The short version
- Insurers demand multi-factor authentication with no exceptions for email access, VPN and remote access, administrator accounts and privileged application access. SMS as a second factor is increasingly rejected.
- For backups the 3-2-1 rule applies — three copies, two media, one off-site — with at least one copy offline or immutable, and documented restore tests.
- Flat networks are considered no longer acceptable: VLAN separation between client and server networks is expected, along with blocking direct access such as SMB or RDP from client into server networks.
- These points are ongoing obligations. If they are not met when a claim arises, the insurer can reduce or refuse payment.
A few years ago a cyber insurance application looked like a form. Today it looks like a technical audit — and that is no accident: insurers have learned which claims they had to pay and which gaps sat behind them.
Multi-factor authentication: the question it hangs on
MFA is where most applications fail or become expensive. It is required not selectively but across four areas: email access (Microsoft 365, Google Workspace, on-premises Exchange), VPN and remote access, administrator accounts and privileged application access. Exceptions are not envisaged.
There is also a tightening on method: SMS as a second factor is increasingly rejected in favour of app or hardware tokens. Anyone who introduced MFA three years ago using SMS may no longer meet the requirement today — without anything having changed on their own premises.
Backup: the word that matters is “tested”
The 3-2-1 standard is required: three copies, two different media, one off-site. At least one copy must be offline or immutable — an air gap, write-once media, or object lock in object storage. And restore tests must be documented regularly.
That last point is where most organisations stumble in practice. A backup whose restore has never been verified is a hope when a claim arrives. To the insurer it is an unmet obligation.
The points that sit in the network
Three of the required measures cannot be handled by software on the workstations. They are network work:
Separation of client and server networks
Flat networks are considered no longer acceptable. VLAN separation between workstations and servers is expected — and, where present, between office and production.
Blocked direct access
Direct SMB or RDP connections from the client into the server network should be prevented by firewall rule. Those two protocols are the usual path along which ransomware spreads.
Controlled remote access
Every path from outside — home office, IT provider, machine builder — needs MFA and a named authorisation. The forgotten maintenance link of a former supplier is the classic finding.
Traceable patch management
What gets asked is the process, the tools and the response times — with evidence of when which system was updated. Routers, firewalls and switches count; they are the most frequently forgotten.
Anyone with those four in place also answers much of the supply chain questionnaire customers now send — the requirements overlap almost entirely. More on that in the article about your customer's NIS2 questionnaire.
The order that makes sense
If everything cannot happen at once — and it rarely can — the order by effect per effort is: MFA on email and remote access first, then a tested restore run, then separation of client and server networks, then the rest. The first two steps cost little and cover the most common causes of loss.
One point often gets lost here: the answers in the application are assurances. Ticking what is about to be implemented moves the problem into the claim — where it is most expensive. How we build smaller networks so these questions are answerable is described on our page for smaller companies.
Sources
Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.
- Cyber insurance 2026: what insurers demand from SMEsopens in a new tab
DATAZONE · retrieved 2 August 2026
- Cyber insurance obligations for SMEsopens in a new tab
ING-ISM · retrieved 2 August 2026

