Cyber Insurance Readiness: What Underwriters Actually Ask For
MFA, EDR, backups, DMARC, and incident response, mapped to common carrier questionnaires so renewal season isn't a scramble.
Cyber insurance renewals got stricter. Carriers that used to checkbox "do you have antivirus?" now ask about MFA scope, EDR deployment, offline backups, email authentication, and incident response plans.
If your answers are aspirational, premiums spike, or coverage disappears.
Controls appearing on most 2025–2026 applications
Identity
MFA on email and remote access for all users, especially admins. SMS-only often doesn't count for privileged accounts.
Endpoint
Managed EDR on servers and workstations, not legacy AV signatures alone.
Backup
Encrypted, tested, with offline/immutable component. "We use cloud sync" fails here.
Email security
SPF, DKIM, DMARC published; phishing training conducted.
Patching
Critical patches within defined window (often 14–30 days).
Incident response
Documented plan or retainer; sometimes 24-hour notification requirement to carrier.
Evidence you'll need handy
- Screenshot/export of MFA enforcement policy
- EDR deployment report (% coverage)
- Last successful restore test date
- DMARC aggregate report or DNS record
- Training completion summary
- Patch compliance dashboard
Keep a renewal packet updated quarterly, not assembled in 48 hours before deadline.
Gaps that trigger denials or exclusions
- Remote desktop exposed to internet without controls
- No MFA on M365/Google
- Unpatched VPN appliances
- Prior incident undisclosed on application
- PHI or payment data without segmentation story
Working with your MSP
Your provider should help produce technical evidence, not hand you the insurer PDF alone. If they can't, they're helpdesk-only.
Precipice clients receive posture documentation suitable for insurance renewal. Request a readiness review.