Patch management
Also called: patching, updates
In one sentence
Keeping software and devices updated so known security holes get closed before attackers use them.
Patch management is the routine of applying security updates to operating systems, applications, and network gear on a known schedule. Unpatched, internet-facing software is now a leading way attackers get in.
Why it's on your cyber insurance application
Applications ask how fast you apply critical patches and whether you run any end-of-life systems.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Patching & vulnerabilities
How are security updates applied to your systems and software?
Why carriers ask: Unpatched, internet-facing software is now a leading initial-access vector. Applications ask about patch cadence and end-of-life systems specifically.
If the answer is no: Have whoever manages IT produce a list of what's patched automatically vs. manually. That list becomes your patch-management policy's appendix.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Guides that cover this
Cybersecurity 101: the basic precautions insurers actually notice
A plain-English starter guide to the cybersecurity basics that move the needle on a cyber insurance application: MFA, EDR, tested backups, patching, email protection, training, and a written incident response plan — most fixable in an afternoon.
The 7 controls every cyber insurance application asks about in 2026
Cyber insurance applications in 2026 require MFA, EDR, tested backups, patching, email security, security awareness training, and a written incident response plan. Here's each requirement, why carriers ask, and what evidence you need before you sign the attestation.
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.