← All Articles

August 8, 2026

Cyber Insurance Security Controls Checklist

Illustration of a cyber insurance security controls checklist: professionals reviewing a large clipboard of completed checkboxes surrounded by shields and locks

A cyber insurance application can make a small business feel like it is being asked to prove it has an enterprise security department. It is not. But insurers do want evidence that your business can prevent common attacks, spot suspicious activity, and recover when something goes wrong. This cyber insurance security controls checklist helps you focus on the controls that usually matter most and the documentation that makes your answers credible.

The goal is not to check a box once and forget it. Insurance carriers assess whether security controls are actually operating. A policy may be harder to obtain, more expensive, or contain exclusions when basic protections are missing. More importantly, the same gaps that concern an underwriter are often the gaps attackers use.

Why insurers ask about security controls

Ransomware, business email compromise, and stolen credentials can quickly interrupt payroll, customer service, operations, and cash flow. Insurers are managing that risk across thousands of policyholders. Their applications are designed to identify organizations that have reduced the most common paths to a costly claim.

Questions vary by carrier, industry, revenue, and the type of data you handle. A professional services firm with five laptops will not face the same review as a healthcare organization or manufacturer. Still, the core expectations are increasingly consistent: multifactor authentication, managed endpoints, timely patching, protected backups, user awareness, and a practical incident-response plan.

A security tool by itself is not always enough. If endpoint software flags malicious activity at 2:00 a.m., someone needs to investigate it, contain a confirmed threat, and make sure the issue is resolved. Detection is only useful when someone responds.

Cyber insurance security controls checklist

Use this as a working checklist before you complete a new application or renewal. For every control, identify who owns it, how it is verified, and where the evidence is stored. If your outside IT provider handles part of the work, confirm the details rather than assuming the control is covered.

1. Multifactor authentication is enforced

Multifactor authentication, or MFA, is one of the most common insurance requirements because passwords are routinely stolen through phishing, reused across sites, or guessed. MFA should protect email, cloud file-sharing platforms, remote access tools, administrative accounts, financial systems, and any application that holds sensitive data.

Do not rely on a policy that says employees should use MFA. Confirm it is technically enforced. Review exceptions, especially legacy accounts, service accounts, and executives’ accounts. Insurers may ask whether MFA is enabled for remote access and email, but securing every available system is the better operating standard.

Authenticator apps and security keys generally provide better protection than text-message codes. The right choice depends on your workforce and systems, but convenience should not create a permanent exception for high-risk accounts.

2. Endpoint protection is actively monitored

Traditional antivirus can block known threats, but it cannot reliably handle every suspicious behavior, newly created attack, or unauthorized remote-access tool. Most applications now ask about endpoint detection and response, often called EDR, because it provides deeper visibility into activity on computers.

The operational question matters just as much: who watches the alerts? A managed EDR service should continuously monitor endpoints, investigate suspicious activity, contain confirmed threats, remediate affected systems, and communicate what happened. PC Vax provides this focused layer of managed endpoint security without requiring a business to replace its existing IT provider.

Keep an accurate inventory of protected devices. A strong EDR deployment on 20 computers does not help if the owner’s laptop, a shared workstation, or a newly issued device was never enrolled. Review coverage regularly, including remote staff and devices that are rarely connected to the office.

3. Operating systems and applications are patched

Attackers often exploit vulnerabilities that already have fixes available. Managed patching reduces this exposure by keeping operating systems, browsers, office applications, and other commonly targeted software current.

A patch policy should define how quickly critical updates are addressed, who approves exceptions, and how failed updates are identified. Some business applications require testing before changes are deployed. That is reasonable, but an exception needs a compensating control and a deadline. “We cannot patch that system” is not a risk decision that should remain open indefinitely.

For insurance purposes, be ready to describe your patching process and produce reports showing patch status. A written policy without actual deployment records is less persuasive after an incident or during a detailed underwriting review.

4. Backups can be restored, not just created

Backups are a recovery control, not a substitute for prevention. They can reduce downtime and limit the pressure to pay a ransom, but only when they are protected from deletion or encryption and can be restored quickly.

Maintain backups of the data and systems needed to operate. Consider cloud applications as well. Files stored in a cloud platform may have retention features, but that does not automatically mean you have a complete, independent backup strategy.

At a minimum, your backup process should include:

  • Regular backup schedules that match how quickly your data changes
  • A separate or immutable copy that attackers cannot easily alter
  • Access controls that prevent everyday user accounts from deleting backups
  • Periodic restoration tests with documented results

The restoration test is where many plans fail. A backup that exists but cannot be located, opened, or restored within a useful timeframe does not provide the recovery confidence an insurer expects.

5. Email and payment fraud controls are in place

Business email compromise is often less visible than ransomware and can be just as damaging. An attacker may impersonate a vendor, executive, employee, or customer to redirect a payment or steal confidential information.

Technical email filtering helps, but financial controls are essential. Establish a documented out-of-band verification process for changes to bank details, payment instructions, or unusually urgent requests. That means calling a known number already on file, not replying to the message that requested the change.

Limit who can initiate and approve payments. Separate duties where possible, particularly for wire transfers and ACH changes. A small business may not have enough staff for complete segregation, so use a second-person approval process and clear verification steps instead.

6. Employees receive practical security training

Security awareness training should prepare people for decisions they actually make: identifying suspicious messages, reporting a possible mistake quickly, protecting passwords, and verifying payment requests. Annual training is a common starting point, but short recurring training and phishing simulations can reinforce good habits without turning security into a lecture.

Avoid treating training results as a way to punish employees. Fast reporting is valuable. An employee who reports a suspicious click immediately gives your security and IT teams a better chance to contain the issue before it spreads.

Keep records of completed training, onboarding training for new hires, and any phishing exercises. These records support insurance applications and demonstrate that your business is managing human risk as an ongoing responsibility.

7. Access is controlled and reviewed

People should have access to the data and systems necessary for their role, not broad access because it is easier to set up. Administrative privileges deserve particular attention. Everyday work should not require local administrator rights, and privileged accounts should be protected with MFA and used only when needed.

Create a reliable offboarding process. When an employee or contractor leaves, disable access promptly across email, cloud applications, remote tools, shared drives, and financial platforms. Review inactive accounts and high-privilege accounts on a regular schedule.

For vendors, use named accounts where available and remove access when the project ends. Shared credentials make accountability difficult and create a quiet route back into your environment.

8. An incident-response plan names real people

An incident-response plan does not need to be a 100-page binder. It needs to tell your team what to do when a threat is suspected. Include contact information for business leaders, IT support, managed security providers, legal counsel, insurance contacts, and any breach-response resources supplied by your carrier.

Define who can authorize actions such as isolating a device, shutting down a system, notifying customers, or contacting law enforcement. Practice a short tabletop exercise at least annually. Walk through a realistic event, such as an employee entering credentials into a fake Microsoft 365 sign-in page, and identify where decisions would stall.

Also preserve evidence. Avoid wiping or rebuilding an affected device before your security team or incident-response partner has assessed it unless containment requires immediate action. Quick action matters, but so does understanding what occurred.

How to prepare evidence before renewal

Start early. Insurance applications often move quickly, while locating asset lists, configuration screenshots, patch reports, backup test results, and training records can take time. Create a simple security evidence folder with current documents, dates, system owners, and notes about exceptions.

Be accurate in your answers. Overstating a control can create a serious problem if a claim occurs and the insurer finds that the control was not enforced. If something is incomplete, explain the status, the interim protection, the responsible owner, and the expected completion date. Clear facts are better than vague assurances.

This checklist is not a promise of coverage, and your carrier’s requirements control the policy decision. It is a practical way to turn insurance questions into security work that protects the business regardless of the policy outcome.

The best time to find a missing control is before a renewal deadline, not after an attacker has already found it. Assign an owner, verify what is really in place, and make sure someone is ready to act when an alert becomes a real threat.

PC Vax provides cybersecurity services, not insurance advice. Cyber insurance requirements vary by carrier, policy, and applicant, and PC Vax does not guarantee insurance eligibility, approval, coverage, or premiums.


Professional Cybersecurity. Made Simple.

Get Protected