Cyber insurers assess controls that reduce the likelihood or impact of common events. Requirements vary, but several themes appear consistently.

Multi-factor authentication

Insurers commonly expect MFA for remote access, cloud email, privileged accounts and important systems.

Isolated backups

Backups should be frequent, tested and protected from the credentials used in the live network.

Patching

Identify internet-facing and critical systems, update promptly and replace unsupported software.

Email and payment controls

Call-back verification, dual authorisation and staff training can interrupt invoice fraud even after an email compromise.

Incident response

Identify decision-makers, IT providers, legal support and the insurer hotline. Keep an offline copy and test the plan.

Prepare evidence

  • MFA coverage
  • Latest restore test
  • Patching timeframes
  • Payment procedures
  • Training records

This information is general and does not take into account your objectives, financial situation or needs. Policy wording and individual circumstances determine cover. Seek advice before acting.