Cyber insurance has undergone a quiet but significant transformation since the ransomware surge of 2020-2022 drove the industry to near-crisis. Premiums increased by as much as 130% in some segments. Coverage terms narrowed. War exclusions appeared. And the application questionnaire — which was once a checkbox exercise handled by the IT team — became a detailed technical interrogation that security leaders now routinely own.
If you haven’t renewed a policy recently, the conversation with your broker and underwriter is going to be substantively different from anything you’ve experienced before.
What the Application Now Covers
The major carriers operating in the UK and EU market — and increasingly their Lloyd’s of London counterparts — now require detailed attestations on a specific set of security controls. The list has stabilised over the past eighteen months and broadly reflects the controls that would have prevented most of the large claims paid out since 2021.
Multi-factor authentication remains the non-negotiable. But the question has evolved. It’s no longer “do you have MFA?” — it’s “do you have MFA on all remote access (VPN, RDP, Citrix), all email, all privileged administrative consoles, and all cloud management interfaces?” The key addition is the requirement to attest to privileged accounts specifically. Underwriters have paid out too many claims where MFA was deployed for regular users but the domain admin credentials that ransomware operators actually targeted were protected only by passwords.
Endpoint Detection and Response (EDR) coverage across the estate. Most applications now ask for the percentage of endpoints covered, the vendor, and whether the product is in active-detection mode or merely logging. Passive logging without response capabilities doesn’t count. Isolated networks without EDR — manufacturing OT environments, healthcare clinical networks — are a known gap and underwriters will ask about them specifically.
Privileged Access Management (PAM) for administrative credentials. The question is whether privileged credentials are stored in a vault, whether sessions are recorded, and whether there is break-glass access management for emergency accounts. This has moved from a best-practice question to a requirement in the top-tier coverage tiers.
Network segmentation has become more specific. The question is whether the environment is segmented such that a compromise in one segment (user workstations, for example) cannot directly reach backup infrastructure, domain controllers, or the core financial systems. The practical test underwriters apply: would a ransomware operator who had compromised a standard user workstation have a clear path to your backups? If yes, that’s a coverage risk.
Offline or immutable backups is the other control with strong correlation to recovery cost. Applications now typically ask whether backups are stored in a location that cannot be accessed or encrypted from the production network, and whether backup restoration has been tested within the past twelve months.
The Attestation Problem
Here’s where it gets consequential. Cyber insurance applications are increasingly treated as warranty-level attestations. Several high-profile coverage disputes in 2024 and 2025 involved insurers declining claims on the grounds that the application contained material misrepresentations about security controls — specifically, that the organisation attested to having MFA or EDR deployed when in fact coverage was partial or inactive.
If you’re signing the application as CISO, you should have direct evidence for every attestation, not a good-faith belief based on what you were told. That means:
- Pull your EDR deployment report. Verify the coverage percentage yourself.
- Get the MFA configuration screenshots from your identity team for each system attested to.
- Verify backup isolation with the team that manages backups — not with the vendor’s sales slides.
The risk isn’t just a declined claim. Submitting a materially false insurance application is a contractual and potentially legal liability issue. More CISOs are personally named in these disputes than was the case five years ago.
What Underwriters Are Excluding
Exclusion language has become more precise. The areas where you should expect coverage gaps or sub-limits:
Vendor and supply chain events where the breach originated at a third party. Exclusions for “contingent business interruption” caused by a third party are common, though limits vary significantly by policy. If you’re dependent on a small number of critical SaaS or infrastructure vendors, review whether your policy covers a scenario where those vendors are breached rather than your own environment.
State-sponsored attacks (the war exclusion). Lloyd’s mandated clearer language in 2023, and most carriers have followed. Attacks attributed to nation-states — Russia, China, North Korea, Iran — may fall outside standard coverage depending on the attribution language in your policy. This is particularly relevant for critical infrastructure and financial services organisations that are frequently targeted by state actors. Some carriers offer supplemental coverage for this risk; it’s worth discussing explicitly.
Unencrypted data losses in some policies. If data subject to breach notification requirements was stored unencrypted and that fact wasn’t disclosed in the application, some carriers treat it as a misrepresentation.
Preparing for the Renewal Conversation
Start the internal preparation three to four months before renewal. The process that works:
-
Pull the prior application and note which attestations you made. Identify where the reality has changed or where the original attestation was aspirational rather than factual.
-
Commission a gap assessment against the controls underwriters are asking about. This doesn’t need to be a full audit — a one-day internal review against the MFA, EDR, PAM, segmentation, and backup questions is usually sufficient to identify where the gaps are.
-
Remediate what you can before renewal. Deploying MFA on the remaining 15% of privileged accounts before the renewal date is worth doing both for the coverage position and because it’s the right thing to do. Underwriters do notice year-over-year improvement; it affects both coverage availability and pricing.
-
Quantify the risk for your board conversation. If you’re requesting a higher coverage limit or a premium increase, the board needs context. The FAIR (Factor Analysis of Information Risk) methodology for estimating probable maximum loss and annual loss expectancy gives you a defensible basis for the number you’re asking for. Several major consultancies now offer rapid FAIR engagements specifically for insurance limit-setting.
-
Engage your broker early, before the formal submission. A good specialist cyber broker knows which carriers have appetite for your sector, risk profile, and control posture. The submission itself matters less than the relationship context in which it arrives.
The Carrier Conversation No One Has
There’s a question most organisations don’t ask their insurer that they should: “What would cause you to decline a claim in a realistic ransomware scenario?” Getting the underwriter to walk through their claims criteria explicitly — under what circumstances the war exclusion would apply, what counts as a material misrepresentation, how they handle attribution disputes — is more valuable than reading the policy language on your own.
The most important thing an insurer covers isn’t the ransom. It’s the business interruption losses, the forensics, the legal and notification costs, and the crisis PR. Those costs often exceed the ransom payment by a significant multiple. Understanding whether each of those cost categories is fully covered — and at what sublimit — is the conversation that tends to reveal the gaps in coverage that only become visible when you actually need to make a claim.