Cyber insurance used to be a form and a premium. After several years of ransomware losses it is a security assessment with money attached - and the answers you give are contractual statements, not marketing. The most expensive mistake in this area is not underinsuring; it is answering a proposal form optimistically.
What insurers now require before quoting
Many of these have moved from "influences your premium" to "we will not quote without it":
- MFA everywhere that matters - remote access, email, privileged accounts, and increasingly all administrative interfaces. This is the most common hard requirement.
- Endpoint detection and response, not just traditional antivirus.
- Tested, immutable or offline backups. Insurers ask specifically whether backups are separated from production credentials, because that determines whether a ransomware claim becomes a total loss.
- Privileged access management and a small, controlled administrator population.
- Patch cadence with stated timelines for critical vulnerabilities.
- Email filtering and awareness training, given how claims actually originate.
- An incident response plan that has been exercised - the word "tested" appears increasingly often.
- Network segmentation, particularly for larger organisations and anyone with operational technology.
These map almost exactly onto ISO 27001, SOC 2 and NCA ECC control sets. Organisations that have done compliance work usually find the proposal form straightforward - and can evidence their answers, which is the part that matters at claim time.
How compliance affects the economics
Certification is rarely a formal discount line, but it changes the conversation in three concrete ways. Underwriters price uncertainty, and an organisation that can produce evidence rather than assertions presents less of it. Independent verification of controls is worth more than self-attestation. And a mature programme signals lower likelihood of the operational failures that drive severity.
The practical effects are better terms, higher limits, lower retentions, and access to insurers who decline weaker applicants outright. In a hard market, availability matters more than price.
Answer the proposal form from evidence
GRC Copilot keeps control status and evidence current across your frameworks - so underwriting questions are answered from records rather than recollection.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
The answer that voids the claim
Proposal form answers are typically warranties or representations the insurer relies on. If you state that MFA is enforced on all remote access and an incident occurs through a remote account without it, the insurer may reduce or deny the claim - and this has happened in litigated cases.
Two disciplines follow:
- Answer from evidence, not intention. "MFA is enforced except on three legacy systems, which are compensated by X" is a perfectly acceptable answer that gets priced. An unqualified yes that is 94% true is a problem waiting for an incident.
- Have the security team review the form before it is signed. Proposal forms are frequently completed by finance or operations using an optimistic reading of what IT told them a year ago.
Mid-term material changes may also need disclosing - decommissioning a control you declared is not a neutral act.
What is covered, and what is not
Coverage typically spans first-party costs (incident response, forensics, notification, business interruption, data restoration, extortion payments where lawful) and third-party liability (claims from affected parties, regulatory defence, and fines where insurable - which varies by jurisdiction).
Exclusions worth reading closely:
- War and state-sponsored attack exclusions, significantly tightened in recent years and genuinely contentious given attribution difficulty.
- Failure to maintain declared security standards - the warranty issue above, expressed as an exclusion.
- Prior known incidents or vulnerabilities - an unpatched critical vulnerability you knew about can fall outside cover.
- Infrastructure and third-party outages, often limited or excluded despite being a common cause of loss.
- Betterment - insurers pay to restore, not to upgrade.
Insurance is not a control
Risk transfer moves financial consequence; it does not move the event, the disruption, the regulatory obligation or the reputational damage. It belongs in the risk register as a treatment applied after mitigation, alongside the residual risk it addresses - not as a substitute for controls. A board that treats a policy as coverage of the risk itself has misunderstood the product, and it is worth saying so plainly in the risk discussion.
Frequently asked questions
Does ISO 27001 certification reduce premiums?
Not usually as a stated discount, but it improves terms and access by reducing the uncertainty underwriters price. The specific controls matter more than the certificate.
How much cover do we need?
Model it: incident response and forensics, notification at your record volume, business interruption at your revenue per day, plus legal and regulatory defence. A business impact analysis gives you most of the inputs.
Are ransom payments covered?
Often, subject to sanctions law and insurer approval - and paying may be unlawful depending on the party involved. Never assume it is a simple commercial decision.
When should we start renewal preparation?
Three months out. Underwriting questions have grown considerably, and a control gap found in week one of renewal can often still be closed before the form is signed.
Key takeaways
- Underwriting is now a control assessment - MFA, EDR and tested backups are frequently mandatory.
- Proposal answers are binding; qualify them honestly rather than answering an unqualified yes.
- Read the war, prior-knowledge and declared-standards exclusions closely.
- Insurance transfers financial consequence only - it is a treatment, not a control.