Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
Back to Blog

MFA, EDR, and Backups: The Three Things to Fix Before Your Next Insurance Application

Cybersecurity
Last updated: July 24, 2026

Most cyber insurance applications now ask about multi-factor authentication, endpoint detection and response, and tested offline backups, since federal cybersecurity guidance names all three as baseline controls insurers expect before writing or renewing a policy.

Fill out the application the way you did three years ago and something will get flagged. Not rejected, necessarily. Flagged. The underwriter comes back with follow-up questions, the renewal drags into a second round, or the quote lands higher than the number you were expecting. I see this happen to businesses running perfectly reasonable security. Good security, wrong paperwork. They just answered the questions the old way, and the questions changed underneath them.

Two people reviewing a printed cyber insurance application checklist

The Application Looks Different Than It Did a Few Years Ago

Cyber insurance used to run on a short questionnaire and a fair amount of trust. That changed once claims data caught up with underwriting. Ransomware payouts got bigger, recovery took longer, and carriers started tying premiums directly to the strength of a company’s actual controls rather than a checkbox saying “yes, we have security.” A 2021 Government Accountability Office report found that premium increases are shaped in part by how strong a company’s cyber controls already are. Weak controls, higher premium. That’s the mechanism GAO documented. The same report also flagged that New York’s Department of Financial Services now directs insurers to actively educate policyholders on cybersecurity as a condition of doing business in the state. Not a footnote you can skip if you operate in the Tri-State area.

The joint 2023 #StopRansomware Guide from CISA, the FBI, NSA, and MS-ISAC goes further. It names phishing-resistant MFA, EDR on every asset, and regularly tested offline backups as baseline controls, then lists your cyber insurance company right alongside your IT department as a stakeholder in the plan. Federal guidance and the underwriting process are pointing at the same three things now. That’s not a coincidence, and it’s the reason this keeps coming up during renewal season for VJNetworks’ cybersecurity clients across Rockland, Westchester, and Bergen.

New York’s own Department of Financial Services goes further than a general nudge. Its 2021 ransomware guidance lists nine controls the Department expects regulated companies to implement whenever possible, and three of them are exactly these three: MFA, EDR, and tested, segregated backups. MFA for remote access isn’t just expected, either. It’s required by regulation, under 23 NYCRR 500.12. Government guidance and the underwriting questionnaire are reading from the same page now.

None of this means your risk went up. Nothing changed there. It means the paperwork finally caught up to what a real defense actually requires.

MFA: “Available” Isn’t What Insurers Mean by “Enforced”

Multi-factor authentication requires a second proof of identity, typically a phone prompt or authenticator app code, before someone can log into email, a VPN, or an admin account. Simple concept. Having MFA turned on for some accounts is not the same as having it enforced across every account that touches sensitive systems. One admin login isn’t the whole company.

This is where most applications get tripped up. A business owner checks the MFA box because IT set it up for the admin login two years ago. Everyone else in the office still logs in with a password alone, because rolling MFA out to the whole staff felt like a project for later. Later never came. When an underwriter’s questionnaire asks whether MFA is “enforced,” they mean every account with access to email, financial systems, remote desktop, and the VPN, not just the ones somebody remembered to configure. Microsoft Authenticator, Duo, and similar tools all do this. Any of them work fine. The tool matters less than the coverage.

A full breakdown of “enforced” versus “available” and what insurers specifically check during underwriting is its own topic. For now, the short version: partial MFA reads to an underwriter almost the same as no MFA at all.

EDR: What the Questionnaire Is Actually Asking For

Behavior, not signatures. That’s the shift. Endpoint Detection and Response watches behavior on a device, not just files against a known-bad list. It catches a process trying to encrypt hundreds of files in sequence, or a login attempting to disable security software, even when nothing matches a signature anyone has cataloged yet. That’s the capability insurers are checking for when an application asks about “endpoint protection” or “EDR/XDR coverage.”

Some carriers now go past a yes-or-no answer and verify it. A handful run their own external scans against a company’s public-facing infrastructure before binding a policy, cross-checking what the application claims against what they can actually see. Get flagged there and the application stalls while someone explains the gap. Not a fun call. I’d rather my clients never have to make it.

Partial doesn’t count. Real coverage looks like CrowdStrike, SentinelOne, or Microsoft Defender for Business running on every laptop, server, and workstation in the environment, not a subset. Partial EDR deployment shows up the same way partial MFA does. Technically true on the application. Thin in practice. Exactly the kind of gap an underwriter’s own verification process is built to catch.

ControlWhat Insurers Actually CheckThe Gap That Trips Up Most Applications
Multi-factor authenticationEnforced on email, VPN, remote access, and admin accountsSet up for admins only, optional for everyone else
Endpoint detection and responseBehavior-based monitoring on every endpoint, with a documented response processAntivirus alone, mistaken for EDR coverage
BackupsOffline or immutable copies, with a restore that’s actually been testedBackups run every night, but nobody has tried restoring from one
IT security consultant explaining cyber insurance security requirements to a small business owner

Backups: Why “We Back Up Every Night” Doesn’t Answer the Question

Backups are the control I see businesses feel most confident about, right up until someone asks a follow-up question. Yes, there’s a backup job. No test, though. Nobody has actually tried restoring from it in the last six months. That gap matters more than almost anything else on this list, because a backup nobody has tested is a guess, not a plan.

The CISA-led #StopRansomware Guide is specific about what “backed up” needs to mean: offline, encrypted copies, with the availability and integrity of those backups tested regularly against an actual disaster-recovery scenario. Not a checkmark. Not a green light in a dashboard. An actual restore, timed, on a schedule someone owns. Ransomware crews have gotten good at finding and encrypting connected backup drives before they ever touch your production files, which is exactly why “connected” and “offline” stopped meaning the same thing to underwriters. VJNetworks covered the mechanics of how fast that spread happens in an earlier piece on ransomware protection, and the backup gap is the same one that shows up there.

Here’s the part that surprises people: a business can have MFA and EDR fully dialed in and still get flagged, if backups are the one control nobody’s tested lately. Insurers weight all three. Two out of three doesn’t clear the bar.

IT technician checking a rack-mounted backup appliance in a server room

Before Your Next Application Goes In

A few weeks of runway is usually enough to close these gaps. Start now. Not the week the form is due.

  • Pull a list of every account with access to email, VPN, or admin systems, and confirm MFA is enforced on all of them, not just the accounts IT remembers.
  • Confirm EDR is actually installed and reporting on every endpoint, including the laptops that live outside the main office.
  • Run a real restore from your backup, on a real schedule, and write down when it last happened and how long it took.
  • Ask whoever handles your IT whether they can show proof of all three, not just describe them. “Trust me” doesn’t satisfy an underwriter.
  • Get the gaps fixed before the renewal conversation starts, not during it.

VJNetworks has walked clients across the Tri-State area through this exact list before every renewal cycle for over 20 years, and the businesses that start early are the ones that don’t end up on a follow-up call with their broker.

What Happens When One of the Three Is Missing

Outcomes vary by carrier and by how big the gap is. Sometimes it’s minor. A straightforward premium increase. Sometimes it’s a sublimit added specifically for ransomware, capping what the policy pays out even though the headline coverage number looks the same. Occasionally it’s a denied application outright, sent back with a list of what needs fixing before anyone will underwrite it. No incident needed for any of that. Underwriters are pricing the gap itself, based on what similar gaps have cost across their whole book of business, not waiting to see if it costs you specifically.

There’s a fourth outcome. This is the one that actually stings. A 2024 National Association of Insurance Commissioners report documented it. Some carriers write a “failure to maintain security” exclusion directly into the policy. Coverage gets denied on a claim, after the fact, specifically because the standards weren’t kept up. That’s a different problem than a higher premium. That’s paying for a policy for years and finding out it never would have paid out.

Straight Answers Before You Sign the Application

Checking the MFA box on the application, does that mean it’s actually done?
Not the same thing, and insurers have caught on. A box checked because MFA exists somewhere in the environment isn’t the same as MFA enforced on every account that touches email, VPN, or admin systems. Underwriters increasingly ask for the specific scope, not just a yes.
Do insurers actually verify EDR is running, or just take your word for it?
Increasingly, they verify it. Some carriers run their own external scans against a company’s public-facing systems before binding coverage, comparing what the application claims to what they can see from the outside. A mismatch there slows everything down.
Nightly backups already run here. So why does that still get flagged?
It’s the most common wrong assumption on the whole application. A nightly job proves backups run. It doesn’t prove they’re offline, encrypted, or restorable, and federal guidance specifically calls for testing that restore against a real scenario, not just confirming the job completed.
How long does it actually take to get these three things in order before a deadline?
A few weeks, most of the time. Rarely longer. The MFA rollout and EDR deployment move fast once someone owns the project. The backup piece takes slightly longer only because a real restore test has to actually run and finish.
If we get flagged during underwriting, does that always mean a higher premium?
Not always, though it can. It can also mean a coverage sublimit, a request to fix specific gaps before binding, or in rarer cases a denial. None of those outcomes require anything to have gone wrong yet. Underwriters price the gap on its own.

Insurers didn’t invent these three controls out of nowhere. Federal cybersecurity guidance already lists MFA, EDR, and tested backups as the baseline, and the underwriting questions are just catching up to that same list. VJNetworks walks clients through managed IT services that keep all three current, not scrambled together the week an application is due. If you want a straight read on where your own gaps sit, a free assessment covers exactly that, and it’s the same review businesses across Rockland, Westchester, and Bergen have leaned on for over 20 years.

Further reading: the #StopRansomware Guide from CISA, NSA, FBI, and MS-ISAC covers the full federal baseline these controls come from.

Know Exactly Where Your Application Stands

A free assessment checks MFA enforcement, EDR coverage, and backup restorability against what your next cyber insurance application will actually ask for. No obligation, no sales pitch.

Get Your Free IT Assessment →

Or call (845) 440-5000