Tech Y Cluster Tech Business What Cyber Insurers Now Require From Small Businesses (and How to Meet It)

What Cyber Insurers Now Require From Small Businesses (and How to Meet It)


Title card: What Cyber Insurers Now Require From Small Businesses

Last updated: 28 September 2026

Short answer: most cyber insurers now expect a small business to have multi-factor authentication (MFA) on email, remote access and admin accounts, backups that are separate from the main network and regularly tested, up-to-date software, endpoint protection, staff training on phishing and a written incident response plan. Meet those, answer the application accurately, and read the policy's limits for payment fraud in particular. The same controls also cut the chance of needing to claim at all.

This article explains common market practice. It is not insurance or legal advice; policies vary widely, so check the wording of any policy you are offered with your broker.

Why have insurance applications become security checklists?

Because insurers learned from years of ransomware and payment-fraud claims which controls make the difference. The broker Marsh puts it bluntly: the adoption of certain controls "has now become a minimum requirement of insurers, with organizations' potential insurability on the line."

Small businesses are the main target. Munich Re's 2026 report notes that the majority of cyber incidents and claims affect micro-companies and SMEs, and that most cyber risk is still uninsured. In the UK government's latest survey, 43% of businesses reported a breach or attack in the previous 12 months, but only 15% of small businesses held a specific cyber policy.

The good news on price: Marsh reports global cyber insurance rates fell for the twelfth consecutive quarter in the second quarter of 2026. Cover is easier to buy than a few years ago, provided you can show the controls.

What does cyber insurance typically cover?

The US Federal Trade Commission's small business guide, written with state insurance regulators, splits cover into two parts:

First-party (your own losses) Third-party (claims against you)
Legal advice on notification duties Payments to affected customers
Data recovery and system restoration Legal defence and settlements
Notifying customers and running a call centre Regulatory investigations
Lost income while systems are down Claims over defamation or copyright in your content
Extortion (ransomware) response and forensics Accounting costs
Crisis management and PR

Policies are not standardised; wording varies from insurer to insurer, so compare what each one actually includes.

Common limits and exclusions to check

  • Payment fraud. When a criminal impersonates a supplier and persuades you to pay a fake invoice, many cyber policies pay only a small sublimit, or leave it to a separate crime policy. Insurance Journal reports fraudulent transfer cover is often capped at $250,000 or less, and some policies require a separate confirmation call before any change to bank details. If you skip that step, the claim may not be paid.
  • State-backed attacks. Since March 2023, the Lloyd's market has required standalone cyber policies to exclude losses from state-backed cyber-attacks, and many other insurers use similar clauses. Ask how your policy defines them.
  • Unpatched systems and failure to maintain the controls you declared. Some policies reduce or deny cover if a known security update was not applied.

What controls do insurers ask about?

The lists differ slightly between insurers, but they overlap heavily. Marsh's twelve key controls and the insurer Coalition's five essential requirements both start with the same items. For a small business, they come down to these:

1. Multi-factor authentication everywhere that matters

Email, remote access (VPN or remote desktop), cloud services, banking and every administrator account. This is the single most common question, and the one with the most serious consequences if answered wrongly (see below). Prefer an authenticator app, passkeys or security keys over text messages.

2. Backups that survive an attack

Insurers ask whether backups are encrypted, stored separately from the main network (offline or immutable), and tested. Ransomware groups deliberately look for and delete connected backups. Being able to restore quickly is what turns a ransomware attack from a business-ending event into a bad week. My 30-minute backup setup covers the 3-2-1 approach for a small office.

3. Updates and end-of-life systems

Apply security updates promptly, especially for anything facing the internet, and replace systems that no longer receive updates, such as old Windows versions, old routers and unsupported NAS boxes.

4. Endpoint protection

Modern endpoint detection and response (EDR) software on laptops and servers, not just basic antivirus. Many business plans for Microsoft 365 and similar platforms include it.

5. Email security and training

Filtering for phishing and malicious attachments, plus regular staff training and phishing tests. Business email compromise is where most small business claims start.

6. Limited admin rights

Staff should not work day to day with administrator accounts. Separate admin accounts, protected with MFA, limit how far an attacker can get.

7. An incident response plan

A short written plan: who to call (the insurer's breach hotline first, before any outside IT firm), how to isolate systems, how to contact customers and banks, and where the offline contact list lives.

What causes most small business claims?

Coalition's 2026 Cyber Claims Report, covering its claims in 2025, shows where the money goes:

  • Business email compromise and funds transfer fraud made up 58% of incidents. Average funds transfer fraud losses were $141,000, and over half of those cases began with a compromised email account.
  • Ransomware remained the most expensive claim type, averaging $269,000, although 86% of affected businesses refused to pay the ransom.

Verizon's 2025 Data Breach Investigations Report found ransomware in 44% of the breaches it analysed, and the two most common ways in were stolen or misused login credentials and unpatched vulnerabilities. That is why MFA and patching head every insurer's list.

What happens if the application is wrong?

The application is part of the contract. The best-known example is Travelers v. International Control Services in the US in 2022. The company had stated on its application that it used MFA; after a ransomware attack, the insurer found MFA protected only the firewall, not the server that was attacked. The two sides agreed in court that the policy was void from the start, leaving the company without cover.

The lessons:

  • Have the person who manages your IT check every answer on the application, not just the person who signs it.
  • If a control is only partly in place, say so. Insurers can often still offer cover, perhaps with conditions.
  • Keep the controls in place for the whole policy year, and tell your broker if something changes.

A practical checklist before you apply

Control Quick way to meet it
MFA on email, cloud, remote access, banking and admin accounts Turn on the built-in MFA in Microsoft 365 or Google Workspace; use an authenticator app
Separate, tested backups A cloud backup service plus an offline copy; restore a file every quarter
Updates Automatic updates on all devices; replace unsupported equipment
Endpoint protection Use the EDR included in your business software plan
Phishing training Short yearly training and occasional test emails
Payment verification Always confirm bank-detail changes by phone, using a number you already had
Password hygiene A company password manager; see my guide to moving everyone onto one
Incident plan One page, printed, with the insurer's hotline number

Government schemes that map to these requirements

If your business handles customer data, these controls also help with your legal duties, which I covered in what engineers should know about data privacy laws in 2026.

FAQ

Does a small business need cyber insurance?
It depends on how much a week without systems, or a fraudulent payment, would cost you, and whether clients require it in contracts. Many professional services contracts now ask for it. Compare the premium with the cost of a realistic incident.

Is cyber insurance included in my business insurance?
Sometimes, in a limited form. The UK survey found many businesses are covered "in some way" through wider policies, but with much less cover than a dedicated cyber policy. Check the limits.

Will insurers pay a ransom?
Some policies cover extortion payments where legal, but most businesses in Coalition's data refused to pay, relying on backups instead. Always involve the insurer before making any decision.

What is the first thing to do after an attack?
Call your insurer's incident hotline before calling an outside IT company, unless the policy says otherwise. Using the insurer's approved responders is often a condition of cover.

Leave a Reply

Your email address will not be published. Required fields are marked *