A few years ago, getting cyber insurance was mostly a matter of filling in a form and paying a premium. That’s changed considerably. As claims and payouts have climbed, insurers have tightened what they’ll actually cover — and increasingly, what they’ll insure at all. Businesses renewing this year are finding that the questionnaire has grown teeth: specific technical controls are now expected to be in place, not just described in good faith.
If your policy hasn’t been reviewed against current requirements recently, it’s worth checking before you need to make a claim rather than after.
Why insurers have tightened the rules
Cyberattacks have increased sharply in both frequency and cost over the past few years, and insurers have felt that directly through rising claims. Their response has been to move from taking businesses at their word to requiring evidence that specific controls are actually in place. That shift matters because a policy that looks fine on paper can still leave you exposed if a claim gets challenged over a control you assumed you had.
The controls insurers are actually asking about
Multi-factor authentication, everywhere. This is consistently the single most cited reason cyber insurance claims get denied or reduced — MFA missing on email, remote access, or admin accounts. Insurers no longer treat this as a nice-to-have; it’s typically a baseline condition of cover.
Endpoint detection and response (EDR). Traditional antivirus is increasingly considered insufficient on its own. Insurers are asking whether you have something that can actually detect unusual behaviour and isolate an affected device, not just recognise known malware signatures.
Documented patch management. It’s no longer enough to say updates “generally happen.” Insurers are asking for evidence of a patching process and timeline, particularly for known, publicly disclosed vulnerabilities.
Backups that meet a specific standard. Encrypted backups, tested regularly, with at least one copy that can’t be altered or deleted by an attacker (immutable) are increasingly expected. Ransomware coverage in particular can be limited or excluded if secure backups can’t be demonstrated.
Email security controls. Business email compromise remains one of the most common and costly incident types, and insurers are increasingly checking for anti-phishing filtering and correctly configured sender verification (SPF, DKIM, and DMARC) alongside staff awareness training.
A written incident response plan. Insurers increasingly want to see that a business knows what it would actually do in the first hours of an incident, not just that it has a policy in a drawer.
The gap between “we think we’re covered” and “we can prove it”
The riskiest position isn’t lacking these controls — it’s assuming they’re in place without anything to show for it. A claim can be delayed, reduced, or denied entirely if a business can’t produce evidence that a control insurers required was genuinely active at the time of the incident, even if it technically was. Screenshots, configuration exports, and patch logs matter here as much as the technology itself.
What to do before your next renewal
A sensible approach is to work through the renewal questionnaire, or a recent one, as if it were an audit rather than a form: for each control asked about, can you point to actual evidence it’s in place today, not just a policy that says it should be? Where the answer is uncertain, that’s the gap to close before a claim forces the question.
This is also where having a managed IT partner pays for itself in a very concrete way. Most of the controls insurers now expect — MFA, EDR, tested backups, documented patching, email security — are exactly the fundamentals a well-run managed IT setup maintains as a matter of course, with the logs and records to prove it.
The bigger picture
Cyber insurance requirements are only going to get more specific, not less. Treating them as a periodic box-ticking exercise leaves businesses exposed to the exact scenario the policy was meant to protect against: a claim that doesn’t pay out when it’s needed most. Getting ahead of it now is considerably less stressful than doing it during a renewal deadline, or worse, during a live incident.
Not sure whether your current setup would meet this year’s requirements? Get in touch with Valetech Solutions for a clear-eyed review against what insurers are actually asking for.