What You Need to Know About Cybersecurity Insurance

Reviewing a cyber insurance policy and its security requirements

Cyber insurance used to be straightforward to buy. You answered a short questionnaire, paid a modest premium, and the policy sat in a drawer. That market is gone. After several years of heavy ransomware losses, insurers rewrote how they underwrite these policies — and the practical effect for a small business is that the application is now a security audit.

That change is worth understanding before renewal season rather than during it, because the controls insurers ask about take weeks to put in place, not days.

What a Cyber Policy Typically Covers

Coverage varies enormously between carriers, so your own policy is the authority. Broadly, these policies tend to split into two halves.

First-party coverage addresses your own losses: business interruption while systems are down, the cost of digital forensics and incident response, data restoration, extortion payments and negotiation where legally permitted, and notification costs if personal information was exposed.

Third-party coverage addresses what others claim from you: liability for a privacy breach affecting clients, regulatory defense costs, and contractual penalties where a customer’s data was involved.

Two gaps catch people out. Losses from a fraudulent wire transfer — where someone was tricked into sending money rather than having it stolen technically — often sit under a separate social engineering or funds transfer fraud endorsement rather than the main policy, and sometimes at a much lower limit. And insurers increasingly exclude incidents attributed to state-backed actors, which is a live question in ransomware rather than a theoretical one.

What Insurers Now Require

The questionnaire is where most of the work now sits. While every carrier differs, the controls asked about most consistently are:

  • Multi-factor authentication on email, remote access and administrative accounts. This is the one that most often decides whether a policy is offered at all.
  • Endpoint detection and response rather than traditional antivirus, usually with someone monitoring it — which is what managed detection and response provides.
  • Tested, offline or immutable backups. Applications increasingly ask not just whether you have backups but whether you have restored from them, and whether an attacker with administrative access could delete them. Our backup and disaster recovery page covers what air-gapped actually means here.
  • Security awareness training with phishing simulation, and records showing it happens on a schedule.
  • Patch management with a defined timeframe for critical updates.
  • A written incident response plan naming who does what, rather than an intention to work it out at the time.
  • Email filtering and separation of administrative accounts from everyday user accounts.

Read that list again and notice something: it is simply a description of a competent security program. The insurance application has become, in effect, a free checklist of what a business your size ought to have anyway.

The Part That Causes Trouble Later

The application is a legal document, and the answers on it are representations the insurer relies on. If you attest that multi-factor authentication is enabled across the business and it turns out to have been enabled for some staff but not all, a claim can be challenged on the basis of that discrepancy rather than on the merits of the incident.

This is rarely dishonesty. It is usually that whoever completed the form answered in good faith about what they believed was in place. The controls drift — a new server is added and never brought into the backup job, an exception is made for a manager who found MFA inconvenient, an agent stops reporting after an update and nobody notices.

The protection against that is verification rather than recollection. A network health and security assessment establishes what is actually true before you sign the attestation, and ongoing vCISO and compliance-as-a-service keeps the evidence current between renewals.

How to Approach a Renewal

Start about ninety days out. Get the questionnaire early, walk through it with whoever manages your technology, and treat every question you cannot answer with confidence as a task rather than a guess. Where a control is missing, there is usually time to implement it before the form is due — which is the difference between a declined application and a better premium.

Your broker is the right person to interpret coverage, limits and exclusions. What we contribute is the technical half: confirming what is genuinely in place, closing the gaps the questionnaire exposes, and producing the documentation that supports your answers.

Common Questions

Do small businesses actually need cyber insurance?

That depends on what an incident would cost you and whether you could absorb it. Increasingly the decision is made for you: customer contracts, particularly with larger organisations and public bodies, often require you to carry it. It is also worth checking whether your general liability policy excludes cyber events, as many now do explicitly.

Why was our application declined or priced so high?

Usually one or two missing controls rather than anything about your industry. Absent multi-factor authentication and the lack of monitored endpoint detection are the two most common reasons. Both are fixable, and re-applying after closing them frequently produces a materially different outcome.

Can a claim be denied even though we have a policy?

It can, and the most common reason is a mismatch between what the application said was in place and what actually was. This is why the answers matter as much as the coverage. Treat the questionnaire as something to verify rather than complete from memory.

Does having good security reduce the premium?

It affects whether you are offered terms at all, and it generally affects pricing, though carriers weigh things differently and your broker will know the market better than we will. What is consistent is that businesses able to evidence their controls have an easier time than those asserting them.

How We Can Help

We work through insurance questionnaires with clients regularly. That means reviewing the application before you sign it, telling you plainly which answers your environment currently supports, closing the gaps that matter, and documenting the result so you have evidence rather than assertions. For businesses without an IT department, this comes as part of small business IT support; where a formal program is needed, it sits within managed security services.

We are not insurance brokers and do not advise on coverage or policy terms — that is your broker’s job, and a good one is worth having. What we do is make sure the technical answers are true.

If a renewal is coming up, the useful time to look is now rather than the week the form is due. Get in touch or call us at 303-552-0018.

Related Posts