Cyber insurance has changed. For many small and mid-sized businesses, the underwriting process is no longer a quick questionnaire followed by a policy quote. Insurers commonly ask more detailed questions about the organization’s security controls, how broadly those controls are deployed, and whether the business can prove they are working.
That shift is understandable. Cyber insurance exists to help organizations manage financial and operational risk after certain cyber incidents, but it is not a replacement for cybersecurity. It also is not a guaranteed payout mechanism. Policy terms, exclusions, application representations, sublimits, incident response requirements, and carrier-specific conditions can all matter.
This article is general educational information only. It is not legal advice, insurance advice, or a guarantee that any specific control will qualify your organization for coverage. For policy-specific questions, ask your broker, carrier, legal counsel, or other qualified advisor.
For SMB and mid-market IT leaders, the practical goal is simple: build an evidence-ready security baseline before underwriting, renewal, or a claim forces the conversation.
Why Cyber Insurance Underwriting Has Become More Technical
Cyber insurance applications used to rely heavily on self-attestation. A business might answer “yes” to questions about antivirus, backups, or employee training without much follow-up.
Today, insurers often expect more precision. They may ask whether multi-factor authentication is enforced for all remote access, whether endpoint detection and response covers every workstation and server, whether backups are tested, and whether privileged accounts are reviewed. They may also request supporting evidence such as screenshots, policy exports, reports, logs, or written procedures.
This reflects a broader reality: the controls insurers commonly ask about are often the same controls that reduce real-world losses from ransomware, credential theft, business email compromise, data exposure, and operational disruption.
For IT leaders, that means cyber insurance readiness is not just a finance task. It is a security, operations, leadership, and documentation task.
Cyber Insurance Is an Evidence Conversation, Not Just a Checkbox
One of the biggest surprises for SMBs is the difference between “we have a tool” and “we can prove the control is deployed and monitored.”
For example:
MFA may be enabled for most Microsoft 365 users, but not for admin accounts, VPN, remote desktop, payroll, or finance systems.
Endpoint protection may be installed on laptops, but missing from servers or remote devices.
Backups may exist, but no one has tested whether they can restore critical systems.
Patching may happen informally, but there is no report showing critical vulnerabilities are being addressed.
An incident response plan may be saved somewhere, but the team has never reviewed roles, contacts, or decision paths.
Insurers commonly care about these details because partial deployment can leave the business exposed. From an underwriting perspective, an organization that has controls documented, monitored, and consistently applied may present a different risk profile than one that only has tools installed.
Common Cyber Insurance IT Requirements Insurers May Ask About
Requirements vary by carrier, industry, revenue, data sensitivity, policy limits, prior claims, and risk profile. There is no universal checklist that guarantees coverage. However, several controls appear frequently in cyber insurance conversations and cybersecurity guidance.
1. Multi-Factor Authentication
Multi-factor authentication, or MFA, is one of the most commonly expected security controls.
Insurers often ask whether MFA is enforced for:
- Email accounts
- Remote access
- VPN connections
- Cloud applications
- Administrative portals
- Privileged accounts
- Remote desktop access
- Financial, payroll, and HR systems
CISA recommends MFA wherever possible, especially for privileged, administrative, and remote access users. For SMBs, the important detail is scope. Saying “we have MFA” is less useful than being able to show where MFA is enforced, which users are covered, and what exceptions remain.
Practical evidence may include identity provider reports, conditional access policies, screenshots of MFA enforcement, admin account lists, and exception documentation.
2. Endpoint Protection and EDR
Traditional antivirus is no longer the whole conversation. Insurers commonly ask about endpoint detection and response, often called EDR, or managed detection and response, known as MDR.
The goal is not simply to check whether a security product is installed. The stronger question is: can the organization detect suspicious behavior on endpoints and respond quickly?
For SMBs and mid-market companies, endpoint protection evidence may include:
- Device coverage reports
- Lists of protected workstations and servers
- Alerting and response workflows
- MDR provider documentation
- Unprotected device exceptions
- Recent detection or health status reports
If endpoint protection is only deployed to some devices, document the gap and the plan to close it.
3. Tested, Recoverable, and Protected Backups
Backups are essential, especially in ransomware scenarios. But backups only reduce risk if they are usable.
A stronger statement than “we have backups” is: “We have protected backups, we test restores, and we can show recent recovery results.”
Insurers may ask about:
- Backup frequency
- Backup encryption
- Offsite or cloud backup storage
- Immutable or isolated backup copies
- Backup admin access controls
- MFA for backup consoles
- Restore testing
- Recovery time expectations
CISA and NCSC guidance both emphasize the importance of backups and recovery planning. For SMBs, a quarterly or semiannual restore test can be a practical starting point. Keep the results: what was restored, when the test happened, who performed it, how long it took, and whether any issues were found.
4. Patching and Vulnerability Management
Many cyber incidents begin with known vulnerabilities that were not patched in time. Because of that, insurers often ask how an organization handles updates, unsupported systems, and vulnerability remediation.
This does not mean every SMB needs an enterprise-grade vulnerability management program on day one. But it does mean the business should know:
- What systems it owns
- Which systems are internet-facing
- Which systems are unsupported or end-of-life
- How quickly critical updates are applied
- Who is responsible for patching
- How patch status is verified
CISA recommends enabling automatic updates where possible, replacing unsupported systems, and testing and deploying patches quickly. For insurance readiness, patch reports and vulnerability summaries can be valuable evidence.
5. Incident Response Planning
An incident response plan is not just a document. It is a repeatable process for making decisions under pressure.
NIST’s incident response guidance emphasizes preparation, roles, coordination, communication, and repeatable processes. NCSC also advises organizations to understand what incident support may be included in a policy and what must be in place to claim or renew.
A practical SMB incident response plan should define:
- Who leads the response
- Who contacts the insurer or broker
- Who contacts legal counsel
- Who contacts outside IT, forensics, or incident response providers
- How evidence is preserved
- How business leaders are updated
- How customers, vendors, or regulators may be handled when appropriate
- Where emergency contacts are stored
- What systems are most critical to restore first
A tabletop exercise once or twice a year can turn the plan from paperwork into operational readiness. Keep notes from the exercise as part of your evidence pack.
6. Access Control and Privileged Access Management
Insurers commonly ask about access management because compromised credentials are a major pathway into business systems.
For SMBs, access control should start with three questions:
- Who has access?
- What do they have access to?
- Do they still need it?
CISA recommends least privilege and maintaining inventories of users, vendors, partners, and network connections. FTC guidance also stresses limiting access to sensitive data on a need-to-know basis.
Practical steps include:
Reviewing admin accounts regularly
Removing accounts for former employees
Separating user accounts from admin accounts
Requiring MFA for privileged access
Limiting vendor access
Documenting access approvals
Reviewing shared accounts and replacing them where possible(5/11)
The evidence can be simple: access review spreadsheets, identity provider exports, privileged account lists, and documented offboarding procedures.
7. Security Awareness and Phishing Resilience
Security awareness is not about blaming employees. It is about helping people recognize common threats and respond appropriately.
Business email compromise, phishing, credential theft, and social engineering remain practical risks for SMBs and mid-market companies. Verizon’s DBIR resource page highlights themes such as MFA, software updates, phishing training, encryption, testing defenses, and incident response planning.
Insurers may ask whether employees receive cybersecurity training and how often. They may also ask whether phishing simulations are used.
A practical program might include:
New-hire security training
Annual refresher training
Short quarterly reminders
Phishing reporting procedures
Role-specific training for finance, payroll, HR, and executives
Tracking completion rates
Keep training completion reports and phishing simulation summaries if available.
8. Logging and Monitoring
Logging and monitoring can sound complex, especially for smaller organizations. The practical concept is visibility.
If an incident occurs, can the organization determine what happened, which accounts were used, which systems were affected, and when suspicious activity began?
Insurers may not always use the same terminology, but endpoint detection, incident response, and claims investigation all depend on useful records.
SMBs should consider retaining logs for:
Email access
Identity and login activity
Admin actions
Endpoint alerts
Cloud application activity
Firewall or VPN connections
Backup job status
Critical server events
Not every business needs a full SIEM immediately. But the organization should know which logs exist, how long they are retained, and who can access them during an incident.
9. Email Security and Domain Protection
Email remains one of the most common entry points for cyber incidents. Munich Re has identified business email compromise as a costly attack vector, and CISA and Verizon both emphasize phishing-related defenses.
Practical email security controls include:
MFA for email accounts
Anti-phishing and anti-malware filtering
External sender warnings where appropriate
Blocking legacy authentication
Reviewing mailbox forwarding rules
SPF, DKIM, and DMARC domain protections
Finance approval workflows for payment changes
Training users to report suspicious messages
For insurance readiness, email security settings, MFA reports, and domain authentication records can all support the underwriting conversation.
10. Asset Inventory
Asset inventory is foundational. You cannot protect, patch, monitor, or recover what you do not know exists.
CISA’s Cyber Essentials encourages organizations to understand who and what is on their network, including users, vendors, business partners, systems, and connections.
For SMBs, inventory does not need to be perfect to be useful. Start with:
Laptops and desktops
Servers
Cloud services
SaaS applications
Network devices
Critical business applications
Admin accounts
Vendor access
Internet-facing systems
Asset inventory supports nearly every other control: MFA rollout, EDR coverage, patching, backup planning, incident response, and access reviews.
11. Cloud and SaaS Controls
Many SMBs now depend heavily on cloud platforms such as Microsoft 365, Google Workspace, Salesforce, QuickBooks, cloud file storage, and industry-specific SaaS tools.
Munich Re notes growing dependence on cloud technology and digital services as part of the broader cyber risk landscape. Insurers may ask how cloud systems are secured, especially when sensitive data or business-critical operations are involved.
Cloud control topics may include:
MFA for cloud admin accounts
Conditional access policies
SaaS backup and recovery
Admin audit logs
Role-based access
Secure configuration
Vendor management
Data sharing controls
Offboarding procedures
For many SMBs, cloud security is now core infrastructure security.
The Evidence Pack: What IT Leaders Should Prepare
A strong cyber insurance readiness effort should produce evidence, not just intentions.
Consider preparing a simple evidence folder with:
- MFA enforcement reports
- Endpoint or EDR coverage reports
- Backup job logs and restore test results
- Vulnerability scan or patch status summaries
- Incident response plan
- Incident response tabletop notes
- Security awareness training completion reports
- Phishing simulation summaries, if used
- Privileged access review records
- Asset inventory
- Cloud admin and logging configuration screenshots
- Email security settings
- Vendor access list
- Written exceptions and remediation plans
The goal is not perfection. The goal is accuracy, transparency, and steady improvement.
A 60–90 Day Cyber Insurance Renewal Readiness Plan
Do not wait until the week before renewal to review your security posture. A 60–90 day timeline gives IT, finance, operations, and leadership time to identify gaps and resolve the highest-priority issues.
90 Days Before Renewal
- Review the prior application and policy questions.
- Ask your broker or carrier what has changed in underwriting expectations.
- Confirm which controls may affect eligibility, premium, sublimits, or exclusions.
- Review MFA scope across email, VPN, admin accounts, and cloud systems.
- Check endpoint protection coverage.
- Identify unsupported systems or critical patch gaps.
60 Days Before Renewal
- Run or update an asset inventory.
- Complete a privileged access review.
- Test backup restoration.
- Review incident response contacts.
- Confirm logging is enabled for key systems. (8/11)
- Review cloud admin accounts and SaaS access.
- Document known exceptions and remediation plans.
30 Days Before Renewal
- Gather evidence reports and screenshots.
- Have IT, finance, and leadership review application answers together.
- Confirm statements match the actual environment.
- Ask policy-specific questions before signing.
- Store final documentation for future reference.
The cyber insurance application should reflect reality. Overstating controls can create risk later, especially if policy conditions or claim handling depend on accurate representations.
Questions to Ask Your Broker or Carrier
Because requirements vary, SMB and mid-market leaders should ask direct questions before renewal or purchase.
Useful questions include:
- Which controls are mandatory for this policy or quote?
- Which controls affect premium, retention, limits, or sublimits?
- Are there specific MFA requirements for email, VPN, remote access, or admin accounts?
- Is EDR required, or is traditional antivirus acceptable?
- What backup practices are expected?
- Are restore tests required or recommended?
- What incident response vendors or hotlines are included?
- What must happen before or during a claim?
- Are there ransomware, funds transfer fraud, social engineering, war, infrastructure, or third-party service provider exclusions?
- What evidence should we retain?
- How should we report material changes in our environment?
For legal or policy interpretation, involve qualified counsel. The goal is to understand obligations before an incident, not during one.
Security Stack vs. Security Program
Many SMBs have more security tools than they realize. The issue is often not total absence of technology. It is consistency, coverage, monitoring, and proof.
A security stack is the set of tools you own.
A security program is the repeatable way those tools are deployed, reviewed, tested, documented, and improved.
Insurers commonly care about the program because claims are rarely prevented by tool ownership alone. MFA must be enforced. Backups must restore. Endpoint protection must cover the actual devices. Access must be removed when people leave. Incident response contacts must be current. Logs must exist before an incident happens.
That is the mindset shift: cyber insurance readiness is operational readiness.
Final Takeaway
Cyber insurance can be a valuable part of a broader risk management strategy, especially for SMB and mid-market organizations that need financial support and incident response resources after certain cyber events. But it does not replace strong security controls, accurate documentation, or executive ownership of cyber risk.
The most practical path is to build an evidence-ready baseline around the controls insurers commonly ask about:
- MFA
- Endpoint protection or EDR
- Tested backups
- Patching and vulnerability management
- Incident response planning
- Security awareness
- Privileged access reviews
- Logging and monitoring
- Email security
- Asset inventory
- Cloud controls
Start before renewal. Involve IT, finance, operations, leadership, your broker, your carrier, and counsel where appropriate. Be accurate about the current environment, document exceptions, and prioritize the controls that reduce both underwriting friction and real operational risk.
Prepare for Cyber Insurance Conversations with Prometheus Cybersecurity
Prometheus Cybersecurity helps SMB and mid-market organizations turn cyber insurance requirements into practical, evidence-ready security improvements.
Whether you are preparing for a first cyber insurance application, an upcoming renewal, or a security control review, Prometheus Cybersecurity can help you assess your current environment, close priority gaps, document key controls, and build a practical roadmap aligned to your business risk.
If you want a clearer path to cyber insurance readiness without unnecessary complexity, contact Prometheus Cybersecurity today to schedule a cybersecurity readiness consultation.
Resources
TenisiTech: “Cyber Insurance and IT: What Insurers Actually Require Before They’ll Cover You”
https://tenisitech.com/cyber-insurance-and-it-what-insurers-actually-require-before-theyll-cover-you/
UK National Cyber Security Centre: “Cyber insurance guidance”
https://www.ncsc.gov.uk/guidance/cyber-insurance-guidance
CISA: “Cyber Essentials”
https://www.cisa.gov/resources-tools/resources/cyber-essentials
CISA: “#StopRansomware Guide”
https://www.cisa.gov/stopransomware/ransomware-guide
NIST: “Small Business Cybersecurity Corner”
https://www.nist.gov/itl/smallbusinesscyber
NIST CSRC: SP 800-61 Rev. 3, “Incident Response Recommendations and Considerations for Cybersecurity Risk Management”
https://csrc.nist.gov/pubs/sp/800/61/r3/final
Federal Trade Commission: “Start with Security: A Guide for Business”
https://www.ftc.gov/business-guidance/resources/start-security-guide-business
Insureon: “Cybersecurity Insurance Requirements”
https://www.insureon.com/small-business-insurance/cyber-liability/requirements
Embroker: Cyber insurance liability overview
https://www.embroker.com/blog/cyber-insurance-liability/
Munich Re: “Cyber Insurance: Risks and Trends 2024”
https://www.munichre.com/en/insights/cyber/cyber-insurance-risks-and-trends-2024.html
Verizon: Data Breach Investigations Report resource page
https://www.verizon.com/business/resources/reports/dbir/
NetDiligence: “Cyber Claims Study 2024 Report”
https://netdiligence.com/cyber-claims-study-2024-report/ (11/11)