Meet new cyber insurance requirements. Reduce new cyber risks.
A practical guide to Identity Security for cyber insurance, from passing the questionnaire to enforcing control at runtime.
Insurers are asking harder identity questions, and the gap between what you document and what you actually enforce increasingly decides renewals and claims. This guide shows security and identity leaders how to close it.
Get the guide here
AI scales attacks. Identity decides risk.
2bn
~2 billion credentials were harvested through infostealer malware in 2025.
47%
47% of ransomware insurance claims trace back to stolen credentials as the initial access point.
276m
276 million of those credentials carried live session cookies—enough to bypass MFA entirely.
Recorded Future (2025); Coalition Cyber Threat Index 2025
What's inside the definitive guide to Identity Security for cyber insurance
- Why identity has become a core pillar of cyber insurance underwriting
- The identity controls insurers now expect to see and what it takes to actually enforce them
- The most common Identity Security gaps that organizations struggle to close
- Why runtime enforcement is the difference between passing an audit and reducing real risk
- Best practice framework for building an insurable Identity Security program

Passing the questionnaire isn't the same as reducing your risk
Cyber insurance runs on a familiar cycle: audit, remediate, renew. Attackers don’t follow that calendar.
Most identity controls are checked off, but still leave critical gaps. For example:
- MFA that covers the cloud, but not internal authentication
- Privileged accounts that sit outside the vault
- Service accounts that run unmonitored behind critical processes
These are the gaps a point-in-time audit misses and the paths attackers use after login.
The organizations that actually reduce risk enforce controls at runtime, evaluating every authentication, privilege request, and access attempt as it happens.
That’s what shifts the insurance conversation from “here’s what we deployed” to “here’s how we contain an attack in real time.”
Insurers and attackers care about the same thing: do your controls work at the moment that matters?
See how to strengthen your cyber insurance posture by closing identity gaps and enforcing protection at runtime—across every user, privileged account, service account, and AI agent.
FAQs
What identity controls do cyber insurers require?
Does the EU AI Act affect my cyber insurance requirements?
Are cyber insurers starting to ask about AI agents?
Yes, though it’s still an emerging area. AI agents authenticate and act autonomously, often through overprivileged non-human identities that sit outside existing controls. Insurers are beginning to ask how you discover, control, and monitor these identities—not just whether you use AI. Regulatory pressure points the same way: the EU AI Act’s high-risk rules (now set for December 2027) and financial-sector frameworks like DORA both expect organizations to govern and log automated systems, not simply deploy them.
Why is Active Directory such a common sticking point in cyber insurance underwriting?
AD has no built-in MFA, and it’s usually where privileged accounts and non-human identities pile up unmanaged, which makes it a leading driver of ransomware claims. Insurers including Arch, Beazley Security, Sompo, and Howden recognize Silverfort specifically for closing that AD security gap without disrupting AD performance. See how fast, effective AD security works for cyber insurance qualification.