Cyber insurance has quietly changed. A few years ago you could tick a box and get covered. Today, insurers ask detailed questions about your security controls — and if the answers on the application don't match reality when you make a claim, the claim can be declined. Cyber insurance readiness is about making sure that never happens.
Why claims get refused
The most common reason a cyber claim is reduced or rejected is a misrepresentation on the application: the business said it had a control in place, and it didn't — or it lapsed. Typical examples:
- "We enforce MFA everywhere" — but several admin accounts were exempt.
- "We have tested backups" — but no restore had actually been tested.
- "We run endpoint protection" — but it wasn't deployed on every machine.
These aren't lies; they are usually optimistic answers nobody verified. The insurer's loss adjuster verifies them after an incident, which is the worst possible time to find a gap.
What insurers now expect
The questions vary by insurer, but the core controls are consistent — and they map closely to the Essential Eight:
| Control area | What insurers look for |
|---|---|
| Multi-factor authentication | Enforced on email, remote access, and admin accounts |
| Backups | Off-site, immutable, and restore-tested |
| Endpoint protection | EDR on every endpoint, monitored |
| Patching | Operating systems and applications kept current |
| Email security | Filtering, anti-phishing, and user awareness |
| Privileged access | Admin rights restricted and controlled |
| Incident response | A documented, tested plan |
Getting ready — before renewal
- Read the application as a checklist. Every question is a control you must be able to prove.
- Verify, don't assume. Confirm MFA coverage, test a restore, check EDR is on every device.
- Close the gaps. Most are configuration, not capital spend.
- Document the evidence. Keep proof you can hand to an adjuster.
- Answer the application truthfully — now that the answers are actually true.
Done well, readiness can also lower your premium, because a demonstrably well-controlled business is a better risk.
How Umbrella helps
We align your security posture to the questions your insurer is actually asking — closing gaps across MFA, backup and recovery, endpoint protection, and incident response — and give you the evidence pack to back every answer. It is the same control set that makes you genuinely harder to breach in the first place.
Talk to Umbrella Technology before your next renewal.