By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity | Serving organizations across Canada, the US, and beyond | Last updated August 17, 2026
Quick answer: A cyber insurance application is rejected or repriced when the organization cannot demonstrate the security controls that underwriters now consider baseline requirements. Multi-factor authentication, endpoint detection and response, immutable backups, a tested incident response plan, and vendor risk management are the most commonly cited gaps. These are not aspirational standards: they are the minimum controls most carriers expect before issuing coverage. Organizations that close these gaps before applying consistently see better terms than those that attempt to answer underwriting questionnaires around gaps they have not addressed.
Key Takeaways
- Cyber insurance underwriting has hardened significantly over the past several renewal cycles. Controls that were optional enhancements two years ago are now baseline requirements in most carrier questionnaires. Organizations that have not kept pace with these expectations face rejection, sub-limits, exclusions, or significant premium increases.
- MFA on all remote access and all privileged accounts is the single most consistently cited control in cyber insurance underwriting. An application that cannot demonstrate MFA coverage across these access points will face adverse underwriting outcomes at virtually every major carrier.
- EDR coverage on all endpoints is the second most commonly cited control. Carriers that accepted antivirus documentation three years ago now expect behavioral endpoint detection with the ability to detect and contain threats that bypass signature-based detection.
- Immutable backups, backups that cannot be encrypted or deleted by ransomware, are now a standard underwriting expectation. The backup question has evolved from asking whether backups exist to asking whether backups are immutable, offsite, and tested for restoration.
- A tested incident response plan is increasingly required rather than merely preferred. Carriers ask not only whether a plan exists but when it was last tested through a tabletop exercise or simulation, and who participated.
How Cyber Underwriting Has Changed
Three or four years ago, a typical cyber insurance application asked a handful of high-level questions: Do you have a firewall? Do you have antivirus? Do you train employees on cybersecurity? The questions were broad, the evidence requirements were minimal, and coverage was offered at predictable premiums to most mid-market applicants. That environment no longer exists. The claims experience of the cyber insurance industry, driven by a sustained wave of ransomware attacks across every sector and size of organization, forced a fundamental restructuring of underwriting standards.
Underwriting questionnaires now span dozens of pages. They ask specific questions about the deployment scope of MFA, not just whether MFA is enabled, but whether it covers every remote access point, every privileged account, every cloud administration console, and every email account. They ask about the specific capabilities of endpoint security tooling, the architecture of backup systems, the testing cadence of incident response plans, and the maturity of vendor risk management programs. The evidence requirements have shifted from attestation (yes, we have this) toward documentation (show us the configuration, the report, the test results). Organizations that are not prepared for this level of scrutiny frequently find that questionnaire submission results in rejection or materially worse terms than expected. Knowing what a policy would actually pay out is the companion question, covered in what cyber insurance actually covers.
The Controls Underwriters Most Commonly Penalize the Absence Of
These are the cyber insurance denial reasons that show up again and again across carriers. Each maps to a control underwriters now treat as baseline.
Multi-factor authentication
MFA is the non-negotiable baseline of current cyber underwriting. Every major carrier’s questionnaire asks about MFA in detail, and the questions have become progressively more specific. It is no longer sufficient to state that MFA is in place. Underwriters want to know whether MFA covers all remote access (VPN, RDP, remote desktop solutions), all privileged and administrative accounts, all cloud administration consoles, all email accounts including executive and finance team members, and all access to systems holding sensitive data. Partial MFA deployment, for example MFA on VPN but not on cloud administration, is a known gap that attracts adverse terms. Broad MFA coverage is usually delivered through identity and privileged access management, and organizations that cannot demonstrate it face the highest rate of underwriting adverse outcomes.
Endpoint detection and response
The transition from antivirus to EDR in underwriting expectations reflects the inadequacy of signature-based detection against the file-less malware, living-off-the-land techniques, and novel ransomware variants that are responsible for the majority of current claims. Carriers that accepted antivirus documentation in prior renewal cycles now ask specifically whether the organization has deployed a behavioral endpoint detection and response solution with response capabilities on all managed endpoints. The questions often extend to coverage percentage, asking whether EDR is deployed on 100% of endpoints or whether there are gaps in coverage such as legacy systems, OT environments, or recently onboarded endpoints from acquisitions. Coverage gaps below 100% are a noted risk factor.
Immutable and tested backups
Ransomware’s impact on the cyber insurance market was driven in large part by the frequency with which ransomware encrypted or deleted the victim’s backups alongside their primary data, eliminating the ability to restore without paying the ransom. Underwriters have responded by asking specifically whether backups are immutable (protected from modification or deletion by ransomware that has compromised the primary environment), whether backup copies are maintained in a location that is logically and network-separated from the primary environment, and whether backups are tested for restoration on a defined cadence. Organizations that maintain backups without immutability, that store backups in a location accessible from the primary environment, or that have never tested restoration face adverse backup-related underwriting outcomes.
Tested incident response plan
The shift from asking whether an incident response plan exists to asking when it was last tested represents a meaningful evolution in underwriting expectations. A plan that has never been exercised provides limited assurance to underwriters because organizations consistently discover gaps in their plans during actual incidents that a tabletop exercise would have surfaced. Carriers now typically ask for the date of the most recent tabletop exercise, who participated, and what remediations were identified and addressed. Organizations that cannot point to a tested plan within the past twelve months, or that have a plan that was last updated several years ago and has never been exercised, are at a disadvantage in underwriting.
Privileged access management
Privileged access, the administrative credentials that can make changes to systems and access all data, is the most valuable target for attackers who have gained initial access to an environment. Underwriters ask about privileged access management practices including whether privileged accounts are separated from standard user accounts, whether just-in-time access is used to limit the window during which privileged credentials are active, whether privileged session monitoring is in place, and whether privileged credentials are stored in a dedicated credential vault rather than in shared documents or password managers accessible to multiple people. Weak privileged access controls are a noted risk factor that can result in coverage exclusions for incidents where privileged account compromise played a role.
Vendor risk management
As supply chain attacks have grown as a claims driver, underwriters have added more detailed vendor risk management questions to their questionnaires. They ask whether the organization has a documented supplier risk management program, whether critical vendors are assessed for security controls, whether vendor contracts contain security and breach notification provisions, and whether the organization monitors vendors for security incidents. Organizations with no formal vendor risk program, or that manage all vendors identically regardless of their access level, face growing scrutiny in this category.
Why Misrepresentation Creates Post-Claim Risk
Under the pressure of a complex questionnaire with an application deadline, some organizations are tempted to answer questions more favorably than the actual state of their controls warrants. This is a significant post-claim risk. Cyber insurance policies are contracts of utmost good faith: the carrier’s willingness to provide coverage and the terms on which it is provided are based on the accuracy of the questionnaire responses. A material misrepresentation in the questionnaire provides grounds for the carrier to deny a claim or void the policy. The consequence of misrepresentation discovered at claim time, when the organization most needs coverage, is far worse than the consequence of an accurate questionnaire that results in adverse terms or a requirement to implement specific controls before coverage is bound.
Accurate questionnaire completion, with responses supported by evidence, is the foundation of a defensible insurance application. Armour Cybersecurity’s Cyber Insurance Advisory engagement drafts questionnaire responses collaboratively with the organization’s internal team, ensuring that responses are accurate, supported by evidence, and presented in the way that best reflects the organization’s actual security posture.
Closing Gaps Before Applying
The good news is that many of the controls underwriters most commonly penalize the absence of can be implemented quickly. MFA can typically be enabled across Microsoft 365 and remote access systems in days. EDR can be deployed across a managed endpoint fleet in a week or two. Backup immutability can often be configured within an existing backup solution or by adding an immutable backup tier. An incident response plan can be drafted and a tabletop exercise scheduled within a matter of weeks. These are not multi-month infrastructure projects: they are focused implementations of specific controls that have an immediate and material impact on underwriting outcomes.
The advisory engagement identifies which gaps are present, prioritizes them by their impact on underwriting outcomes, and provides a quick-win remediation plan designed to close the most material gaps before the questionnaire is submitted. Organizations that implement quick wins before submission consistently see better terms than those that submit with known gaps and hope underwriters will not notice them.
Frequently Asked Questions
Can we appeal a cyber insurance rejection?
Yes. A rejection is not necessarily final. Carriers will typically reconsider an application if the organization can demonstrate that gaps identified in the initial review have been remediated. The reconsideration package should include documentation of the remediation actions taken, evidence that the controls now meet the carrier’s requirements, and a cover letter from the broker explaining what has changed since the initial application. Working with a cybersecurity advisor to close gaps and prepare the resubmission package is the fastest path to an acceptable outcome. Some organizations that are rejected by one carrier find coverage at comparable terms through an alternative carrier with different underwriting criteria; carrier comparison is a component of the advisory engagement for organizations in this situation.
How much can closing security gaps reduce our premium?
The premium impact of control improvements varies by carrier, the specific gaps being closed, and market conditions at the time of application or renewal. Organizations that implement the controls underwriters most commonly penalize the absence of, particularly MFA coverage, EDR deployment, and immutable backups, frequently see premium improvements that justify the cost of implementation many times over in the first renewal cycle. The relationship is not purely linear: the most significant premium impact comes from moving from a posture where material gaps exist to one where baseline controls are met. Incremental improvements beyond the baseline have diminishing premium impact but continue to affect coverage terms, exclusions, and sub-limits.
Do carriers verify the security controls we claim to have?
Increasingly, yes. Some carriers conduct technical validation of specific control claims, particularly MFA deployment, as part of the underwriting process. Security ratings services that provide externally observable indicators of the organization’s security posture are used by some carriers to supplement questionnaire responses. And at claim time, carriers conduct forensic investigation that will reveal whether the controls represented in the questionnaire were actually in place at the time of the incident. The risk of control claims being found inaccurate is highest at the worst possible moment: when the organization is filing a claim and the carrier is reviewing whether coverage applies.
What if we cannot implement all the required controls before renewal?
If remediation of all identified gaps cannot be completed before the renewal deadline, the priority should be to close the gaps that have the most direct impact on underwriting outcomes: MFA, EDR, and backup immutability. Document the remediation plan for remaining gaps and share it with the broker to present to carriers as evidence of a credible roadmap. Some carriers will bind coverage with specific conditions requiring remediation of identified gaps within a defined timeframe after binding. A credible, documented plan with evidence of progress is significantly better than an application that acknowledges gaps without any remediation commitment. The advisory engagement supports prioritization and documentation of this plan as a standard deliverable.
Should we work with a cyber insurance broker or a cybersecurity advisor or both?
Both serve different functions and work best together. The broker’s role is to access the insurance market: selecting carriers, obtaining quotes, negotiating terms, and managing the policy relationship. The cybersecurity advisor’s role is to ensure that the organization presents the strongest possible security posture and questionnaire responses to that market. The broker knows the insurance market; the cybersecurity advisor knows what the questionnaire questions actually mean technically and how to demonstrate controls in the way underwriters expect. Organizations that use both consistently achieve better underwriting outcomes than those relying on the broker alone to navigate technical questionnaire requirements. Armour Cybersecurity works alongside existing broker relationships; we do not sell insurance and we do not compete with brokers.
The Bottom Line
A cyber insurance application is rejected or repriced for reasons that are now predictable: missing MFA, no EDR, backups that ransomware can reach, an untested incident response plan, weak privileged access, and no vendor risk program. Underwriters have turned these from optional extras into baseline requirements, and they increasingly ask for evidence rather than attestation. The fix is not a multi-month project; the highest-impact controls can be closed in days to weeks, before the questionnaire is submitted. A cyber insurance advisory engagement finds the gaps, prioritizes them by underwriting impact, and helps you present accurate, evidenced responses so the application holds up both at binding and at claim time.
About the author
David Chernitzky is Co-Founder and CEO of Armour Cybersecurity, a Toronto-based cybersecurity firm founded by military intelligence veterans and advised by senior leaders from PwC, KPMG, Deloitte, EY, and Mandiant. Armour serves more than 260 organizations across 52-plus industries, including finance, healthcare, technology, energy, legal, and government, with a 97 percent client retention rate.



