Cyber insurance 2025: what you must have to qualify — and how MDR cuts your premium.
Insurers now audit your controls before issuing coverage. Organizations with MDR report 97.5% lower premiums. Here's exactly what you need.
The cyber insurance market that exists in 2025 is fundamentally different from the one that existed five years ago. Insurers absorbed catastrophic ransomware losses from policyholders in 2020-2022 and responded by raising premiums dramatically, tightening underwriting requirements, and — in an increasing number of cases — denying claims based on security control failures that weren't discovered until a breach made them relevant.
For Tennessee businesses renewing cyber insurance in 2025, the conversation has shifted from "how much coverage do we need" to "do we qualify for coverage at all, and at what premium?"
The controls cyber insurers require in 2025
While requirements vary by carrier and coverage level, the following controls have become de facto prerequisites for most commercial cyber insurance policies:
- Multi-factor authentication: Required on email, VPN, remote desktop, privileged access, and cloud services. This is now binary — either you have MFA on all external-facing services or your application may be declined or rated significantly higher.
- Endpoint detection and response: Antivirus is explicitly insufficient for most carriers. EDR — behavioral endpoint monitoring — is now listed as a required control in most underwriting questionnaires.
- 24/7 security monitoring: Carriers are increasingly distinguishing between "monitoring tools" and "monitored with human analysts." The former doesn't satisfy the requirement; the latter does.
- Privileged access management: Controls on administrative account access, particularly for Active Directory, backup systems, and cloud consoles.
- Tested offline backups: Backups that ransomware cannot reach, tested for recoverability. Backup systems that are online and reachable do not satisfy this requirement.
- Patch management: Documented process for applying critical patches within defined timelines.
- Incident response plan: A documented, tested IR plan with defined roles and external contact information.
How MDR changes your premium
The Sophos Quantifying ROI Report (February 2025) found that organizations using MDR report 97.5% lower cyber insurance premiums than those relying on endpoint protection alone. The actuarial reason is straightforward: MDR fundamentally changes the risk profile. With 24/7 behavioral monitoring and an active response team, the probability and severity of a catastrophic breach event — the kind that generates large claims — drops dramatically. Insurers price that reduced risk into premiums.
In practical terms, a business spending $10,000 annually on basic cybersecurity and paying $50,000 in annual cyber insurance premiums may find that spending $20,000 on managed security (including MDR) reduces their insurance premium to $15,000 — producing a net saving while simultaneously increasing their actual security posture.
Claim denial: what to know before you need to file
Cyber insurance claim denials are increasing. Common grounds: EDR not deployed on all endpoints despite attestation, MFA not enforced on email despite attestation, backup systems found to be encrypted by ransomware, security monitoring described as "24/7" but actually running on business hours. The underwriting questionnaire you sign when applying for coverage is a legal attestation. Discrepancies discovered during a claim investigation may constitute misrepresentation and void the policy. Getting your controls right before a breach — not discovering the gap during one — is the only reliable approach.