Last updated: 28 September 2026
Short answer: most cyber insurers now expect a small business to have multi-factor authentication (MFA) on email, remote access and admin accounts, backups that are separate from the main network and regularly tested, up-to-date software, endpoint protection, staff training on phishing and a written incident response plan. Meet those, answer the application accurately, and read the policy's limits for payment fraud in particular. The same controls also cut the chance of needing to claim at all.
This article explains common market practice. It is not insurance or legal advice; policies vary widely, so check the wording of any policy you are offered with your broker.
Why have insurance applications become security checklists?
Because insurers learned from years of ransomware and payment-fraud claims which controls make the difference. The broker Marsh puts it bluntly: the adoption of certain controls "has now become a minimum requirement of insurers, with organizations' potential insurability on the line."
Small businesses are the main target. Munich Re's 2026 report notes that the majority of cyber incidents and claims affect micro-companies and SMEs, and that most cyber risk is still uninsured. In the UK government's latest survey, 43% of businesses reported a breach or attack in the previous 12 months, but only 15% of small businesses held a specific cyber policy.
The good news on price: Marsh reports global cyber insurance rates fell for the twelfth consecutive quarter in the second quarter of 2026. Cover is easier to buy than a few years ago, provided you can show the controls.
What does cyber insurance typically cover?
The US Federal Trade Commission's small business guide, written with state insurance regulators, splits cover into two parts:
| First-party (your own losses) | Third-party (claims against you) |
|---|---|
| Legal advice on notification duties | Payments to affected customers |
| Data recovery and system restoration | Legal defence and settlements |
| Notifying customers and running a call centre | Regulatory investigations |
| Lost income while systems are down | Claims over defamation or copyright in your content |
| Extortion (ransomware) response and forensics | Accounting costs |
| Crisis management and PR |
Policies are not standardised; wording varies from insurer to insurer, so compare what each one actually includes.
Common limits and exclusions to check
- Payment fraud. When a criminal impersonates a supplier and persuades you to pay a fake invoice, many cyber policies pay only a small sublimit, or leave it to a separate crime policy. Insurance Journal reports fraudulent transfer cover is often capped at $250,000 or less, and some policies require a separate confirmation call before any change to bank details. If you skip that step, the claim may not be paid.
- State-backed attacks. Since March 2023, the Lloyd's market has required standalone cyber policies to exclude losses from state-backed cyber-attacks, and many other insurers use similar clauses. Ask how your policy defines them.
- Unpatched systems and failure to maintain the controls you declared. Some policies reduce or deny cover if a known security update was not applied.
What controls do insurers ask about?
The lists differ slightly between insurers, but they overlap heavily. Marsh's twelve key controls and the insurer Coalition's five essential requirements both start with the same items. For a small business, they come down to these:
1. Multi-factor authentication everywhere that matters
Email, remote access (VPN or remote desktop), cloud services, banking and every administrator account. This is the single most common question, and the one with the most serious consequences if answered wrongly (see below). Prefer an authenticator app, passkeys or security keys over text messages.
2. Backups that survive an attack
Insurers ask whether backups are encrypted, stored separately from the main network (offline or immutable), and tested. Ransomware groups deliberately look for and delete connected backups. Being able to restore quickly is what turns a ransomware attack from a business-ending event into a bad week. My 30-minute backup setup covers the 3-2-1 approach for a small office.
3. Updates and end-of-life systems
Apply security updates promptly, especially for anything facing the internet, and replace systems that no longer receive updates, such as old Windows versions, old routers and unsupported NAS boxes.
4. Endpoint protection
Modern endpoint detection and response (EDR) software on laptops and servers, not just basic antivirus. Many business plans for Microsoft 365 and similar platforms include it.
5. Email security and training
Filtering for phishing and malicious attachments, plus regular staff training and phishing tests. Business email compromise is where most small business claims start.
6. Limited admin rights
Staff should not work day to day with administrator accounts. Separate admin accounts, protected with MFA, limit how far an attacker can get.
7. An incident response plan
A short written plan: who to call (the insurer's breach hotline first, before any outside IT firm), how to isolate systems, how to contact customers and banks, and where the offline contact list lives.
What causes most small business claims?
Coalition's 2026 Cyber Claims Report, covering its claims in 2025, shows where the money goes:
- Business email compromise and funds transfer fraud made up 58% of incidents. Average funds transfer fraud losses were $141,000, and over half of those cases began with a compromised email account.
- Ransomware remained the most expensive claim type, averaging $269,000, although 86% of affected businesses refused to pay the ransom.
Verizon's 2025 Data Breach Investigations Report found ransomware in 44% of the breaches it analysed, and the two most common ways in were stolen or misused login credentials and unpatched vulnerabilities. That is why MFA and patching head every insurer's list.
What happens if the application is wrong?
The application is part of the contract. The best-known example is Travelers v. International Control Services in the US in 2022. The company had stated on its application that it used MFA; after a ransomware attack, the insurer found MFA protected only the firewall, not the server that was attacked. The two sides agreed in court that the policy was void from the start, leaving the company without cover.
The lessons:
- Have the person who manages your IT check every answer on the application, not just the person who signs it.
- If a control is only partly in place, say so. Insurers can often still offer cover, perhaps with conditions.
- Keep the controls in place for the whole policy year, and tell your broker if something changes.
A practical checklist before you apply
| Control | Quick way to meet it |
|---|---|
| MFA on email, cloud, remote access, banking and admin accounts | Turn on the built-in MFA in Microsoft 365 or Google Workspace; use an authenticator app |
| Separate, tested backups | A cloud backup service plus an offline copy; restore a file every quarter |
| Updates | Automatic updates on all devices; replace unsupported equipment |
| Endpoint protection | Use the EDR included in your business software plan |
| Phishing training | Short yearly training and occasional test emails |
| Payment verification | Always confirm bank-detail changes by phone, using a number you already had |
| Password hygiene | A company password manager; see my guide to moving everyone onto one |
| Incident plan | One page, printed, with the insurer's hotline number |
Government schemes that map to these requirements
- UK: the Cyber Essentials certification covers firewalls, secure configuration, updates, access control and malware protection. UK organisations with turnover under £20 million that certify their whole organisation are automatically entitled to a basic cyber liability insurance policy with 24/7 incident response. The NCSC's free Small Business Guide is a good starting point.
- US: NIST's Cybersecurity Framework 2.0 Small Business Quick-Start Guide and CISA's Cross-Sector Cybersecurity Performance Goals cover the same ground in plain terms.
If your business handles customer data, these controls also help with your legal duties, which I covered in what engineers should know about data privacy laws in 2026.
FAQ
Does a small business need cyber insurance?
It depends on how much a week without systems, or a fraudulent payment, would cost you, and whether clients require it in contracts. Many professional services contracts now ask for it. Compare the premium with the cost of a realistic incident.
Is cyber insurance included in my business insurance?
Sometimes, in a limited form. The UK survey found many businesses are covered "in some way" through wider policies, but with much less cover than a dedicated cyber policy. Check the limits.
Will insurers pay a ransom?
Some policies cover extortion payments where legal, but most businesses in Coalition's data refused to pay, relying on backups instead. Always involve the insurer before making any decision.
What is the first thing to do after an attack?
Call your insurer's incident hotline before calling an outside IT company, unless the policy says otherwise. Using the insurer's approved responders is often a condition of cover.
