Before Your Next Cyber Insurance Renewal: 7 Security Controls to Review

Cyber insurance applications have become more detailed in recent years. Businesses are often asked specific questions about multi-factor authentication, backups, employee training, endpoint protection, patching and incident response.

The challenge is that the person completing the application may not know exactly how those protections are configured—or whether they are being used consistently across the organization.

Before your next renewal, it is worth reviewing these seven areas.

1. Multi-Factor Authentication

Having multi-factor authentication available is not the same as having it fully enforced.

Make sure MFA is being used for:

  • Microsoft 365 and company email
  • Remote access and VPN connections
  • Administrative accounts
  • Cloud applications containing sensitive information

A single account without MFA can create an unnecessary point of exposure.

2. Endpoint Protection and Monitoring

Most businesses have some form of antivirus, but insurance applications may ask whether the company uses endpoint detection and response, commonly called EDR.

EDR provides more advanced monitoring and can help identify suspicious activity that traditional antivirus may miss. It is also important to know who receives and responds to security alerts when something is detected.

3. Reliable and Tested Backups

A backup is only useful when the data can actually be restored.

Review whether your organization:

  • Backs up critical servers, files and applications
  • Maintains separate protection for Microsoft 365 data
  • Monitors backup failures
  • Protects backups from ransomware
  • Regularly tests the restoration process

Discovering that a backup is incomplete or unusable during an emergency is far too late.

4. Patch Management

Unpatched and unsupported systems can leave known security weaknesses open to attack.

Your company should know which devices are being updated, who is responsible for those updates and whether critical patches are being tracked. Older operating systems and applications that are no longer supported should also be identified and addressed.

5. Email Security and Employee Training

Email continues to be one of the most common ways attackers target businesses.

Technical protections matter, but employees also need to recognize suspicious messages and know how to report them. Training should cover phishing attempts, unexpected attachments, fraudulent payment requests and messages asking users to reset passwords or provide login information.

6. Account and Access Management

Access permissions tend to accumulate over time. Employees change roles, temporary accounts remain active and former users may not always be removed promptly.

Review:

  • Former employee accounts
  • Shared accounts
  • Unused accounts
  • Local administrator rights
  • Access to sensitive files and systems
  • Remote-access tools

Employees should only have access to the information and systems required for their jobs.

7. Incident Response Planning

If a company email account were compromised tomorrow morning, would everyone know what to do?

A basic incident response plan should identify:

  • Who employees should contact
  • Who can disable accounts or devices
  • When the insurance carrier should be notified
  • How leadership and affected parties will be informed
  • How the business will continue operating during an investigation

The plan does not need to be overly complicated, but it should exist before an incident occurs.

Verify Before You Answer

One of the most important parts of completing a cyber insurance application is making sure the answers accurately reflect your environment.

For example, MFA may be enabled for most employees but missing from an older administrative account. Backups may run every night, but restoration may never have been tested. Security training may have been completed once but not repeated for new employees.

These details matter.

Miken Technologies can help your organization review the technical portions of a cyber insurance application, verify the protections currently in place and identify areas that may need attention before renewal.

We are not an insurance provider and cannot guarantee coverage, approval or pricing. Requirements vary by carrier and policy. However, we can help make sure you have a clearer and more accurate understanding of your IT and cybersecurity environment before submitting your application.

Is your cyber insurance renewal approaching? Contact Miken Technologies to schedule a review of your current security controls.