Skip to content
English - United States
  • There are no suggestions because the search field is empty.

Cyber Insurance Requirements Checklist: The Controls Insurers Ask For

The controls insurers ask about, and what each one actually means.

Cyber insurers now condition coverage and pricing on a specific set of controls: multi-factor authentication, endpoint detection and response, tested and immutable backups, patch management, privileged access management, email security, security awareness training, logging, and an incident response plan. Answering yes without having them in place is the most common way a claim gets denied.

The checklist

  1. MFA on email, remote access and VPN, cloud applications, and all administrator accounts. Enforced by policy, not optional. See what is MFA.
  2. EDR on every workstation and server, centrally managed, with tamper protection. Not just antivirus. See what is EDR.
  3. 24/7 monitoring of endpoints and identity, typically through MDR or a SOC.
  4. Backups that are encrypted, off-site, immutable or offline, separated from domain credentials, and tested with documented restore results. See what is an immutable backup.
  5. Patch management with critical patches applied within a defined window and no end-of-life operating systems in production.
  6. Privileged access management. Separate admin accounts, no daily use of admin rights, no shared admin passwords.
  7. Email security. Filtering, link and attachment protection, and SPF, DKIM and DMARC records.
  8. Security awareness training with phishing simulations, at least annually and preferably more often.
  9. Logging retained long enough to investigate an incident, ideally centralized.
  10. Incident response plan, written and tested.
  11. Network protections. Managed firewall, no Remote Desktop exposed to the internet, segmentation of critical systems.
  12. Encryption of laptops and sensitive data.
  13. Vendor and payment controls. Verification procedures for payment changes to limit funds transfer fraud.

How to prepare

Pull last year's application and audit every yes. Fix the gaps before renewal, not after. Keep evidence: MFA policy screenshots, EDR coverage reports, backup test logs, training completion records. Have your IT provider review the application before you sign it.

Why it pays beyond the premium

This list is also, not coincidentally, the set of controls that prevents most ransomware and business email compromise. See what cyber insurance covers for the policy side.

Mentis Group implements every control on this list for Fully Managed IT clients and supports questionnaires, control validation, remediation planning and insurer audits through Enhanced Cybersecurity.

Have a question about your own environment? Schedule a consultation with Mentis Group or call (866) 901-7808.