Blog

Cyber Insurance Requirements: What Insurers Expect Now

Most cyber insurance requirements these days come down to six controls your agent’s application will ask about: multi-factor authentication on email, remote access, and administrator accounts; endpoint detection and response rather than plain antivirus; backups that are offline and actually tested; current, patched systems; email filtering and staff training; and a written incident response plan. The application is the requirements list, and every “yes” you check is a signed statement about what your network really looks like. If one answer turns out to be only half true, the insurer can deny the claim or void the policy. Start on the application the moment your agent can send it, and verify each answer against what is actually configured.

Key Takeaways

  • The application is the requirements list, and it is a signed statement about your network.
  • Most carriers now expect MFA, EDR, tested offline backups, patched systems, email security, and an incident response plan.
  • A “yes” that is only partly true can void the policy, not just deny the claim.
  • Start the application early and verify every answer against what is actually configured.
  • The controls reduce risk; they never remove it. Insurance pays for a bad week, it does not shorten it.

Why did cyber insurance get harder to buy?

Three or four years ago this was a short form and a check. You answered a dozen questions, most of them some version of “do you have antivirus,” and you were covered. Then the claims stacked up. Ransomware became a business model, and insurers paid for a few years of it. The FBI’s 2025 Internet Crime Report logged 3,611 ransomware complaints last year, up from the year before, and those are only the attacks someone reported. The reported dollar figures leave out most of what hurts a small business: the days you could not bill, ship, or see patients.

So the carriers did what any insurer does after paying too many claims. They started inspecting. The application you get now is not “do you have security.” It asks you to describe the vendor and version of your endpoint protection. That is a different document from the one you signed three years ago.

Think about a homeowner’s policy. The underwriter asks about smoke detectors and deadbolts, prices the policy on your answers, and takes your word. Cyber insurance works the same way, except the house is your network and the questions are far more specific. And like a house fire, the first time anyone checks whether the smoke detector was really mounted is after something has gone wrong.

What do insurers actually require now?

Applications vary by carrier and by industry. A clinic gets different questions than a seed dealer. But almost every form crossing our clients’ desks now circles the same six things.

Multi-factor authentication, in more places than email

This is the first question on nearly every form and the one that gets people into the most trouble. The application asks about MFA in several places: email, remote access like VPN or remote desktop, cloud apps, and administrator accounts. Having it on email does not mean you have it everywhere. Having MFA on Microsoft 365 says nothing about the bookkeeper’s remote desktop connection into the file server. Same house, different door.

CISA’s guidance on MFA is blunt about this: people who turn it on are far less likely to get breached, because a stolen password alone is no longer enough. A lot of break-ins start with a password someone typed into a page that only looked like the real one. MFA is the least dramatic thing on the list and the one that stops the most attacks. It annoys people. That is the point.

Endpoint detection and response, not plain antivirus

Traditional antivirus looks for known bad files by signature. Endpoint detection and response watches what programs actually do, and it can stop something behaving like ransomware even if nobody has seen that exact file before. Insurers increasingly ask for EDR by name. If your answer is “the antivirus that came with the computer,” expect a follow-up question or a higher premium. A small business gets hit the same way as a large one, because most attacks are automated and they hit whatever answers the door.

Backups that are offline and tested

Every application asks whether you back up. The better ones ask whether the backups are separated from your network and when you last restored from one. Both matter. Per the #StopRansomware Guide from CISA and the FBI, many ransomware strains go looking for reachable backups first and encrypt or delete them before the rest of the system. A backup on the same network can disappear with everything else.

The most common finding in a first audit is a backup that has never been restored from. The job runs every night, the log is green, and no one has ever pulled anything back from it. If that restore fails at 2 a.m. during a ransomware event, you find out the hard way. You do not want that to be the first time.

Patching and supported systems

Expect questions about how fast you apply security updates and whether anything is past end of support. If you still have Windows 10 machines or a Windows Server 2016 box, the underwriter wants to know, and you should already have a date for replacing it. We laid those out in our 2027 IT budget guide. People do not plan for it. They see the date and think they will deal with it later, and then the premium goes up, or they cannot get coverage at all. Budget for it now.

Email security and staff training

Most carriers ask whether you filter incoming email for phishing and whether employees get security awareness training. Some ask how often and how many completed it. Answer with real numbers. People will say “yes, we do training,” and when you push, they will say “we sent an email in January.” That’s not training. That’s an email. Get the completion rate. If it is 40 percent, say 40 percent.

A written incident response plan

This is the question that catches small businesses flat. An incident response plan does not have to be a binder. It has to answer who decides what, who you call first (your IT provider and your insurer’s breach hotline, in a written list), how you reach people if email is down, and where the plan lives if the server holding it is encrypted. Write it down, print a copy, and keep it somewhere that is not on the network. A plan that lives in a Word document on the file server goes down with the server, and you cannot read it when you need it most.

What happens if an answer on the application is wrong?

Here is where the smoke detector stops being a metaphor. In 2022, Travelers went to federal court in Illinois to undo a cyber policy it had sold to an electronics manufacturer. The signed application said MFA protected the company’s administrative access. After a ransomware attack, the investigation found MFA on the firewall and nowhere else. As Insurance Journal reported, the two sides agreed to have the court rescind the policy and declare it void from the start.

The insurer did not just refuse that claim. The policy was treated as though it never existed. A homeowner who checked “yes” for smoke detectors, had one in a kitchen drawer with no battery, and found out after the fire is the same situation.

I do not think most people who get this wrong are lying. They ask someone, “Do we have MFA?” Someone says, “Yeah, we turned that on,” and that was true for Microsoft 365. Nobody thought about the remote desktop connection the bookkeeper uses from home. The form asked about both, and the person signing it did not know the difference.

My honest advice: I would rather you check “no” and attach a plan with dates than check “yes” and hope. Insurers can work with a gap they know about. They can price it, and they can put a condition in. A gap that surfaces during a claim is a different conversation.

How do you get ready before your renewal?

Ask your agent for the renewal application as early as they can send it. Many of these controls take weeks to put in properly, and MFA tends to surface an old app or a scanner that does not support it.

Sit down with whoever runs your IT and go through the application one question at a time. For every “yes,” ask them to show you the evidence: a screenshot of the MFA enforcement settings, the report from your EDR console showing every machine checking in this week, the date of your last successful test restore and what came back clean. If they cannot produce it, the honest answer is “in progress,” and that is fine with a plan attached.

Fix the gaps in the order the application weighs them, which is almost always MFA and backups first. Keep the evidence in a folder. Next year’s application asks the same questions, and you will be glad you did not rebuild the answers from scratch. The record lived in someone’s head, and that person left.

If you have one internal IT person who is already stretched, bring in help for a few weeks rather than hire. That is exactly what co-managed IT is for. If nobody owns your IT, the application makes that obvious fast, and it is worth comparing managed IT, in-house staff, and break-fix before renewal season.

Does cyber insurance replace good security?

No. And nobody selling you either should tell you otherwise.

Insurance pays. It can cover forensic investigators, legal counsel, customer notification, lost income, and liability if someone sues. The FTC’s small business cyber insurance guide is a good checklist for what your policy includes, because the exclusions section is where the surprises live. What insurance cannot do is get your systems back on Monday. The check arrives after a bad week, not instead of it.

The objection I hear is “we’re small, nobody is coming after us.” You do not get to choose whether you are on the list. Most attacks are automated, and they hit whatever answers the door. The controls insurers ask for are the same controls that stop most of those attacks. Security is layered, and no single layer removes risk, but those six cover a lot of ground. Do them because they work. A better premium is a side effect.

Where ANP fits

Advanced Network Professionals has run and protected technology for businesses, clinics, schools, and city offices across northwest Iowa from Spencer since 2017. We are a local team of about 20, Microsoft and Fortinet certified, with 24x7x365 support for every client. Every engagement starts with an audit, which is the walk-through above done properly: what is actually configured, where MFA is and is not enforced, whether the backups restore, and what is past end of support. You come out with a written list you can hand to your agent. From there, our managed IT services keep those controls in place and monitored, so a “yes” in March is still true in November. If ransomware readiness is the worry, our Cryptolocker Consulting work focuses on that. We cannot promise an attack never lands. We can make sure your application tells the truth, and that your backups are tested and ready when you need them.

Frequently Asked Questions

Should small businesses carry cyber insurance?

That is a decision for you and your agent, and it depends on what data you hold and what a week of downtime costs you. What has changed is that buying it now means meeting real security requirements. Those controls are worth having whether or not you carry a policy.

Is cyber insurance required by law?

Generally not for a typical small business, but contracts are a different matter. Customers, vendors, and lenders write cyber coverage into their agreements, so check your contracts and ask your agent.

What does cyber insurance not cover?

Exclusions vary by carrier, so read that section with your agent. The FTC suggests confirming coverage for attacks on data held by vendors, attacks outside the United States, a duty to defend in a lawsuit, and whether the policy pays for upgrading systems or only restoring them. A restore gets you back where you were. An upgrade gets you past what breached you.

What if we cannot meet every requirement by renewal?

Tell your agent the truth and bring a plan with dates. Many carriers will work with a known gap, sometimes with a higher premium or a lower limit. Do not answer “yes” for something still in progress.

Does adding MFA and EDR lower my premium?

Sometimes, but pricing depends on the carrier, your industry, and the market, so no one can promise a number. More often, these controls are what get you offered a policy at all. Treat any savings as a bonus.

Fill it out once, and fill it out right

If your renewal is coming up and you are not sure every “yes” would hold up, that is a good time to talk. You have not signed yet, and you can still fix it. Request a quote or contact ANP, and we will start with what is actually configured today.