For brokers and their clients · September 2026
Pass your cyber insurance application
Eight controls the forms ask about, and what a yes needs behind it.
Give this to a client before they fill in a cyber application. Each line is a control that current small-business cyber applications ask about, the question as one carrier prints it, and the evidence a yes needs. Answer yes only where you can show that evidence.
In Travelers v. ICS (2022), the insured had MFA on its firewall and nowhere else. A federal court entered judgment rescinding the policy. (Lockton's summary of the case)
The PDF prints on one US Letter page and has a blank “Provided by” box for your agency's stamp or card.
The eight controls
1. MFA on email, remote access and admin accounts
The form asks
“For which of the following services do you enforce Multi-Factor Authentication (MFA)?”
Coalition, New Business Cyber Application, Q6The form then lists email, remote access (VPN, RDP), and admin or privileged accounts, one line each.
A yes needs
An export from Microsoft 365 or Google Workspace showing MFA enforced for every user, the remote-access settings showing it there too, and a list of admin accounts with their MFA status.
2. EDR or MDR on every computer, servers included
The form asks
“Do you use an endpoint detection and response (EDR) product across your enterprise?”
The Hanover, Ransomware Supplemental Application, Q9The follow-up asks whether it is tied to a continuous monitoring platform and process.
A yes needs
The device count from the EDR console matched against the device inventory, workstations and servers both, and the name of whoever watches the alerts around the clock.
3. Backups kept offline or immutable, locked with MFA, and restore-tested
The form asks
“Which of the following are in place for your backup solution(s)?”
Corvus, Smart Cyber Insurance Application v3.2, Q10bThe choices include an offline or air-gapped copy, immutable backups, and MFA required for access to backups.
A yes needs
Backup settings showing an offline or immutable copy, MFA on the backup console with credentials separate from the office network, and a dated test restore from the last 12 months. OneDrive or Dropbox sync is not a backup, and Beazley asks about that separately.
4. Phishing training, with simulated phishing emails
The form asks
“Do you proactively use Phishing simulation testing on employees?”
Fusion MGA, Cyber Insurance Application, Q22A yes needs
Training completion records for every staff member and dated results from simulated phishing campaigns. Include the people who pay invoices and send wires.
5. A written call-back rule for wire and payment-change requests
The form asks
“When a vendor or supplier requests any change to its account details (including routing numbers and account numbers), do you confirm requested changes via an out-of-band authentication (a method other than the original means of request)?”
Beazley, Cyber Application F00863, Q21A yes needs
A written procedure: every payment or bank-detail change is confirmed by calling a number already on file, never one taken from the request, at any dollar amount. Add proof that the people who move money were trained on it.
6. A deadline for critical patches
The form asks
“In what time frame do you install critical and high severity patches across your enterprise?”
The Hanover, Ransomware Supplemental Application, Q14It is a write-in. Fusion asks the same thing as a yes or no at 30 days from vendor release.
A yes needs
A written patch standard that states the deadline in days, and a report from the device-management tool showing which machines are current.
7. No end-of-life software on the network
The form asks
“Do you use any end-of-life software within your systems or network infrastructure?”
Fusion MGA, Cyber Insurance Application, Q44A yes leads to two more: is it connected to the internet, and has extended support been bought.
A yes needs
An inventory of operating systems and major applications showing each is still supported by its vendor. For anything that is not: proof it is off the internet and walled off, or covered by paid extended support.
8. Encryption on every laptop
The form asks
“Does Named Insured implement encryption on laptop computers, desktop computers, and other portable media devices?”
Coalition, New Business Cyber Application, Q3The answers are No, Yes and Sometimes.
A yes needs
A BitLocker or FileVault report from the device-management tool showing every laptop encrypted, with recovery keys stored centrally.
Questions are quoted from the carrier applications named. Forms change, so check the client's current application. This is a readiness aid, not legal or insurance advice. Obsidian Ridge prepares businesses for these questions in the Cyber Insurance Readiness Sprint. More for agencies is on the broker page.
Disclosure
Obsidian Ridge is not an insurance producer, broker, or agent. We do not sell, place, or advise on insurance products.
Obsidian Ridge LLC · 964 High House Rd, PMB 2086, Cary, NC 27513 · (984) 999-7785
