Most cyber insurance policies require specific technical controls to be in place, not just claimed. Here's what insurers check, and how to be ready.
Prisca Nova is not an insurance broker or provider. Requirements vary by carrier and policy. This page is educational, confirm exact requirements with your broker or insurer.
Cyberattacks have become a routine cost of doing business, not a rare event. Cyber insurance exists to help cover that risk, but coverage isn't automatic. Insurers require documented technical controls before issuing a policy, and just as importantly, before paying out a claim.
$4.4M
Average cost of a data breach, globally
$10.22M
Average cost of a data breach, United States
$7.42M
Average cost of a data breach, healthcare industry
$5.56M
Average cost of a data breach, financial services industry
Source: IBM Cost of a Data Breach Report 2025, via Huntress
These costs include detection, notification, legal fees, regulatory fines, and lost business. It's a major reason insurers now require documented controls before offering coverage, and why maintaining those controls matters even after the policy is signed.
Getting approved for a cyber insurance policy is only part of the picture. Most policies require you to maintain the controls you attested to on your application, things like multi-factor authentication, endpoint protection, and tested backups. If a claim reveals that those controls weren't actually in place, insurers can deny the claim entirely. In other words: the goal isn't just to check boxes on an application. It's to actually have the protections in place, so your policy does what it's supposed to do when you need it.
Common security control categories used broadly across cyber insurance underwriting. Specific requirements vary by carrier and policy.
| Requirement | What It Means | Who Handles It |
|---|---|---|
| Email Security | Spam filtering, anti-phishing protection, and email authentication (SPF, DKIM, DMARC) to stop the most common way attackers get in. | Prisca Nova configures and manages this as part of every plan. |
| Endpoint & Network Security | Antivirus alone usually isn't enough anymore. Insurers increasingly look for endpoint detection and response (EDR), firewalls, and network segmentation. Tools like Huntress and SentinelOne represent the kind of endpoint detection and response technology insurers are increasingly looking for, this is the category Prisca Nova builds into managed security plans. | Prisca Nova deploys and monitors EDR across every device we manage. |
| Patching & Vulnerability Management | Operating systems and software kept current, with a documented process for closing known vulnerabilities before they're exploited. | Prisca Nova handles automated patch management as a standard part of managed IT. |
| Backup & Recovery | Regular, tested backups, ideally immutable, so a ransomware attack doesn't also take out your ability to recover. | Prisca Nova sets up and tests backups; you confirm recovery objectives fit your business. |
| Employee Training | Documented, recurring security awareness training, since most breaches start with a click, not a technical exploit. | Prisca Nova provides training as part of our cybersecurity services. |
| Wire Transfer & Process Controls | Written procedures requiring verification (a phone call, a second approver) before wiring money or changing payment details, to stop business email compromise scams. | You and your team, we can help document the policy, but it has to be followed internally. |
Don't have a cyber insurance policy in place? Prisca Nova can point you toward reputable cyber insurance providers and help you get your technical controls in order first, so you're applying from a position of strength, not scrambling to catch up after a denial or a high-premium quote.
Related reading: our Cybersecurity services and Managed IT services pages cover the underlying infrastructure these controls are built on.
Our IT & Security Assessment checks exactly these controls and gives you a clear report, useful whether you're applying for cyber insurance, renewing a policy, or just want to know your real exposure.