Back to Business

What Cyber Insurers Are Now Asking Before They Pay Out

What Cyber Insurers Are Now Asking Before They Pay Out

Cyber insurance is sold as a safety net. What a lot of businesses do not realise until they actually need to make a claim is that the net has conditions attached, and most of those conditions were agreed to, unknowingly, on the application form.

Cyber insurers used to ask a handful of general questions and take the answers largely on trust. That has changed. Claims have climbed, insurers have gotten better at investigating what actually happened after an incident, and a mismatch between what a business claimed on its application and what was actually in place has become one of the most common reasons a payout gets refused. Not because the business lied deliberately. Usually because someone ticked "yes" to a question they assumed was close enough to true.

Here is what insurers are now commonly asking proof of, not just a checkbox, before they will quote, renew, or pay out.

The checklist

Multi-factor authentication, across every account that matters. Not just email. Insurers increasingly want MFA enforced on remote access, admin accounts, and any system holding sensitive data, not a partial rollout that technically counts as "having MFA" on the form.

Endpoint detection and response, not just antivirus. Traditional antivirus catches known threats. Insurers are increasingly distinguishing between that and genuine EDR, which can detect and contain behaviour that does not match a known signature. The form may not always ask the question this precisely, but the gap matters if a claim is ever investigated closely.

Backups that are actually immutable and actually tested. This is its own detailed topic, and we have covered it properly in a separate piece: Immutable Backups: What Your Cyber Insurance Form Is Really Asking. The short version is that "we have backups" and "we have backups an insurer would accept" are frequently two different things.

Security awareness training, with a completion record. Having a training program is one answer. Being able to show who completed it, and when, is a different and more defensible one if a claim is ever challenged on the basis that staff were not adequately prepared for a phishing attempt.

A documented patching and vulnerability management process. Insurers are increasingly asking not just whether systems are patched, but how regularly, and whether there is an actual process rather than an ad hoc one. Unpatched, publicly known vulnerabilities are one of the easiest things for an insurer's investigator to find after the fact.

A written incident response plan, with named ownership. Some insurers now ask directly whether a plan exists, and increasingly whether it specifies who is responsible for what, a point we covered in detail in our piece on incident response accountability. A business that cannot show who owns the decision to notify the insurer, or who the single point of contact is during an incident, is in a weaker position when a claim is reviewed.

Alignment with a recognised framework, where relevant. This is becoming more common for larger or higher-risk businesses specifically, rather than a universal requirement yet. Where it applies, insurers are increasingly referencing the Essential Eight as a benchmark. Our piece on what the Essential Eight framework actually involves is a reasonable starting point if this is new territory.

Why the gap between "yes" and "true" is the expensive part

None of these controls are unreasonable to ask for. The actual risk sits in the space between what a business believes about its own setup and what is demonstrably true. A business that genuinely has MFA on email but not on its remote access tool, and answers "yes, we have MFA" without clarifying the scope, has not lied exactly. It has answered a more specific question than it realised it was being asked.

This matters because misrepresentation, even unintentional, on a cyber insurance application is a recognised reason for a claim to be denied, and in some cases for a policy to be voided entirely after the fact, not just going forward. The insurer is not looking for an excuse. They are looking at what was actually in place against what was claimed, and the two need to match.

Where Affinity MSP Fits In

The honest moment to check this is before a renewal, not after an incident, because that is the only point where finding a gap costs nothing more than the time it takes to close it. In our experience, most businesses discover a mismatch between their insurance answers and their actual setup during a renewal cycle, which is a far better place to find it than during a claim. A free AffinityScan assessment gives a factual, evidence-based picture of where your current controls actually stand, which is the same picture an insurer is ultimately going to be checking against if you ever need to rely on the policy.


FAQ

Why would a cyber insurance claim get denied even if we have a policy?
The most common reason is misrepresentation, where the controls described on the application do not match what was actually in place at the time of the incident. This is often unintentional, such as answering "yes" to a general MFA question without realising the insurer meant MFA across every relevant system, not just one.

What is the most commonly checked control after a cyber insurance claim?
Backups are one of the most closely scrutinised, specifically whether they are immutable, tested, and recoverable, rather than simply running on a schedule. MFA coverage and patching records are also commonly checked.

Does my business need to follow the Essential Eight to get cyber insurance?
Not universally, though insurers are increasingly referencing it as a benchmark for larger or higher-risk businesses. Even where it is not explicitly required, aligning with it tends to cover most of what insurers ask about separately.

How does Affinity MSP help with cyber insurance requirements?
We assess a business's actual security controls against what insurers commonly ask about, including MFA coverage, backup immutability, patching, and incident response documentation, so any gap between what is claimed on an application and what is actually in place gets identified and closed before it matters.

Franchesca Michaela Antonio
Franchesca Michaela Antonio
Back to Business