Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
Map how Cohesity Identity Resilience satisfies cyber insurance requirements
With Active Directory being involved in 95% of security incidents (and the majority of major incidents), it’s no wonder that insurers and regulators are placing far greater emphasis on identity posture when assessing cyber risk. In fact, 8 out of 8 major cyber insurers now ask and validate that identity-specific security and resilience is met when underwriting policies. Moreover, for organizations looking to decrease their premiums, demonstrating adequate identity system hardening and proven security and recovery capabilities directly correlates to lower premiums and higher coverage.
For insurers, strong identity controls reduce the likelihood that a single compromised account can lead to widespread disruption or data loss, supporting more sustainable underwriting decisions.
Cohesity Identity Resilience directly addresses every stage of an attack lifecycle and maps directly to cyber insurance asks:
MFA & Privileged Access Management
Insurance category
What insurers ask
How Cohesity Identity Resilience addresses it
Evidence you can provide
Insurer coverage
MFA on all privileged accounts
Universal requirement—refusal criteria if absent
“Is MFA enforced on all admin, Domain Admin, and privileged accounts?”
“Are service accounts protected with MFA or equivalent controls?”
Least privilege / PAM
Increasingly required for >$5M policies
“Do you have privileged access management (PAM) controls?”
“Are admin accounts separate from daily-use accounts?”
“Is just-in-time (JIT) access provisioning in place?”
Active Directory Monitoring & Threat Detection
Continuous AD monitoring
Real-time change detection
“Do you continuously monitor Active Directory for unauthorized changes?”
“Can you detect privilege escalations in real time?”
“Do you monitor GPO, group membership, and Tier 0 asset changes?”
Audit trail & log retention
Min. 90 days required by most carriers
“Do you maintain audit logs for privileged account activity?”
“What is your log retention period?”
“Can you produce who changed what, when, and from where?”
Identity Vulnerability & Misconfiguration Management
AD misconfiguration detection
Risk scoring for underwriting
“Do you conduct regular assessments of Active Directory misconfigurations?”
“Are stale, orphaned, or dormant privileged accounts identified and removed?”
“Do you have a process to detect Kerberoastable accounts?”
Access reviews & certification
Quarterly minimum for most carriers
“Do you conduct regular access reviews for privileged accounts?”
“How often are admin group memberships reviewed and certified?”
“Is there a defined offboarding process that includes AD account revocation?”
Incident Response & AD Recovery Readiness
AD forest recovery capability
Direct ransomware coverage requirement
“Do you have a tested (i.e., actual recovery) Active Directory forest recovery plan?”
“How long would AD recovery take after a ransomware attack?”
“Are AD backups stored offline / air-gapped and tested regularly?”
“What is your last clean backup validation date?”
Ransomware IR playbook
Required by all carriers for ransomware coverage
“Do you have a documented ransomware incident response playbook?”
“Does your playbook include identity system recovery steps?”
“Has the playbook been tested via tabletop exercise?”
*Features that are bolded are unique to Cohesity’s Identity Resilience solution.
9100107-001