By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 17, 2026
Quick answer: Cyber insurance security requirements in underwriting come down to 13 domains that carriers assess when evaluating an application: governance and oversight, regulatory compliance, third-party risk, infrastructure security, log management, vulnerability management, cloud security, application security, identity and privileged access, data protection, threat monitoring, incident response, and security awareness training. An organization’s posture across these 13 domains determines whether coverage is offered, at what limit, with what exclusions, and at what premium. Understanding what underwriters assess in each domain is the foundation of presenting a strong insurance application.
Key Takeaways
- Cyber underwriting is not a generic security assessment. It focuses on the 13 domains that drive claims and that carriers have learned, through claim data, are the most predictive of incident likelihood and severity. Understanding the domain framework helps organizations prioritize the right controls for insurance purposes.
- Each of the 13 domains has evolved in terms of what underwriters consider acceptable. The baseline expectations in most domains are materially higher than they were two or three renewal cycles ago. Organizations that have not actively managed their security posture against current underwriting expectations may find that controls they implemented several years ago no longer satisfy current requirements.
- The 13 domains map to the frameworks underwriters most commonly reference: NIST CSF, CIS Controls v8, ISO 27001, and SOC 2. Organizations that have invested in alignment to any of these frameworks have a strong foundation for demonstrating underwriting readiness, though the mapping is not always direct and carrier-specific questionnaires often ask about controls in ways that require translation from the framework language.
- Gaps in any of the 13 domains can affect underwriting outcomes. But not all domains carry equal weight. Identity and privileged access, incident response, and endpoint security are the domains most directly tied to the ransomware claims that have driven the hardening of cyber underwriting standards.
- The evidence pack produced alongside the questionnaire is the mechanism through which the organization demonstrates its posture across all 13 domains. Responses without supporting evidence are self-attestations; responses with supporting evidence are substantiated claims that underwriters can rely on.
Domain 1: Governance and Oversight
Underwriters assess whether the organization has documented accountability for cybersecurity at the leadership level. They look for a named owner of the security program (CISO, vCISO, or equivalent), a cybersecurity policy framework that has been approved by leadership, board-level or executive committee visibility into cyber risk, and a defined process for reviewing and updating security policies. Organizations without any formal governance structure, where security is managed entirely as an IT function without executive ownership or board visibility, score poorly on this domain. Evidence includes policy documents, board meeting minutes that reference cyber risk, and organizational charts showing security leadership.
Domain 2: Regulatory Compliance
Regulatory compliance assessment covers the frameworks applicable to the organization given its industry and data profile: PIPEDA and Quebec Law 25 for Canadian businesses handling personal information, HIPAA for healthcare, PCI DSS for organizations handling payment card data, GDPR for businesses with European customers or operations, and sector-specific mandates for financial services, energy, and critical infrastructure. Underwriters assess whether the organization knows which regulations apply, whether it has a compliance program, and whether it has experienced any regulatory investigations or enforcement actions. A history of regulatory violations is a significant adverse factor. Evidence includes compliance program documentation, self-assessment records, and any recent third-party compliance reviews.
Domain 3: Third-Party Risk Management
Third-party risk has become a significant focus of cyber underwriting following the major supply chain attacks of recent years. Underwriters ask whether the organization has a supplier risk management program, whether vendors are assessed before being granted access to systems or data, whether critical vendors are subject to ongoing monitoring, and whether vendor contracts contain security and breach notification provisions. Organizations with no formal vendor risk program are increasingly at a disadvantage in underwriting as carriers seek to understand the supply chain exposure of every policyholder. Evidence includes vendor risk policy, vendor inventory with risk tiering, assessment questionnaires, and sample vendor contract security provisions.
Domain 4: Infrastructure Security
Infrastructure security assessment covers the foundational controls protecting the network and computing environment: firewall configuration and segmentation, patch management practices, remote access security, network monitoring, and the hardening of servers and workstations. Underwriters ask about the frequency of patching, whether critical patches are applied within defined windows, whether remote access is secured with MFA (assessed in detail in the identity domain), and whether network segmentation prevents lateral movement between environments holding different levels of sensitive data. Evidence includes patch management reports, firewall configuration summaries, and network architecture diagrams.
Domain 5: Log Management
Log management has become a more prominent underwriting domain as forensic investigations have repeatedly demonstrated that organizations without adequate logging cannot detect intrusions in progress, determine the scope of a breach, or support a legal or regulatory investigation. Underwriters ask whether security logs are collected from key systems including servers, network devices, and endpoint security tools, whether logs are retained for a sufficient period (typically 90 days minimum, with 12 months preferred), whether logs are stored in a location that cannot be modified or deleted by an attacker who has compromised the primary environment, and whether logs are reviewed or analyzed through a SIEM or equivalent tool. Evidence includes logging architecture documentation and retention policy.
Domain 6: Vulnerability Management
Vulnerability management assessment covers the organization’s process for identifying, prioritizing, and remediating known vulnerabilities in its systems. Underwriters ask about the cadence of vulnerability scanning, the process for prioritizing and tracking remediation of identified vulnerabilities, and the timeline for applying critical security patches. They also ask whether the organization conducts penetration testing and at what frequency. The trend toward asking about vulnerability management in the context of known exploited vulnerabilities reflects carriers’ awareness that unpatched vulnerabilities with available exploits are a direct underwriting risk. Evidence includes vulnerability scan reports, remediation tracking records, and penetration test reports.
Domain 7: Cloud Security
Cloud security has become a dedicated underwriting domain as organizations’ reliance on cloud infrastructure has grown. Underwriters ask about which cloud platforms are in use, how cloud administration consoles are secured (MFA, privileged access controls), whether cloud security posture management tools are in use to detect misconfigurations, how cloud storage containing sensitive data is protected, and whether cloud environments are covered by the same security monitoring as on-premises environments. Misconfigured cloud storage and cloud console takeover through compromised administrative credentials are among the most common causes of cloud-related cyber claims. Evidence includes cloud security configuration documentation and CSPM reports.
Domain 8: Application Security
Application security assessment is most relevant for organizations that develop or operate their own software applications, particularly those accessible externally over the internet. Underwriters ask whether application security testing is integrated into the development process (SAST, DAST, or equivalent), whether web applications are protected by a web application firewall, and whether APIs exposed externally are inventoried and protected. For organizations that rely primarily on third-party software rather than developing their own, application security assessment focuses on patching and configuration of externally facing applications and web services. Evidence includes application security testing reports, WAF configuration documentation, and software development lifecycle security policy.
Domain 9: Identity and Privileged Access
Identity and privileged access is the domain most directly linked to the ransomware and business email compromise claims that drive the largest losses in the cyber insurance market. Underwriters assess MFA coverage across all remote access, all cloud administration, all privileged accounts, and all email accounts. They ask about identity and privileged access management practices: whether privileged accounts are separated from standard user accounts, whether just-in-time or just-enough access is used to limit privilege window, whether privileged session monitoring is in place, and whether administrative credentials are stored in a dedicated credential vault. They also ask about account lifecycle management: whether former employee accounts are deactivated promptly, whether dormant accounts are reviewed, and whether service accounts are inventoried and protected. Evidence includes identity policy documentation, PAM tool configuration, and MFA enforcement policy screenshots.
Domain 10: Data Protection
Data protection assessment covers how the organization protects sensitive data at rest and in transit, how it classifies and inventories the data it holds, how it manages data retention and deletion, and how backup data is protected. Underwriters ask about encryption of sensitive data on servers and endpoints, the use of data loss prevention tools, the inventory of personal data held and where it resides, and the backup architecture assessed in terms of immutability, offsite storage, and restoration testing. Organizations that hold significant personal information without a data classification and protection program, or that cannot describe their backup architecture in terms that satisfy current underwriting expectations, face gaps in this domain. Evidence includes data classification policy, encryption configuration, and backup architecture documentation.
Domain 11: Threat Monitoring
Threat monitoring assessment covers the organization’s ability to detect and respond to threats in the environment through active monitoring rather than relying on reactive incident response after an intrusion has become visible. Underwriters ask whether a security information and event management system is in use, whether endpoint detection and response tools provide behavioral monitoring across the endpoint fleet, whether a security operations center function monitors the environment during and outside business hours, and whether threat intelligence is integrated into monitoring processes. Organizations without any active monitoring capability, where security incidents are discovered through user reports or external notification rather than internal detection, face the most significant gap in this domain. Evidence includes SOC service documentation, SIEM architecture, and EDR deployment reports.
Domain 12: Incident Response
Incident response is assessed in terms of the existence of a documented plan, the currency and testing of that plan, the organizational structure for executing it, the retainer relationships that provide specialist support, and the preparedness of leadership to manage an incident. Underwriters ask for the date of the most recent plan update, the date and participants of the most recent tabletop exercise, whether the organization has a breach coach retainer, whether a forensic response retainer is in place, and whether the incident response plan covers the specific scenarios most relevant to the organization such as ransomware, data breach, and business email compromise. Evidence includes the incident response plan, tabletop exercise records, and retainer agreements.
Domain 13: Security Awareness Training
Security awareness training is assessed as a control for the social engineering and phishing attacks that serve as the initial access vector for a significant proportion of cyber incidents. Underwriters ask whether all employees receive security awareness training, how frequently training occurs, whether training includes phishing simulation exercises, and whether training is role-specific for higher-risk roles such as finance and executive assistants who are more likely to be targeted by business email compromise and social engineering. Training programs that occur annually without phishing simulation are considered minimal; programs with quarterly or monthly training and regular phishing simulations with targeted follow-up for users who click are considered more robust. Evidence includes training platform records, completion rates, and phishing simulation results.
How Armour Cybersecurity Maps Your Posture to These 13 Domains
The Cyber Insurance Advisory engagement conducts a structured readiness assessment across all 13 domains, mapping findings against the specific questionnaire the broker and carrier are using. The output is a gap analysis that identifies which domains present the most material underwriting risk, a quick-win remediation plan for the most insurance-relevant gaps, and an evidence pack that supports questionnaire responses across all domains. It is the domain-by-domain complement to the work of completing the underwriting questionnaire accurately, and it directly targets the reasons applications get rejected or repriced.
Frequently Asked Questions
Are all 13 domains assessed equally by every carrier?
No. Carrier questionnaires vary in the weight they apply to different domains and in the specificity of their questions within each domain. Most carriers weight identity and privileged access, incident response, and endpoint security most heavily because these domains are most directly linked to the ransomware claims that drive the largest losses. Cloud security and third-party risk have received increased weight in recent renewal cycles as cloud-related and supply chain incidents have grown as claims drivers. The advisory engagement reviews the specific questionnaire being used and maps the assessment to the domains that carry the most weight for that carrier and that submission.
Do we need to be fully mature in all 13 domains to get covered?
No. Cyber insurance is available to organizations that are not fully mature across all 13 domains. The underwriting decision is a risk-weighted assessment: carriers accept some level of gap in exchange for a premium that reflects the risk. The goal of the readiness assessment and questionnaire advisory is not to achieve full maturity before applying, but to ensure that the most critical baseline controls are in place, that the questionnaire accurately reflects the organization’s actual posture, and that any gaps are disclosed with a credible remediation plan rather than obscured in ways that create claim risk. Coverage at favorable terms requires demonstrating that the most material risks are managed; it does not require perfection across all 13 domains.
How do NIST CSF and CIS Controls map to the 13 underwriting domains?
NIST CSF and CIS Controls provide comprehensive security frameworks that cover the control areas underwriters assess, but the mapping is not always direct. NIST CSF 2.0 organizes controls by six functions (Govern, Identify, Protect, Detect, Respond, Recover) rather than by the domain categories underwriters use, with the Govern function added in the 2.0 revision to reflect exactly the leadership accountability that Domain 1 assesses. CIS Controls v8 organizes controls into implementation groups that map partially but not precisely to underwriting questionnaire structure. The advisory engagement performs the translation from the framework language the organization is familiar with into the specific questionnaire language the carrier uses, ensuring that controls implemented under a framework are accurately represented in underwriting responses without requiring the organization to re-learn its own security program through a different lens.
What is a NIST CSF maturity tier and does it matter for insurance?
NIST CSF defines four implementation tiers: Partial (Tier 1), Risk Informed (Tier 2), Repeatable (Tier 3), and Adaptive (Tier 4). The tiers describe the degree to which cybersecurity risk management practices are formalized, documented, and integrated into organizational decision-making. Most cyber insurance underwriting does not directly ask organizations to self-assess their NIST CSF tier, but the substance of the tier definitions maps closely to what underwriters assess: Tier 1 organizations that manage security reactively without documented processes will struggle with underwriting questionnaires that ask for policy documentation, testing evidence, and governance structures. Tier 2 and Tier 3 organizations that have documented and repeatable processes are better positioned to answer underwriting questions accurately and with evidence.
How does the evidence pack differ from just answering the questionnaire?
The questionnaire response provides the answers. The evidence pack provides the documentation that supports those answers. A questionnaire response that states MFA is enforced on all remote access is a claim. An evidence pack that includes a screenshot of the conditional access policy showing MFA enforcement scope, a coverage report showing the percentage of accounts with MFA enabled, and a configuration confirmation from the VPN management console is a substantiated claim. The distinction matters at underwriting because some carriers conduct technical validation and will ask for evidence on key controls. It matters even more at claim time because the carrier’s forensic investigation will determine whether the controls represented in the questionnaire were actually deployed as claimed, and a pre-existing evidence pack is the organization’s best documentation of its posture at the time of binding.
The Bottom Line
Cyber insurance security requirements come down to 13 underwriting domains, from governance and third-party risk through identity, data protection, monitoring, incident response, and training. Carriers weight them by claims impact, with identity and privileged access, incident response, and endpoint security carrying the most, and they increasingly want evidence rather than attestation for each. The organizations that get the best terms are not the ones that are perfect across all 13; they are the ones that meet the critical baselines, represent their posture accurately, and disclose gaps with a credible plan. A cyber insurance advisory engagement runs the domain-by-domain readiness assessment, builds the evidence pack, and closes the highest-impact gaps before the application goes in.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



