Yes. Cyber insurers increasingly treat certain controls as underwriting gates, not merely “nice-to-have” security improvements. The exact requirements vary by carrier, industry, revenue, exposure, and policy limit, but the following controls are the strongest common priorities.
Controls to prioritize
| Control | What insurers generally expect | Insurance impact |
|---|
| MFA | MFA for remote access, email/cloud apps, VPN, privileged/admin accounts; ideally phishing-resistant MFA | Critical / often mandatory |
| Privileged Access Management (PAM) | Separate admin accounts, least privilege, controlled/elevated admin access | Critical |
| Endpoint Detection & Response (EDR/XDR) | Managed endpoint protection with centralized monitoring and response capability | Critical |
| Secure backups | Offline/immutable or otherwise isolated backups, encryption, regular restore testing | Critical |
| Email & web security | Anti-phishing, malicious attachment/link filtering, web filtering | High |
| Patch/vulnerability management | Rapid remediation of critical/high vulnerabilities; documented process and scanning | High |
| Identity & access management | Least privilege, strong passwords, joiner/mover/leaver process, privileged-account controls | High |
| Network segmentation | Separation of critical systems, backups, production/OT, and user networks where appropriate | High |
| Security logging/monitoring | Centralized logs, alerting, SIEM/MDR or equivalent monitoring | High |
| Incident response plan | Written IR plan, named responsibilities, external response resources, regular tabletop exercises | High |
| Security awareness training | Recurring employee training, especially phishing/BEC and social engineering | Medium–High |
| Encryption | Encryption of sensitive data in transit and at rest, particularly laptops and cloud data | Medium–High |
Marsh specifically identifies MFA, EDR, secured/encrypted/tested backups, PAM, and email/web security among the controls with the greatest positive impact on cyber risk and insurability.
The biggest “insurance gate”: MFA
Don't interpret “we have MFA” as sufficient. Underwriters increasingly care about coverage of MFA across the environment. MFA should generally cover:
- Remote access/VPN
- Microsoft 365/Google Workspace and other cloud services
- Privileged/admin accounts
- Critical applications
- Sensitive data access
CISA likewise recommends MFA whenever possible, while its more recent assessment emphasizes phishing-resistant MFA, identity/access management, granular privileged access controls, and access-log monitoring.
Marsh's analysis found that MFA is substantially more effective when implemented broadly across critical/sensitive data, remote logins, and administrator accounts.
Backups need to be demonstrable
For ransomware coverage, insurers are particularly interested in whether you can actually recover, not simply whether a backup product is installed.
Aim for:
- Automated backups of critical systems/data
- Offline, immutable, or otherwise isolated copies
- Encryption
- Separation of backup administration from normal user accounts
- Regular restoration tests
- Documented recovery objectives
CISA recommends continuously backing up critical data and configurations and keeping backups in a location isolated from the organizational network.
Patch management can materially affect underwriting
Have a documented vulnerability-management program with defined remediation deadlines—for example, an accelerated SLA for critical internet-facing vulnerabilities.
This isn't just an audit checkbox: Marsh's claims/control analysis found that patching high-severity vulnerabilities within seven days was among the more effective controls it studied.
Don't overlook business-email compromise
Insurers are seeing substantial losses from BEC and funds-transfer fraud, not just ransomware. Coalition's 2026 claims report says BEC and funds-transfer fraud continued to comprise the majority of its cyber-insurance claims.
Consequently, controls such as:
- MFA
- Email filtering
- Anti-phishing protection
- Payment/ACH verification procedures
- Dual approval for large transfers
- Out-of-band verification of changed payment instructions
- Security-awareness training
can be particularly valuable.
What I would implement first
If the firm is trying to improve insurability and negotiate better terms quickly, I'd prioritize in this order:
- Phishing-resistant MFA everywhere possible, especially admins, remote access, and cloud/email.
- EDR/MDR across endpoints and servers.
- Immutable/offline backups + documented restoration tests.
- PAM/least privilege and elimination of unnecessary admin accounts.
- Rapid critical-vulnerability patching.
- Email/web anti-phishing controls.
- Incident-response plan + tabletop exercise.
- Centralized logging/monitoring.
- Network segmentation for critical systems and backups.
- Documented security awareness and BEC/payment controls.
The important distinction is that there is no universal checklist that guarantees a lower premium. Insurers underwrite the overall risk and may impose specific warranties or conditions on the policy. Marsh, for example, currently describes MFA, PAM, email filtering, and EDR as controls that can be minimum requirements for obtaining coverage, while also noting that implementing recommended controls can lead to increased coverage.
If you're preparing for an actual renewal, I can also give you a cyber-insurance readiness checklist mapped to the typical insurer questionnaire, including which controls are usually mandatory, premium-reducing, and nice-to-have.