The modern commercial cyber liability application has ten or more categories of control questions. They are not equally weighted. If you read the carrier commentary, the claims data, and the government's own ransomware guidance side by side, three controls keep surfacing as the ones that carry disproportionate weight in whether a renewal goes well: multi-factor authentication, endpoint detection and response, and tested immutable backups.
This is not a claim that the other seven categories don't matter. They do. But an applicant strong on these three and weak elsewhere generally has a path to a quote. An applicant weak on these three and strong elsewhere often does not. Here is why these three, specifically, decide so much.
The loss data points at these three.
Coalition's 2025 Cyber Claims Report, covering full-year 2024 data, reports that Coalition policyholders experienced approximately 73% fewer claims than the broader industry average. Coalition attributes the gap to the proactive security posture it underwrites for and monitors. The report does not present the difference as luck. It presents it as a function of controls.
When you decompose the claim categories that drive cyber loss (ransomware on the severity side, business email compromise and funds transfer fraud on the frequency side), the controls that interrupt those loss paths are a short list. MFA interrupts the credential-theft path that leads to both BEC and ransomware initial access. EDR interrupts the lateral-movement and execution phase that turns an intrusion into an encryption event. Tested immutable backups weaken ransomware extortion by making recovery possible without paying.
Carriers underwrite against loss. The three controls that most directly interrupt the highest-loss paths are, predictably, the three controls carriers weight most heavily on the application. The underwriting is not arbitrary. It mirrors the loss data.
The government recommends exactly these three.
A useful tell that these three controls are not a carrier marketing construct: the U.S. government, with no financial stake in your insurance premium, recommends the same three.
The CISA and MS-ISAC #StopRansomware Guide (joint federal guidance, not an insurance document) explicitly recommends multi-factor authentication, endpoint detection and response, and maintained offline or immutable backups as primary defenses against ransomware. The guide names other controls too, but these three are foundational in its recommendations.
When the carrier's claims data and the government's threat guidance independently converge on the same three controls, it is reasonable to treat them as the load-bearing controls of a defensible security posture. The carrier wants them because they reduce the carrier's losses. CISA wants them because they reduce the nation's ransomware exposure. The interests differ; the recommended controls are the same.
What "good" looks like on each of the three.
The applicant who treats these three as binary yes/no questions misses what the underwriter is actually evaluating. Each has a depth dimension.
Multi-factor authentication. The weak answer is "yes." The strong answer specifies enforcement across every authentication surface (email, VPN, RDP, all administrative accounts, all cloud applications), with legacy authentication explicitly disabled. Marsh's market commentary makes the point that MFA is most effective, and most credited by underwriters, when it is implemented fully rather than partially. The gap that voids the value is the carve-out: the service account on legacy auth, the third-party VPN without MFA, the admin account that was an exception.
Endpoint detection and response. The weak answer is the platform name. The strong answer is the coverage percentage plus the operational cadence: what fraction of endpoints are actually covered, who reviews the alerts, on what schedule, and what gets escalated. EDR deployed and ignored is, for loss purposes, close to EDR not deployed. Underwriters increasingly probe the operational reality, not just the procurement.
Tested immutable backups. The weak answer is "we have backups." The strong answer addresses four properties: immutability, encryption, restore-test cadence, and segregation from production credentials so that ransomware against production cannot also destroy the backups. The most common documentation gap in this category is the restore test that was never recorded. Backups that exist but have never been restored from are an assumption, not a control.
Why the renewal hinges here.
The Insurance Journal's coverage of the Arctic Wolf Cyber Insurance Outlook Report reported that 26% of cyber insurance rejections cited inadequate security controls and that carriers increasingly impose additional controls as an explicit condition of renewal. The article does not name the specific three. It stays at the level of "inadequate controls", but the underwriting reality the broader sources describe is consistent: the controls a carrier conditions a renewal on are the controls whose absence the carrier's loss data has shown to be expensive.
For an SMB facing a renewal, the practical implication is a prioritization decision. Limited time before the renewal date is best spent making these three controls both real and documented, in that order:
- Real first. If MFA has carve-outs, close them. If EDR coverage is incomplete, complete it. If backups have never been restore-tested, test them.
- Documented second. The configuration export, the coverage report, the restore-test log. The carrier increasingly wants the artifact, not the assertion.
Get these three right and documented, and most of the renewal conversation goes well even if the other categories are merely adequate. Get these three wrong, and strength elsewhere rarely compensates. The application has many questions. These three answer most of the underwriter's actual question, which is whether your environment is positioned against the losses the carrier knows it underwrites.