For years, cyber insurance worked as a business safety net. If a ransomware attack locked your systems or a data leak exposed customer information, the policy was supposed to cover the cost of recovery. That assumption is getting weaker. As attacks have become more frequent and more expensive, insurers have tightened their standards, and the days of getting coverage after filling out a simple questionnaire are largely over.
Cyber insurance is moving toward a simple model: it does not replace sound security; it prices and rewards it. Carriers are no longer satisfied with broad assurances that controls exist somewhere in the environment. They want proof.
Two items have moved from recommended to required in many underwriting conversations: Multi-Factor Authentication (MFA) and endpoint encryption. If those basic controls are missing, that gap can become a reason to deny coverage when a claim is filed.
The Shifting Stance Of Insurance Carriers
The reason is not mysterious. It’s economics. Carriers have absorbed a heavy run of ransomware-related claims, and many of those incidents traced back to weak, preventable security gaps. From an underwriting standpoint, covering a company without basic cyber hygiene is a lot like covering a house with no locks on the doors. The exposure is too high, and insurers know it.
That is why underwriting has become much tougher. A new application or renewal now reads less like a routine form and more like a security review. Carriers ask specific technical questions about controls, scope, and enforcement. If the answers are weak, incomplete, or inconsistent, the result may be a denial, narrower coverage, or premiums that become hard to justify.
Requirement 1: Multi-Factor Authentication (MFA)
MFA is widely considered the single most effective control you can put in place to stop unauthorized access to your network. It requires a user to present two or more verification factors before getting into a system, such as a password (something they know) plus a code from their phone or an authenticator app (something they have). In practice, that is why insurers look closely at MFA coverage for Microsoft 365, Google Workspace, VPN access, and other remote login paths.
Why it’s now mandatory:
Most successful cyberattacks still start with a stolen or guessed password. An attacker can buy credential lists on the dark web, run password-spraying attacks against Microsoft 365 or VPN portals, and get in if nothing blocks that login. What they usually cannot do is satisfy the second factor tied to your employee’s phone, hardware key, or authenticator app. That is why MFA cuts off so much of the risk from stolen credentials. Carriers know this because they have reviewed years of breach claims, and Microsoft has said MFA stops more than 99.9% of account compromise attacks. From an insurer’s perspective, a business that does not enforce MFA across critical systems like email, VPN, and remote access is leaving the front door open.
The consequence of lacking it:
If you suffer a breach and your policy application said you had MFA in place, but the compromised account did not actually have MFA turned on, expect the claim to be denied. From the carrier’s standpoint, that is a misstatement of your security posture, not a minor paperwork issue. In practice, this often comes up when one account is left out of enforcement. If that gap is what the attacker used, the insurer can argue the policy is void.
Requirement 2: Endpoint Encryption
Your “endpoints” are the devices your employees use every day: laptops, desktops, and mobile phones. Those devices store and reach sensitive company and customer data, whether that is email, saved files, browser sessions, or access tokens. Endpoint encryption means that data is scrambled so nobody can read it without the right authentication key. In real terms, that usually means full-disk encryption tools such as BitLocker on Windows, FileVault on Macs, and device encryption enforced through mobile device management on iPhone and Android fleets.
Why it’s now mandatory:
What happens when an employee leaves a company laptop in a coffee shop or gets it stolen from their car? Without encryption, the person holding that laptop may have direct access to every file on it, along with cached email, saved passwords, and synced folders. That is a data breach. With full-disk encryption, the data on the stolen device is just unintelligible gibberish unless the attacker also has the right credentials or key. The hardware is gone, but the data is still protected. That distinction matters because the downstream costs get expensive fast: breach notification, legal review, forensic work, and possible obligations under rules such as HIPAA, GDPR, or state privacy laws. Insurance carriers look at unencrypted laptops as ticking time bombs for data leaks and the regulatory fines and notification costs that can follow.
The consequence of lacking it:
If a stolen, unencrypted laptop leads to a data breach, your cyber insurance carrier will likely deny the claim. Their argument is straightforward: you did not take a basic, commercially reasonable step to protect sensitive data, which they can frame as negligence and use to void coverage. This is exactly why insurers now ask whether encryption is enforced across the fleet, not whether you merely own devices that support BitLocker or FileVault.
FAQs
We are a small business. Do these strict requirements really apply to us?
Yes. Cybercriminals and insurance carriers no longer make much of a distinction based on size. A 10-person company is often an easier target than a 1,000-person one because smaller teams tend to have fewer IT controls, less monitoring, and more shared responsibilities. Insurers know that. That is why they now apply the same baseline requirements, especially MFA and encryption, to a 10-person company that they apply to a 1,000-person company. Those controls are no longer viewed as advanced security. They are the floor.
Is implementing MFA and encryption difficult or expensive?
It used to be harder than it is now. Today, MFA is built into platforms like Microsoft 365 and Google Workspace, and many companies add products like Duo or Okta for tighter enforcement. Endpoint encryption, is already a standard feature in modern operating systems. The bigger cost is usually not the software itself. It’s the planning, rollout, testing, and ongoing management needed to make sure MFA is enabled for every account and encryption is deployed correctly across every device without breaking access or slowing down day-to-day work.
My policy is up for renewal. What should I do to prepare?
Do not leave this until the last minute. Start several months before your renewal date with your IT partner or a qualified consultant, then audit your current security posture against the controls the application is likely to ask about. That usually means confirming MFA is enforced for every user and admin account, checking that encryption is active on every laptop, desktop, and mobile device, and making sure you can prove it with screenshots, policy exports, or device-management reports if the carrier asks. That lead time gives you room to find and fix gaps, like rolling out MFA or enforcing encryption, before you submit the application.
What other security controls are insurers starting to require?
Beyond MFA and encryption, carriers now often want proof that you have Endpoint Detection and Response (EDR) in place, not just traditional antivirus. Plus regular employee security awareness training, phishing drills, and a formal incident response plan that has actually been tested. The underwriting bar keeps moving up, and insurers are asking more questions about whether these controls work in the real world, not just whether they appear on a checklist.
From Safety Net to Final Exam
A cyber insurance policy is no longer a simple safety net. It has become the final exam for your cybersecurity program. You cannot buy a policy to cover for weak security; you have to put the security controls in place first to qualify for the policy on workable terms. In that sense, the insurance application is a practical roadmap: it shows which baseline controls carriers now treat as standard business practice, from MFA and endpoint encryption to EDR, backup discipline, and incident response readiness.
Skipping basic controls like MFA and endpoint encryption is not just a security problem. It is a direct financial risk that can leave your business fully exposed after an attack, especially if a carrier argues that missing controls voided coverage or reduced the claim payout. For most companies, the cost of turning on MFA, enforcing BitLocker or FileVault, and tightening endpoint management is small compared with the cost of a denied claim, downtime, legal review, and customer notification. The right time to fix this is before an incident, not after a claim denial.
If you’re not sure whether your current security posture will satisfy the increasingly strict demands of cyber insurance carriers, get a professional assessment before renewal time. A review should check the controls insurers now scrutinize most closely, including MFA coverage, endpoint encryption, EDR deployment, privileged access, backup recovery, and incident response testing. Reach out to IPM Computers to help make sure your business is not only secure, but insurable.
