Not long ago, buying cyber insurance meant filling in a short form and paying a premium. Today it looks more like an exam. Before an insurer quotes a policy or renews one, it wants evidence that specific security controls are in place, and a business that cannot show them can face higher premiums, narrower coverage, or a declined application.
The reason is in the claims data. The FBI’s Internet Crime Complaint Center reported roughly $20.9 billion in losses from cyber-enabled crime in 2025, up 26 percent from the year before, and business email compromise alone accounted for about $3 billion of it. Coalition, a cyber insurer, reported that business email compromise and funds transfer fraud together made up 58 percent of the incidents it saw in 2025, and that ransomware remained its costliest type of claim, at an average loss of $269,000.
Insurers respond by asking about the controls that prevent those losses. The list varies by carrier, but the same items appear on most applications. Multi-factor authentication on email, remote access, and administrator accounts, and increasingly on any cloud application that holds sensitive data. Endpoint detection and response on company computers, since basic antivirus no longer satisfies most underwriters. Encrypted backups that include one copy kept isolated from the main network, with restores that have actually been tested. A regular patching routine. Limited administrator rights. Employee security training. And a written incident response plan.
Two details catch businesses out. The first is that partial coverage of a control is often treated as a gap: multi-factor authentication on email but not on the remote access tool, for example. The second is documentation. Many businesses have the controls but cannot prove it. The records that come up most often are a written information security policy, a patch log, and the results of backup restore tests.
Photo: Photo via Unsplash
Accurate answers matter, because a claim is reviewed against what the application said. Coalition’s report credits viable backups and incident response plans for better outcomes when incidents do happen, which is a good reason to treat those two items as more than a box to tick.
A practical way to prepare, starting at least 60 days before renewal. Get last year’s application, or your broker’s current questionnaire, and answer it as if you were the underwriter. For every yes, save the evidence: a screenshot of the multi-factor setting, the patch log, the date and result of the last backup restore. For every no, decide whether it can be fixed before renewal or whether to tell your broker now. Then put the fixes on a calendar. Many of them are configuration work rather than new purchases.
This is a natural fit for a managed IT arrangement, because the evidence insurers ask for is what a managed provider produces as a byproduct of doing the work: patch reports, backup test records, and an inventory of who has access to what. We help clients answer the questionnaire accurately and close the gaps it exposes. We are not insurance brokers, and coverage decisions belong with your broker and carrier.