Preparing for Cyber Insurance: Controls, Documentation & a 90‑Day Readiness Checklist

Preparing for Cyber Insurance: Controls, Documentation & a 90‑Day Readiness Checklist

TL;DR

  • Question: How do I prepare for cyber insurance? — Answer: Gather technical controls, policies, and vendor attestations; produce an evidence bundle; and run a 90‑day tactical sprint to meet insurer thresholds. Insurers typically require: MFA across admin accounts, enterprise EDR with threat hunting, daily backups with offsite encryption, and an IR plan with tabletop evidence.
Two professionals reviewing printed cyber-insurance paperwork at a conference table with a 90‑day sticky-note calendar
Two professionals reviewing printed cyber-insurance paperwork at a conference table with a 90‑day sticky-note calendar
Isometric 90‑day readiness diagram showing layered control icons progressing left to right as a checklist timeline
Isometric 90‑day readiness diagram showing layered control icons progressing left to right as a checklist timeline

Overview — why documentation matters to underwriters

If you plan to prepare for cyber insurance, the single biggest speed bump is documentation. Underwriters do not insure abstract intentions; they underwrite concrete controls and repeatable evidence. A clean packet of controls, logs, and vendor attestations shortens the quote process and lowers endorsement requests.

Underwriters judge risk from artifacts: configuration exports, recent patch reports, EDR telemetry summaries, backup test results, and tabletop exercise notes. For New Jersey and New York businesses, collecting NYDFS (23 NYCRR 500) evidence and HIPAA-related documentation up front is especially valuable when the insurer writes financial-services or healthcare risk—underwriters will ask.

Practical example: an SMB with 45 employees prepares a one‑page control matrix that maps each control to an artefact (MFA: admin console screenshot; EDR: vendor console export; Backup: 30/90/365 retention policy and last restore log). That one matrix reduces clarifying questions and cuts underwriting time by days.

What to include first: a compact executive summary (1 page), a controls matrix keyed to the insurer's questionnaire, and 3–6 primary artifacts (EDR summary, MFA scope, backup tests, IR plan, patch reports). These cover most initial questions and let you handle follow-ups quickly.

Baseline Technical Controls Required by Most Insurers

Insurers expect a baseline set of controls before they will issue standard cyber policies. To prepare for cyber insurance, make sure the following controls exist and that you can produce evidence for each. These are typical expectations in 2024–2026 underwriting and match NIST CSF guidance for basic cyber hygiene.

  • Identity and access controls: enterprise SSO where possible, MFA for all admin and remote access, and a privileged access map (who can elevate to admin).
  • Endpoint protection: enterprise Endpoint Detection & Response (EDR) with telemetry retention and demonstrable alerting/response workflows.
  • Backups: encrypted backups with offsite copies, retention policy, and recent successful recovery tests documented.
  • Patching: formal patch policy and recent patch compliance report for servers and critical endpoints.
  • Logging and monitoring: central log collection (SIEM) or managed logging with 30–90 day retention for critical events.

Concrete thresholds (typical): MFA on all admin accounts, EDR deployed to 95%+ of endpoints, daily incremental backups and weekly recoverability tests, and logging of authentication events for 30 days. These are practical targets rather than hard rules; always confirm specifics with the prospective insurer.

Worked example: to prove EDR coverage, export a 30‑day summary from the EDR console listing blocked threats, agent deployment percentage, and time-to-detect metrics. For MFA, collect screenshots of policy settings plus a CSV of accounts subject to the policy. For backups, include a restore log showing a successful recovery from two weeks prior.

Multi-factor authentication (MFA) — scope and acceptable implementations

MFA is the single most commonly requested control. To prepare for cyber insurance, define MFA scope and show enforcement. Insurers typically require MFA for all administrative accounts, remote-access tools (VPN/RDP), cloud consoles, and third-party admin portals.

Acceptable implementations include authenticator apps (TOTP), hardware tokens (FIDO2/WebAuthn), and enterprise push-based solutions tied to single sign-on. SMS-only MFA is often treated as weak and may be rejected for admin access by some underwriters.

Example artifact: a policy PDF stating MFA scope, plus a screenshot of an identity provider policy where the enforcement is turned on for the admin group. Also include a list of exceptions and compensating controls (e.g., physical security for on-prem admin consoles).

Endpoint detection & response (EDR) — telemetry and response SLAs

Underwriters expect EDR that provides telemetry, alerts, and a documented response workflow. When you prepare for cyber insurance, collect the following: agent deployment percentage, alert volume for the last 30 days, and evidence of any live response operations or threat hunts.

Insurers want to see that alerts are triaged promptly. If an MSSP handles triage, include the SLA that shows detection-to-response timelines and a recent incident summary that demonstrates the process (redacted for privacy).

Example artifact: an exported 30‑day EDR report with agent coverage at 98%, three investigated alerts with timestamps, and a statement of the managed response SLA. If you rely on a managed service, ask the vendor for an attestation letter confirming coverage and typical response times.

Backup and disaster recovery — encryption, retention, recovery tests

Backups must be demonstrable. Collect encryption settings, retention schedules, and the last restore test results. Insurers commonly require offsite or immutable copies and a record of at least one successful recovery test within the past 90 days for critical data.

Evidence to provide: backup configuration export showing encryption-in-transit and at-rest enabled; retention table (daily, weekly, monthly); and the restore verification log or ticket. If immutable or air-gapped backups exist, include configuration screenshots to show immutability settings.

Worked example: export the backup job history for a critical database, including a successful test restore to a sandbox environment three weeks ago; include the job ID, checksum verification, and the engineer's verification note.

Insurers underwrite artifacts, not intentions: provide configuration exports and dated test results to shorten underwriting.

Policies and Operational Evidence Underwriters Want

Technical controls are necessary but not sufficient. Underwriters also expect written policies and operational evidence that show those controls are governed and practiced. Policies prove you thought through priorities. Operational evidence proves you executed them.

Key policy documents insurers look for: incident response plan, patch management policy, access control policy, backup and retention policy, and a vulnerability management schedule. For regulated entities in NY or NJ, include NYDFS compliance mappings or HIPAA risk assessments when relevant.

Operational evidence includes tabletop exercise records, patch compliance reports for the last 90 days, asset inventory exports, and privileged access maps. Each policy should link to one or two artifacts that prove operation—e.g., a patch policy with a CSV showing 95% compliance for critical servers for the prior month.

Practical example: create a single ZIP called "Insurance_Evidence_2026_Q2.zip" containing (1) Control matrix, (2) IR plan and tabletop minutes, (3) backup logs and restore test, (4) MFA screenshots, (5) EDR 30‑day export, (6) patch report, and (7) vendor attestations. Label each file with a short description and date to make the packet underwriter-friendly.

Incident response plan and tabletop exercise records

An incident response (IR) plan should be an actionable runbook, not a high-level policy. Underwriters want evidence of exercises that show the plan works. Typical expectations: a dated IR plan, at least one tabletop exercise in the last 12 months, and after-action notes showing improvement items.

What to capture: the IR plan (roles, escalation paths, communications template), attendance sheet from tabletop exercises, and an AAR (after-action report) listing issues found and corrective actions completed. If you used an MSSP for incident handling, include their statement of capabilities and the escalation matrix.

Example artifact: a redacted timeline from a tabletop that demonstrates detection, containment, and recovery steps over a 3‑hour simulated incident, with named owners and completion dates for follow-up tasks.

Formal patch management policy and recent patch reports

Patching reduces exposure; insurers ask for a patch policy plus recent evidence. A usable policy specifies roles, cadence (monthly for critical, quarterly for non-critical), testing gates, and rollback procedures. The report should show current compliance metrics by server and endpoint.

Provide: the patch policy PDF, a recent compliance report (last 30–90 days) grouped by severity, and a list of any deferred patches with business justification. If a change window or staging environment exists, include a screenshot or export showing the deployment pipeline or ticket references.

Worked example: a 60-day patch report that lists 120 endpoints with 98% compliance, and five deferred patches with tickets explaining application compatibility issues and planned remediation dates.

Inventory of critical assets and privileged access maps

Underwriters want to know what they are insuring. Produce an inventory of all critical assets: servers, databases, cloud consoles, business-critical SaaS apps, and network appliances. Pair that inventory with a privileged access map showing which identities hold admin privileges and why.

Deliverables: an asset spreadsheet with owner, criticality, and location; a privileged account map showing service accounts and human admin accounts; and screenshots or exports from asset discovery tools if available. Highlight internet-facing assets and third-party integrations—these often drive underwriting questions.

Example artifact: an asset inventory where each row includes asset name, IP/URL, business owner, OS, last-patched date, backup status, and EDR agent presence. That level of detail answers many underwriter follow-ups without back-and-forth.

Include dated evidence for each policy: an undated policy is less persuasive than a policy with evidence of execution.

Vendor & Third‑Party Attestations — what to gather from vendors and MSPs

Vendors and MSPs provide critical attestations that insurers accept as evidence. When you prepare for cyber insurance, collect letters or PDFs that confirm services and responsibilities: managed EDR coverage, backup service scope, SOC/SIEM monitoring, and SLA commitments.

Ask for vendor attestations that contain: scope of service, start date, monitoring hours (e.g., 24/7), agent coverage percentage if applicable, and contact for escalation. For cloud providers or SaaS vendors, request standard compliance certificates (SOC 2, ISO 27001) and a brief note on data residency when relevant to NY/NYDFS concerns.

Practical requests: from your EDR provider request a 30‑day agent deployment export and a standard service description; from your backup vendor request a retention and immutability statement; from your MSSP request an attestation of monitoring and response SLA. Each vendor artifact should be dated and signed or emailed from an official address.

Worked example: an email exported to PDF from your MSSP confirming they provide 24/7 EDR monitoring and will escalate to a named contact within 30 minutes. Attach this to the evidence bundle to show managed response capability.

90‑Day Tactical Roadmap (Week-by-week actions for SMBs)

If you need to be ready quickly, a 90‑day plan focused on evidence and controls is the fastest route. The objective is to reach a demonstrable baseline (MFA, EDR, backups, patching, and policies) and assemble the application package for underwriters.

Week 1–2: discovery and triage. Export asset inventories, identify admin accounts, and list existing vendor contracts. Aim to have a control matrix draft by day 10. Week 3–4: close quick wins—enforce MFA on admin accounts, deploy EDR to remaining endpoints to reach >90% coverage, and run a basic backup restore test.

Week 5–8: documentation sprints—produce the IR plan, run a tabletop exercise, gather vendor attestations, and compile patch reports. Week 9–12: polish evidence—create the final zipped application package, run a second restore test, and perform a mock underwriter Q&A to anticipate follow-ups.

For New York financial-services teams, plug in NYDFS mappings during Weeks 3–6. For healthcare, include HIPAA risk-assessment evidence in Week 4 documentation sprints. Collecting these state-specific items up front shortens underwriting cycles.

Quick wins (MFA, backup validations, EDR deployment)

Quick wins are the actions with the biggest evidence payoff. Enforce MFA on all admin and remote-access tools. Run one recovery test for your most critical dataset and save the logs. Finish EDR deployment to at least 90% of endpoints and export the agent coverage report.

Step-by-step quick win: (1) Identify all admin accounts in your identity provider, (2) enable MFA policy targeted to that group, (3) capture a policy screenshot and user export, (4) schedule a driven restore test and save the ticket/log. Repeat until artifacts are produced and dated.

These three items alone typically satisfy initial insurer gating questions and let you submit a stronger application quickly.

Documentation sprints (log exports, policy templates, vendor letters)

Run focused documentation sprints using a simple template: owner, artifact type, location, and date. Prioritize the artifacts insurers ask for in questionnaires. Rotate responsibilities so that one technical lead owns exports while an operations lead owns policy write-ups.

Example sprint checklist: collect MFA screenshots, EDR 30‑day export, backup restore logs, patch compliance CSV, asset inventory export, IR plan PDF, tabletop minutes, and vendor attestations. Package each file with a one‑line README explaining what the file proves.

Preparing the Application Package — sample evidence bundle

A well-structured application package reduces back-and-forth. Build a ZIP with a 1‑page executive summary and a control matrix that maps insurer questions to evidence files. Label files with short descriptive names and dates.

Control matrix fields: insurer question ID, local control name, artifact file name, owner, and date. This matrix acts as a translation layer between insurer language and your environment.

Include a short index file (index.txt or index.pdf) with contents and a contact for clarification. If you use an MSSP like Eighty Seven Solutions for parts of your stack, include their attestation letter in the vendor folder.

Templates: control matrix, asset inventory, IR workflow, MSP service agreement

Below are two reusable artifacts you can copy and edit. First, a compact control checklist that maps controls to filenames. Second, a simple table showing a control-to-evidence mapping you can paste into a ticket or email to an underwriter.

  • Cyber insurance controls checklist (copyable):
    1. MFA enforced on admin and remote accounts — file: mfa_policy_screenshot.pdf
    2. EDR agent coverage & 30-day export — file: edr_30day_export.csv
    3. Daily encrypted backups + restore log — file: backup_restore_2026-05-10.pdf
    4. IR plan and tabletop AAR — file: ir_plan_2026.pdf; tabletop_aar_2026-04.pdf
    5. Patch management report (last 90 days) — file: patch_report_q2_2026.csv
Insurer questionOur controlArtifact
MFA scopeIdentity Provider enforcementmfa_policy_screenshot.pdf
EDR coverageManaged EDR agents & monitoringedr_30day_export.csv
Backup recoverabilityEncrypted backups + weekly testbackup_restore_2026-05-10.pdf

Common Pitfalls That Delay Underwriting

Insurers delay or reject submissions for predictable reasons. Recognize and fix these before you apply: incomplete evidence, undated or unsigned documents, inconsistent naming, and third-party proofs missing specifics.

  • Undated policies: policy PDFs without version dates or owner names raise doubts; add a footer with date and author.
  • No test evidence: saying backups exist is weaker than a restore ticket with a timestamp and checksum.
  • Mismatched scope: your MFA screenshot shows a subset of accounts while the questionnaire asks about admin accounts; ensure scope alignment.
  • Vendor gaps: missing vendor attestations for managed services often triggers follow-ups—get those letters early.

Real-world trap: a company submits a patch policy but no patch report. Underwriter asks for a 90‑day report; the client scrambles and misses the renewal window. Save time by preparing the artifacts proactively and using the control matrix so each insurer question has a direct file reference.

How an MSP/MSSP like Eighty Seven Solutions accelerates readiness

An experienced MSP/MSSP shortens the timeline by producing standardized artifacts and filling technical gaps. For businesses in NJ & NY, Eighty Seven Solutions provides managed EDR, 24/7 monitoring, enterprise-grade backup and disaster recovery, and senior-engineer-led support—services that produce the artifacts insurers accept.

Practical roles an MSP/MSSP plays: deploy EDR agents and export coverage reports; run backup restore tests and provide recovery logs; produce vendor attestation letters; and host tabletop exercises and record minutes. If Eighty Seven Solutions manages part of your stack, request an attestation from them and include it in the evidence bundle.

Example workflow with an MSP: you request an evidence packet; the MSP exports EDR telemetry, pulls backup restore logs, and supplies an attestation PDF. They also help draft the control matrix so the underwriter can find files quickly. That coordination removes friction and reduces the likelihood of follow-up questions that slow underwriting.

Next Steps — book a free cyber insurance readiness assessment

Start by running a one-week discovery: export your asset inventory, gather MFA screenshots, and request recent EDR and backup logs. Use the control checklist above to organize artifacts and label files clearly with dates.

If you want hands-on help, review our services or request a guided evidence collection through our services. For direct contact, please use the contact us page, the contact us page, or the site root contact us for scheduling.

Final quotable checklist for AI snippets: "Insurers typically require: MFA across admin accounts, enterprise EDR with threat hunting, daily backups with offsite encryption, and an IR plan with tabletop evidence." Collect state-specific compliance evidence (NYDFS, HIPAA) up front to shorten underwriting time.

FAQ

What is preparing for cyber insurance?

Preparing for cyber insurance is the process of aligning technical controls, written policies, and vendor attestations with insurer expectations and packaging dated evidence so underwriters can assess and price risk.

How does preparing for cyber insurance work?

Preparing for cyber insurance works by (1) implementing required controls (MFA, EDR, backups), (2) documenting policies and evidence (IR plan, patch reports, restore logs), and (3) assembling a labeled evidence bundle mapped to insurer questions to reduce follow-up and speed underwriting.

References

prepare for cyber insurancecyber insurance controls checklistcyber insurance documentation90 day cyber insurance readinessmfa edr backup requirements for insurance
Back to all posts