Two professionals discussing documents during a business meeting in a bright office with natural light.

What Cyber Insurance Underwriters Actually Look at During a Security Assessment (And How to Pass)

August 28, 2026

In This Article


Underwriters shifted from checkbox questionnaires to scored technical controls applications after ransomware losses made flat-rate coverage untenable. Carriers like Coalition, Corvus, and At-Bay now weight specific controls, meaning your answers determine both whether you qualify and what you pay.

From Checkbox to Scored Controls

The old application asked whether you had a firewall and antivirus. Modern applications ask whether MFA is enforced on every remote access method, whether EDR covers 100% of devices, and whether backups are tested and air-gapped. A checkbox "yes" that doesn't survive a follow-up question is a liability at claim time.

Mid-Term Audits and Renewal Scrutiny

Carriers now trigger mid-term audits and apply tighter scrutiny at renewal. For Raleigh-area SMBs, especially professional services and light manufacturing firms across the Research Triangle, a policy that renewed easily two years ago may face surcharges or non-renewal if security posture hasn't kept pace.

The 7 Controls Underwriters Score First (And What "Pass" Actually Means)

Passing an underwriter's security review means each control is correctly configured and documented, not just licensed. Seven controls appear on nearly every modern cyber insurance application, and several trigger automatic decline or significant surcharge if answered incorrectly.

EDR (Endpoint Detection and Response): Security software that monitors endpoint devices in real time, detects suspicious behavior, and enables rapid response, distinct from traditional antivirus, which only scans for known signatures.
  • Multi-Factor Authentication (MFA) on email, VPN, and privileged accounts: MFA must cover all three. A carrier asking "Do you enforce MFA on remote access?" is looking for VPN and RDP coverage specifically. MFA on Microsoft 365 but not your VPN concentrator still fails most questionnaires. This is an automatic decline trigger at most major carriers.
  • EDR on all endpoints: Coverage must be 100% of managed devices, centrally monitored, not self-managed antivirus rebranded as EDR. Coalition and At-Bay specifically ask whether EDR is centrally monitored.
  • Offline or immutable backups with tested restore capability: Backups must be isolated from production so ransomware cannot encrypt them. "Immutable" means storage cannot be modified for a defined retention period. Underwriters ask whether restores are tested—not just whether backups run. Documented tested recovery capability with a restore time objective on record is what "yes" requires.
  • Patching cadence—critical patches within 30 days: Underwriters define "critical" as CVSS 9.0 or above. Vulnerabilities left unpatched beyond 30 days are both a scoring penalty and a frequent cause of claim denial.
  • Privileged Access Management (PAM) and least-privilege enforcement: PAM controls, monitors, and audits administrative accounts. Least-privilege means users and service accounts have only required permissions. Shared admin credentials and standing domain-admin rights are red flags on underwriting calls.
  • Security awareness training with documented phishing simulation: A one-time annual video does not satisfy this control. Underwriters expect recurring training, typically quarterly, plus documented phishing simulations with pass/fail metrics.
  • Written incident response (IR) plan: The plan must exist on paper, be assigned to named individuals, and have been reviewed within the past 12 months. Carriers increasingly ask for the date of last tabletop exercise.
Control Common "Pass" Threshold Auto-Decline Risk if Failed
MFA on email, VPN, privileged accounts 100% coverage across all three Yes — most carriers
EDR on all endpoints 100% managed, centrally monitored Yes — Coalition, At-Bay
Offline/immutable backups + tested restore Isolated storage, documented restore test Heavy surcharge or exclusion
Critical patching within 30 days CVSS 9.0+ patched within 30 days Surcharge; claim denial risk
PAM / least-privilege No shared admin credentials; scoped access Surcharge
Security awareness + phishing simulation Recurring training, documented metrics Scoring penalty
Written IR plan Named roles, reviewed within 12 months Scoring penalty

What Underwriters Find When They Look Beyond Your Application

Carriers like Coalition and At-Bay run automated external attack-surface scans before binding. A clean application paired with an exposed perimeter results in denial, coverage exclusions, or immediate remediation requirements, regardless of your answers.

External Attack-Surface Scanning

An external attack-surface scan probes your internet-facing infrastructure for open RDP ports, exposed administrative panels, unpatched public-facing services, and known vulnerabilities. Coalition and At-Bay perform these scans as standard pre-binding procedure. Results are compared against your application answers, and discrepancies are treated as misrepresentation.

Dark-Web Credential Exposure

Carriers also check whether your domain's credentials appear in known breach databases. If employee passwords are circulating on dark-web markets, underwriters treat that as an active risk indicator, even without an internal breach disclosure. American Frontier's cybersecurity services include external perimeter scanning and credential exposure monitoring through our vCSO advisory, addressing exactly what carriers check before issuing your policy.

The Misrepresentation Risk

Answering "yes" to a control you don't fully have configured is grounds for coverage rescission at claim time. If your carrier's scan finds open RDP ports and your application stated all remote access is MFA-protected, that contradiction can void your policy when you need it most.

How to Close the Gaps Before Your Renewal Date: What a Cyber Insurance Readiness Assessment Covers

American Frontier's Cyber Insurance Readiness Assessment maps your security controls against underwriter scoring criteria, identifies gaps, and produces a prioritized remediation plan ranked by underwriter impact, before your renewal, not after a denial.

What the Assessment Includes

  • Internal controls audit: Review of MFA coverage, EDR deployment, backup configuration, patching cadence, PAM setup, training records, and IR plan against current carrier requirements.
  • External attack-surface scan: The same perimeter scan Coalition and At-Bay run, performed by American Frontier before your carrier sees your network.
  • Gap report with remediation priorities: Each gap is ranked by underwriter impact: auto-decline risks first, surcharge triggers second, scoring penalties third.
  • Pre-application attestation letter: Documentation of your control posture that supports accurate application answers and reduces misrepresentation risk.

For Raleigh businesses with policies renewing in Q3 or Q4 2026, the assessment provides lead time to remediate high-impact gaps before your broker submits your application. Organizations with an internal IT team needing targeted gap remediation can engage American Frontier through co-managed IT support to address specific control deficiencies without displacing existing staff.

Frequently Asked Questions

What controls do cyber insurance underwriters require in 2026?

Modern underwriters score seven core controls: MFA on email, VPN, and privileged accounts; managed EDR on all endpoints; offline or immutable backups with tested restores; critical patching within 30 days; privileged access management; documented security awareness training with phishing simulations; and a written, reviewed incident response plan.

Can I get cyber insurance without multi-factor authentication?

Most carriers will automatically decline or non-renew a cyber insurance policy if MFA is not enforced across email, VPN, and privileged accounts. Partial MFA, such as email only, still fails most modern questionnaires. MFA is the single most commonly cited automatic-decline trigger on current carrier applications.

What does a cyber insurance security assessment involve?

A cyber insurance security assessment audits internal controls against underwriter scoring criteria, runs an external perimeter scan to surface the same exposures carriers check, produces a gap report prioritized by underwriter impact, and provides documentation to support accurate application answers and reduce coverage rescission risk.

Why was my cyber insurance application denied?

Denial most commonly results from missing MFA on remote access, no managed EDR, unprotected or untested backups, or a mismatch between application answers and what the carrier's external scan found. Carriers like Coalition and At-Bay run automated perimeter scans before binding, so exposed infrastructure is discovered regardless of application answers.

How long does it take to qualify for cyber insurance after fixing security gaps?

Timeline depends on which gaps exist. Deploying MFA and EDR can be completed in days to weeks. Establishing documented backup testing, phishing simulation records, and a written IR plan typically takes four to eight weeks. Starting a readiness assessment at least 60 days before your renewal date provides enough lead time for most remediation scenarios.

Do small businesses in North Carolina need cyber insurance?

No North Carolina statute currently mandates cyber insurance for most small businesses, but clients, contracts, and lenders increasingly require it—especially in professional services, healthcare-adjacent, and manufacturing sectors. Beyond contractual requirements, cyber insurance for small business provides critical financial protection against ransomware, data breach response costs, and regulatory notification expenses.

What is a cyber insurance readiness assessment?

A cyber insurance readiness assessment is a pre-application review that audits your security controls against underwriter scoring criteria, scans your external perimeter for the exposures carriers check, and produces a prioritized remediation plan. American Frontier's Cyber Insurance Readiness Assessment also provides a pre-application attestation letter to support accurate answers at renewal.

Will my carrier run an external scan on my network before issuing a policy?

Yes. Coalition, At-Bay, and several other carriers run automated external attack-surface scans before binding a cyber insurance policy. These scans check for open RDP ports, exposed admin panels, unpatched public-facing services, and dark-web credential exposure. Findings are compared against your application answers, and discrepancies can result in denial, exclusions, or rescission.

What happens if I misrepresent my security controls on a cyber insurance application?

Misrepresentation on a cyber insurance application is grounds for coverage rescission, meaning your carrier can void the policy and deny a claim after an incident. Carriers compare application answers against external scan results and post-incident forensics. Inaccurate answers, even unintentional ones, create significant financial exposure when a claim is submitted.

Not Sure Your Security Controls Will Pass Your Next Underwriter Review?

Book a free 15-minute discovery call with American Frontier's Raleigh team. We'll assess your systems and let you know what requirements you need to address before your policy renewal.

Schedule A 15-Minute Discovery Call