Cyber insurance used to be a questionnaire you filled out honestly and mostly on the honor system. That’s over. Carriers now run external attack surface scans during underwriting, and roughly three out of four do it before ever approving a policy — checking for exposed services, missing MFA, and other gaps directly instead of just trusting what’s written on the form.
The Five Controls Nearly Every Carrier Requires
Across major carriers, five controls show up on almost every application: enforced multi-factor authentication across email, remote access, and privileged accounts; endpoint detection and response (EDR) or managed detection and response (MDR) on every endpoint; immutable backups with regularly tested restores; a written incident response plan that’s been through a recent tabletop exercise; and a documented patch management program. Missing any one of these is now a commonly cited reason for denial or non-renewal — not a minor deduction, an actual disqualifier.
Why Antivirus Alone No Longer Qualifies
Traditional signature-based antivirus doesn’t satisfy the endpoint protection requirement with most carriers anymore. Insurers specifically want real-time threat detection and automated response — what EDR and MDR provide, and legacy antivirus doesn’t. If your current endpoint protection hasn’t been evaluated against this standard recently, that’s worth confirming before your next renewal, not during a claim dispute when it’s too late to fix.
What an Immutable Backup Actually Means
An immutable backup can’t be altered, encrypted, or deleted once written, even by someone with administrative access, for a defined retention period. Insurers require this specifically because ransomware increasingly targets backup systems first, on the theory that a business with no clean recovery option is far more likely to pay. A backup ransomware can encrypt right alongside your production data isn’t a real safety net — it’s a false sense of one.
What This Actually Costs
Cyber insurance premiums vary significantly by industry, revenue, and existing controls, generally running $1,000 to $7,500 annually. Professional services firms with strong controls in place tend to land on the lower end, around $1,500-$3,000. Healthcare practices often pay $3,000-$7,500 given HIPAA-related risk, and retailers handling card payments often pay $2,000-$5,000 tied to PCI-DSS exposure. Documented, verifiable controls can swing premiums 20-40% in either direction at renewal — this is real money, not a rounding error.
The Part Most Businesses Miss: Misrepresentation Risk
Missing controls don’t just risk a higher premium or a denial at application — they can void an existing policy after the fact. Insurers have explicitly cited missing MFA and missing EDR as grounds to decline renewal or void coverage entirely if an application misrepresented controls that weren’t genuinely in place. This is one of the most common reasons real claims get denied: not the incident itself, but the gap between what was claimed on the application and what was actually running.
How CelereTech Helps
CelereTech implements and documents the five baseline controls carriers now expect — MFA, EDR/MDR, immutable tested backups, a written and tabletop-tested incident response plan, and documented patch management — and provides the documentation you need to complete applications accurately. Going into a renewal with verifiable, real controls in place is the single biggest lever you have over your premium.
Get your controls assessed before your next renewal — we’ll tell you exactly where the gaps are.