Why this matters now
Cyber insurers have tightened their requirements significantly. Many policies now require multi-factor authentication, endpoint detection and response, and tested backups before they will issue or renew coverage. Businesses that can't check those boxes are seeing higher premiums, exclusions, or outright denials.
What insurers commonly require
- Multi-factor authentication on email, remote access, and administrative accounts
- Endpoint detection and response (EDR), not just traditional antivirus
- Tested, immutable backups that ransomware can't encrypt or delete
- A documented incident response plan with named roles
- Security awareness training for staff, with phishing simulations
- Patch management with evidence that critical updates are applied promptly
How ransomware actually gets in
Most incidents in small businesses start with one of three things: a phishing email that captures a password, an unpatched remote access tool, or a reused password that leaked from another site. None of these require a sophisticated attacker. All of them are preventable with the controls above.
How we help
We assess your current setup against common insurer requirements, close the gaps in priority order, and give your broker the documentation they ask for. If you've received a questionnaire you're not sure how to answer, send it to us. We'll walk through it with you.

