Cyber Insurance Readiness
Your insurer no longer takes your word for it.
Cyber insurers may ask for evidence of MFA, endpoint protection, verified backups, and incident response readiness at application, renewal, and claim time. FCI helps you support your answers with documented controls. Requirements and coverage depend on your insurer and policy.
Cyber insurance readiness means the proof your insurer asks for — MFA enforcement records, EDR coverage, backup verification, incident response documentation — already exists when the application, renewal, or claim arrives. FCI enforces those controls every day and produces timestamped evidence continuously through the FCI Portal, so attestations are backed by proof.
2026 Cyber Claims Study
Real claims show why these controls matter.
NetDiligence’s announcement of its 2026 Cyber Claims Study reports that ransomware and business email compromise (BEC) accounted for 64% of SME claims in 2025. The announcement describes a study of 10,309 claims from 2021–2025.
For financial-services firms, the practical takeaway is to prepare for both disrupted operations and compromised communications — not simply complete an insurance questionnaire.
FCI’s practical recommendations:
Protect identities and payment workflows.
Pair phishing-resistant MFA and email monitoring with independent verification of changes to payment instructions. Confirm changes through a trusted contact using a known phone number, not contact details supplied in the request.
Prove recovery works.
Keep evidence of backup isolation, successful restoration tests, and endpoint protection — not just confirmation that backups ran. Agree on recovery responsibilities with your IT and security providers before an incident.
Prepare the response before the incident.
Establish escalation contacts, rehearse the response plan, and preserve relevant records. Review notification deadlines, response-provider requirements, and any consent requirements with your broker and insurer.
Source: NetDiligence’s 2026 Cyber Claims Study launch announcement. Visit the publisher’s report page. The study spans industries; the 64% figure describes SME claims in its 2025 sample, not the likelihood of an incident or a financial-services-specific rate. The recommendations above are FCI’s interpretation, not outcomes measured by the study.
What Insurers Ask For
The renewal questionnaire is a controls audit.
Renewal questionnaires commonly ask about these five control areas and may request records that show how they operate. Specific requirements vary by insurer, policy, and the firm's risk profile.
“We have MFA” is not the same as “here is evidence that MFA is enforced for every user, on every login, with no exceptions.” Insurers ask for the second. FCI deploys phishing-resistant MFA aligned with CISA Zero Trust guidance and produces the enforcement records insurers require.
Endpoint detection and response deployed, active, and documented — per device, per day, including BYOD. The FCI Portal shows real-time enforcement status across every endpoint, exportable for underwriter review.
Backups that run and are verified — not assumed. FCI documents backup verification as part of cloud app security, so recovery capability is evidenced rather than asserted on the application.
Insurers ask whether users are trained and tested against phishing. FCI runs phishing campaigns and documents the results — tied to individual users, across every registered representative and every branch.
Documented, tested, and backed by a 24×7 SOC with forensic capability — and the experience to work directly with the FBI, regulators, and cyber insurers when an incident occurs.
The Attestation Trap
Your application should reflect the controls actually in place.
Cyber insurance applications ask firms to describe their controls: MFA coverage, endpoint protection, backup testing, and more. Each answer is a representation to the insurer. Verify the scope of your answers, disclose exceptions, and retain supporting records rather than assuming a control is in place.
For Brian Edelman’s advisory on this shift, read Cyber Insurance Applications Are Becoming Evidence Requests. For insurance organizations, also see the NAIC Model Law evidence guide.
An inaccurate answer about a material control can create underwriting or coverage disputes. Verify the control before answering and discuss any uncertainty with your broker. Consequences depend on the policy, applicable law, and the facts.
Documented controls support underwriting and claim review. Coverage and payment depend on the policy's terms, conditions, exclusions, and the circumstances of the incident. Evidence alone does not guarantee payment.
Records help establish which controls were active and what happened during an incident. Missing or inconsistent records can complicate that review. Documentation should accurately reflect both enforcement and any known gaps.
A firm's IT provider turned off multi-factor authentication to simplify upgrade scripts. A phishing site captured credentials. A bad actor wired $700,000 from a client account. When FCI was brought in, the FBI's primary suspect was the advisory firm itself — because without documented controls, the firm couldn't prove what happened.
How FCI Prepares You
The renewal evidence package builds itself, every day.
FCI does not run a renewal-prep project. Every control FCI enforces generates evidence as it runs, and that evidence assembles continuously in the FCI Portal — organized, timestamped, and current. When the questionnaire arrives, the compliance officer doesn't launch a scramble. They open the FCI Portal and export the record.
"The renewal application is pre-supported by the FCI Portal's continuous compliance record — timestamped evidence of enforcement, not just policy statements."
Claim Time
Two versions of claim day.
Documented controls support underwriting and claim review. Coverage and payment depend on the policy's terms, conditions, exclusions, and the circumstances of the incident. FCI helps establish the technical record; it does not determine or guarantee coverage.
After an incident, the insurer may request evidence of the controls described in the application. If logs were not retained, IT must try to reconstruct the record while responding to the breach. Missing information can complicate the investigation and claim review; it does not by itself establish whether coverage applies.
FCI's 24×7 SOC supports incident response through device isolation, forensic evidence preservation, documented remediation, and coordination with the firm's compliance team. Existing timestamped control records help establish what was in place before the incident. FCI supports the technical investigation and coordinates with the insurer and other relevant parties as appropriate. The insurer determines coverage under the policy.
Cyber insurance readiness — common questions
See what your next renewal will ask for — and what you can prove today — in 30 minutes.
FCI works with broker-dealers and branch offices, insurance carriers and agencies, and RIAs. Request a gap analysis. You will have a clear picture of what controls must be in place, what is missing, and what your next cyber insurance renewal, regulatory exam, or home office audit will ask for.