Mapped to CIS Controls IG1 via Control Assist

Your cyber application stopped taking your word for it.

The questions on a cyber insurance application look much as they always did. What sits behind them does not. Underwriters increasingly want to know whether a control was actually running, actually enforced, and actually tested, and they ask for something that shows it. Six questions, and you will know which of your answers would survive a follow-up.

A self-assessment, not insurance advice. Underwriting decisions belong to the carrier.·Checked July 2026

Not whether you have it. Whether you can show it.

Five of these mirror the areas every SMB application concentrates on. The sixth is the one that has changed, and it is usually the one that decides how the rest are read.

1. Where is multi-factor authentication actually enforced?
2. What is running on the endpoints?
3. Backups: running, out of reach, and tested?
4. Is there a written incident response plan?
5. Security awareness training
6. If an underwriter asked you to prove one of the answers above, could you?

Answer the six questions and your readiness readout appears here, including which answers are most likely to draw a follow-up.

Different carriers, the same ground

Forms vary. What they are trying to establish does not. Some carriers ask for more than this. Almost none ask for less.

AreaWhat is actually being askedWhere it usually falls down
Multi-factor authentication Whether it is enforced on remote access, VPN and administrator accounts, not just on email. Enforced on email, assumed everywhere else.
Endpoint protection Whether real detection and response runs on every machine, including the laptop somebody takes home. Bundled antivirus counted as endpoint detection.
Backups Three things: they run, at least one copy is somewhere an attacker who owns the network cannot reach, and somebody has restored from them. The third one. Backups nobody has ever tested.
Incident response plan A document that names who gets called, in what order, with what authority. A concept of a plan rather than a document.
Security awareness training Whether staff are trained on a schedule, and whether there is a record of who completed it. Training happened; nobody kept the record.

This is a plain-language summary of the ground SMB cyber applications cover, not a reproduction of any carrier's form. Your carrier's questions are the ones that count, and your broker has them.

Three answers that stall a submission

Almost never because the business is uninsurable. Nearly always because an answer cannot be supported.

"Yes, mostly."

MFA on email but not on the VPN. Backups running but never tested. A partial yes recorded as a full yes is the most common way an application becomes a coverage problem later, because it reads as a clean answer right up until somebody checks.

"Our IT company handles that."

Often true, and still not an answer. Somebody has to know what is configured, and in a lot of small businesses nobody has asked the IT provider that question in writing.

"We have a policy for that."

Usually means a document exists. The follow-up question is whether anything attaches to it: a schedule, a record, a date. A policy with no evidence of operation behind it can be worse than none, because it establishes that the business knew what it should have been doing.

The pattern underneath all three

The person who signs the application is almost never the person who knows the answers. The owner or office manager fills it in, the IT provider holds the actual configuration, and the two never compare notes. The cheapest fix is to have whoever manages the systems initial each answer before it goes back.

Why this outlives the policy. An application is a document the business signs, and the answers can be read again if a claim is made. If a control was recorded as in place and was not, the exposure can move back to the business at precisely the moment the policy was meant to help. That is why an unsupported yes is a bigger problem than a no. A no is just a gap, and gaps have known fixes.

There is now a public answer to "what does good look like?"

And usefully, it does not come from a vendor.

On November 19, 2025, the Center for Internet Security and CyberAcuView released Control Assist, which aligns the CIS Critical Security Controls Implementation Group 1, the 56 safeguards that make up basic cyber hygiene, with the questions that appear on cyber insurance applications. CIS described the problem it solves as SMBs struggling to translate their security efforts into language insurers understand. CyberAcuView described it as translating essential controls into the language of underwriting.

The reason it is worth knowing by name: AIG, AXIS, Beazley, Chubb, The Hartford, Liberty Mutual and Travelers are named as supporting insurers. If somebody asks why a small business should care about a security framework, seven carriers is a better answer than anything a consultant can tell them. It is free and public.

You will notice there are no percentages on this page

There is a great deal of material circulating with confident figures on how many applications get declined, how far premiums rise, and what proportion of carriers now mandate a given control. Almost all of it traces back to marketing rather than to a source you could check, and much of it cites other marketing.

We only put numbers in front of people when we can point at where they came from. So this page names a framework, the two organisations behind it, the date it was published, and the carriers supporting it, all of which you can verify in a minute. The statistics are left to whoever can source them.

Common questions

What do cyber insurance applications ask for in 2026?

Whatever the carrier and whatever the form, SMB applications concentrate on the same five areas: multi-factor authentication on remote access, VPN and administrator accounts rather than email alone; endpoint detection and response running on every device; backups that run, keep at least one copy an attacker on the network cannot reach, and have actually been restored from in a test; a written incident response plan that names who is called and in what order; and security awareness training delivered on a schedule with a record of who completed it. Some carriers ask for more. Almost none ask for less.

Why do cyber insurance applications get stalled or declined?

Most often because an answer cannot be supported rather than because the business is uninsurable. Three patterns account for the majority: a partial yes recorded as a full yes, such as multi-factor authentication on email but not on the VPN; deferring to an IT provider without anyone having confirmed in writing what is actually configured; and pointing at a written policy that has no schedule, record or date attached to show it operates. The underlying problem is that the person who signs the application is usually not the person who knows the answers.

What is Control Assist and who is behind it?

Control Assist is a free framework released on November 19, 2025 by the Center for Internet Security and CyberAcuView. It aligns the CIS Critical Security Controls Implementation Group 1, the 56 safeguards that make up basic cyber hygiene, with the questions that appear on cyber insurance applications, so a business can describe its security in terms an underwriter recognises. AIG, AXIS, Beazley, Chubb, The Hartford, Liberty Mutual and Travelers are named as supporting insurers.

Does a cyber insurance application matter after the policy is bound?

Yes. An application is a document the business signs, and the answers can be reviewed if a claim is made. If a control was recorded as in place and was not, the exposure can move back to the business at exactly the moment the policy was supposed to help. That is why an answer nobody can support is a larger problem than a no, which is simply a gap with a known fix.

Can this check tell me whether I will be approved for cyber insurance?

No, and nothing can. Underwriting decisions belong to the carrier, appetite differs between carriers and changes over time, and every application is read alongside the industry, revenue, claims history and controls of the specific business. This check is a self-assessment of whether your answers would survive a follow-up question, which is a different and more useful thing to know before you submit.

The questions change. This page will not tell you when.

A control that was optional on last year's application can be the reason this year's gets held up.

Security, Sized Right is a monthly issue on what actually changed: what underwriters started asking for, what the enforcement record shows, and what either one means for a practice too small to have a security team. It is written from real client work, not from vendor research.

You can read the current issue in full before deciding whether to subscribe.

Most of this is one assessment away.

The controls on a cyber application are the same ones a CIS Controls IG1 or HIPAA security risk analysis walks you through, and the output is the dated, documented record an underwriter is asking to see. Seqora runs both as guided assessments. See a finished sample, or run one on a demo business right now. No signup.