Most cyber insurance applications now ask about multi-factor authentication, endpoint detection and response, and tested offline backups, since federal cybersecurity guidance names all three as baseline controls insurers expect before writing or renewing a policy.
Fill out the application the way you did three years ago and something will get flagged. Not rejected, necessarily. Flagged. The underwriter comes back with follow-up questions, the renewal drags into a second round, or the quote lands higher than the number you were expecting. I see this happen to businesses running perfectly reasonable security. Good security, wrong paperwork. They just answered the questions the old way, and the questions changed underneath them.

The Application Looks Different Than It Did a Few Years Ago
Cyber insurance used to run on a short questionnaire and a fair amount of trust. That changed once claims data caught up with underwriting. Ransomware payouts got bigger, recovery took longer, and carriers started tying premiums directly to the strength of a company’s actual controls rather than a checkbox saying “yes, we have security.” A 2021 Government Accountability Office report found that premium increases are shaped in part by how strong a company’s cyber controls already are. Weak controls, higher premium. That’s the mechanism GAO documented. The same report also flagged that New York’s Department of Financial Services now directs insurers to actively educate policyholders on cybersecurity as a condition of doing business in the state. Not a footnote you can skip if you operate in the Tri-State area.
The joint 2023 #StopRansomware Guide from CISA, the FBI, NSA, and MS-ISAC goes further. It names phishing-resistant MFA, EDR on every asset, and regularly tested offline backups as baseline controls, then lists your cyber insurance company right alongside your IT department as a stakeholder in the plan. Federal guidance and the underwriting process are pointing at the same three things now. That’s not a coincidence, and it’s the reason this keeps coming up during renewal season for VJNetworks’ cybersecurity clients across Rockland, Westchester, and Bergen.
New York’s own Department of Financial Services goes further than a general nudge. Its 2021 ransomware guidance lists nine controls the Department expects regulated companies to implement whenever possible, and three of them are exactly these three: MFA, EDR, and tested, segregated backups. MFA for remote access isn’t just expected, either. It’s required by regulation, under 23 NYCRR 500.12. Government guidance and the underwriting questionnaire are reading from the same page now.
None of this means your risk went up. Nothing changed there. It means the paperwork finally caught up to what a real defense actually requires.
MFA: “Available” Isn’t What Insurers Mean by “Enforced”
Multi-factor authentication requires a second proof of identity, typically a phone prompt or authenticator app code, before someone can log into email, a VPN, or an admin account. Simple concept. Having MFA turned on for some accounts is not the same as having it enforced across every account that touches sensitive systems. One admin login isn’t the whole company.
This is where most applications get tripped up. A business owner checks the MFA box because IT set it up for the admin login two years ago. Everyone else in the office still logs in with a password alone, because rolling MFA out to the whole staff felt like a project for later. Later never came. When an underwriter’s questionnaire asks whether MFA is “enforced,” they mean every account with access to email, financial systems, remote desktop, and the VPN, not just the ones somebody remembered to configure. Microsoft Authenticator, Duo, and similar tools all do this. Any of them work fine. The tool matters less than the coverage.
A full breakdown of “enforced” versus “available” and what insurers specifically check during underwriting is its own topic. For now, the short version: partial MFA reads to an underwriter almost the same as no MFA at all.
EDR: What the Questionnaire Is Actually Asking For
Behavior, not signatures. That’s the shift. Endpoint Detection and Response watches behavior on a device, not just files against a known-bad list. It catches a process trying to encrypt hundreds of files in sequence, or a login attempting to disable security software, even when nothing matches a signature anyone has cataloged yet. That’s the capability insurers are checking for when an application asks about “endpoint protection” or “EDR/XDR coverage.”
Some carriers now go past a yes-or-no answer and verify it. A handful run their own external scans against a company’s public-facing infrastructure before binding a policy, cross-checking what the application claims against what they can actually see. Get flagged there and the application stalls while someone explains the gap. Not a fun call. I’d rather my clients never have to make it.
Partial doesn’t count. Real coverage looks like CrowdStrike, SentinelOne, or Microsoft Defender for Business running on every laptop, server, and workstation in the environment, not a subset. Partial EDR deployment shows up the same way partial MFA does. Technically true on the application. Thin in practice. Exactly the kind of gap an underwriter’s own verification process is built to catch.
| Control | What Insurers Actually Check | The Gap That Trips Up Most Applications |
|---|---|---|
| Multi-factor authentication | Enforced on email, VPN, remote access, and admin accounts | Set up for admins only, optional for everyone else |
| Endpoint detection and response | Behavior-based monitoring on every endpoint, with a documented response process | Antivirus alone, mistaken for EDR coverage |
| Backups | Offline or immutable copies, with a restore that’s actually been tested | Backups run every night, but nobody has tried restoring from one |

Backups: Why “We Back Up Every Night” Doesn’t Answer the Question
Backups are the control I see businesses feel most confident about, right up until someone asks a follow-up question. Yes, there’s a backup job. No test, though. Nobody has actually tried restoring from it in the last six months. That gap matters more than almost anything else on this list, because a backup nobody has tested is a guess, not a plan.
The CISA-led #StopRansomware Guide is specific about what “backed up” needs to mean: offline, encrypted copies, with the availability and integrity of those backups tested regularly against an actual disaster-recovery scenario. Not a checkmark. Not a green light in a dashboard. An actual restore, timed, on a schedule someone owns. Ransomware crews have gotten good at finding and encrypting connected backup drives before they ever touch your production files, which is exactly why “connected” and “offline” stopped meaning the same thing to underwriters. VJNetworks covered the mechanics of how fast that spread happens in an earlier piece on ransomware protection, and the backup gap is the same one that shows up there.
Here’s the part that surprises people: a business can have MFA and EDR fully dialed in and still get flagged, if backups are the one control nobody’s tested lately. Insurers weight all three. Two out of three doesn’t clear the bar.

Before Your Next Application Goes In
A few weeks of runway is usually enough to close these gaps. Start now. Not the week the form is due.
- Pull a list of every account with access to email, VPN, or admin systems, and confirm MFA is enforced on all of them, not just the accounts IT remembers.
- Confirm EDR is actually installed and reporting on every endpoint, including the laptops that live outside the main office.
- Run a real restore from your backup, on a real schedule, and write down when it last happened and how long it took.
- Ask whoever handles your IT whether they can show proof of all three, not just describe them. “Trust me” doesn’t satisfy an underwriter.
- Get the gaps fixed before the renewal conversation starts, not during it.
VJNetworks has walked clients across the Tri-State area through this exact list before every renewal cycle for over 20 years, and the businesses that start early are the ones that don’t end up on a follow-up call with their broker.
What Happens When One of the Three Is Missing
Outcomes vary by carrier and by how big the gap is. Sometimes it’s minor. A straightforward premium increase. Sometimes it’s a sublimit added specifically for ransomware, capping what the policy pays out even though the headline coverage number looks the same. Occasionally it’s a denied application outright, sent back with a list of what needs fixing before anyone will underwrite it. No incident needed for any of that. Underwriters are pricing the gap itself, based on what similar gaps have cost across their whole book of business, not waiting to see if it costs you specifically.
There’s a fourth outcome. This is the one that actually stings. A 2024 National Association of Insurance Commissioners report documented it. Some carriers write a “failure to maintain security” exclusion directly into the policy. Coverage gets denied on a claim, after the fact, specifically because the standards weren’t kept up. That’s a different problem than a higher premium. That’s paying for a policy for years and finding out it never would have paid out.
Straight Answers Before You Sign the Application
Checking the MFA box on the application, does that mean it’s actually done?
Do insurers actually verify EDR is running, or just take your word for it?
Nightly backups already run here. So why does that still get flagged?
How long does it actually take to get these three things in order before a deadline?
If we get flagged during underwriting, does that always mean a higher premium?
Insurers didn’t invent these three controls out of nowhere. Federal cybersecurity guidance already lists MFA, EDR, and tested backups as the baseline, and the underwriting questions are just catching up to that same list. VJNetworks walks clients through managed IT services that keep all three current, not scrambled together the week an application is due. If you want a straight read on where your own gaps sit, a free assessment covers exactly that, and it’s the same review businesses across Rockland, Westchester, and Bergen have leaned on for over 20 years.
Further reading: the #StopRansomware Guide from CISA, NSA, FBI, and MS-ISAC covers the full federal baseline these controls come from.
A free assessment checks MFA enforcement, EDR coverage, and backup restorability against what your next cyber insurance application will actually ask for. No obligation, no sales pitch.
