Lloyds Cyber Insurance Requirements - Risk Selection and Cyber Hygiene Underwriting Criteria. Underwriters must conduct rigorous risk selection + due diligence assessing insured-cyber hygiene including: (a) Mandatory cyber hygiene requirements (insurance-grade baseline expectation): Multi-Factor Authentication (MFA) on all privileged accounts + all remote access + email + cloud admin consoles + Endpoint Detection and Response (EDR) on all endpoints + immutable + air-gapped + tested backups + Email Security Gateway + DMARC + SPF + DKIM + Patch SLA Critical 7 days + High 30 days + Vulnerability Disclosure programme + Security Operations Centre (SOC) capability + Incident Response Plan + tabletop exercises + Privileged Access Management (PAM); (b) Additional underwriting criteria for higher coverage: NIST Cybersecurity Framework alignment + ISO 27001 certification + SOC 2 Type II + Penetration testing reports + bug bounty programme + employee security awareness training + Third Party Risk Management; (c) Risk Engineering Pre-Bind Assessments: independent cyber risk assessment + external attack surface scanning (Bitsight + SecurityScorecard + Black Kite + RiskRecon + UpGuard) + dark web monitoring + threat intelligence on insured + exposed credentials check + ransomware vulnerability assessment; (d) Industry-specific hygiene (healthcare + financial services + manufacturing + critical infrastructure + retail + technology); (e) SME-specific simplified hygiene requirements + Cyber Essentials + Cyber Essentials Plus + ISO 27001 SME-tier; (f) Cyber hygiene declarations + warranties + breach of which voids coverage. Coordination with Lloyds Coverholder Cyber Risk Assessment + delegated authority cyber underwriting + Cyber Hygiene Index + insurance broker cyber risk advisory.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.