Cyber Insurance Isn't a Blank Check Anymore
A few years ago, cyber insurance applications were often little more than a short form. That's no longer the case. As claims volume and payout sizes have grown, insurers have gotten far more specific about what they check before issuing a policy — and far more willing to deny a claim, or price a renewal much higher, when a business turns out to have gaps in a handful of well-known areas.
The frustrating part is that most of these gaps are avoidable, and businesses often don't discover them until after an incident, when it's too late to fix anything before a claim is reviewed.
The Controls Underwriters Check Most
- MFA on admin and email accounts — this is consistently the single most-checked control. Missing MFA on privileged accounts is one of the fastest ways to get declined outright.
- EDR or modern endpoint protection — legacy signature-based antivirus alone is increasingly treated as insufficient by underwriters comparing it against active detection and response tools.
- Tested backup restores — having backups isn't the same as knowing they work. Insurers specifically ask whether restores have actually been tested, not just whether backups exist.
- A documented incident response plan — a written plan that's actually known to staff demonstrates preparedness and speeds recovery, both of which underwriters factor into pricing.
- Regular security awareness training — phishing remains the top initial access vector in breach claims, and insurers look for recurring, not one-time, training programs.
- Least-privilege access — broad, unmanaged admin rights increase the blast radius of any single compromised account.
- Email authentication (SPF/DKIM/DMARC) — missing or misconfigured records make domain spoofing and business email compromise easier, a common trigger for claims.
Why Weighting Matters
Not every gap carries equal weight in an underwriter's eyes. MFA, EDR, and tested backups tend to be treated as higher-stakes than, say, a vendor review process that's slightly informal. Prioritizing fixes by impact — closing the highest-weight gaps first — gets you a meaningfully stronger application faster than trying to fix everything simultaneously.
Self-Assessing Before You Apply
Running through these checks honestly before you talk to a broker does two things: it flags what to fix first, and it prepares you for the specific questions an underwriter is likely to ask, so nothing comes as a surprise mid-application.
This Isn't a Substitute for Your Broker
A self-assessment is preparation, not a guarantee. Actual policy terms, pricing, and claim decisions are determined by the insurer based on their own underwriting process. But walking into that process having already closed your biggest gaps puts you in a meaningfully stronger position — for both getting coverage and for what it costs.
Frequently Asked Questions
Yes — the Cyber Insurance Readiness Scorecard checks 10 weighted controls insurers commonly require and gives you a readiness score plus a prioritized gap list. It's a one-time $4.99 purchase — no subscription, no account required.
No. This tool reflects commonly checked underwriting requirements, but actual approval, pricing, and claim decisions are made by the insurer based on their own process. Use it as preparation, not a guarantee.
Each control is weighted based on how heavily it's typically factored into underwriting decisions — controls like MFA, EDR, and tested backups carry more weight than lower-impact items, and the gap list is sorted accordingly.
Yes, there's a one-click download that generates a full text report with your score, tier, and the complete gap list with explanations.
No. The scorecard runs entirely in your browser and nothing you select is transmitted to a server.