A cyber insurance application isn't paperwork, a formality, or something your broker fills in for you. It's an attestation, not a form - a set of statements about your security controls that you are affirming to be true, and that the carrier is pricing and underwriting on.

Cyber insurance readiness is the state of having the controls a carrier asks about actually in place and provable before the application arrives. Not planned. Not budgeted. Running, and documented.

The gap between those two things is where the expensive surprises live, and the deadline is not negotiable. Renewals arrive on a date. Controls take weeks or months.

What do carriers actually ask about?

I went through what four carriers publish themselves - not broker summaries, the carriers' own forms and requirements pages. The overlap is substantial and the pattern is clear.

Chubb publishes the most detailed of the four. Its Cyber ERM standard proposal form asks about MFA on webmail and cloud email, remote access, and cloud applications, with a separate question for privileged access. It asks about EDR and advanced anti-malware with percentage coverage of the environment. On backups it asks specifically whether they are "Immutable or Write Once Read Many (WORM)" and "Completely Offline / Air-gapped," and whether "Full restore from backup tests" have been performed, including ransomware-specific restore scenarios. It asks whether you have "a formal cyber-specific incident response plan that is tested at least annually." It asks about phishing exercises and training modules, formal patch management with day targets tiered by CVSS severity, SPF and DKIM and attachment sandboxing and macro defaults, end-of-life systems and whether they're segregated, access logs retained at least 90 days, and encryption at the database level, in transit, and of backups.

Worth flagging honestly: the detailed Cyber ERM proposal form Chubb publishes online is a UK document. Chubb's live US small-business cyber application is a much shorter form and doesn't mention MFA at all. So use the UK form to understand what a thorough carrier asks - not as proof of what Chubb requires in Florida.

At-Bay's ransomware supplemental is narrower and more technical: patch management approach and critical-patch timeframes, SIEM, identity provider and SSO, MFA deployment by location (remote access, email, critical assets, privileged accounts, contractors), privileged access management, EDR by named vendor with workstation and server coverage, end-of-life hardware and software including whether it's segmented or internet-exposed, and remote access.

Something changed there that's worth noting: the current edition of that form does not ask about backups at all. The word doesn't appear in it. Neither does incident response plan, security awareness training, or encryption. That's a meaningful shift from the earlier edition, and it means anyone citing At-Bay as the source for backup requirements is citing a document that no longer says that.

Travelers publishes five practices: implement multi-factor authentication, keep systems up to date, use endpoint detection and response, have an incident response plan, and back up your data using a 3-2-1 approach with an offline copy.

Coalition names MFA, cybersecurity training, backups that are regularly tested, identity access management, and data classification with least privilege, plus a secondary list including EDR, firewalls, incident response plans, and security risk assessments.

Strip out the differences and the common core is short: MFA, EDR, tested backups, a written and tested incident response plan, training with phishing exercises, least privilege and access reviews, a patching program with deadlines, email authentication and filtering, no unmanaged end-of-life software, vendor risk management, centralized logging, and encryption. Twelve items. That's the exam.

What happens if the answers are wrong?

This is where the real risk sits, and it's not where people expect.

Cyber insurance requirements bite at application and renewal, not at claim time. The carrier isn't checking your MFA deployment when you file a claim - it's relying on what you told it when you applied. And when an application misstates the controls, a carrier can go after the policy itself rather than the claim.

That happened in *Travelers Property Casualty Company of America v. International Control Services, Inc.*, filed in the Central District of Illinois in July 2022. Travelers alleged that ICS had answered yes to whether it required multi-factor authentication and had signed an MFA attestation affirming that MFA was required "for all remote access to the network," when in fact MFA was deployed only on the firewall and not on the server later hit with ransomware. The court entered an order on August 30, 2022 rescinding the policy and declaring it "null and void from its inception."

Here's the nuance almost every retelling drops: that order recites that "the parties having stipulated to the following facts" and that they "stipulated and agreed to the entry of an order." It was a consent rescission, not a contested ruling on the merits. No court held that an MFA misstatement legally voids coverage. Both sides agreed to unwind the policy and the court entered what they asked for.

I'd rather tell you that than repeat the cleaner version, because the cleaner version is the one that gets used to sell things. The accurate takeaway is still serious: a rescinded policy is not a denied claim. It's no coverage at all, retroactively, as if you had never bought it. And the mechanism that got there - an application answer that didn't match reality - is entirely within your control.

I also looked for a more recent example. I couldn't verify one from a court docket. If someone tells you rescissions are a growing trend, ask them for the case numbers.

Is the market getting easier or harder?

Easier on price, for the moment, which is a change.

The NAIC's 2025 Report on the Cybersecurity Insurance Market, covering data year 2024, reports total US cyber direct written premium of $9.14 billion including alien surplus lines, and $7.08 billion for US-domiciled insurers - a 7 percent decrease from 2023. Policies in force were essentially flat at 4,368,614. The report notes that "cyber insurance rates in the U.S. declined an average of 5% in the fourth quarter of 2024, marking the first quarterly decrease following seven years of rising rates," with global rates down roughly 22 percent from their mid-2022 peak.

Claims went the other way: nearly 50,000 reported, up about 40 percent year over year, with 9,941 closed with payment and 28,555 closed without.

What I'd take from that is not "coverage got cheap." It's that softer pricing sits alongside rising claim volume, which historically doesn't last. Applications don't get less rigorous when carriers are absorbing more claims.

*The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional. We are not an insurance carrier or broker. Confirm requirements with your carrier - their application is the authority on what they require.*