What Does Cyber Insurance Require From a Small Business? (And How to Prove It at Renewal)

Small business owner and IT consultant reviewing cyber insurance requirements and a security dashboard at renewal

Most cyber insurance carriers now require small businesses to enforce MFA on email, VPN, and admin accounts, run EDR on every endpoint, keep tested offsite backups, train employees, and maintain a written incident response plan — and to prove it at renewal. These cyber insurance requirements are now the baseline for getting a policy quoted at all, and carriers verify each one before they renew you.

Why are insurers suddenly demanding proof?

For years, a cyber policy was a checkbox and a signature. That ended when ransomware claims blew up carriers’ loss ratios. Ransomware severity and frequency climbed fast enough between 2020 and 2022 that insurers paid out more than they collected, and the market hardened — premiums jumped, capacity shrank, and the one-page application became a technical questionnaire.

Today that questionnaire is effectively a security audit. It asks whether MFA is enforced (not merely available), whether you run EDR, how your backups are protected, and whether you have a written incident response plan. Answer it wrong and you either get declined, priced punitively, or — worse — issued a policy a carrier can later void. Much of that underwriting anxiety traces straight back to how attackers get in: stolen credentials and social engineering, the same playbook behind the Microsoft Teams vishing and ransomware attacks we’ve broken down elsewhere.

Cyber insurance requirements matrix: what carriers demand — and what counts as proof

Carrier applications vary, but the controls below show up on nearly every one. What trips businesses up is the second half of each row: it’s not enough to have the control — at renewal you have to prove it. Here’s the matrix we walk clients through.

Control carriers requireWhy insurers require itHow you prove it at renewal
Enforced MFA (email, VPN, remote access, admin accounts)Stolen passwords are the #1 ransomware entry point; MFA blocks the reused-credential attack.MFA policy exports/screenshots showing it is enforced — not optional — across M365 or Google, the VPN, RDP/remote access, and every admin account.
EDR / MDR on every endpointSignature antivirus misses fileless and living-off-the-land attacks; carriers want behavioral detection plus response.An EDR/MDR console report listing every managed endpoint, agent health, coverage percentage, and who monitors the alerts.
Tested, offsite/immutable backupsRansomware now deletes or encrypts backups first; only recoverable backups end a claim without a ransom payment.Backup job logs plus a dated restore-test record — evidence a test recovery actually succeeded, not just that backups ran.
Security awareness trainingPhishing is the top initial-access vector; carriers want the human layer hardened, not just the tech.Training completion records with dates and pass rates, plus phishing-simulation results.
Written incident response planA tight reporting clock and a coordinated response separate a contained incident from a catastrophic one.The dated IR plan document with named roles, a contact tree, and evidence it was reviewed or tabletop-tested.
Patching + least-privilege accessUnpatched internet-facing systems and over-privileged accounts are how attackers move laterally once inside.A patch-status/vulnerability report and an access review showing admin rights are limited and periodically checked.

Two rows do the most damage when they’re answered wrong: enforced MFA and tested backups. Both are places where the honest answer and the convenient answer differ, and both are where carriers look hardest at claim time.

What does “enforced MFA” actually mean on the application?

This is the single most common gap we find. A business turns on MFA for Microsoft 365 email, sees the login prompt, and answers “yes, we have MFA.” But the application isn’t asking whether MFA is available — it’s asking whether it’s enforced across every remote entry point: email, VPN, remote desktop (RDP), and all administrator accounts.

“Available” and “enforced” are different facts. MFA that a user can skip, or that covers webmail but not the VPN, or that exempts the domain admin account “because it’s inconvenient,” is not enforced. Attackers target exactly the accounts you exempt. When a carrier asks the question, what they mean is: can a stolen password alone get someone into your network? If the answer is yes anywhere, your attestation of “MFA enforced” is inaccurate — and that inaccuracy has consequences, which is the next section.

Can a carrier really deny a claim after you’ve paid premiums?

Yes. The mechanism is material misrepresentation. A cyber application is a set of attestations — statements you warrant are true. If a statement that influenced the carrier’s decision to insure you turns out to be false, the carrier can deny the claim or rescind the policy, unwinding it as if it never existed and returning your premium instead of paying your loss.

The anchor example is Travelers Property Casualty Co. of America v. International Control Services, Inc. The insured had attested on its application that it enforced multi-factor authentication. After a ransomware incident, Travelers alleged the company actually ran MFA only on its firewall — not across the systems the application covered — and moved to rescind the policy for misrepresentation rather than pay the claim. However that case ultimately resolved, the lesson is unambiguous: the MFA box you check is a warranty, and a carrier will test it against reality when money is on the line.

This is why “just check yes to get the lower premium” is dangerous advice. An inaccurate attestation doesn’t save you money — it buys a policy that may not pay.

How do you prepare for the renewal questionnaire?

Assemble an evidence pack before you fill anything out, so every “yes” is backed by a document you can hand an underwriter. The pack we build with clients contains:

  • MFA policy exports showing enforcement across email, VPN, RDP, and admin accounts
  • An EDR/MDR console report listing every endpoint, agent health, and who watches the alerts
  • Backup restore-test logs — a dated, successful test recovery, not just “backups completed”
  • Training completion records with dates and phishing-simulation results
  • The dated written incident response plan, with named roles and evidence it was reviewed

If any of those don’t exist yet, that’s the gap to close before renewal — and closing gaps in exactly these areas is the daily work of security administration. If you’d rather start from a plain-English list you can run yourself, our small business cybersecurity checklist for Indiana covers the same controls without the insurance jargon. And when it is a customer asking rather than an insurer, the same evidence pack answers a customer security questionnaire, too.

What an MSP owns vs. what stays with your broker

Here’s the boundary, stated plainly, because getting it wrong wastes your money and our credibility. We are not insurance brokers. We don’t recommend coverage amounts, compare carriers, interpret policy language, or tell you what limits to buy — that’s your broker’s lane, and a good broker is worth every dollar.

What QOS MSP does is implement and evidence the technical controls the application asks about: enforcing MFA everywhere, deploying and monitoring EDR, protecting and restore-testing backups, running security awareness training, and writing and testing the incident response plan. Then we produce the reports that let you answer the questionnaire truthfully and prove each control at renewal. We’ve run managed IT since 2007 and support more than 75,000 users across our customers, so the controls carriers ask about are the ones we deploy every week. If you want the gaps mapped before you touch the application, that’s exactly what a cyber risk assessment produces.

So the division is clean: your broker owns the policy; we own the controls behind your answers. Anyone offering to do both at once is stepping outside their lane on one side or the other — ask which one they actually do.

When it’s an afternoon of screenshots, not a project

Candor, because it saves you money: if your questionnaire is short and your controls are genuinely in place, meeting your cyber insurance requirements is an afternoon of gathering screenshots and reports — not a remediation project. Plenty of small businesses already enforce MFA, run EDR, and back up properly; they just never documented it. Documentation is a day of work, not a monthly contract.

Don’t let a vendor talk you into buying remediation you don’t need. If you already have the controls, buy help with the evidence, not a rebuild. The businesses that genuinely need a project are the ones running a flat network, with MFA only on email, no EDR, and untested backups — because for them the questionnaire isn’t a paperwork exercise, it’s a to-do list they haven’t started. If that’s closer to your situation, that’s where we help.

Frequently asked questions

Does cyber insurance require MFA?

Yes. Nearly all carriers now require multi-factor authentication, and it must be enforced across email, VPN, remote access, and administrator accounts — not merely available for users who choose to turn it on. MFA that covers email but not the VPN or admin accounts does not meet the requirement.

Is antivirus enough for cyber insurance, or do I need EDR?

Traditional antivirus no longer qualifies with most carriers. They expect EDR or MDR — endpoint detection and response — because it catches the behavioral and fileless attacks that signature-based antivirus misses. Expect the application to ask specifically whether EDR is deployed on every endpoint.

What happens if you answer a cyber insurance application question wrong?

An inaccurate answer is treated as a material misrepresentation. Because the application is a set of attestations, a carrier can deny the claim or rescind the policy entirely — as Travelers sought to do in Travelers v. International Control Services after the insured attested to MFA it had not fully enforced.

What kind of backups do cyber insurers require?

Offsite or immutable, encrypted, and — critically — with documented restore tests. Carriers want proof that a recovery actually worked, not just that backup jobs ran. Untested backups do not count, because ransomware now targets backups first, and an untested backup is one you cannot be sure will restore.

Who should fill out the cyber insurance security questionnaire?

Whoever runs your IT, because the answers are technical attestations you are warranting as true. Have your IT provider or internal IT team verify each answer against how the systems are actually configured before anyone signs. A wrong answer is not just an error; it can void your coverage.

Renewal coming up and not sure your answers would survive a claim? We’ll map your controls against what carriers ask, close the real gaps, and hand you the evidence pack — no insurance advice, just the technical proof. Get in touch.

Put this to work in your business

Talk with a QOS engineer about what you read here — practical answers, no sales pressure.
Schedule Introductory Meeting
There is no cost or obligation.