Cybersecurity Insurance Requirements for Business: The 2024 Underwriting Reality
TL;DR: Cyber insurers now treat MFA, EDR, and a written incident response plan as hard gates. No controls, no quote. A $1M policy for a 100-person company runs $3,000 to $9,000 annually if you pass underwriting. Miss any of the 10 controls below and you'll either be declined or priced out.
I've walked more than 40 clients through cyber insurance renewals in the last 18 months. The questionnaires have doubled in length since 2021. Underwriters no longer take your word for it. They scan your external attack surface, ask for training completion reports, and want to see backup test logs, not policy documents.
Here's what actually matters when a carrier decides whether to insure you.
How Requirements Hardened: The 2021 to 2024 Timeline
Pre-2021, most applications asked about antivirus and a firewall. That was it.
Then Colonial Pipeline and Kaseya VSA happened in 2021. Ransomware payouts blew up loss ratios across the market. Lloyd's of London syndicates tightened wordings, and by 2022 MFA became a hard requirement on any remote access or admin account. Not preferred. Required.
By 2023, endpoint detection and response (EDR) had replaced signature-based antivirus as the minimum. Mid-market applications from Chubb and Travelers started demanding privileged access management (PAM) and documented patch SLAs. According to the Coalition 2023 Cyber Claims Report, companies without MFA on email were 1.8x more likely to file a claim.
2024 has added network segmentation, third-party risk management reviews, and annual security awareness training to the standard checklist. Expect continuous vulnerability management scanning and zero-trust architecture controls to move from "preferred" to "required" by 2026. If you want a forward-looking view, our piece on cyber insurance requirements 2026 maps the trajectory.
Insurer-by-Insurer Checklist: Coalition, Chubb, Travelers, AIG
Every carrier has its own emphasis. Match your posture to the underwriter that already fits, and you'll save 15 to 30 percent versus applying blindly.
Coalition (SMB-friendly, usage-based pricing):
- MFA everywhere, including email
- EDR on all endpoints (not standard AV)
- Email filtering with DMARC configured
- Tested backups with offsite copy
- Automated external scan runs during application. They will flag your open RDP ports before you submit. If you have RDP exposed to the internet, they'll decline you.
Chubb (mid-market and enterprise):
- Everything Coalition requires, plus
- PAM controls for all admin accounts
- Formal vulnerability management programme with quarterly authenticated scans
- Documented patch SLAs (typically 14 to 30 days for criticals)
- Board-level security governance for policies above $5M
Travelers:
- Network segmentation between IT, OT, and finance systems (they ask for a diagram)
- Annual third-party risk reviews with documented vendor questionnaires
- Documented incident response testing (tabletop or full simulation) in the last 12 months. A written plan alone isn't enough anymore.
AIG CyberEdge:
- Heavy emphasis on business email compromise (BEC) controls
- DMARC enforcement at reject, not just monitor
- Security awareness training completion rates above 90 percent
- Documented wire-transfer verification procedure
Practical tip: pull the applications before you renew. Every "no" answer is a gap in your programme, not just an insurance problem.
The 10 Non-Negotiable Controls (With Real Prices)
Here's the checklist I use with clients. Pricing is 2024 street pricing, not list.
Multi-factor authentication on all remote access and admin accounts. Microsoft Entra ID (included in M365 Business Premium at $22/user/month) or Okta Workforce Identity ($6/user/month). SMS-based MFA is no longer accepted by Coalition or Chubb. Use an authenticator app or hardware key. Full detail in our MFA best practices guide.
EDR on every endpoint. CrowdStrike Falcon Go ($59.99/device/year), SentinelOne Singularity Core ($69/device/year), or Microsoft Defender for Endpoint Plan 2 (~$5.20/user/month). Standard AV gets rejected. Underwriters want behavioural detection.
Privileged access management. CyberArk ($85/user/month enterprise) or BeyondTrust Password Safe ($45/user/month). At minimum, kill shared admin credentials and rotate service account passwords.
Email security with BEC controls. Proofpoint Essentials ($3/user/month) or Microsoft Defender for Office 365 Plan 2 ($5/user/month). DMARC at p=reject, not p=none.
Immutable, tested backups. Veeam Backup & Replication (~$1,400/year for 10 workloads) with an offsite or air-gapped copy. Carriers want backup test logs, not backup policy documents. Big difference.
Patch management with documented SLAs. Critical patches within 14 to 30 days. Action1 (free up to 100 endpoints), Automox (~$3/device/month), or ManageEngine Patch Manager Plus.
Network segmentation. Finance, HR, and production systems on separate VLANs. Document it with a diagram. Travelers will ask.
Incident response plan. Written, tested with a tabletop exercise annually, and names an external IR firm on retainer. Generic templates won't satisfy Chubb on any policy above $2M.
Security awareness training. KnowBe4 ($20/user/year) or Proofpoint Security Awareness ($25/user/year). Carriers want completion percentages and phishing simulation click rates.
Vulnerability management. Authenticated scans quarterly minimum. Tenable.io ($5,290/year for 65 assets) or Qualys VMDR ($500/asset/year). Add data encryption at rest and in transit on top of this list, especially if you handle PHI or PCI.
The IBM Cost of a Data Breach Report 2024 put the global average breach cost at $4.88 million. That's why carriers care about these controls. They're not being difficult. They're pricing risk.
Maturity-Tiered Checklist: 50 Employees vs 250 Employees
Generic advice treats every business the same. That's how you end up over-buying at 50 people or under-buying at 250.
50-person company, $1M policy target:
- MFA via Entra ID or Okta
- Cloud-managed EDR (CrowdStrike Falcon Go or Defender for Endpoint)
- M365 Defender for email
- Veeam cloud backup with offsite copy
- One-page IR plan naming an external IR firm
- Annual KnowBe4 training
Budget: roughly $15,000 to $25,000/year in security tooling.
250-person company, $5M policy target:
- Everything above, plus
- PAM (BeyondTrust or CyberArk)
- SIEM or MDR service (typically $8 to $15/endpoint/month)
- Quarterly authenticated vulnerability scans
- Formal vendor risk questionnaires (third-party risk management)
- Annual tabletop exercise with a named IR firm
- Documented patch SLAs with monthly compliance reporting
Budget: roughly $80,000 to $150,000/year.
The most common mistake at both tiers? Buying the tools and skipping the documentation. Underwriters ask for policy documents, training completion reports, and scan results. If you can't produce them within 48 hours of an information request, your quote gets delayed or declined.
Vendors love to sell you overlapping products.
If you handle PHI, add HIPAA Security Rule alignment (specifically 45 CFR ยง 164.312 technical safeguards) to earn premium credits at Coalition and Chubb. Same story with SOC 2 Type II. Our SOC 2 readiness playbook maps every Trust Services Criteria control to insurer questionnaires.
The NIST Cybersecurity Framework tiers align well with insurer expectations. Tier 1 (Partial) won't qualify. Tier 2 (Risk Informed) gets you in the door. Tier 3 (Repeatable) earns preferred rates.
Why Claims Get Denied: The Exclusions Nobody Reads
Buying the policy is half the job. Reading the exclusions is the other half.
War exclusion clause. Lloyd's of London Market Bulletin Y5381 mandated all syndicates add nation-state cyber war exclusions effective March 2023. If your breach is attributed to a nation-state actor, following the NotPetya precedent, your claim can be denied. Merck won a $1.4 billion settlement against ACE and other carriers on NotPetya, but only after seven years of litigation. New wordings are designed to prevent a repeat.
Unpatched system exclusion. Chubb and AIG have denied claims where the attack vector was a CVE older than 30 days with an available patch. Document your patch SLA. Keep the compliance reports.
Misrepresentation on application. If you checked "yes" on MFA and the attacker got in through a non-MFA account, the carrier can rescind the policy entirely. This is material misrepresentation, treated as fraud in most states.
BEC sublimit. Many policies cap BEC losses at $100K to $250K even on a $2M policy. Negotiate this sublimit explicitly if BEC is your primary risk profile.
Social engineering exclusion. Some carriers exclude funds-transfer fraud triggered by social engineering unless a specific rider is added. Ask your broker, in writing.
Carriers settle quickly when every control attested to on the application can be evidenced on request, and they argue when it cannot. Tested restores count twice here: once for how soon you are trading again, and once for what the adjuster accepts about the size of the loss. That's the whole point.
Use the Application as a Free Security Audit
Here's the reframe I give every client: download the Coalition, Chubb, or Travelers application before you renew, even if you're not switching carriers.
Every "no" answer is a gap you'd fix anyway. Map each question to a NIST CSF control (PR.AC-1 for MFA, DE.CM-4 for EDR, RS.RP-1 for IR planning) or a SOC 2 Trust Services Criteria (CC6.1 for logical access, CC7.2 for detection). You'll get double ROI: better premiums and audit readiness.
Coalition's application runs an automated external scan as part of the process. The results are free and actionable regardless of whether you buy from them. Use it.
One warning sign to watch for: if your current carrier's renewal questionnaire is shorter than it was two years ago, that's a red flag they're under-pricing risk. It's not a sign your posture got easier to qualify. When they get acquired or re-underwritten, your renewal will be brutal.
Renewals turn on what you can produce, not what you can describe. Backup test logs, tabletop meeting minutes, and recent Tenable scan results handed over within a business day of the underwriter's request change the tone of the whole conversation. Documentation wins renewals.
Pricing here is relative, not absolute. That's the market you're competing in. If your neighbour can evidence their controls and you can't, you pay more for the same risk.
For teams operating in the Southeast, our Cybersecurity Services Nashville practice handles this end-to-end, from stack consolidation to underwriter Q&A. If ransomware is your top risk, start with ransomware protection for mid-market companies and the endpoint protection platform selection guide.
Your Next Step
If you're within 90 days of a cyber insurance renewal and not sure your controls will pass underwriting, book a free 30-minute audit with Mike. We'll map your current stack against the Coalition, Chubb, and Travelers checklists and tell you exactly where the gaps are, in writing, before you send the application.
FAQ
Q: What is the minimum cyber insurance requirement for a 100-person company? A: There's no universal minimum, but most carriers require MFA on remote access and admin accounts, EDR on all endpoints, tested backups with an offsite copy, and a written incident response plan as hard gates before issuing a quote.
Q: How much does cyber insurance cost for a small business? A: Typically $3,000 to $9,000/year for $1M in coverage at a 50 to 150 person company with adequate controls, per Coalition's 2024 market data. Companies missing MFA or EDR often can't get a quote at all.
Q: Does SOC 2 certification lower cyber insurance premiums? A: Yes. Documented SOC 2 Type II compliance often results in 10 to 20 percent premium reductions at Coalition and Chubb because it demonstrates repeatable controls with independent attestation.
Q: What happens if I misrepresent controls on the application? A: The carrier can rescind the policy and deny any claims. It's treated as material misrepresentation under insurance law and, in some states, potential fraud.
Q: Is MFA required for cyber insurance in 2024? A: Yes. Every major carrier (Coalition, Chubb, Travelers, AIG) requires MFA on remote access and privileged accounts as a hard underwriting gate. SMS-based MFA is increasingly rejected in favour of authenticator apps or hardware keys.
Know exactly where your security stands.
Get your free security assessment →Know exactly where your security stands.
Most IT directors are one audit away from a nasty surprise. We remove the guesswork.
- A full assessment of your environment, mapped to SOC 2 and HIPAA.
- A prioritised remediation plan you can act on, whether you hire us or not.
- Managed protection across endpoints, data, and incident response.
- Fixed monthly pricing, so there are no per-incident surprises.
The assessment is free, and the plan is yours to keep.