Five years ago, a cyber insurance application was a formality: a few checkboxes, a premium quote, done. Today the application is closer to a technical audit, and answering it wrong has real consequences. Insurers have paid out enough ransomware claims that they now demand proof of specific security controls before they will bind a policy, and they increasingly deny claims when the application turns out to have been inaccurate. If your Maryland business is coming up on a renewal, or applying for the first time because a client or contract requires coverage, this is what underwriters are actually looking for and what each requirement means in practice.
Why the questions got so hard
Cyber insurance is one of the few lines of insurance where the insurer can directly reduce its own losses by changing the policyholder's behavior. Most ransomware incidents trace back to a short list of preventable failures: a stolen password with no second factor, an unpatched internet-facing system, backups that were connected to the network and encrypted along with everything else. So insurers built their applications around exactly those failures. The controls below are not arbitrary. Each one exists because its absence has cost carriers real money, repeatedly.
The practical consequence for you: the application is now a statement of fact that the insurer may verify, sometimes with external scanning tools, and may rely on to deny a claim. Treat every answer as if it will be checked after a breach, because after a breach it will be.
The core controls almost every carrier requires
1. Multi-factor authentication (MFA)
MFA means a login requires something beyond a password: a code from an app, a push notification, or a hardware key. Underwriters usually ask about three specific places, and you need MFA on all of them:
- Email. Microsoft 365 or Google Workspace accounts for every user, not just administrators. Compromised email is the starting point for most wire fraud.
- Remote access. VPNs, remote desktop, and any tool that lets someone reach your network from outside. Exposed remote desktop without MFA is one of the most common ransomware entry points, and some carriers will simply decline to quote if they scan your public addresses and find it.
- Administrative accounts. Any account that can change settings, create users, or touch backups.
A common trap: answering yes because MFA is available to your users rather than enforced for all of them. Enforcement is what the question means. If four of your forty staff have opted out, the honest answer is no, and an adjuster reviewing a claim will find those four accounts.
2. Endpoint detection and response (EDR)
Traditional antivirus checks files against a list of known bad software. EDR watches behavior: a process encrypting hundreds of files in a minute, a login at 3 a.m. from an unusual location, a legitimate tool being used the way attackers use it. Many carriers now require EDR by name and some ask which product you run, because they track which ones performed well in claims they paid. EDR is almost always deployed and monitored by an IT provider rather than bought directly, since an alert nobody reads at 2 a.m. is worth little. When you evaluate managed providers, ask specifically who watches the EDR console overnight and what they do when it fires.
3. Backups that would survive a ransomware attack
Underwriters do not just ask whether you have backups. They ask whether the backups are separated from the network (offline, or in a cloud service with separate credentials), whether they are encrypted, and whether you have tested a restore. The reasoning is blunt: attackers deliberately find and destroy backups before triggering encryption, because a business with working backups does not pay ransoms. A useful mental model is the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy off-site and disconnected. If your only backup is a drive plugged into the server, or a cloud sync folder that mirrors deletions instantly, you should answer the application accordingly and fix it before renewal.
4. Patching and end-of-life software
Carriers ask how quickly you apply security updates, with a common expectation that critical patches land within days or a couple of weeks, not months. They also ask whether you run software the vendor no longer supports, such as old Windows Server versions, because unsupported systems never receive fixes for newly discovered flaws. If a legacy application forces you to keep an old server alive, the workable answer is isolation: keep it off the internet, wall it off from the rest of the network, and be ready to describe that arrangement on the application.
5. Security awareness training and email filtering
Most applications ask whether employees receive phishing training, often with simulated phishing tests, and whether inbound email is filtered. These are inexpensive controls, and answering no to them signals to an underwriter that nobody is minding the store.
6. The next tier: increasingly common asks
- An incident response plan. A written document naming who you call, in what order, when something goes wrong.
- Privileged access management. Limits on who holds administrator rights and how those accounts are used day to day.
- Email authentication (SPF, DKIM, DMARC). DNS settings that make your domain harder to spoof in wire fraud attempts.
- Logging and retention. Keeping system logs long enough for an investigator to reconstruct an incident.
The Maryland angle
Two local realities raise the stakes here. First, Maryland's Personal Information Protection Act requires businesses to notify affected residents after a breach of personal information, generally within 45 days, and to notify the Attorney General when the incident is large enough. Breach response costs, including legal guidance, notification, and credit monitoring, are exactly what a good cyber policy pays for, which is why having coverage and having it actually pay out both matter.
Second, a large share of Maryland businesses sit inside someone else's supply chain: federal agencies, defense primes around Fort Meade, hospital systems, and financial firms all push security and insurance requirements down onto their vendors. It is now routine for a contract to require both cyber coverage at a stated limit and specific controls such as MFA and EDR. If you sell into the defense industrial base, those contractual requirements converge with formal certification. Our guide to CMMC compliance for Maryland defense contractors covers that path, and the overlap with insurance requirements is substantial: the same controls satisfy both.
A practical order of operations before your renewal
- Get the application early. Ask your broker for the carrier's current form 90 days before renewal. Requirements change year to year, and you want the real questions, not last year's.
- Answer it honestly with your IT provider in the room. Every yes should be verifiable. A denied claim on grounds of misrepresentation is worse than a higher premium.
- Gap-list the noes. MFA enforcement and email filtering are typically quick wins measured in days. EDR deployment is usually weeks. Restructuring backups or replacing end-of-life systems can take a quarter, which is why 90 days matters.
- Fix in risk order. MFA on email and remote access first, then backups, then EDR, then patching discipline, then the paperwork controls like the incident response plan.
- Keep evidence. Screenshots of MFA enforcement policies, backup test logs, patch reports. Evidence speeds underwriting and protects you in a claim dispute.
What this means for your IT provider relationship
Here is the honest tradeoff: nearly everything above is standard equipment in a competent managed services agreement, and nearly none of it exists by default in a business that calls an hourly technician when things break. If you are weighing those two models, the insurance application itself is a useful forcing function; our comparison of break-fix versus managed services walks through the math. But managed providers vary widely in how well they handle insurance work. When you evaluate one, ask directly: Will you complete carrier questionnaires with us and stand behind the answers? Can you produce evidence of MFA enforcement, backup tests, and patch compliance on request? Is EDR monitored around the clock, by whom, and is it included in the base price or an add-on? Getting clear commitments on these points is part of what a well-run RFP process is for, and the answers belong in your service level agreement, not in a salesperson's reassurances.
None of this needs to be overwhelming. The list of controls is finite, well understood, and achievable for a business of almost any size. The businesses that struggle at renewal are the ones that discover the list for the first time with two weeks to go.
Need an MSP that can get you insurable?
We match Maryland businesses with vetted managed IT providers who handle carrier questionnaires, MFA, EDR, and backup testing as standard work, and the matching service is free.
Start Your Free Match