Skip to content
(888) 538-6881Client Portal
The Network Gurus

Blog

What cyber insurers require from small businesses now

The application has become a security audit. Here's what underwriters ask for, why it matters at claim time, and how to get ready before renewal.

Backup and recovery equipment in a server rack

October 10, 2026 · The Network Gurus

The short answer

Most cyber insurance carriers now expect a small business to have six controls in place before they'll quote at a reasonable price: multi-factor authentication on email, remote access, and admin accounts; endpoint detection and response (EDR) on every computer and server; backups that are separate from the network and tested; timely patching; email filtering; and regular security awareness training. Many also ask about an incident response plan and how administrator accounts are managed.

Having these controls matters twice: once to get a policy, and again when you file a claim. If your application says a control was in place and the claim investigation finds it wasn't, the claim can be disputed.

This is general information, not insurance advice. Requirements vary by carrier and policy, so review your application with your agent.

What underwriters ask for, and why

Multi-factor authentication

Expect questions about MFA on email (including webmail), remote access such as VPN or remote desktop, cloud apps, and administrator accounts. Insurers care because stolen passwords are the starting point for most business email compromise and ransomware incidents. "Most users" is not the same as "all users"; a single executive or service account without MFA is often how attackers get in.

Endpoint detection and response

Carriers increasingly ask specifically for EDR, not just antivirus, on every workstation and server, and sometimes whether it's monitored around the clock. EDR spots attacker behavior and can isolate an infected machine before ransomware spreads.

Backups that survive an attack

Underwriters want to know whether backups are encrypted, stored off site or offline, protected from deletion (often called immutable), and tested. Attackers go after backups first. A backup that sits on the same network with the same passwords will be encrypted along with everything else.

Patching

Expect questions about how quickly critical updates are installed and whether you run any unsupported software, such as an old version of Windows or a server past end of life. Unpatched systems facing the internet are a common way in.

Email security

Most attacks start with an email. Carriers ask about filtering for phishing and malicious attachments, and sometimes about email authentication records (SPF, DKIM, and DMARC) that make it harder to impersonate your domain.

Security awareness training

Many applications ask whether staff receive training and phishing simulations at least annually. Some carriers discount for it.

Administrator access and incident planning

Expect questions about whether staff have administrator rights on their own computers, how admin accounts are protected, and whether you have a written incident response plan that names who to call.

The claim-time problem

The application is signed by the business, not the IT provider, and it's usually filled out quickly by an office manager or owner. Common mistakes:

  • Checking "yes" for MFA when it's on Microsoft 365 but not on the VPN or the accounting system
  • Checking "yes" for tested backups when nobody has ever restored from them
  • Checking "yes" for EDR when the computers run free or consumer antivirus
  • Forgetting the one server or laptop that sits outside the normal setup

Each of those can become an argument after an incident. Accuracy is worth more than a slightly lower premium.

A renewal checklist

Sixty to ninety days before renewal:

  1. Get a copy of last year's application and read every security question.
  2. Confirm MFA is enforced on every account that can reach email, remote access, cloud apps, and admin tools, not just most of them.
  3. Confirm EDR is installed and reporting on every computer and server.
  4. Do a test restore from backup and write down the date and result.
  5. Find anything unsupported or unpatched and replace or isolate it.
  6. Confirm everyone completed security training this year.
  7. Update a one-page incident response plan with your insurer's hotline number, your attorney, and your IT provider.
  8. Keep screenshots and reports as evidence in a folder you can reach if your systems are down.

How we help

Every Network Gurus managed plan includes the controls insurers ask about most: enforced MFA, endpoint detection and response, email security, staff training, a managed firewall, patching, and tested, immutable backups. We'll also help you answer the technical questions on your application accurately. Start with a free IT and compliance assessment, a 60-minute on-site visit that ends with a written list of gaps to close before your next renewal.

Keep reading

More from the blog

Questions we hear

Frequently asked questions

Don’t see your question? Call us and a real person will answer.

Do I need MFA to get cyber insurance?

For most carriers, yes. Multi-factor authentication on email, remote access, and administrator accounts is the most common baseline requirement, and many carriers will decline or limit coverage without it.

Can a cyber insurance claim be denied?

Yes. If the application said a control was in place and it wasn't, such as MFA on every account or backups that were actually tested, the carrier may dispute or deny the claim. Answer every question accurately and keep evidence.

Does cyber insurance cover ransomware?

Many policies cover ransomware response, recovery costs, and business interruption, but limits, sublimits, and exclusions vary widely. Read the ransomware and social engineering sections closely with your agent.

What is EDR and why do insurers ask about it?

Endpoint detection and response is security software that watches computers for attacker behavior and can isolate a machine automatically. Insurers ask for it because traditional antivirus misses most modern ransomware attacks.

How can an IT provider help with a cyber insurance application?

A good IT provider can answer the technical questions accurately, put missing controls in place before renewal, and give you documentation to keep on file in case of a claim.

Free IT assessment

Know where you stand before something breaks

A plain-English review of your security, backups, and support experience. No cost, no obligation, and the report is yours to keep.