Blog / Practical controls

Practical controls

Renewal Season: Answer the MFA, EDR and Backup Questions Before the Broker Asks Twice

Cyber insurance renewal questions on MFA, EDR and backups: the eight-item evidence pack that shortens the form, sharpens the quote and protects the claim.

Sam KhanSam Khan The Cyber ExpertFounder and CEO24 September 2026 · 6 min read

Five weeks out, and question 17 is a lie by accident

The managing partner of a 60-person engineering and design firm gets the renewal application from the broker on a Tuesday in early December. The policy incepts on 1 January. There are 41 questions and he answers them in eleven minutes, between meetings, the way he has for four years.

Question 17 asks whether multi-factor authentication is enforced on all email accounts. He ticks yes, because the firm rolled it out in spring.

The underwriter comes back with three follow-ups and a request for evidence. His IT provider exports the list. Multi-factor authentication is on for 54 of 61 mailboxes. The seven without it: two directors excepted while travelling, a shared projects mailbox the delivery team uses, an accounts mailbox with a password taped in the finance drawer, and three service accounts nobody has touched since a 2024 migration.

That answer was not dishonest. It was unverified, which a claim treats as worse.

The renewal still binds, at a higher retention and with a sublimit on funds transfer fraud. What the partner remembers afterwards is not the premium. It is that a stranger at an insurance company produced a more accurate picture of his firm's security in four days than his own team had in four years.

What the heck does this mean

A cyber insurance application is a security assessment with money attached. The carrier is not curious. Each question maps to a loss the carrier has already paid, more than once.

Multi-factor authentication, MFA: a second proof beyond the password, usually an app prompt or a hardware key. Stolen passwords lead their claim data.

Endpoint detection and response, EDR: software on laptops and servers that records what programs do, alerts a human, and lets that human isolate a machine remotely. Different from antivirus, which mostly matches known bad files.

Immutable or offline backup: a copy that the account running your day-to-day systems cannot delete or encrypt. It decides whether ransomware is an outage or an ending.

Funds transfer fraud: the coverage that pays when your money leaves on a fraudulent instruction. It is a separate section with its own limit, and it is often capped.

Warranty and material misrepresentation: the legal reason unverified answers are dangerous. A yes you cannot evidence at claim time is the thread the carrier pulls.

The numbers that matter

Business email compromise and funds transfer fraud together accounted for 58% of claims in the Coalition 2026 Cyber Claims Report. The email questions are not filler; they are the majority of what carriers pay out on.

Ransomware appeared in 88% of breaches at small and medium organizations in the Verizon 2026 Data Breach Investigations Report. Backup and EDR questions exist because of that number, and the median ransom in the same report, USD 139,875, is not an amount most 60-person firms have sitting idle.

Implementation Group 1 of the CIS Controls, 56 safeguards, defends against 77% of attack techniques overall and 78% of ransomware techniques according to the CIS Community Defense Model v2.0. Almost every question on a renewal form sits inside those 56, so doing the work and answering the form are the same project.

What to do this week

  1. Export the account list from your email tenant, including shared and service accounts, and mark which ones have multi-factor authentication enforced. Fix the exceptions, then keep the export with the date on it. That single file answers three or four questions on the form. (CIS 6 Access Control Management)
  2. Name your endpoint product out loud and say who receives its alerts. If the honest answer is that the alerts go to a mailbox nobody reads, write that down too, then fix it before the form goes back. An unwatched console is not a defense and will not behave like one in a claim. (CIS 10 Malware Defenses)
  3. Restore one file and one full system from a copy that is not connected to your network. Record what, from where, how long, and by whom. Do it this month, so the date is recent when the underwriter reads it. (CIS 11 Data Recovery)
  4. Confirm, in writing from whoever runs your backups, that at least one copy is out of reach of your daily administrator accounts. Ask for the setting, not the reassurance. (CIS 11 Data Recovery)
  5. Write the payment change rule on one page and train the two people who process payments: any change to bank details is confirmed by voice on a number already held on file, and the call is logged with a name and a time. Tell your suppliers you do this, so the call is expected. (CIS 14 Security Awareness and Skills Training)
  6. Build the evidence folder for this policy year, named for the policy period, with the account export, the endpoint console screenshot, the restore log, the payment rule, the training attendance sheet and last year's application. Next December you update a folder instead of guessing. (CIS 11 Data Recovery)

Where AccuSights fits

Our assessment answers the renewal form as a by-product. We check the same controls a carrier asks about, produce the evidence in a form an underwriter accepts, and give you a ranked plan for the answers you cannot truthfully give yet. Start with the 3-minute Cyber Hygiene Test to see where you stand before the application arrives.

our assessment maps you against the regulators that apply to your business, and the read-only compliance agent keeps that picture current with continuous insight across your cloud and infrastructure. We have no access and we do not remediate. You or your IT partner fix, we show you where.

Questions people ask

What does an insurer mean by MFA on everything? Every way into your systems from outside, and every account, including the ones people forget. Email for all staff, remote access and VPN, the remote management tools your IT provider uses, cloud administrator accounts, and shared or service mailboxes. The application question is short; the underwriter's follow-up is not, because skipped accounts are exactly what attackers look for. Answer with a list of what is covered and what is not, rather than a single yes.

Is antivirus enough, or do insurers require EDR? Most carriers now distinguish between the two, and the distinction matters more for the claim than for the quote. Antivirus matches known bad files. Endpoint detection and response records behaviour, raises alerts and lets someone isolate a machine from a console. If your form says EDR, be ready to name the product, say who receives the alerts and say who looked at them last weekend, because that third answer is the one that decides whether the tool did anything.

How do I prove our backups actually work? Restore something and write it down. A dated log with what you restored, from which copy, how long it took and who did it is worth more to an underwriter than any product name, and it is the same record that tells you whether you could survive a ransomware event. Include the fact that one copy is out of reach of the account that runs your daily systems, because that is the question behind the question.

The form is not the exam. The attacker is. Fill the form in with what is true, and you will have spent the week fixing the things that would have cost you the claim anyway.

Questions people ask

What does an insurer mean by MFA on everything?

Every way into your systems from outside, and every account, including the ones people forget. Email for all staff, remote access and VPN, the remote management tools your IT provider uses, cloud administrator accounts, and shared or service mailboxes. The application question is short; the underwriter's follow-up is not, because skipped accounts are exactly what attackers look for. Answer with a list of what is covered and what is not, rather than a single yes.

Is antivirus enough, or do insurers require EDR?

Most carriers now distinguish between the two, and the distinction matters more for the claim than for the quote. Antivirus matches known bad files. Endpoint detection and response records behaviour, raises alerts and lets someone isolate a machine from a console. If your form says EDR, be ready to name the product, say who receives the alerts and say who looked at them last weekend, because that third answer is the one that decides whether the tool did anything.

How do I prove our backups actually work?

Restore something and write it down. A dated log with what you restored, from which copy, how long it took and who did it is worth more to an underwriter than any product name, and it is the same record that tells you whether you could survive a ransomware event. Include the fact that one copy is out of reach of the account that runs your daily systems, because that is the question behind the question.

Controls this post maps to

CIS 6 Access Control ManagementCIS 10 Malware DefensesCIS 11 Data Recovery

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with your Risk Assessor draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.