A cyber insurance application isn't paperwork, a formality, or something your broker fills in for you. It's an attestation, not a form - a set of statements about your security controls that you are affirming to be true, and that the carrier is pricing and underwriting on.
Cyber insurance readiness is the state of having the controls a carrier asks about actually in place and provable before the application arrives. Not planned. Not budgeted. Running, and documented.
The gap between those two things is where the expensive surprises live, and the deadline is not negotiable. Renewals arrive on a date. Controls take weeks or months.
I went through what four carriers publish themselves - not broker summaries, the carriers' own forms and requirements pages. The overlap is substantial and the pattern is clear.
Chubb publishes the most detailed of the four. Its Cyber ERM standard proposal form asks about MFA on webmail and cloud email, remote access, and cloud applications, with a separate question for privileged access. It asks about EDR and advanced anti-malware with percentage coverage of the environment. On backups it asks specifically whether they are "Immutable or Write Once Read Many (WORM)" and "Completely Offline / Air-gapped," and whether "Full restore from backup tests" have been performed, including ransomware-specific restore scenarios. It asks whether you have "a formal cyber-specific incident response plan that is tested at least annually." It asks about phishing exercises and training modules, formal patch management with day targets tiered by CVSS severity, SPF and DKIM and attachment sandboxing and macro defaults, end-of-life systems and whether they're segregated, access logs retained at least 90 days, and encryption at the database level, in transit, and of backups.
Worth flagging honestly: the detailed Cyber ERM proposal form Chubb publishes online is a UK document. Chubb's live US small-business cyber application is a much shorter form and doesn't mention MFA at all. So use the UK form to understand what a thorough carrier asks - not as proof of what Chubb requires in Florida.
At-Bay's ransomware supplemental is narrower and more technical: patch management approach and critical-patch timeframes, SIEM, identity provider and SSO, MFA deployment by location (remote access, email, critical assets, privileged accounts, contractors), privileged access management, EDR by named vendor with workstation and server coverage, end-of-life hardware and software including whether it's segmented or internet-exposed, and remote access.
Something changed there that's worth noting: the current edition of that form does not ask about backups at all. The word doesn't appear in it. Neither does incident response plan, security awareness training, or encryption. That's a meaningful shift from the earlier edition, and it means anyone citing At-Bay as the source for backup requirements is citing a document that no longer says that.
Travelers publishes five practices: implement multi-factor authentication, keep systems up to date, use endpoint detection and response, have an incident response plan, and back up your data using a 3-2-1 approach with an offline copy.
Coalition names MFA, cybersecurity training, backups that are regularly tested, identity access management, and data classification with least privilege, plus a secondary list including EDR, firewalls, incident response plans, and security risk assessments.
Strip out the differences and the common core is short: MFA, EDR, tested backups, a written and tested incident response plan, training with phishing exercises, least privilege and access reviews, a patching program with deadlines, email authentication and filtering, no unmanaged end-of-life software, vendor risk management, centralized logging, and encryption. Twelve items. That's the exam.
This is where the real risk sits, and it's not where people expect.
Cyber insurance requirements bite at application and renewal, not at claim time. The carrier isn't checking your MFA deployment when you file a claim - it's relying on what you told it when you applied. And when an application misstates the controls, a carrier can go after the policy itself rather than the claim.
That happened in *Travelers Property Casualty Company of America v. International Control Services, Inc.*, filed in the Central District of Illinois in July 2022. Travelers alleged that ICS had answered yes to whether it required multi-factor authentication and had signed an MFA attestation affirming that MFA was required "for all remote access to the network," when in fact MFA was deployed only on the firewall and not on the server later hit with ransomware. The court entered an order on August 30, 2022 rescinding the policy and declaring it "null and void from its inception."
Here's the nuance almost every retelling drops: that order recites that "the parties having stipulated to the following facts" and that they "stipulated and agreed to the entry of an order." It was a consent rescission, not a contested ruling on the merits. No court held that an MFA misstatement legally voids coverage. Both sides agreed to unwind the policy and the court entered what they asked for.
I'd rather tell you that than repeat the cleaner version, because the cleaner version is the one that gets used to sell things. The accurate takeaway is still serious: a rescinded policy is not a denied claim. It's no coverage at all, retroactively, as if you had never bought it. And the mechanism that got there - an application answer that didn't match reality - is entirely within your control.
I also looked for a more recent example. I couldn't verify one from a court docket. If someone tells you rescissions are a growing trend, ask them for the case numbers.
Easier on price, for the moment, which is a change.
The NAIC's 2025 Report on the Cybersecurity Insurance Market, covering data year 2024, reports total US cyber direct written premium of $9.14 billion including alien surplus lines, and $7.08 billion for US-domiciled insurers - a 7 percent decrease from 2023. Policies in force were essentially flat at 4,368,614. The report notes that "cyber insurance rates in the U.S. declined an average of 5% in the fourth quarter of 2024, marking the first quarterly decrease following seven years of rising rates," with global rates down roughly 22 percent from their mid-2022 peak.
Claims went the other way: nearly 50,000 reported, up about 40 percent year over year, with 9,941 closed with payment and 28,555 closed without.
What I'd take from that is not "coverage got cheap." It's that softer pricing sits alongside rising claim volume, which historically doesn't last. Applications don't get less rigorous when carriers are absorbing more claims.
*The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional. We are not an insurance carrier or broker. Confirm requirements with your carrier - their application is the authority on what they require.*
If you're a small or midsize business, the application is probably the most thorough security assessment anyone will ever perform on you, and you'll encounter it under a deadline.
That's the structural problem. The form arrives four to six weeks before renewal. It asks twelve or twenty or forty questions about controls that take three months to implement. And the person filling it out is usually an owner or office manager who doesn't independently know whether MFA covers every remote access path, or whether anyone has ever restored a backup.
What happens next is predictable and it's the actual risk. Not fraud - nobody sets out to lie on an insurance form. What happens is optimistic answering. "Do you require MFA for remote access?" Well, we have MFA. "Are backups tested?" They run every night and we've never had a problem. Both answers feel true. Neither is what the question asked.
So the move is to see the questions early, on a day when nothing is due. Our Cyber Insurance Readiness Checklist is the twelve-item common core, each item with what carriers want to see, cited to the carrier document it came from. Free, five minutes, no email required to see results.
Two limits I'll state plainly. Checking every box does not get you approved and does not lower your premium - carriers set their own underwriting and pricing, and we don't control either. And every carrier's form is different, with ransomware supplementals going deeper than the base application. This is the common core, not your carrier's actual application. We are not a carrier or a broker.
What the checklist reliably does is remove surprises. And for each unchecked item, it points at where the work happens - our Cyber Risk Management, GRC, and Third-Party Assessments pages.
One last thing, because it's the question I'd ask in your position: when should you start? Before either the application or the renewal. Your renewal date is already on the calendar, so work backward from it. Starting after the form arrives means attesting to intentions instead of controls, and that's the one thing not to do.
Disclaimer. This article is provided for general information only. It is not legal, regulatory, or professional advice, and reading it does not create a client relationship with WOM Technology Management Group. Regulations, threats, and vendor products change; specific obligations depend on your industry, jurisdiction, contracts, and data. Verify anything you plan to rely on against the primary source and consult qualified counsel or a security professional before acting.
Sources are cited as of the last-reviewed date shown above. Where a linked source has moved or been withdrawn, the citation reflects what was verifiable at review time.