Guide

Meet new cyber insurance requirements. Reduce new cyber risks.

A practical guide to Identity Security for cyber insurance, from passing the questionnaire to enforcing control at runtime.

Insurers are asking harder identity questions, and the gap between what you document and what you actually enforce increasingly decides renewals and claims. This guide shows security and identity leaders how to close it.

Get the guide here

AI scales attacks. Identity decides risk.

2bn

~2 billion credentials were harvested through infostealer malware in 2025.

47%

47% of ransomware insurance claims trace back to stolen credentials as the initial access point.

276m

276 million of those credentials carried live session cookies—enough to bypass MFA entirely.

Recorded Future (2025); Coalition Cyber Threat Index 2025

What's inside the definitive guide to Identity Security for cyber insurance

CyberInsuranceBook_mock-up_02

Passing the questionnaire isn't the same as reducing your risk

Cyber insurance runs on a familiar cycle: audit, remediate, renew. Attackers don’t follow that calendar.

Most identity controls are checked off, but still leave critical gaps. For example: 

  • MFA that covers the cloud, but not internal authentication
  • Privileged accounts that sit outside the vault
  • Service accounts that run unmonitored behind critical processes

These are the gaps a point-in-time audit misses and the paths attackers use after login.

The organizations that actually reduce risk enforce controls at runtime, evaluating every authentication, privilege request, and access attempt as it happens.

That’s what shifts the insurance conversation from “here’s what we deployed” to “here’s how we contain an attack in real time.”

privelage_user.svg

Insurers and attackers care about the same thing: do your controls work at the moment that matters?

See how to strengthen your cyber insurance posture by closing identity gaps and enforcing protection at runtime—across every user, privileged account, service account, and AI agent.

FAQs

What identity controls do cyber insurers require?
Most questionnaires now ask about MFA coverage, privileged access controls, and service account visibility, since stolen credentials are behind a large share of ransomware claims. But insurers are moving past checkbox questions. With AI attacks becoming a core risk, they want proof that these controls actually hold at the moment of an attack, not just that they exist on paper.
Indirectly, yes. The EU AI Act’s obligations for high-risk AI systems include cybersecurity and human oversight requirements, and financial-sector rules like DORA, the EU’s Digital Operational Resilience Act, already require banks and insurers to govern AI and third-party technology risk themselves. Insurers are applying the same logic to policyholders: many now ask whether every AI agent has a unique identity, least-privilege access, and logged activity, not just whether you’ve deployed the technology. The EU recently pushed some AI Act deadlines back to 2027, but insurers aren’t waiting for enforcement to start asking.

Yes, though it’s still an emerging area. AI agents authenticate and act autonomously, often through overprivileged non-human identities that sit outside existing controls. Insurers are beginning to ask how you discover, control, and monitor these identities—not just whether you use AI. Regulatory pressure points the same way: the EU AI Act’s high-risk rules (now set for December 2027) and financial-sector frameworks like DORA both expect organizations to govern and log automated systems, not simply deploy them.

AD has no built-in MFA, and it’s usually where privileged accounts and non-human identities pile up unmanaged, which makes it a leading driver of ransomware claims. Insurers including Arch, Beazley Security, Sompo, and Howden recognize Silverfort specifically for closing that AD security gap without disrupting AD performance. See how fast, effective AD security works for cyber insurance qualification.