Cyber insurance used to run on a short questionnaire and a signature. That’s no longer how it works. Underwriters now treat the application more like a technical audit, and multiple insurers, including Coalition in its cyber claims research, have identified incomplete multi-factor authentication as one of the most common factors behind denied claims. Not missing entirely, incomplete: enabled on email, but not on the admin account or the one server that ends up being the entry point.
If you’re heading into a renewal or a new application and haven’t looked closely at what’s actually being asked of you, this is worth reading before the questionnaire lands on your desk.

What Changed
For years, cyber insurance applications asked yes-or-no questions and mostly took the answers at face value. Ransomware claims got expensive enough that insurers stopped doing that. A pattern shows up across current industry reporting on carrier requirements: applications now function as a technical audit, and after a breach, some carriers will compare what you attested to on the application against what your environment actually looked like when the incident happened. A mismatch, even an unintentional one, is increasingly treated as grounds to deny the claim or challenge the policy itself.
That shift matters most for small and mid-size businesses, because it’s exactly the group most likely to have partial coverage: MFA turned on for most employees but not a shared service account, an EDR tool installed on laptops but not the file server in the back office, a backup that runs nightly but was never actually tested for restoration.
The Controls Insurers Are Asking About
Based on current underwriting trends reported across the cyber insurance industry, a consistent set of controls shows up on renewal questionnaires:
| Control | What Insurers Are Actually Checking For |
|---|---|
| Multi-factor authentication | Enforced on all accounts, including admin, remote access, and service accounts, not just user email |
| Endpoint detection and response (EDR) | Deployed on every endpoint and server, not just managed laptops |
| 24/7 monitored response | Alerts on that EDR tool actually get watched and acted on around the clock, not just during business hours |
| Backup and recovery | Backups exist, are isolated from the main network, and have been tested for actual restoration |
| Incident response plan | A documented plan that’s been reviewed or exercised, not just a document that exists somewhere |
| Security awareness training | Ongoing training for employees, not a one-time onboarding video |
| Logging and retention | Security logs are being kept, and for long enough to support an investigation if something happens |
Notice what’s common across nearly every row: it’s not just “do you have this,” it’s “is it complete, and can you show it.” That second part is where most businesses actually fall short.
The Trap: Partial Deployment
The single most common gap isn’t a missing control. It’s an incomplete one. MFA that covers 90% of accounts still leaves the 10% as the likely entry point, and from an underwriting standpoint, attesting that MFA is “in place” when it’s only partially deployed is treated as a misrepresentation, not a technicality.
The same pattern shows up with EDR. A tool installed on employee laptops but not on servers or network devices creates exactly the kind of blind spot that both attackers and, after the fact, insurers, tend to find.
This is why a genuine gap assessment matters more than a self-reported checklist. It’s easy to answer “yes, we have MFA” on a form. It’s a different thing entirely to verify that it’s actually enforced everywhere it needs to be.
Getting Ready Before the Questionnaire Arrives
A few steps make the biggest difference heading into a renewal or new application:
- Get an outside look at your actual environment, not just a self-assessment. A network and security risk assessment is built to catch exactly the kind of partial-deployment gaps that cause claim denials, before an insurer or an attacker finds them first.
- Confirm MFA coverage account by account, including service accounts, admin accounts, and anything with remote access, not just standard employee logins.
- Make sure EDR (or better, a monitored MDR service) covers servers and network devices, not just workstations. If nobody’s actually watching those alerts around the clock, that’s the gap an underwriter is likely to ask about directly.
- Test your backups, not just confirm they run. A backup that fails during an actual restoration is functionally the same as having no backup at all.
- Document your incident response plan, and make sure it’s been reviewed recently enough that someone could actually follow it under pressure.
Where This Connects to Your Broader Security Setup
These aren’t separate initiatives from the rest of your security program. They’re largely the same controls that reduce your actual breach risk, which is exactly why insurers ask about them.
DCG’s MDR services and SOC services both directly address the 24/7 monitored response requirement that shows up on nearly every current cyber insurance questionnaire, and a free security risk assessment is the fastest way to find out exactly where your current setup has gaps, before your renewal date forces the question.
If your renewal is coming up and you’re not confident your controls would hold up to a closer look, it’s worth having that assessment done now rather than during the underwriting process.







































