← Back to blog
Cybersecurity & Compliance

Navigating Cyber Insurance Underwriting in Singapore, Key Attestations for 2026/2027 Policies

Can your organization prove every control it attests to on a cyber insurance application? For 2026 and 2027 cyber insurance policies in Singapore, underwriters concentrate on a core set of attested controls: multifactor authentication on email, remote, and privileged access; endpoint detection and response coverage; isolated, restore-tested backups; privileged access management; patching cadence; and a tested incident response plan. Verify each attestation with evidence before signing, because claims are assessed against what you attested.

Underwriting has moved from self-reported questionnaires toward requests for proof, and a well-known 2022 case showed what happens when an attestation and the environment disagree. This guide is for CFOs, risk managers, CISOs, and company secretaries in Singapore preparing a first application or a renewal.

What Cyber Insurance Underwriting Attestations Are

Underwriting attestations are the statements an applicant makes about its security controls in a cyber insurance proposal form or questionnaire, typically signed by a senior officer. Insurers use them to decide whether to offer cover, on what terms, and at what price.

Each answer describes the state of the environment on the day it is signed. If a control covers most systems but excludes a legacy VPN, a service account, or a contractor’s laptop, a plain yes on the form describes a better environment than the one the insurer is actually covering.

How Cyber Insurance Underwriting Singapore Has Shifted Toward Evidence

Carriers now test answers where they once accepted them. Huntress reports that MFA requirements are increasingly verified instead of self-reported, and that missing MFA is the most commonly cited reason for application denial. In Singapore, ArkShield describes a move to proof-based underwriting, in which businesses may be asked at renewal for evidence of MFA enforcement, a tested backup process, or logs from security monitoring tools.

National certification gives applicants another way to show baseline controls. CSA launched the Cyber Essentials and Cyber Trust marks on 29 March 2022, and BSI notes that both were expanded in April 2025 to cover cloud and AI security. Insurers active in Singapore, QBE among them, reference the marks in their cyber product material. How much a mark affects terms depends on the insurer, so ask your broker.

The Attestations Underwriters Focus On for 2026 and 2027 Policies

Questionnaires differ by insurer, but they converge on the same control families. The last column in the table shows where attested controls most often turn out to be incomplete when tested.

AttestationWhat underwriters typically askEvidence to keep on fileWhere it often fails under test
Multifactor authenticationMFA on email, remote access, cloud consoles, and privileged accountsIdentity provider policy export, enrollment rate, exemption listLegacy mail protocols, service accounts, VPN fallback, break-glass accounts
Endpoint detection and responseCoverage across endpoints and servers, with monitoringConsole coverage report reconciled to the asset inventoryUnmanaged servers, Linux hosts, contractor devices
BackupsIsolated or immutable copies with tested restorationDated restore test with time to recoverBackup console reachable with ordinary domain credentials
Privileged access managementNo standing admin rights, separate admin accountsPrivileged account inventory and review recordDomain admin accounts used for daily work, shared local admin passwords
PatchingCadence for critical vulnerabilities and end-of-life systemsPatch compliance reports and an end-of-life registerInternet-facing VPNs and firewalls patched later than servers
Email securitySPF, DKIM, and DMARC, plus filteringDNS records and policy settingsDMARC left in monitoring mode
Incident responseA written plan, tested by exercisePlan version and tabletop recordOut-of-date contacts, no out-of-band channel
Third-party accessControls on vendor and contractor accessVendor access list with MFA statusVendor remote access accounts exempt from MFA
Security testingRegular penetration testing with remediationLatest report and retest evidenceHigh-severity findings still open at renewal

Why an Inaccurate Attestation Can Cost More Than a Missing Control

A missing control is priced into the policy. An attested control that turns out to be absent can put the policy itself in question. The clearest public example is Travelers v. International Control Services in the United States.

According to Browne Jacobson, ICS stated in its application that MFA protected administrative and privileged access. After a ransomware attack in May 2022, Travelers found MFA protected only the firewall. Reed Smith reports that Travelers filed suit on 6 July 2022 seeking a declaration that the policy was rescinded, and Insurance Journal reported that the parties jointly filed a stipulation to rescind on 30 August 2022.

Singapore policies are governed by their own wording and by Singapore law, and outcomes will differ. Ask your broker and legal counsel how your policy treats inaccurate statements in the proposal form. The practical lesson carries across jurisdictions: an attestation should describe the environment as tested.

How to Verify Your Attestations Before You Sign?

Verification works best when it starts well before renewal and treats each questionnaire answer as a claim to be tested. The steps below fit most mid-sized organizations:

Start 90 to 120 days before renewal. Assign each questionnaire item an internal owner and an evidence source.

Reconcile coverage against the asset inventory. Compare MFA, EDR, and backup coverage against every account and host you own, including cloud and contractor devices.

Test the attestations directly. Commission a focused penetration test that tries to disprove each claim, for example by attempting authentication through legacy protocols, finding hosts without EDR, or reaching the backup console from a standard user account.

Fix, or qualify the answer. Close gaps before signing where possible. Where a gap remains, describe it accurately and record a compensating control and a remediation date.

File the evidence. Keep exports, reports, and test results together, dated, so they can be produced during underwriting or after an incident.

Cyber Insurance Attestation Readiness Checklist

Work through this list before signing a proposal form or renewal questionnaire.

• Export MFA policies and list every exempted account with a reason

• Reconcile EDR coverage against a current asset inventory, including servers

• Run and document a timed restoration from isolated backups

• Remove standing domain admin rights and inventory privileged accounts

• Confirm patch status of internet-facing VPNs, firewalls, and gateways

• Move DMARC to an enforcing policy

• Test the incident response plan in a tabletop and record the outcome

• Confirm vendor remote access is covered by MFA

• Close or formally risk-accept open high-severity pentest findings

• Have the signing officer review the evidence file before signing

Frequently asked questions (FAQs) about cyber insurance underwriting Singapore

These answers cover what finance and security leaders ask most often during renewal.

Q1. What controls do cyber insurers typically require in 2026?

Most questionnaires focus on MFA for email, remote, and privileged access; endpoint detection and response; isolated, tested backups; privileged access management; patching; email authentication; and a tested incident response plan.

Q2. How does a penetration test help with cyber insurance?

A focused test checks whether attested controls hold in practice, such as whether MFA can be bypassed through legacy protocols or whether backups are reachable by an ordinary user. It also produces dated evidence for the file.

Q3. What happens if an attestation turns out to be inaccurate?

It depends on the policy wording and governing law. In the US case Travelers v. ICS, the parties agreed to rescind a policy after the insurer found MFA covered only the firewall. Ask your broker and counsel how your policy treats misstatements.

Q4. Do CSA’s Cyber Essentials or Cyber Trust marks affect cyber insurance?

They provide independent evidence of baseline controls, and some insurers in Singapore reference them. Any effect on terms depends on the insurer.

Q5. When should we start preparing for renewal?

Start 90 to 120 days before the renewal date, which leaves time to test attestations, close gaps, and assemble evidence.