What Cyber Insurance Underwriters Actually Ask For

In short
How to Boost Cyber Insurance with Intrusion Systems In today’s interconnected digital landscape, businesses face an ever-growing array of cyber threats that can compromise their data, systems, and operations. To mitigate these risks, many organizations turn to intrusion prevention and detection systems (IDS/IPS) as critical components of their cybersecurity infrastructure.
In this article
Cyber insurers have stopped asking whether you take security seriously and started asking for specific controls by name. If you cannot evidence them, you will either be declined, quoted at a premium that reflects the uncertainty, or issued a policy with exclusions that matter at claim time.
Intrusion detection and prevention sits on most of those questionnaires now. Understanding what underwriters are actually looking for, and why, is the difference between a renewal that is a formality and one that becomes a scramble.
Think your IT is in good shape?
What do cyber insurance underwriters ask for?
Questionnaires vary by carrier, but a common core has emerged. Expect to be asked to evidence most of the following:
| Control | What they are really assessing |
|---|---|
| Multi factor authentication | Whether stolen credentials alone can get someone in. Often a hard requirement now, particularly for email and remote access. |
| Endpoint detection and response | Whether you can see and stop malicious behavior, not just match known signatures. |
| Backup regime | Frequency, whether copies are isolated from the network, and critically whether restores are tested. |
| Patch management | How quickly known vulnerabilities get closed, and whether that is enforced or hoped for. |
| Email filtering | The dominant delivery route for both ransomware and fraud. |
| Security awareness training | Whether staff are trained and tested, with records. |
| Privileged access control | How many people hold administrative rights and how that is reviewed. |
| Intrusion detection and prevention | Whether anyone would notice an intruder already inside the network. |
| Incident response plan | Whether there is a written plan and whether it has ever been rehearsed. |
Two patterns are worth noticing. Several of these are about detection and response rather than prevention, because underwriters have accepted that prevention sometimes fails. And several ask whether a control is tested, not merely present, because untested controls fail at exactly the wrong moment.
What intrusion detection and prevention actually do
An intrusion detection system (IDS) watches network traffic or host activity for patterns that suggest an attack, and raises an alert. An intrusion prevention system (IPS) does the same and can block the traffic itself.
The distinction underwriters care about is less IDS versus IPS and more this: is anyone reading the alerts?
A device generating alerts into a log nobody opens provides no protection and, at claim time, may provide evidence that an intrusion was visible and ignored. That is a materially worse position than not having had the capability at all. The control being assessed is not the appliance. It is the monitoring behind it.
This is why questionnaires increasingly ask whether monitoring is staffed around the clock. Attacks are disproportionately launched outside business hours precisely because the response is slower. A system watched between nine and five on weekdays is unwatched for about two thirds of the week.
Why claims get reduced or denied
Most disputes are not about whether the incident happened. They are about whether the insured was in the state they described when the policy was written.
The control was described but not in place.
MFA was answered yes because it was on some accounts, and the compromised account was not one of them.It lapsed between renewal and incident.
True at signing, quietly untrue eleven months later. Nothing prompted a re check.Backups existed but restores had never been tested.
Discovered during the incident, which is the worst possible moment.Alerts were generated and not actioned.
The timeline shows detection days before impact.The policy excluded the thing that happened.
Social engineering and funds transfer fraud are frequently carved out or sub limited, and they are among the most common losses.
That last one deserves its own consideration. Business email compromise, where an attacker persuades someone to change payment details, is one of the most frequent and expensive incidents small businesses experience, and it is not always covered by a standard cyber policy. Ask your broker specifically.
Preparing for a renewal questionnaire
Get the questionnaire early.
Ask for it well before renewal. It is the specification you are being measured against, and some answers take weeks of work to make true.Answer it honestly, then fix the gaps.
An inaccurate yes is worse than a no. A no is a premium conversation. An inaccurate yes is a coverage dispute.Gather evidence, not assertions.
Screenshots of policy settings, reports showing patch compliance, dated records of restore tests and training completion.Close the easy gaps first.
MFA coverage, admin account review and training records are usually the quickest wins.Document what you cannot do.
A control you have consciously accepted the risk of not having, with a reason recorded, is a defensible position. An unexamined gap is not.
The useful reframe: treat the questionnaire as a free security assessment written by people who pay out when it goes wrong. Underwriters see loss data across thousands of businesses, and what they ask about is what actually causes claims.
How this maps to a managed security stack
Most of the controls above are standard components of a managed security service rather than individual purchases. Corporate Technologies delivers them as Secure Advantage, which includes 24/7 security operations center monitoring, next generation antivirus and endpoint detection and response, multi factor authentication, spam filtering, security awareness training, CEO fraud protection, website restrictions, and application and storage control.
The reason that packaging matters for insurance specifically is the evidence question. A questionnaire does not ask whether you own tools. It asks whether controls are operating, monitored and reviewed, and whether you can show it. Assembling that from several unmanaged products, each with its own console and nobody watching any of them, is where small businesses lose weeks before a renewal.
Frequently asked questions
Will having an IDS lower my premium?
On its own, rarely. Underwriters price the overall control picture, and detection without monitoring adds little. What moves premiums most reliably is MFA coverage, tested backups and endpoint detection and response, because those correlate most strongly with whether an incident becomes a large claim.
Do we need 24/7 monitoring, or is business hours enough?
Increasingly the questionnaire asks directly. Attacks are frequently timed for evenings, weekends and holidays. If you answer that monitoring is business hours only, expect that to be reflected in terms.
What if we answered a question wrong last year?
Raise it with your broker before you need to claim, not after. Correcting the record at renewal is a manageable conversation. Discovering the discrepancy during a claim is not.
Is cyber insurance worth it for a small business?
That is a decision for you and your broker, and it turns on what an incident would actually cost you: the response, the downtime, the notification obligations, the legal exposure. The process of applying has value regardless, because the questionnaire tells you what informed parties consider baseline.
Does the policy cover ransom payments?
Sometimes, often with conditions and sub limits, and the landscape is shifting. Read the extortion section specifically, and ask what the insurer requires before any payment is made, because doing the wrong thing first can void the cover.
Sources
Control categories reflect items commonly appearing on cyber insurance applications across carriers, and are described generically rather than quoted from any single insurer’s form. Requirements, exclusions and sub limits vary significantly between carriers and policy years, and your own questionnaire is the only authoritative version. Claim dispute patterns are described qualitatively and are not drawn from a published dataset.
This article is general information about security controls and is not insurance advice, legal advice, or a security assessment of any specific environment. Coverage terms, conditions and exclusions vary by policy and should be reviewed with your broker or counsel. Corporate Technologies supports clients in implementing security controls and does not advise on insurance placement.
Keep reading
More in Security →
Cybersecurity Insurance in Maryland: What Carriers Now Require from Your IT Infrastructure
Learn what cybersecurity insurance carriers require from Maryland businesses and how managed IT services help meet security controls, compliance, and audit expectations.

Cyber Insurance Requirements in Illinois: What Underwriters Ask For in 2026
What Illinois businesses need for cyber insurance: MFA, EDR, immutable backups, email security. Plus the Illinois laws behind the exposure and policy…

Dental Ransomware Incidents: What Actually Happens
Learn how ransomware attacks dental offices, what happens during an attack, and how backups and security can help you recover safely.
Free, same business day
What would managed IT cost for your team?
Tell us how many computers and users you have. An engineer sends a per-user range, usually the same business day. No credit card, no bot.
- Live service specialist in about a minute, 24/7
- 21 offices across 18 states
- 60-day money-back guarantee
Get your instant IT support estimate
Tell us how many computers and users you have and we send a per-user range, usually the same business day.

