Skip to content
Cybersecurity

What Security Controls Does Cyber Insurance Require From NYC Businesses Now?

Insurers now demand proof that MFA, endpoint detection, tested backups, and incident response plans actually run and were enforced when claims occur.

Manhattan office building facade with stone and glass exterior
116 John Street in Manhattan, New YorkEpicgenius · CC BY-SA 4.0 · via Wikimedia Commons

Cyber insurance underwriters have tightened their requirements sharply in 2025 and 2026. To get approved for coverage—or to keep an existing policy at renewal—New York businesses must now deploy and prove enforcement of a specific set of security controls. The verification standard has shifted from asking whether companies own tools to demanding evidence that those tools actually run, are actually monitored, and were actually running on the day something went wrong.

For most NYC businesses seeking cyber insurance, insurers now require multi-factor authentication across email, VPN, cloud services, and administrative accounts; endpoint detection and response on at least 95 percent of endpoints; immutable or offline backups with documented restore tests completed within the last 90 days; and a written incident response plan with named roles and evidence of tabletop exercises. The stakes are clear: 82 percent of cyber insurance claims denied in recent years involved organizations that lacked multi-factor authentication, and 27 percent of data breach claims end up partially or completely unpaid due to exclusions tied to security control failures.

Multi-factor authentication is now the line

MFA is now treated as a non-negotiable baseline. Insurers require MFA on email, VPN and remote desktop access, cloud applications holding sensitive data, and any administrative account. Partial deployment—protecting email but leaving VPN unsecured, or adding MFA to only some cloud services—raises premiums by 30 to 50 percent or triggers coverage exclusions.

The requirement extends beyond simply turning the feature on. NYDFS's Cybersecurity Regulation Part 500, which applies to covered financial entities in New York, mandates MFA for all user access to all information systems as of November 1, 2025. But cyber insurers go further, demanding what NYDFS calls 'phishing-resistant' MFA. The department's guidance warns that push-based and SMS authentication, while permitted, are vulnerable to modern attacks and should be supplemented with number matching or challenge-response verification that shows the user the details of the login attempt before approving it.

New York courts have shown the cost of this enforcement gap. In Travelers v. ICS, a federal court found that a company's firewall-only MFA contradicted the broader MFA claims made in the policy application, leading to a $1 million policy cancellation. For insurers, the lesson stuck: they now want to see that enforcement actually happened, not just that the tool existed.

Endpoint detection, backups and incident response

Endpoint Detection and Response (EDR) installation alone is no longer sufficient in most markets. Insurers want proof that alerts are being acted on, which is why they increasingly recommend managed detection and response—outsourced 24/7 monitoring and investigation—or evidence that in-house security teams are monitoring and responding to alerts around the clock.

Backups must be immutable, meaning attackers or insiders cannot overwrite or delete them even with admin access, or they must be offline and isolated from the network. Insurers require documentation showing that restoring from those backups actually works, with the most recent test completed within 90 days. Many businesses fall short here: insurers flag companies that have backups but no proof of recent restore testing, and that gap alone can trigger denial of a ransomware claim.

A written incident response plan is non-negotiable. The plan must define roles, escalation procedures, and decision rules for triggering response. Insurers verify this by asking for evidence of tabletop exercises—scenarios where the team walks through a breach without live systems at risk—completed within the past year.

Patch management, email security and access controls

Patching must follow a documented schedule prioritizing internet-facing systems and known exploited vulnerabilities. Insurers want to see evidence that patching is routine, not reactive: a defined service-level agreement for critical patches applied within 14 days, for example, and logs showing it happened.

Email security must include advanced phishing detection, impersonation controls, and DMARC enforcement configured to quarantine or reject messages that fail authentication checks. Insurers also verify that employees can report suspicious emails directly to security teams and that security acknowledges and acts on those reports.

Privileged access management requires separate admin accounts kept in a credential vault, with just-in-time elevation and monitoring of administrative actions. Access to sensitive data should be restricted to roles that legitimately need it, with logs recording who accessed what and when.

New York regulations shape the baseline

NYDFS's Cybersecurity Regulation already requires many of these controls for covered financial entities, and that framework shapes what cyber insurers now demand across all industries. The regulation mandates that covered entities use multi-factor authentication for any individual accessing any information system. As of March 21, 2025, New York's SHIELD Act—which applies to any business holding personal information of New York residents, regardless of where the business is located—now extends its definition of protected data to include medical histories, diagnoses, and health insurance claims and policy data, expanding the scope of businesses that must implement the regulation's required safeguards.

NYDFS warns that it sees MFA deficiencies as the single most exploited gap in breach incidents, and considers 'robust and complete adoption of MFA' one of the most effective and inexpensive ways to reduce risk.

“When carriers deny a claim tied to missing MFA or untested backups, they are enforcing a preventive principle: the security wasn't strong enough to prevent the loss, so the policy shouldn't have been issued in the first place.”

Non-compliance now triggers denials and exclusions

The cost of falling short has become immediate and visible. In 2025, approximately 21 percent of cyber insurance claims were denied or partially denied, up from 15 percent in 2023. The primary driver is failure to maintain attested security controls. When carriers deny a claim tied to missing MFA or untested backups, they are enforcing a preventive principle: the security wasn't strong enough to prevent the loss, so the policy shouldn't have been issued in the first place.

Organizations now face three renewal outcomes: approval with no changes, coverage exclusions that eliminate specific scenarios from protection (ruling out backup recovery claims, for example, if backups weren't immutable), or outright denial. Businesses unable to meet the baseline controls are pushed into surplus lines markets, where premiums can run triple the standard rate.

Insurers are also treating renewal questionnaires as formal audits. A business claiming MFA coverage must provide authentication logs showing MFA enforcement on the loss date. A business claiming incident response capability must show the plan was current and that the team practiced. The expectation is that security controls were not aspirational but enforced.

The 90-day preparation window

Most brokers recommend beginning preparation 90 days before renewal. The timeline reflects the work involved: deploying EDR across 95 percent of endpoints, configuring MFA across all critical systems, testing backups in a production environment, documenting incident response procedures, and gathering evidence that these controls were running and enforced. Rushed implementations and retrofitted controls raise red flags with underwriters and often result in higher rejection rates or premium increases of 40 to 100 percent.


Related