The set of minimum cybersecurity practices and measures that any organization should implement to reduce its exposure to common cyber threats.
Cyber hygiene refers to the baseline of cybersecurity practices considered necessary and non-negotiable for any organization, regardless of its size or sector. This baseline typically includes the regular updating of software and systems, multi-factor authentication for sensitive access, rigorous backup management and regular testing, network segmentation, user awareness training on phishing risks, and identity and privileged access management. In the regulatory context, the NIS2 Directive formalized this baseline in European law via its Article 21, which lists ten categories of mandatory measures for essential and important entities. For cyber insurers, cyber hygiene is the first underwriting filter, the level below which a risk becomes either uninsurable or insured only on very restrictive terms. The concept has evolved with the threat landscape: the 2020 standard rarely included continuous behavioral monitoring or least-privilege access segmentation, which are now part of the expected minimum. NIS2 gives cyber hygiene a legal dimension, making its absence not merely an aggravating factor at underwriting but a sanctionable regulatory breach.
When renewing its cyber policy, an industrial SME presents an underwriting questionnaire revealing the absence of multi-factor authentication on its remote access and the absence of tested backups for eighteen months. The insurer declines to renew on previous terms, citing an insufficient level of cyber hygiene. It offers a policy with a doubled deductible and a sub-limit for incidents linked to unprotected access, and conditions a return to normal terms on the implementation of multi-factor authentication within three months of the effective date.
cyberhygiène, bonnes pratiques cyber, socle de sécurité, baseline security