Cyber Insurance: The Technical Requirements to Meet
MFA, EDR, backups, patching: the technical controls cyber insurers demand before covering your SMB, and how to put them in place with Microsoft Intune.
Buying cyber insurance is no longer a matter of quickly filling in a declaration form. Faced with the surge in ransomware, insurers now tie coverage, deductibles and premiums to concrete technical measures that can be verified after a claim. A poorly completed questionnaire or a missing control can lead to a reduced payout, or an outright denial. Understanding what the insurer expects, and knowing how to implement it across your entire fleet, has become a financial issue as much as a security one.
The logic is simple: the insurer wants to measure your real exposure to risk. The more controlled, documented and up to date your fleet, the lower the risk, and the more accessible the coverage at a reasonable price. Conversely, an approximate declaration turns against you the day you must prove the measures you claimed were actually in place. Here are the most common requirements and, above all, how to meet them concretely.
Why insurers are tightening their requirements
The cyber insurance market has been badly shaken by the ransomware wave of recent years. Claims outpaced premiums, forcing insurers to rethink their model. Rather than refusing everyone, they chose to select and support companies able to demonstrate a minimum security baseline.
- Ransomware almost always exploits the same entry points: phishing, accounts without MFA, unpatched software flaws.
- The required measures are precisely those that block these vectors at low cost.
- The insurer wants to verify afterward that the declared measure was actually active at the time of the attack.
- A company that can prove due diligence enjoys lower premiums and reduced deductibles.
The four pillars insurers demand
Questionnaires differ from one insurer to another, but four controls come up almost every time, because they are the measures that most reduce the risk of ransomware and account compromise.
- Multi-factor authentication (MFA) on every access point: email, VPN, admin accounts and cloud apps.
- Endpoint detection and response (EDR or next-gen antivirus) active and monitored on every device.
- Regular, tested and isolated backups following the 3-2-1 rule to recover quickly after ransomware.
- Patch management: operating systems and third-party apps kept up to date within short, documented deadlines.
MFA and blocking legacy authentication
Multi-factor authentication is the number-one measure, because it neutralizes most credential-theft attacks. But beware: MFA on email is useless if legacy authentication (basic POP, IMAP, SMTP) stays open and bypasses it. An insurer looks at real coverage, not the ticked box. With Microsoft Entra Conditional Access, you enforce MFA for all users and block legacy protocols in a single policy.
Active, monitored EDR
A classic antivirus no longer cuts it: insurers ask for a detection-and-response solution able to spot suspicious behavior, not just known signatures. Microsoft Defender for Endpoint, built into the ecosystem, meets this requirement. The key is monitoring: the tool must be active on every device and reporting its alerts, which you verify through compliance policies.
Isolated and tested backups
The 3-2-1 rule (three copies, two media, one off-site and isolated) remains the reference. But a backup that is never tested is a false sense of security: insurers ask for regular restore tests. A backup permanently connected to the network can be encrypted by the ransomware along with everything else, so isolation is essential.
System and application patching
Remediation deadlines are often written into the contract: for example, applying critical patches within fifteen or thirty days. This applies to the operating system but also, and this is the most overlooked point, to third-party applications.
Turning requirements into Intune configuration
The good news: most of these measures apply natively through Microsoft Intune and Conditional Access, with no extra tooling or outside provider. Here is how to proceed concretely.
- 1Create a Conditional Access policy enforcing MFA for everyone and blocking legacy authentication.
- 2Deploy and monitor Microsoft Defender for Endpoint across all managed devices.
- 3Configure Windows Update for Business update rings, staggered by group.
- 4Deploy the latest versions of browsers and third-party software through Intune, then verify coverage.
The weak spot most often overlooked is third-party application patching. Windows Update covers neither Chrome, nor Zoom, nor a PDF reader, nor most line-of-business utilities. An insurer that discovers, during the post-claim investigation, that an outdated browser version served as the entry point can argue a failure of due diligence and sharply cut the payout.
Common mistakes that cost dearly
Some blunders recur regularly and weaken coverage just when you need it most. Knowing them helps you secure your declaration.
- Declaring MFA "enabled" when it only covers some accounts or lets legacy protocols through.
- Treating a built-in antivirus as an EDR, when the insurer expects behavioral detection.
- Forgetting third-party apps in the patch policy and tracking only Windows Update.
- Keeping no dated evidence of the fleet's state, making any demonstration impossible after the fact.
- Ignoring remote-work devices, often outside the scope of centralized controls.
Prove compliance, don't just declare it
During an audit or after a claim, you must document the fleet's real state: MFA coverage rate, compliant devices, software versions actually deployed, remediation dates. An up-to-date inventory and dated reports carry far more weight than a self-declaration, which can be turned against you if it proves inaccurate.
Ideally you should have, at any moment, a consolidated view proving that each requirement is genuinely applied across every device, and not merely configured on paper. This ability to prove, even more than the measure itself, makes the difference when negotiating the premium and when the payout is on the line.
How AuPoint helps
AuPoint helps SMBs and MSSPs cover these requirements without PowerShell expertise: guided rollout of MFA and Conditional Access, Defender activation and monitoring, a complete software inventory of the fleet, detection of vulnerable apps and their associated CVEs, then patch deployment through Intune using official vendor installers, with no reliance on winget on endpoints. You get a clear dashboard to answer your insurer's questionnaire, and above all to prove it when it matters.
Frequently asked questions
Is MFA on email enough for the insurer?
No. Insurers expect MFA on all sensitive access: email, VPN, admin accounts and cloud apps. They also check that legacy authentication, which bypasses MFA, is blocked. Partial coverage can be enough to reduce the payout.
Does Windows Update meet the patching requirement?
Only partly. Windows Update maintains the operating system, but not browsers, PDF readers and other third-party software, which concentrate a large share of exploited vulnerabilities. The patch policy must include these apps, with proof of deployment.
How do I prove the measures were active during a claim?
By keeping dated reports: compliance rates, a time-stamped software inventory, a history of patch deployments. A platform that archives these states lets you demonstrate due diligence after the fact, which a simple declaration cannot.
Don't let a badly ticked box weaken your coverage. With AuPoint, align your Intune fleet with your insurer's requirements and keep, continuously, the proof that each measure is genuinely applied. Request a demo to see your compliance level in minutes.