← Back to blog

Win U.S. Cyber Insurance in 90 Days by Proving MFA, EDR and Backups

September 9, 2026
Win U.S. Cyber Insurance in 90 Days by Proving MFA, EDR and Backups

Three controls decide whether an underwriter approves your application: multi-factor authentication across every remote and admin access point, endpoint detection and response on all endpoints and servers, and backups that are immutable and restore-tested. A supporting layer including a tested incident response plan, privileged access management, patch cadence, email authentication, logging, vendor risk checks, and staff training rounds out what carriers expect. None of it counts unless you can hand over the evidence, not just describe the policy.


TL;DR:

  • Insurers require comprehensive evidence of multi-factor authentication coverage, endpoint detection, and immutable backups, with proof from specific reports and logs.
  • A recent vulnerability assessment or penetration test is essential, and gaps such as unverified backups or SMS MFA for admin accounts can lead to application rejection or delays.
  • Building a structured 90-day remediation timeline that includes system inventories, tests, and documentation ensures smoother application submissions and renewals.
  • Common pitfalls include unsegmented networks, weak log retention, and uncontrolled plan access, which frequently cause applications to be flagged or declined.
  • Preparation through outsourcing or internal review, focusing on controls aligned with recognized frameworks, improves underwriting speed and renewal outcomes.

AccountNext-Nexus
Bring Security Evidence Together
Nexus consolidates cybersecurity, IT management, and compliance services to help create a more coordinated approach to digital security.
Visit AccountNext-Nexus

Table of Contents

Cyber insurance requirements: the essential control checklist

Insurers stopped taking your word for it a while ago. The UnderDefense readiness checklist frames it plainly: a control that exists but isn't enforced or documented might as well not exist at underwriting time. Here's what carriers actually check, and what proves it.

Multi-factor authentication. MFA needs to cover remote access, email, VPN, and every administrative account, not just a subset of "important" logins. For admin accounts specifically, underwriters increasingly want phishing-resistant methods like FIDO2 keys or passkeys rather than SMS codes. The proof to export: an MFA coverage report from your identity provider (Azure AD, Okta, Google Workspace) showing enrollment percentage, ideally at or near 100% for privileged users.

Endpoint detection and response. EDR has to sit on every endpoint and every server, running in active prevention mode rather than passive audit mode. A console export listing deployed agents, last check-in dates, and policy status is the artefact brokers ask for.

Immutable, restore-tested backups. Backups stored somewhere an attacker with domain credentials could reach and delete don't count. Immutability plus a documented restore test, ideally within the last 90 days, with a recorded recovery time objective, is what satisfies this line item.

Supporting controls fill out the rest of the questionnaire:

  1. Privileged access management — separate standing admin accounts from daily-use accounts, apply just-in-time elevation where possible, and keep a current inventory of who holds admin rights.
  2. Email authentication — SPF, DKIM, and DMARC configured correctly, with DMARC set to p=reject treated as strong evidence rather than p=none, which signals a policy that isn't actually enforcing anything.
  3. Vulnerability and patch management — a defined cadence (commonly 30 days for critical CVEs, faster for actively exploited ones) with a remediation log.
  4. Logging and monitoring — centralized logs with a minimum retention window, typically 12 months, and either a SIEM or an MDR provider watching them.
  5. Incident response — a written plan naming specific roles, tested in a tabletop exercise, with the date of the last exercise documented.
  6. Vendor risk management — an inventory of key suppliers with access to your systems or data, plus attestations from the ones handling sensitive information.
  7. Security awareness training — recurring training with phishing simulation results tracked over time, not a one-time onboarding video.

Miss any one of the three non-negotiables and you're likely looking at a decline or a coverage exclusion tied to that gap, regardless of how strong everything else looks.

What underwriters actually want to see in your evidence package

Brokers don't accept a checklist you filled out from memory. The Draxis readiness checklist notes that underwriters increasingly run external verification, scanning for exposed ports, checking DNS records for DMARC configuration, and sometimes confirming EDR agent presence through third-party attack-surface tools, before your application even reaches a human reviewer.

Build a submission binder with these artefacts ready to attach:

  • MFA coverage report from your identity provider
  • Conditional Access policy export (if using Microsoft 365 or Azure AD)
  • EDR deployment and coverage export from your console
  • Backup restore test log with date and recovery time
  • DMARC DNS record showing current policy setting
  • Log retention configuration proof from your SIEM or log platform
  • Incident response tabletop report with date and named participants
Gap found during reviewTypical broker expectation
Fix before signingCarrier requires the gap closed prior to binding coverage
Documented remediation timelineCarrier accepts coverage with a written deadline for the fix
Accept a sub-limitCarrier issues the policy but caps payout for that specific risk category

Which route applies depends on how central the gap is to your risk profile. A missing DMARC policy might get a 30-day remediation clause. Backups reachable from your primary domain, given how central that control is, more often gets a hard "fix it first."

Your 90-day readiness timeline for applying or renewing

Cramming this into the week before your renewal date rarely works. The sequencing below, drawn from how UnderDefense frames remediation planning, spreads the work so nothing gets rushed at the point it matters most.

  1. 90 days out: inventory every system, account, and vendor with access to your network. Run a gap analysis against the checklist above. Start MFA rollout on any account missing it, and begin EDR deployment on unmonitored endpoints. Kick off backup isolation and your first restore test.
  2. 60 days out: finish EDR deployment on servers specifically, since that's where gaps most often hide. Lock in immutable backup configuration if it isn't already in place. Schedule and run your tabletop IR exercise.
  3. 30 days out: assemble the evidence binder. Pull console exports for MFA and EDR, document any remediation timelines still in progress, and confirm your DMARC record reflects the policy you actually intend to enforce.
  4. 14 days out: hand the questionnaire to your broker for review before submission. Finalize any attestation letters and schedule vendor attestations if a key supplier's security posture needs confirming.

Pro Tip: Start the backup restore test earlier than you think you need to. A failed restore test 75 days out gives you time to fix the backup architecture. A failed restore test 10 days out gives you nothing but a worse application.

Common pitfalls that get applications flagged

A handful of gaps show up on nearly every declined or delayed application. Fixing them is usually cheaper and faster than business owners expect.

  • SMS-only MFA for admin accounts gets flagged almost automatically now. Switch privileged users to FIDO2 keys or passkeys.
  • Backups reachable from the primary environment are treated as no backup at all by most underwriters. Move to immutable, isolated storage and log a dated restore test.
  • EDR running in audit-only mode, or missing from servers entirely, is one of the most common gaps InsurableIT's compliance checklist flags in claim disputes. Switch to prevention mode and confirm server coverage.
  • Log retention under a few weeks leaves nothing to investigate an incident with. Configure central retention for at least 12 months.
  • Unrestricted OAuth consent lets employees grant risky third-party apps access to company data. Restrict app consent to admin approval only.

What brokers ask for and how to phrase a remediation plan

Every broker submission tends to converge on the same seven documents: MFA report, EDR export, backup restore log, DMARC record, log retention proof, IR tabletop report, and a vendor risk summary. Assign an owner internally for each, usually your IT lead or managed provider, so nothing stalls waiting on someone to remember where a file lives.

An MSP attestation letter can support your application, but it should state specifically what the MSP manages and monitors, not imply blanket responsibility for your entire security posture.

A remediation timeline works best stated plainly: what's broken, what's being done, and by when. "MFA gap on 3 admin accounts, phishing-resistant keys ordered, deployment complete by [date]" tells an underwriter more than a paragraph of reassurance.

Pro Tip: Underwriters read dozens of these a week. Specific dates and named tools beat vague promises every time.

Data encryption standards for data at rest and in transit

Encryption at rest typically means AES-256 for stored data, databases, file shares, and backup archives alike. Encryption in transit means TLS 1.2 or higher for anything moving between systems, including internal traffic between servers if your network handles sensitive data.

Underwriters generally don't ask for a specific vendor or product, but they do ask whether encryption is applied consistently, not just on your customer-facing website. A common gap: TLS on the public site, but unencrypted internal database connections or unencrypted backup files sitting on a shared drive. That inconsistency is exactly what a questionnaire is designed to surface.

Key management matters almost as much as the encryption itself. If your encryption keys sit in the same environment as the encrypted data, with no separation or rotation policy, an attacker who compromises one compromises both. Cloud providers like AWS, Azure, and Google Cloud all offer managed key services that handle rotation and access logging automatically, which is often the simplest fix for a business without a dedicated security team.

Document your encryption posture the same way you document MFA: what's encrypted, what standard, and where the keys live. A one-page summary showing AES-256 at rest and TLS 1.2+ in transit across your core systems answers this line item cleanly on most applications.

Data encryption standards for data at rest and in transit — overview diagram

Network segmentation and firewall configuration

Flat networks, where a compromised laptop can reach your finance server, your customer database, and your backup appliance with no barriers in between, are one of the fastest ways to turn a minor incident into a full breach. Segmentation splits your network into zones so a compromise in one area doesn't automatically spread.

At minimum, underwriters want to see separation between your general user network, your servers holding sensitive data, and any guest or IoT devices. A point-of-sale system, for instance, has no reason to sit on the same segment as your accounting workstation.

Firewall configuration gets checked alongside segmentation. Default-allow rules, where traffic passes unless specifically blocked, are treated as a red flag. Default-deny, with explicit rules for what's permitted, is the standard carriers expect to see referenced in a network diagram or firewall rule export.

Segmented network zones with default-deny boundaries

You don't need an enterprise-grade setup to pass this line item. A small business running a handful of VLANs with a properly configured next-generation firewall satisfies most questionnaires. What matters is that segmentation exists, is documented, and reflects how data actually flows through your business, not a diagram drawn up once and never updated.

Employee background checks and access control policies

Access control policy is really two separate questions underwriters ask: who can get into your systems, and how do you decide who should. Background checks address the second question at the hiring stage, particularly for roles with administrative access, financial system access, or handling of customer data.

Most cyber insurance applications don't demand a specific background check standard, but they do ask whether you have a documented hiring and access provisioning process. That means a written policy describing how new hires get accounts, how access is approved for sensitive systems, and, just as important, how access gets revoked when someone leaves or changes roles.

The revocation piece trips up more small businesses than the hiring piece. An underwriter reviewing your incident history will notice if a former employee's credentials were still active weeks after departure. A same-day deprovisioning process, tied to your HR offboarding checklist, closes that gap and is simple to document.

Role-based access control, where permissions map to job function rather than being granted ad hoc, is the standard most carriers reference. If your bookkeeper has access to the same shared drive as your sales team, that's worth fixing before it shows up as a finding.

Proof of prior security audit reports or penetration testing results

Carriers ask about audit and penetration testing history for a straightforward reason: it tells them whether you've had independent eyes on your environment recently, and whether you fixed what those eyes found. A SOC 2 report, a penetration test summary, or a vulnerability assessment from the last 12 to 24 months all count as acceptable evidence.

What matters as much as having the report is what you did afterward. An underwriter reviewing a penetration test with several unresolved critical findings from a year ago will read that as a bigger risk signal than having no test at all. If you commission a test, budget time and resources to close the findings, not just file the report.

For businesses without a recent formal audit, a vulnerability scan from your MSP or a managed detection provider can serve as a lighter-weight substitute, particularly for smaller applications where a full penetration test may not be proportionate to the coverage amount requested. Larger limits, or industries like healthcare and finance that MoneyGeek notes face stricter requirements, tend to expect more formal, recent testing.

Keep whatever report you have on hand and current. A three-year-old penetration test carries far less weight than one from the past year, even if nothing has materially changed in your environment.

Minimum cybersecurity insurance coverage limits and deductible requirements

Coverage limits vary by industry, revenue, and data sensitivity, so there's no single number that applies across the board. MoneyGeek's guide notes that businesses in healthcare, finance, and retail typically face higher minimum limits and stricter underwriting than a low-data-sensitivity service business of similar size, because breach costs in regulated industries tend to run higher once notification and regulatory obligations kick in.

Coverage itself generally splits into first-party protection, covering your own costs like incident response, notification, and business interruption, and third-party protection, covering claims from customers or partners affected by a breach. The FTC's guidance on cyber insurance outlines both categories and the notification and regulatory obligations insurers commonly build into a policy.

Deductibles work the same way they do in any commercial policy: higher deductibles lower your premium, but only make sense if you can absorb that amount without disrupting operations after an incident. A business holding stronger evidence, tight MFA coverage, tested backups, and a documented IR plan, is often positioned to negotiate a lower deductible or a broader sub-limit than one presenting the same revenue with weaker controls.

Talk limits and deductibles through with your broker against your actual exposure, not a number pulled from a competitor's policy. A retailer holding payment card data and a professional services firm with minimal stored customer data face very different loss scenarios even at similar revenue.

Compliance with cybersecurity frameworks like NIST and CIS Controls

Most cyber insurance applications don't require formal certification against a specific framework, but mapping your controls to one, most commonly the NIST Cybersecurity Framework or the CIS Controls, gives underwriters a structured way to evaluate what you've built. It also gives you a structured way to find your own gaps before an underwriter does.

The CIS Controls, organized into implementation groups by organization size and maturity, tend to be more approachable for a small or midsize business than the full NIST framework, which is broader and was originally built with larger enterprises in mind. Either one works as a reference point; what matters is that your MFA, EDR, backup, and access control practices align with a recognized standard rather than an ad hoc mix decided department by department.

Some carriers now offer modest premium credits for businesses that can demonstrate framework alignment, though this varies significantly by insurer and isn't something to count on without confirming it directly with your broker. The stronger, more consistent benefit is application speed: a business that can point to a CIS Controls self-assessment or a NIST-aligned control inventory typically moves through underwriting faster than one answering the questionnaire from scratch with no reference framework behind it.

Why preparation, not last-minute fixes, changes your renewal outcome

Evidence reduces friction at claim time because the insurer already has a baseline of what "normal" looked like before the incident. Carriers price renewals on trajectory as much as on a single point-in-time snapshot. A business showing steady improvement, MFA coverage climbing, a second tabletop exercise completed, tends to renew on better terms than one that scrambled to patch gaps the week before applying. Accepting a documented remediation timeline or a sub-limit on a specific gap is often the more honest, and cheaper, choice over pretending the gap doesn't exist.

— Nick - Sr. Executive

Getting ready for underwriting without doing it alone

Most of what carriers ask for, MFA enforcement, EDR across servers and endpoints, immutable backups with restore logs, a tested incident response plan, maps directly to services businesses already outsource rather than build in-house. Some providers work from that same list every day: 24/7 monitoring and managed detection and response, managed immutable backup configuration, identity and access management setup, and incident response tabletop facilitation with documented roles and dates.

AccountNext-Nexus

If you're staring down a renewal date or a first application and aren't sure which of the three non-negotiables you'd fail today, that's worth finding out before a broker does. Some providers offer 24/7 monitoring and cybersecurity services built around these controls, with transparent pricing and clear descriptions of what's included. Request a pre-renewal readiness review to identify your gaps and start assembling the evidence binder your broker will ask for, before the 90-day window becomes a 14-day scramble.

This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.

Sources