a readiness position reliably does is let you answer the application accurately and avoid the gaps that make a policy cheap to write and impossible to claim against. Controls the underwriter rewards, such as enforced MFA, EDR and tested backups, are the ones the readiness work puts in place.
Is this the same as a security audit?
No. A readiness assessment is scoped to what underwriters ask about, which is a specific and fairly short list. A full security review is broader. If your goal is the insurance application, the narrower assessment is the right and cheaper purchase.
We already have a policy. Does this still matter?
It matters more at renewal, because requirements tighten each cycle and an insurer can decline to renew or reprice if the controls have not kept pace. It also matters before a claim, because an existing policy is only as good as the accuracy of the application behind it.
Which control should we fix first?
Enforced MFA, in almost every case. It is the control underwriters weight most heavily, it is the one attackers exploit most often, and the fix is largely configuration rather than new spend. The expensive and slow one is usually restore-tested backups, because immutability may mean a change to how backups are stored and a genuine restore test takes planning. Fix MFA first because it is cheap and it moves the application immediately, then work the backups because they are the control that decides a ransomware outcome.
Want to know what would fail before you apply? We assess your position against the controls underwriters price on, from $2,000, and give you the evidence pack and the gap list so the application is accurate and the policy is one you can actually claim against.
Cyber insurance readinessOr book a callWhat we charge for this. The figures above are market ranges. Our own fixed-scope prices are on the pricing page, alongside every cost breakdown we have written.