Monday to Friday, 8am to 6pm CT832-907-5594
ServicesCyber-Insurance Readiness

You qualify, you bind, and your answers hold up when the carrier looks back.

Carriers no longer take your word for it. They ask which controls you run, and if a claim later shows you did not have one you attested to, they can refuse to pay. We put the required controls genuinely in place, document them, and help you answer the application honestly, so the policy holds when you need it.

What carriers actually check

The application is a controls checklist. Nearly every cyber-insurance application now asks specifically about multi-factor authentication (Marsh), and the rest of the list is consistent across carriers. These are the ones that gate whether you can bind.

Identity

Enforced multi-factor authentication

A second check beyond the password on email, on remote access, and on administrator accounts. Carriers ask about MFA more than any other control, and many will not quote at all without it. A stolen password by itself is not enough to get in.

Email

Email authentication and anti-phishing

Inbound filtering plus enforced SPF, DKIM, and DMARC so spoofed mail is rejected. Most intrusions and most funds-transfer losses begin with a phishing email, so the application asks how your mail is protected.

Detection

Endpoint detection and response (EDR)

Software on every computer and server that watches for malicious behavior, not just known viruses, and can isolate a machine that looks compromised. Carriers increasingly treat consumer antivirus alone as not enough.

Recovery

Encrypted, tested backup

Backups kept offline or in a form that cannot be altered or deleted, with restore tests that prove they actually work. This is what lets you recover from ransomware without paying, and untested backups fail at the worst moment.

Access

Access controls and least privilege

Each person has their own account with only the access their job needs, admin rights are limited and kept separate from daily use, and access is removed when someone leaves. It limits how far one compromised account can reach.

For a plain-English walk through each control and why the insurer asks for it, see the free cyber-insurance requirements explorer.

The gap that gets a claim denied

Underwriting has moved from a checked box to evidence. Carriers now want exports and proof of working controls, not a self-attestation, and the gap that hurts is the space between what you said on the application and what was actually running the day of the incident.

That gap is concrete. Funds-transfer fraud and business email compromise make up the largest share of cyber claims, around 56 percent, at roughly 100,000 dollars in average loss (Coalition 2024 Cyber Claims Report). If a carrier reviews the claim and finds a control you attested to was not in place, the policy you have been paying for can be denied, or even rescinded. A denied claim means you eat the whole loss yourself, after also paying every premium.

In Travelers v. International Control Services (2022), an insurer obtained rescission of a policy after the insured was alleged to have misrepresented its multi-factor authentication. The fix is to make every attested control genuinely true and keep the evidence that proves it.

The same controls do double duty. They are the ones that stop a fraudulent wire from clearing, so this work protects the money and the policy at the same time.

What we deliver

A gap assessment

We take the controls the carrier asks about, check each one against how your office actually runs today, and hand you written findings: what is in place, what is missing, and what to fix before you sign the application. It is a fixed, bounded first step, not a rip-and-replace.

An underwriting-evidence pack

Once the gaps are closed, we assemble the proof a carrier now expects: documentation that MFA is enforced, that email authentication is set to reject spoofed mail, that EDR is deployed, and that backups are tested. You answer the questionnaire honestly with the evidence sitting behind every answer.

An ongoing layer that keeps it true

Controls drift. A setting gets changed, a new laptop skips EDR, a backup quietly stops running. The recurring layer keeps the attested controls in place and the evidence current between renewals, so the policy you bound this year is still the policy you can claim on next year.

Ready versus not ready

StageNot readyReady
QualifyA missing required control means the carrier will not quote.The required controls are in place, so you get a quote.
BindYou guess on the questionnaire and hope the answers hold.You answer honestly because every answer is documented.
ClaimA look back finds a gap, the claim is denied, you eat the loss.The evidence matches the attestation, so the claim stands.

The questionnaire

What the application asks, and which plan covers it

A cyber-insurance application is mostly a controls questionnaire. Below is each control it keeps asking about, what the question is getting at, and the plan tier that includes it. Wording varies by carrier, and the cyber-insurance requirements explorer walks through each one on its own.

MFA on email and remote access
Applications ask whether a second check beyond the password is enforced on email, on remote access, and on administrator accounts. It is the control they ask about most.Included from Tier 1 Manage. On the plans page: MFA, least-privilege roles, and conditional access.
Endpoint detection and response
Applications ask whether software on every computer and server watches for malicious behavior and can isolate a machine that looks compromised. The question is every endpoint, not most of them.Included from Tier 1 Manage. On the plans page: Endpoint protection (EDR), always-on, tool-based monitoring.
Tested offline or immutable backup
Applications ask whether a backup copy sits where ransomware cannot alter or delete it, and whether a restore has actually been tested. Both halves get asked.Included from Tier 1 Manage. On the plans page: Encrypted offsite backup with tested recovery.
Security awareness training
Applications ask whether staff are trained to spot phishing and how often that training runs. Simulated phishing tests are the usual record.Included from Tier 1 Manage. On the plans page: Security awareness training and phishing tests.
Patch cadence
Applications ask how quickly critical updates reach servers and workstations. What they want is a schedule with a record behind it, not an intention.Included from Tier 1 Manage. On the plans page: Software and security updates after hours, plus vulnerability scanning with fixes tracked.
Incident response plan
Applications ask whether the plan is written down and whether anyone has exercised it. A tabletop walkthrough of a real scenario is how that exercise gets documented.Included from Tier 2 Comply. On the plans page: Incident response plan, rehearsed with a tabletop.
Privileged access management
Applications ask how administrator rights are limited, kept separate from daily-use accounts, and reviewed. The review part needs a record someone signed off on.Included from Tier 1 Manage, with the reviews at Tier 2 Comply. On the plans page: MFA, least-privilege roles, and conditional access at Tier 1, then access reviews, with sign-off you can show an auditor, at Tier 2.

Naming a tier is about what is included, not about what a carrier decides. The evidence pack documents each control so every answer on the application has proof behind it.

Each tier includes unlimited in-scope support. Work outside your plan is quoted separately. Full tier detail is on the plans page.

Common questions

Three things, in plain terms: you can answer the carrier questionnaire honestly and qualify, you can bind the policy because the controls they require are genuinely in place, and you keep written evidence so a claim is not denied later over a control you attested to. It is not about a cheaper premium. It is about being insurable and staying covered when you need to file.

Written by Hammad Arain, founder of Arain Systems. CCNA, CompTIA Security+, Microsoft AZ-104. Updated June 2026. Educational, not legal advice.

Get a free wire-fraud and insurability review

We check the controls a carrier would ask about against how your office runs today, show you where the gaps are, and give you written findings.

Get a free gap report

Who this is for

Any office that has to answer a carrier questionnaire or an E&O application and needs the attestation to be true.

On-site across the Houston metro. See the cities we cover.