Article

What cyber insurers now expect from your IT controls

Cyber insurers increasingly want evidence that the basics are in place before they offer or renew coverage: multi-factor authentication, endpoint detection, tested backups, patching and an incident response plan. The questionnaire is not paperwork to rush through; the answers you give can matter when you make a claim.

The short answer

Every insurer and policy is different, but cyber insurance applications and renewal questionnaires commonly ask whether you have:

  • Multi-factor authentication (MFA) on email, remote access and administrator accounts.
  • Endpoint detection and response (EDR) on devices and servers, and who monitors it.
  • Backups that are separated from your network and tested.
  • Patching on a defined schedule, and no unsupported systems exposed to the internet.
  • Security awareness training, often including phishing simulations.
  • An incident response plan, and when it was last tested.
  • Controls on payments, such as call-back verification for changes to supplier banking details.

Underwriters typically assess risk by asking about security audits, safeguards for systems access and how data is handled, and organisations with strong risk management are generally in a better position to obtain cover on reasonable terms. A policy is one part of a risk strategy, not a replacement for cyber resilience. Insurers in Nigeria are regulated by the National Insurance Commission (NAICOM), and the products, terms and conditions on offer, whether from a local insurer or through a broker with access to international markets, vary.

Why the answers matter more than they used to

A questionnaire can look like a formality. It is not. Your answers help the insurer decide whether to offer coverage and on what terms, and the policy wording may refer back to them. If you tick "MFA on all remote access" and a breach later starts through a VPN account without MFA, you could face a difficult conversation at claim time.

We are not insurance advisers, and nothing here is legal or insurance advice. How any policy responds depends on its wording, which your broker and counsel should explain. Our role is narrower and practical: making sure that what you tell your insurer is true, and that you can show it.

The controls, and what "yes" should really mean

MFA. "Yes" should mean every user, not most users. Check shared mailboxes, service accounts, break-glass administrator accounts and remote access for third-party support. International guidance, including from CISA, favours phishing-resistant options, such as FIDO-based security keys, and number matching to resist MFA fatigue attacks. See rolling out MFA without a staff revolt if coverage is patchy.

EDR and monitoring. Insurers increasingly distinguish between having an EDR product installed and having someone who responds to its alerts. Know which devices are covered, which are not (servers and Mac devices are often missed), and who acts on an alert at night. Our comparison of managed EDR and running it yourself covers the options.

Backups. Expect questions about offline or immutable copies, separate credentials, encryption and restore testing. A backup job that reports success is not evidence that you can recover. Record the date and result of your last full restore test, and make sure the backup devices themselves have power protection (UPS or inverter) so an outage does not corrupt a running job.

Patching and end-of-life systems. Be ready to say how quickly critical updates are applied and whether any unsupported operating systems remain. If an old system must stay, document how it is isolated.

Privileged access. Separate administrator accounts, a short list of people who hold them, and MFA on all of them.

Email and payment fraud. Filtering, SPF, DKIM and DMARC, and a written rule that changes to banking details are confirmed by phone using a number you already hold. Bank transfers can be very hard to recall once sent, so this control carries real weight.

Training and planning. Dates of the last training cycle and the last incident response exercise, with attendance.

The NIST Cybersecurity Framework and CISA's #StopRansomware guidance line up closely with these questions and are widely used as international good practice. In Nigeria, ngCERT is the national point for reporting and advice on cyber incidents, and it is sensible to know in advance who in your organisation would contact it, and the insurer, after an incident.

Rather talk it through? If your renewal questionnaire is on someone's desk right now, we can verify the answers and gather the evidence with you. Talk to a Promatics specialist

Build an evidence pack before renewal

Brokers and underwriters ask better questions every year. A short evidence pack saves time and reduces the risk of a wrong answer:

Cyber insurance evidence pack

  • MFA report showing enrolment for all users and administrators, with exceptions explained
  • List of devices and servers with EDR, and who monitors alerts after hours
  • Backup design summary and the date and result of the last full restore test
  • Patch compliance report and a list of any unsupported systems with compensating controls
  • List of privileged accounts and who holds them
  • SPF, DKIM and DMARC status for each domain
  • Payment change verification procedure
  • Training records and phishing simulation summary
  • Incident response plan with the date of the last exercise
  • Contact details for your IT provider, counsel and the insurer's breach line

Keep it current. The same pack helps when a large client or a bank sends you a security questionnaire.

What usually goes wrong

  • Answering from memory. Someone remembers turning MFA on and does not know that a group of users was excluded.
  • Confusing licences with controls. You own an EDR licence, but the agent was never deployed to the servers.
  • Last-minute changes. MFA is switched on for everyone the day before the renewal, staff are locked out, and exceptions are added that nobody removes.
  • Forgetting suppliers. Your IT provider's or software vendor's remote access to your systems counts too.

When to bring in help

If you have a small environment and a clear-headed IT person, you can gather most of this evidence yourself using the admin consoles you already have. It is worth bringing in a professional when:

  • You are not sure the answers are accurate, or different people give different answers.
  • The insurer has declined, added exclusions or asked for controls you do not have.
  • You need gaps fixed within weeks, not months.
  • You want someone accountable for the evidence, not just a document.

A chatbot can explain what a questionnaire means. It cannot check your tenant, confirm the servers are covered, or stand behind the answer when the insurer asks. A Promatics security assessment does exactly that: we review how your organisation is really set up, rank the gaps and give you evidence and a remediation plan in plain language.

Limitations

Insurer requirements vary and change. This article describes commonly asked controls in general terms. It is not insurance or legal advice, and we do not predict whether any insurer will offer, renew or pay under a policy. Discuss coverage and wording with your broker.

Sources and further reading

Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.

  1. #StopRansomware Guide, Cybersecurity and Infrastructure Security Agency (CISA)
  2. Cybersecurity Framework, National Institute of Standards and Technology (NIST)
  3. ngCERT (Nigeria Computer Emergency Response Team), Federal Government of Nigeria
  4. National Insurance Commission (NAICOM), NAICOM

This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.

Talk to Promatics

Answer your insurer's questionnaire with evidence, not guesses

Renewal questionnaires land at busy times and the questions are surprisingly specific. We will check what is actually in place, close the quick gaps and give you evidence you can stand behind.

  • We verify each control rather than taking settings on trust
  • Plain-language evidence pack for your broker and leadership
  • A remediation plan for gaps before the renewal date