Cyber Insurance Minimum Controls: Cyber Hygiene Eligibility Criteria
Cyber Insurance is no longer underwritten on turnover and sector alone. Insurers now assess whether a business can demonstrate a minimum level of cyber hygiene before offering meaningful terms.

Non-Negotiable Underwriting Eligibility Criteria
For many smaller businesses or businesses that haven’t purchased cover before, the biggest challenge isn’t the premium. It’s meeting the eligibility criteria and getting their controls up to speed to become insurable.
Cyber insurers increasingly expect four core controls to be in place before providing terms. These controls are designed to reduce the likelihood of ransomware, phishing emails, data theft, and prolonged operational disruption. Where these minimum cyber controls are missing, applications will typically be declined.
Multi-Factor Authentication (MFA)
Multi-Factor Authentication is now one of the most important cyber insurance eligibility controls. From an underwriting perspective, MFA is no longer a “nice to have”. It is a fundamental control that demonstrates whether the business has taken reasonable steps to secure access to critical systems.
To pass scrutiny, MFA should be enforced across the systems attackers are most likely to target. This includes remote network access and privileged administrative accounts.
Many cyber incidents begin with compromised credentials. If an attacker obtains a valid username and password, MFA provides a second barrier before they can access systems, escalate privileges, move laterally, or initiate fraudulent activity.
Regular Backups
Backups undertaken at regular intervals are a key recovery tool for ransomware attacks. However, some insurers will look closely at how those backups are configured. A backup that is connected to the same network, accessible using the same credentials, or capable of being deleted by an attacker may not provide meaningful resilience.
Insurers will look for regular backups and off-site storage, either through cloud systems or a secondary backup location.
For managed service providers, it is commonly required for backup data to be stored at two separate data centres, that one backup of the data is immutable.
Patch Management
Patch management is a core underwriting control because many cyber attacks exploit known vulnerabilities for which fixes already exist. Insurers expect businesses to demonstrate a structured patching process, not an informal or ad hoc approach.
Insurers have an expectation that there will be regular software updates with timely application of critical patches to minimise the window of exposure to known vulnerabilities. Automated patch management systems are favoured by insurers due to the added layer of consistency they provide.
Anti-virus Software
Anti-virus and anti-malware software are security programs designed to detect, prevent, and remove malicious software. These tools protect against a wide range of threats, including viruses, worms, Trojans, ransomware, spyware, and adware.
The cybersecurity software provides high levels of threat detection by scanning files and system activities for known malware signatures and behaviours. They are also able to block malicious software installation, while repairing infected files and systems.
Secondary Preferred Resilience Controls
Once the minimum controls are in place, insurers look for evidence that the business has moved beyond basic eligibility. These secondary controls can help shift a business from “barely insurable” to a “preferred risk”, improving the likelihood of competitive pricing, broader cover, and higher available limits.
Data Encryption
Measures such as data encryption ensure confidentiality by preventing data breaches, maintaining data integrity. Compliance with data protection and regulatory standards such as GDPR can also be protected by data encryption. Data will remain secure both at rest and in transit while data encryption is in use.
Insurers have high standards for data encryption procedures with a focus on using industry standard encryption algorithms to ensure data security. End-to-end encryption is often mandated by insurers to keep data secure throughout its lifecycle.
Email Authentication (DMARC)
Email remains one of the most common routes for phishing, invoice fraud, credential theft, and business email compromise. Email authentication protocols help reduce the risk of criminals impersonating your domain.
SPF helps identify which mail servers are authorised to send emails on behalf of your domain. DKIM helps verify that an email has not been altered in transit. DMARC tells receiving mail servers what to do when an email fails authentication checks.
Privileged Access Management (PAM)
Privileged Access Management reduces the risk that one compromised account can unlock the entire business. The principle is that users should only have the access they need to perform their role.
This is important because attackers often begin with a standard user account and then attempt to escalate privileges. If everyday accounts have unnecessary administrator rights, a small incident can become a network-wide compromise.
Endpoint Detection & Response (EDR)
Traditional antivirus tools are often signature-based and reactive. They may identify known malware, but they are less effective against modern ransomware, fileless attacks, credential theft, lateral movement, and attacker behaviour that does not match a known malicious file.
Endpoint Detection & Response, often supported by Managed Detection & Response, provides a more active defence. A strong EDR or MDR solution should be capable of monitoring endpoint behaviour, detecting suspicious activity and isolating infected machines.
For higher-risk businesses, insurers increasingly expect 24/7 monitoring so that threats are detected and contained before ransomware spreads across the network.
Protection Against Unauthorised Access and Data Theft
This is particularly important where the business holds a significant amount of personal data, and whether those records contain sensitive information such as payment card information, medical information, or passport details.
Sensitive personal data increases the potential severity of a breach.
Second, high-value data can increase the likelihood of extortion, because attackers may threaten to leak stolen information unless payment is made.
Businesses can seek to mitigate this exposure by implementing:

Encryption at rest and in transit

Role-based permissions

Data retention policies

Logging and monitoring

Regular permission reviews

Incident response planning
Why Minimum Controls Matter for Cyber Insurance Cost
Cyber insurers price risk based on both likelihood and severity. Minimum controls such as MFA, regular backups, anti-virus software, and patch management reduce the likelihood and severity of a major incident. Secondary controls such as encryption, DMARC, PAM, and EDR go further and improve your cyber risk profile.
Businesses are now expected to make statements about a range of controls including MFA, EDR, backups, patching, privileged access, email security, cloud platforms, incident response, and outsourced IT arrangements.
Cyber controls do not just protect your network. They protect your ability to buy effective Cyber Insurance at a sustainable cost.
Meet the Brokers
.webp)





