Cyber insurance used to feel relatively straightforward.
A company completed an application.
The insurer reviewed its:
- Revenue
- Industry
- Number of employees
- Type of data
- Claims history
A quote followed.
That process has changed.
Today’s cyber insurer may want a much clearer picture of how your organization actually protects itself.
Does your company use multi-factor authentication?
Are backups separated from the main network?
Can you restore them?
Are endpoints monitored?
How quickly do you patch serious vulnerabilities?
Do employees receive cybersecurity training?
Do you have an incident-response plan?
The answers can influence whether an insurer offers coverage and, when it does, the policy’s price, deductible or retention, limits and other terms.
Welcome to what we’ll call:
Cyber Insurance 2.0.
Insurance isn’t replacing cybersecurity.
Increasingly, the two work together.
What Does “Proof of Defense” Mean?
“Proof of Defense” isn’t a standardized insurance coverage or universal regulatory term.
For this guide, it means:
Being able to accurately demonstrate the cybersecurity controls your company says it has.
The distinction matters.
An insurance application might ask:
Do you use MFA for remote access?
Checking Yes should mean the control actually exists where represented—not that the company intends to install it next quarter.
Marsh’s cyber insurance application guidance identifies security questions involving MFA, patching, cyber training, backups, incident history, encryption and sensitive records.
Coalition’s application similarly asks whether companies maintain backups of critical data and systems on a separate network or offline and where MFA is enforced.
The modern underwriting conversation is therefore increasingly about:
What controls exist + where they exist + how they operate.
Why Cyber Insurers Care About Security Controls
Cyber insurers ultimately insure financial losses.
A successful attack can produce:
- Forensic expenses
- Data restoration costs
- Business interruption
- Legal expenses
- Customer notification
- Regulatory expenses
- Ransomware response
- Fraud losses
- Third-party claims
The insurer therefore wants to understand the probability and potential severity of those losses.
Security controls provide information about that risk.
Marsh says cyber underwriters assess factors including an applicant’s industry, data, prior incidents and controls such as MFA, backups and endpoint protection. Those factors can affect pricing, deductibles, limits and policy conditions.
The Ransomware Problem Hasn’t Disappeared
Cyber insurance requirements didn’t become more detailed without reason.
Coalition’s 2026 Cyber Claims Report found that initial ransomware demands during 2025 increased:
47% year over year.
At the same time, Coalition reported that 86% of affected businesses in its dataset refused to pay, which it associated with improved resilience, including viable backups and incident-response capabilities.
This illustrates why insurers care about what happens before an attack.
A company capable of restoring systems from reliable backups presents a different recovery scenario from one whose only copy of critical data has been encrypted.
Control #1: Multi-Factor Authentication
MFA is one of the most important controls businesses should expect to discuss.
Instead of relying only on:
Username + Password
MFA requires additional verification.
Depending on the system, that might involve:
- Authenticator application
- Hardware security key
- Biometric verification
- Other authentication factors
The objective is straightforward.
A stolen password alone should not necessarily give an attacker access.
Marsh identifies MFA as a key control, particularly for remote access and privileged or administrator access.
“We Have MFA” May Not Be Enough
Implementation matters.
Imagine a business has 100 employees.
MFA protects its accounting software.
But MFA isn’t enabled for:
- Remote access
- Administrator accounts
Can management simply answer:
“Yes, we use MFA”?
That may provide an incomplete picture.
Coalition’s application, for example, asks applicants where MFA is enforced, including email and various forms of remote access.
The better question is:
Where is MFA enforced?
Control #2: Endpoint Detection and Response
Every:
- Laptop
- Desktop
- Server
- Workstation
can potentially become an entry point.
Endpoint Detection and Response—commonly called EDR—is designed to monitor endpoints for suspicious activity and help organizations detect and respond to threats.
Marsh identifies EDR among its key cyber hygiene controls.
At-Bay’s cyber insurance application also asks applicants which EDR product, if any, they use.
For a company with hundreds of endpoints, simply saying:
“We have antivirus.”
may not provide underwriters with enough information about the broader security posture.
Control #3: Secure Backups
Backups can become crucial during ransomware recovery.
Imagine attackers encrypt:
- Customer records
- Accounting data
- Inventory systems
- Shared drives
- Production databases
Then the business discovers its backup environment is accessible through the same compromised network.
The attacker encrypts that too.
The company technically had:
“Backups.”
But they weren’t sufficiently resilient.
That’s why insurers may ask much more specific questions.
Coalition asks whether critical data and systems are backed up at least weekly offline or on a separate network.
At-Bay asks about backup-and-restoration procedures and whether offline or cloud backups are maintained.
A Backup Isn’t Useful Until You Can Restore It
Businesses should distinguish between:
Creating backups
and
Recovering from backups.
Imagine your IT team tells management:
“Everything is backed up every night.”
A ransomware attack occurs.
Then the company discovers:
- Some backups are corrupted
- Critical databases weren’t included
- Credentials required for restoration are unavailable
- Recovery takes three weeks
This is why backup testing matters.
Marsh identifies secured, encrypted and tested backups as one of its important cyber hygiene controls.
Control #4: Patch and Vulnerability Management
Software vulnerabilities can provide attackers with opportunities to enter networks.
A strong patch-management process helps businesses:
- Identify vulnerabilities.
- Prioritize them.
- Deploy available fixes.
- Verify remediation.
Marsh includes patch and vulnerability management among its recommended cyber resilience controls.
Its research has also found a relationship between timely patching of high-severity vulnerabilities and reduced cyber-event probability.
For insurers, the question may therefore extend beyond:
“Do you patch?”
to:
“How quickly do you remediate critical vulnerabilities?”
Control #5: Privileged Access Management
Not every employee needs administrator privileges.
An ordinary employee might need access to:
- CRM
- Documents
But not:
- Domain administration
- Backup configuration
- Security controls
- Financial systems
- Every customer database
Privileged Access Management, or PAM, is intended to control powerful accounts and limit unnecessary access.
Marsh includes PAM among its key cyber controls.
The principle is simple:
Give users the access they need—not unlimited access they don’t need.
Control #6: Email Security
Email remains an important attack vector.
Employees can receive:
- Phishing links
- Malicious attachments
- Fake invoices
- Impersonation messages
- Credential-stealing pages
Technical controls can help filter malicious content before employees interact with it.
Marsh identifies:
Email filtering and web security
among its important cyber hygiene controls.
But technology alone isn’t enough.
Employees also need to recognize suspicious requests.
Control #7: Employee Cybersecurity Training
Consider this email:
“CEO: I’m in a meeting. Wire $85,000 to this supplier immediately.”
The employee believes it is legitimate.
They transfer the money.
No sophisticated malware was required.
The attacker exploited:
a person.
Cyber insurance applications may therefore ask about cybersecurity training. Marsh’s Cyber Accelerate application guidance specifically lists cyber training among the organization’s security-control information applicants should be prepared to provide.
Control #8: Incident Response Planning
What happens at:
2:15 a.m.
when ransomware begins encrypting your network?
Who gets called?
IT?
CEO?
Legal counsel?
Cyber insurer?
Forensics firm?
Public relations?
An incident-response plan establishes responsibilities before the crisis occurs.
Marsh says incident-response planning is one of the cybersecurity controls cyber insurers ask its clients about during underwriting.
Having a Plan Isn’t the Same as Testing It
Imagine your incident-response document says:
“Contact IT director immediately.”
The IT director left the company eight months ago.
Another contact number is outdated.
Nobody knows where the cyber policy is stored.
The plan exists.
But it isn’t operational.
Businesses should periodically test response procedures through:
tabletop exercises.
Marsh recommends regular, varied tabletop exercises as part of cyber-risk preparedness.
What Might Count as Evidence?
There isn’t one universal evidence package required by every insurer.
Requirements vary.
But businesses should maintain accurate documentation supporting their cybersecurity representations.
Depending on the question and insurer, relevant records might include:
- MFA configuration information
- EDR deployment reports
- Backup logs
- Recovery-test results
- Patch-management reports
- Vulnerability scan summaries
- Security-training records
- Incident-response plans
- Tabletop exercise records
- Access-control policies
- Security vendor information
The goal isn’t to manufacture paperwork for insurance.
It’s to know that what your application says is actually true.
Why Accuracy on the Application Matters
Suppose an application asks:
“Is MFA required for remote access?”
The applicant answers:
Yes.
After a cyber incident, investigation reveals a legacy remote-access system that didn’t require MFA.
That discrepancy can create serious complications.
The exact consequences depend on:
- Policy wording
- Application wording
- Applicable law
- Materiality
- Facts surrounding the claim
The safest approach is straightforward:
Answer cyber insurance applications accurately and completely.
If IT doesn’t know the answer, investigate before checking the box.
Bring IT Into the Insurance Application
Cyber insurance shouldn’t be completed solely by:
Accounting
or
the business owner.
Some questions are technical.
Marsh specifically recommends having someone from the organization’s IT team available when completing its Cyber Accelerate application because of the security questions involved.
For larger organizations, the application process might involve:
- IT
- Information security
- Legal
- Finance
- Risk management
- Insurance broker
Cyber insurance is increasingly a cross-functional responsibility.
Example: The Dangerous “Yes” Box
Imagine a small manufacturer is applying for cyber insurance.
The application asks:
Does your organization use MFA?
The owner knows employees use an authenticator application for Microsoft 365.
So:
Yes.
But the company’s remote-access system doesn’t use MFA.
Its administrator accounts also lack MFA.
The business should not assume that one MFA implementation means it can give a blanket affirmative response to every MFA question.
Read exactly what is being asked.
Security Controls Can Affect Insurance Terms
Cybersecurity doesn’t simply affect whether an insurer likes your company.
Marsh explains that underwriters use information about security controls alongside other risk characteristics to establish:
- Price
- Deductibles
- Limits
- Other policy conditions.
This creates an important business case for cybersecurity investment.
Improving security can potentially:
reduce cyber risk + improve insurability.
However, businesses shouldn’t assume installing one tool automatically guarantees a specific premium discount.
Underwriting remains multifactorial.
Cyber Insurance Is Not a Substitute for Cybersecurity
Imagine buying fire insurance for a warehouse.
Would that mean you should:
- Remove smoke detectors?
- Ignore faulty wiring?
- Disable sprinklers?
Of course not.
Insurance provides financial protection after covered losses.
Risk controls help reduce the probability and severity of those losses.
Cyber insurance works similarly.
Marsh describes cyber insurance as one component of a broader approach that includes cybersecurity controls, business-continuity planning, contractual risk allocation and incident-response readiness.
Why Small Businesses Should Pay Attention
Cybersecurity underwriting isn’t only relevant to multinational corporations.
Small companies can rely heavily on:
- Microsoft 365
- Google Workspace
- Shopify
- Cloud accounting
- Online banking
- Customer databases
- Remote employees
A compromised email account alone can lead to:
- Fraud
- Data exposure
- Business interruption
- Reputation damage
Small businesses therefore shouldn’t wait until renewal week to discover that their cybersecurity posture needs improvement.
Example: E-Commerce Business
Imagine an online retailer with:
$4 million annual revenue
and 25 employees.
The company stores customer information and relies on its online storefront for nearly all revenue.
Before renewal, the insurer asks about:
MFA: Yes
EDR: Yes
Backups: Yes
Security training: Yes
Incident-response plan: Yes
Those answers sound strong.
But management should verify:
MFA: Is it enforced on all systems the question covers?
EDR: Is it deployed across required endpoints?
Backups: Are they separated and recoverable?
Training: Is it current and documented?
Incident response: Has the plan been updated and tested?
That’s the difference between:
having a security checklist
and
maintaining a defensible security posture.
What Happens If You Don’t Have the Controls?
There is no single universal outcome.
Depending on the insurer, company and missing controls, the result could potentially include:
- Additional underwriting questions
- Requirement to improve controls
- Different terms
- Higher retention
- Restricted limits
- Coverage modifications
- Declined coverage
Marsh notes that certain cyber controls have become important to insurability, while its Cyber Pathway offering specifically helps organizations identify control improvements that can potentially lead to increased coverage.
Don’t Install Security Tools Only for Insurance
This is another mistake.
Suppose your renewal is in two weeks.
The application asks about EDR.
You hurriedly purchase a product and install it on:
10 of 80 computers.
Then answer:
“Yes, we have EDR.”
That misses the purpose of the control.
Security should be:
implemented + configured + monitored + maintained.
Cyber insurance underwriting can provide motivation to improve security, but the ultimate goal is reducing actual risk.
Prepare 90 Days Before Renewal
Cyber insurance preparation shouldn’t begin the night before the application is due.
Approximately 60–90 days before renewal, consider reviewing:
Identity Security
- MFA
- Privileged accounts
- Remote access
Endpoint Security
- EDR deployment
- Device inventory
- Unsupported systems
Data Protection
- Backup frequency
- Backup separation
- Recovery testing
- Encryption
Vulnerability Management
- Scanning
- Patching
- Critical vulnerabilities
Human Risk
- Security awareness
- Phishing training
Incident Preparedness
- Incident-response plan
- Contact information
- Tabletop testing
This gives the business time to fix weaknesses rather than simply disclose them.
Create a Cyber Insurance Evidence Folder
A useful internal practice is maintaining a secure repository containing current cybersecurity documentation.
For example:
01 — MFA
02 — Endpoint Security
03 — Backups
04 — Patch Management
05 — Employee Training
06 — Incident Response
07 — Tabletop Exercises
08 — Vendor Security
09 — Policies
10 — Prior Incidents
This isn’t a formal insurance requirement.
It’s simply a practical way to keep information organized for:
- Renewals
- Audits
- Security assessments
- Incident response
Sensitive cybersecurity information should, of course, be appropriately protected.
The 2026 Cyber Insurance Readiness Checklist
Before applying or renewing:
- Verify MFA deployment.
- Review remote-access security.
- Review privileged accounts.
- Confirm endpoint protection/EDR.
- Verify device inventory.
- Review backup architecture.
- Confirm backups are appropriately separated.
- Test data restoration.
- Review patching procedures.
- Address critical vulnerabilities.
- Review email-security controls.
- Conduct employee security training.
- Update the incident-response plan.
- Conduct tabletop exercises.
- Review third-party dependencies.
- Document material controls accurately.
- Have IT review technical application answers.
- Correct inaccurate or outdated information.
- Start the process well before renewal.
- Compare policy terms—not premium alone.
Questions to Ask Your Cyber Insurer or Broker
Before purchasing coverage, ask:
- Which cybersecurity controls materially affect underwriting?
- Where specifically is MFA expected?
- What backup practices are expected?
- Does the insurer expect EDR?
- Are there minimum patching expectations?
- What documentation may be requested?
- What happens if our controls change during the policy period?
- Are ransomware sublimits applicable?
- Does ransomware coverage include coinsurance?
- Are social-engineering losses covered?
- What business-interruption waiting period applies?
- What incident-response vendors can we use?
- Who must we contact immediately after an incident?
- Are third-party cloud outages covered?
- What security improvements could improve our next renewal?
Frequently Asked Questions
Do cyber insurers require MFA in 2026?
Many cyber insurers closely evaluate MFA, especially for remote and privileged access, but requirements vary by insurer and applicant. MFA is one of the controls Marsh identifies as particularly important to cyber resilience and insurability.
Is “Proof of Defense” an official cyber insurance requirement?
No. It is not a universal standardized insurance term. In this article, it describes the increasing need for applicants to accurately demonstrate and document cybersecurity controls during underwriting.
What cybersecurity controls do insurers look for?
Common areas include MFA, EDR or endpoint protection, secure backups, privileged-access management, email security, patch management, employee training and incident-response planning.
Can an insurer ask about backups?
Yes. Coalition’s cyber application, for example, asks whether sensitive or critical data and systems are backed up at least weekly offline or on a separate network.
Does an insurer care which EDR system we use?
Potentially. At-Bay’s cyber application specifically asks applicants which EDR product they use, if any.
Will strong cybersecurity reduce my premium?
It can improve how an insurer evaluates the risk, but there is no guaranteed discount. Pricing also depends on revenue, industry, data, claims history, limits and other underwriting factors.
Can poor cybersecurity cause cyber insurance to be declined?
Potentially. Missing critical controls can affect insurability or the terms offered, depending on the insurer and risk.
Should my IT department complete the cyber application?
Business management should remain involved, but technical answers should be verified by knowledgeable IT or security personnel. Marsh explicitly recommends having IT expertise available during its cyber application process.
Are backups enough to protect against ransomware?
No. Backups are one layer of protection. Organizations should use a broader security strategy incorporating identity security, endpoint protection, vulnerability management, email security and incident-response planning.
How often should cyber controls be reviewed?
There is no universal insurance timetable. Organizations should review them regularly and particularly before insurance applications or renewals, after material technology changes and following significant incidents.
Final Thoughts
Cyber insurance is becoming less about simply answering:
“Have you ever been hacked?”
and more about understanding:
“How difficult would you be to hack—and how effectively could you recover?”
Current cyber underwriting examines controls including:
MFA + endpoint protection + backups + patching + training + incident preparedness.
The trend is understandable.
Coalition’s 2026 claims data shows initial ransomware demands rose 47% during 2025, even as most affected businesses in its dataset refused to pay.
Businesses therefore shouldn’t treat cybersecurity questions as paperwork designed merely to obtain a policy.
They should treat them as a test of operational resilience.
The strongest approach is:
Implement the control → Verify it works → Document it accurately → Maintain it → Answer the insurance application truthfully.
That’s what “Proof of Defense” should mean in 2026.

