Cyber insurance conditions in the United States, on a 90-day clock
In the United States the core list is CIS Controls v8.1 and NIST CSF 2.0. Sector rules are add-ons the applicant ticks, each with its trigger: the FTC Safeguards Rule (financial institutions under FTC jurisdiction, such as tax preparers, mortgage brokers and auto dealers that arrange financing), the HIPAA Security Rule (covered entities and business associates), 23 NYCRR 500 (entities licensed by the New York Department of Financial Services; the section 500.19 limited exemption is a question for the business) and PCI DSS (card data). "Not sure" makes an add-on's lines questions.
Your carrier or broker sets day 0; each gap gets a checkpoint at day 30, 60 or 90 by the default rule, and the applicant reports each fix closed through a private link. Start from the United States template, or mark the controls in the control list.
The controls with a rule in the core list here (28)
- Staff sign in to email and the online services that hold business data (office suite, accounting, practice or client software) with multi-factor authentication
- Customers who log in to an online service you run that holds their sensitive data are offered or required to use multi-factor authentication
- Remote access (VPN, remote desktop) and every administrator account use multi-factor authentication
- Backups of data, applications and settings run on a schedule set by how critical each system is, and can be restored to a common point in time
- Backups are kept in a secure and resilient way (an isolated, offline or unchangeable copy), and ordinary staff accounts cannot change or delete them
- Administrator accounts (other than the backup administrator) cannot change or delete backups
- Restoring from backup is tested as part of a disaster recovery exercise
- Security patches for internet-facing services and devices (websites, remote access, firewalls, email gateways) are applied within the timeframes in the requirement
- Office software, web browsers, email clients, PDF readers, security products and workstation operating systems are patched within the timeframes in the requirement
- Other business applications are patched within the timeframe in the requirement
- Automated asset discovery and an up-to-date vulnerability scanner run on the schedules in the requirements
- Operating systems, office software, browsers, PDF software and online services that the vendor no longer supports are replaced or removed
- Administrators use a separate privileged account and environment for admin work only, with no internet or email on it
- Requests for privileged access are checked and signed off when first requested, and privileged accounts are tracked
- Privileged access is reviewed: switched off after 45 days of inactivity and after 12 months unless revalidated
- Break glass, local administrator and service account passwords are long, unique, unpredictable and managed, and default passwords are changed
- Application control on workstations lets only programs, scripts and installers the business has allowed run, including from user profiles and temporary folders
- Application control also covers internet-facing servers and all other locations, with the recommended blocklist and an annual ruleset review
- Web browsers do not run internet ads or plug-in code from the internet, users cannot change browser security settings, and the old built-in browser is disabled or removed
- Office and PDF software are hardened, blocked from creating child processes and executable content, and users cannot change their security settings
- Privileged access events and logs from internet-facing servers are collected centrally, protected from change, and reviewed in a timely manner
- There is a written cyber security incident response plan, it is enacted when an incident is identified, and incidents are reported internally and to the authority the rule names
- Every workstation and server runs centrally managed, behaviour-based anti-malware (often sold as endpoint detection and response)
- Inbound email is scanned for malware and phishing with unneeded attachment types blocked, and the domain publishes DMARC
- Staff are trained to recognise phishing and other social engineering, and to report a suspected incident
- Laptops, phones and removable media that hold sensitive data are encrypted
- Every device sits behind a correctly configured boundary or host firewall, with inbound rules signed off and unused rules removed
- IT and cloud providers with access to systems or data are listed, and their contracts carry security requirements
Rule sets
- CIS Controls v8: Part of the core list for the United States. A consensus control set, not a law, cited by safeguard number.
- ISO 27001:2022: An optional lens in any jurisdiction: shown as "also cited" beside a gap, never a gap on its own.
- NIST Cybersecurity Framework 2.0: Part of the core list for the United States. A voluntary framework of outcomes, cited at subcategory level.
- FTC GLBA Safeguards Rule (16 CFR Part 314): Financial institutions under FTC jurisdiction, for example tax preparers, mortgage brokers and auto dealers that arrange financing.
- HIPAA Security Rule: HIPAA covered entities (health plans, health care clearinghouses, health care providers that transmit health information electronically) and their business associates.
- NY DFS 23 NYCRR 500: Entities licensed by the New York Department of Financial Services. Section 500.19 sets limited exemptions for smaller covered entities: whether one applies is a question for the business, and this page never decides it.
- PCI DSS 4.0: Any business that stores, processes or transmits payment card data, in any of the three jurisdictions.