Cyber Insurance Underwriting: What Insurers Want Before They’ll Quote You

Published May 6, 2026

A manufacturing client of ours tried to renew their cyber insurance policy last spring. They had held coverage with the same carrier for six years, never filed a claim, and expected renewal to be routine. Instead, the carrier sent back a 14-page questionnaire, requested evidence of specific security controls, and priced the renewal at a 90% premium increase.

The firm had a decision to make: accept the new pricing, shop other carriers (who were likely to ask the same questions), or fix the gaps in their environment to qualify for better terms. They picked option three, spent about four months implementing the controls underwriters were asking about, and ended up with improved coverage at roughly the prior year’s pricing.

Cyber insurance has entered a different era. The 2023 Government Accountability Office report on the cyber insurance market documented that premiums roughly doubled between 2018 and 2022, coverage became more restrictive, and underwriting scrutiny increased sharply. Since that report, the pattern has continued. What used to be a check-the-box process now looks like a security audit. Knowing what underwriters are looking for lets you prepare, price realistically, and, where needed, improve your environment to qualify for the coverage you need.

The Problem: Underwriting Is Now a Security Review

Five years ago, a cyber insurance application was one or two pages asking about revenue, industry, and whether you had any known incidents. Today, the process typically looks like:

  • An application of 10 to 30 pages with detailed questions about security controls
  • Supplemental questionnaires for specific risks (ransomware, privacy, business email compromise)
  • An external attack surface scan of your internet-exposed assets
  • Requests for evidence: MFA screenshots, endpoint protection reports, backup architecture diagrams
  • Interviews with IT or security leadership on specific topics
  • For larger policies, an onsite or deep-dive assessment

Carriers are doing this because their loss ratios told them the old model was broken. Ransomware claims spiked. Business interruption claims from cyber events proved expensive and hard to predict. Underwriters responded by asking harder questions and walking away from risks they cannot price.

For policy shoppers, the implication is that preparation matters. A well-prepared submission gets better terms. An unprepared submission gets rejected or priced at punitive levels.

Why It Matters to You Specifically

For owners, CFOs, and operations leaders evaluating cyber insurance, several specific pressures are in play:

Coverage Is a Prerequisite for Some Contracts

Many large customers, especially defense primes, healthcare systems, and major industrial clients, now require their suppliers to carry cyber insurance with specific minimum limits. Being unable to place coverage does not just increase your risk. It can disqualify you from revenue.

Coverage Gaps Can Be Catastrophic

A cyber event without adequate coverage can cost a mid-size manufacturer or civil firm seven figures in response, recovery, legal, and business interruption expenses. IBM’s 2024 Cost of a Data Breach Report put the global average breach cost at $4.88 million, with industrial sector costs higher. Underinsurance in this space is not a minor oversight.

Premium Increases Come Fast

A firm with gaps in its security posture can see premiums increase significantly at renewal, even without any claim. Getting ahead of underwriter expectations is cheaper than absorbing premium shock.

Claim Denials Are Real

Policies increasingly include conditions that, if unmet, limit or void coverage. A common one is a warranty that MFA is in place on email and remote access. A firm that attests to MFA during underwriting but does not actually enforce it comprehensively can face coverage disputes at claim time.

What Underwriters Are Actually Asking For

Underwriter questions vary by carrier and by policy size, but the same core controls show up on nearly every application.

Multi-Factor Authentication (MFA) Everywhere It Matters

Underwriters want MFA on:

  • All email accounts (Microsoft 365, Google Workspace)
  • All remote access (VPN, RDP, cloud administrative portals)
  • Privileged accounts (domain admins, database admins, cloud root accounts)
  • Backup system access

“Yes” is not sufficient. Evidence is expected. A screenshot of the Azure AD MFA enforcement policy, or a configuration export from the identity provider, is the kind of thing underwriters now request.

Endpoint Detection and Response (EDR)

Underwriters want to see modern endpoint protection on all workstations and servers. Signature-based antivirus alone is generally no longer sufficient. EDR products (CrowdStrike, SentinelOne, Microsoft Defender for Endpoint, Sophos, etc.) are the expectation. The carrier often asks which product, how it is deployed, and who monitors alerts.

Backup Architecture

Backups that are offline or immutable (cannot be overwritten or deleted by a compromised credential) are the new expectation. Cloud backups alone, without immutability, raise flags. Underwriters will ask about backup frequency, retention, and whether restoration has been tested in the past 12 months.

Email Security

Advanced email filtering, DMARC, SPF, and DKIM (three email authentication protocols that help prevent spoofing) are increasingly asked about explicitly. A firm running email through a basic filter and without email authentication is answering “no” to questions that used to be acceptable as “yes.”

Privileged Access Management

How are administrative accounts controlled? Are they separate from regular user accounts? Are they monitored? Do privileged users have MFA? Some underwriters ask about NIST SP 800-63B alignment for identity controls.

Incident Response and Business Continuity

Do you have an incident response plan? When was it last tested? Do you have a business continuity plan that addresses cyber scenarios? Underwriters look for maturity, not just documents.

Third-Party and Supply Chain Controls

Do you have a vendor risk management program? Do vendor contracts include security requirements? For manufacturing, questions about OT/IT segmentation and vendor access are increasingly common.

Security Awareness Training

How often are employees trained? Is phishing simulation part of the program? Training alone is not a magic bullet, but its absence is a specific exposure underwriters flag.

Patch and Vulnerability Management

How quickly are critical patches applied? How are vulnerabilities identified? An external attack surface scan by the carrier will often find unpatched systems directly exposed to the internet, which becomes part of the underwriting conversation.

What Good Looks Like

A firm positioned for favorable cyber insurance outcomes has a clear story to tell underwriters:

  • Written security policies that reflect actual practice
  • Evidence of control implementation, not just claims
  • A mature IT or managed IT provider relationship that can support underwriting conversations
  • Recent tabletop exercise or penetration test results
  • A framework alignment statement (NIST CSF 2.0, CIS Controls, or similar) that shows the firm thinks about security systematically

The firm can answer underwriter questions specifically, support answers with evidence, and demonstrate that security maturity is improving over time.

Practical Takeaways

  1. Request your renewal questionnaire 90 days early. Do not receive it six weeks before expiration. Time is your biggest ally in closing gaps before renewal.
  2. Identify any “no” answers that should be “yes.” MFA on email that applies to 80% of users is a “no” until it applies to 100%. Partial implementation creates honest but weak answers.
  3. Gather evidence now. Screenshots, policy documents, architecture diagrams, and control reports are what turn yes/no answers into credible ones.
  4. Work with an MSP or security partner experienced with cyber insurance. A partner who has walked other clients through underwriting knows what carriers actually look at and how to position a firm favorably.
  5. Treat the application as an operational improvement exercise. The questions carriers ask are, broadly, the controls every firm should have. The best outcome from cyber insurance underwriting is a more resilient environment that happens to cost less to insure.

Cyber insurance is not going to get cheaper or easier. The firms that approach it systematically end up with better coverage, better pricing, and, not coincidentally, lower actual risk.

If you want a conversation about preparing your environment for a cyber insurance renewal or a first-time placement, the HVR Cloud team works with civil firms and manufacturers on exactly this kind of preparation. Get in touch and we can walk through what readiness looks like for your business.