The short answer
Most cyber insurance carriers now expect a small business to have six controls in place before they'll quote at a reasonable price: multi-factor authentication on email, remote access, and admin accounts; endpoint detection and response (EDR) on every computer and server; backups that are separate from the network and tested; timely patching; email filtering; and regular security awareness training. Many also ask about an incident response plan and how administrator accounts are managed.
Having these controls matters twice: once to get a policy, and again when you file a claim. If your application says a control was in place and the claim investigation finds it wasn't, the claim can be disputed.
This is general information, not insurance advice. Requirements vary by carrier and policy, so review your application with your agent.
What underwriters ask for, and why
Multi-factor authentication
Expect questions about MFA on email (including webmail), remote access such as VPN or remote desktop, cloud apps, and administrator accounts. Insurers care because stolen passwords are the starting point for most business email compromise and ransomware incidents. "Most users" is not the same as "all users"; a single executive or service account without MFA is often how attackers get in.
Endpoint detection and response
Carriers increasingly ask specifically for EDR, not just antivirus, on every workstation and server, and sometimes whether it's monitored around the clock. EDR spots attacker behavior and can isolate an infected machine before ransomware spreads.
Backups that survive an attack
Underwriters want to know whether backups are encrypted, stored off site or offline, protected from deletion (often called immutable), and tested. Attackers go after backups first. A backup that sits on the same network with the same passwords will be encrypted along with everything else.
Patching
Expect questions about how quickly critical updates are installed and whether you run any unsupported software, such as an old version of Windows or a server past end of life. Unpatched systems facing the internet are a common way in.
Email security
Most attacks start with an email. Carriers ask about filtering for phishing and malicious attachments, and sometimes about email authentication records (SPF, DKIM, and DMARC) that make it harder to impersonate your domain.
Security awareness training
Many applications ask whether staff receive training and phishing simulations at least annually. Some carriers discount for it.
Administrator access and incident planning
Expect questions about whether staff have administrator rights on their own computers, how admin accounts are protected, and whether you have a written incident response plan that names who to call.
The claim-time problem
The application is signed by the business, not the IT provider, and it's usually filled out quickly by an office manager or owner. Common mistakes:
- Checking "yes" for MFA when it's on Microsoft 365 but not on the VPN or the accounting system
- Checking "yes" for tested backups when nobody has ever restored from them
- Checking "yes" for EDR when the computers run free or consumer antivirus
- Forgetting the one server or laptop that sits outside the normal setup
Each of those can become an argument after an incident. Accuracy is worth more than a slightly lower premium.
A renewal checklist
Sixty to ninety days before renewal:
- Get a copy of last year's application and read every security question.
- Confirm MFA is enforced on every account that can reach email, remote access, cloud apps, and admin tools, not just most of them.
- Confirm EDR is installed and reporting on every computer and server.
- Do a test restore from backup and write down the date and result.
- Find anything unsupported or unpatched and replace or isolate it.
- Confirm everyone completed security training this year.
- Update a one-page incident response plan with your insurer's hotline number, your attorney, and your IT provider.
- Keep screenshots and reports as evidence in a folder you can reach if your systems are down.
How we help
Every Network Gurus managed plan includes the controls insurers ask about most: enforced MFA, endpoint detection and response, email security, staff training, a managed firewall, patching, and tested, immutable backups. We'll also help you answer the technical questions on your application accurately. Start with a free IT and compliance assessment, a 60-minute on-site visit that ends with a written list of gaps to close before your next renewal.




