I see something fairly often when organizations are completing cyber insurance applications.
The application lands on someone’s desk and starts asking questions like:
- Do you use multi-factor authentication?
- Do you have endpoint protection?
- Are your backups protected?
- Do you provide cybersecurity awareness training?
- Do you have an incident response plan?
Someone has to answer those questions. And eventually, someone in leadership may be putting their name behind those answers.
Here’s the problem:
How do you know the answers are actually correct?
It’s one thing to believe your organization has MFA.
It’s another to know which accounts and systems are protected by it, whether it’s enforced, and whether there are exceptions nobody has thought about.
That difference matters when you’re making representations on a cyber insurance application.
This Has Already Been Tested in the Real World
A manufacturing company learned why those distinctions matter after a ransomware attack. Travelers alleged that International Control Services had represented on its cyber insurance application that multi-factor authentication was used for administrative or privileged access.
After the ransomware incident, Travelers said its investigation found that MFA protected the company’s firewall, but not its server or other digital assets as represented on the application.
Travelers went to federal court seeking to rescind the policy. The company and insurer later agreed to rescission of the policy, with the policy treated as null and void from its inception and no coverage available under it for past, present or future claims, losses, costs or expenses.
“We have MFA” and “MFA is implemented everywhere we represented that it is” are not necessarily the same answer.
The lesson isn’t that every cyber insurance claim will turn into a coverage dispute. It is that the details behind a yes-or-no answer matter.
Don’t Let Someone Guess on the Application
If you’re responsible for completing the application and don’t know the answer to a technical question, don’t guess.
Ask the person responsible for the technology to verify it.
And don’t stop with: “Yes, we have that.”
- Where is it implemented?
- Does it cover everyone and everything it should?
- How do we know it’s working?
- Can we document it?
If one of those answers is unclear, that’s something to address before the application is submitted – not after an incident.
Five Questions to Ask Before You Submit the Application
1. You say we have MFA. Where exactly is it required?
Identify the users, administrators, cloud services, remote access methods and critical systems where MFA is enforced. Look for exceptions rather than assuming the control applies everywhere.
2. You say our data is backed up. When did we last prove we could restore it?
Don’t stop with a successful backup notification. Know what is protected, where copies are stored, how frequently backups run, and when a recovery was last tested.
3. You say our computers are protected. Are all of them protected?
Know what protects workstations and servers, whether every device is covered and current, who monitors security activity, and what happens when suspicious behavior is detected.
4. You say our employees receive cybersecurity training. Can we document it?
Know when training occurred, who completed it, who has not completed it, and where those records are maintained.
5. You say we have an incident response plan. What happens if I call tomorrow morning and say we’ve been hit?
Know who gets called, who makes decisions, what your IT provider handles, when the insurance carrier or breach-response resources become involved, and where the current plan is located.
What Should Be Verified Before Cyber Insurance Renewal?
Requirements vary by carrier, policy, organization and risk profile. Your insurance professional and the current application should always be the source for the specific insurance requirements.
From the technology side, applications commonly ask about controls such as MFA, endpoint protection, backups and recovery, employee security awareness, patching, remote access, email security and incident response.
The goal is not to guess what an insurer wants. The goal is to verify that what your organization represents on the application accurately describes what is actually in place.
Do Not Wait Until the Application Is Due
A renewal review is much more useful when there is still time to correct a gap. If a control is missing, partially deployed or poorly documented, leadership can decide what needs to be addressed before the application is submitted.
SpartanTec’s security consulting, managed IT services, SecureGuard360, and backup and disaster recovery services can help organizations understand, verify and manage technology controls that may be relevant to their cyber insurance application.
Cyber Insurance Does Not Replace Cybersecurity or Recovery Planning
Earlier in this series, we looked at what 48 hours without technology could cost an organization. Cyber insurance can be an important part of managing financial risk, but it does not replace cybersecurity controls, backups, recovery planning or the ability to keep the organization operating.
A Simple Next Step: Verify Before You Answer Yes
Pull out your current cyber insurance application before renewal. For every technology-related yes/no question, ask:
- Who owns this control?
- Where is it implemented?
- How do we know it is working?
- What documentation do we have?
To make that review easier, SpartanTec created a Cyber Insurance Technology Verification Worksheet. Use it with your IT provider to connect the answers on your application to the actual controls and evidence behind them.
Download the Cyber Insurance Technology Verification Worksheet
[Publisher: link this CTA to the worksheet PDF or landing page once uploaded to SpartanTec.com.]
This worksheet is designed to help verify the technology side of the application. It is not intended to determine insurance requirements or provide insurance advice. Use your carrier’s current application and your insurance professional for coverage and policy questions.
If something doesn’t match what you thought was in place, schedule a cybersecurity readiness conversation with SpartanTec before the renewal is submitted.
Frequently Asked Questions
How do I verify cybersecurity controls before completing a cyber insurance application?
Start with the current application and verify each technology-related answer with the person responsible for the control. Confirm where the control is implemented, whether it covers the systems and users represented, how it is monitored or tested, and what documentation supports the answer.
Does every cyber insurance carrier require the same cybersecurity controls?
No. Requirements differ by carrier, policy, organization, industry and risk profile. Always use the current application and guidance from your insurance professional.
Why does documentation matter for cyber insurance?
Documentation helps leadership verify that the application accurately describes the organization’s security program and provides evidence of how important controls are implemented and managed.
Is MFA enough to satisfy cyber insurance requirements?
MFA is an important cybersecurity control, but it is only one part of a security program. The specific requirements depend on the carrier and policy, and organizations should verify where MFA is actually enforced rather than assuming a general yes applies everywhere.
Should backups be tested before insurance renewal?
Restore testing is a sound business practice regardless of renewal timing. It helps verify that protected data can actually be recovered and gives leadership a clearer understanding of recovery capability.
Can SpartanTec review a cyber insurance application?
SpartanTec can help evaluate and verify the technology and cybersecurity controls referenced in an application. Questions about coverage, policy interpretation or insurance advice should be addressed by the organization’s insurance professional.


