The premium is not the product
Cyber insurance looks like an easy buy. For a small business, a basic policy often lands in the range of a few hundred to a couple thousand dollars a year, and it covers the scary stuff: ransomware, fraudulent wire transfers, breach cleanup costs.
Then the application arrives, and it is not really an application. It is a security audit disguised as a form. Do you require multi-factor authentication on all email accounts. Do you use endpoint detection and response. Are backups kept separate and tested. How quickly are security updates applied.
How you answer determines your premium, and more importantly, whether a claim gets paid when the worst happens. The questionnaire is the real policy.
What insurers now expect as table stakes
The bar has risen sharply, and these items now appear on nearly every questionnaire I see:
- Multi-factor authentication, or MFA, meaning a second step like a phone prompt at login, required on email, on remote access, and on any admin account
- Endpoint detection and response, or EDR, which is modern security software that watches for suspicious behavior on your computers instead of just matching known viruses
- Backups kept separate from your main network, and actually tested by restoring from them, not just assumed to work
- A patching routine, meaning security updates applied within a defined window rather than whenever someone remembers
- Some form of security awareness training for staff, because most incidents start with a convincing email
- No systems so old the manufacturer no longer patches them
None of this is exotic. It is the same short list that prevents most small-business incidents in the first place, which is exactly why insurers demand it.
Why guessing yes can void the policy
Here is the part owners miss. The application is part of the insurance contract. When you check yes on MFA on all email accounts, you are making a statement the insurer relies on when pricing your risk.
After a claim, the insurer investigates. If the incident walked in through an account that did not have the MFA you attested to, the claim can be denied, and in serious cases the policy can be rescinded, meaning treated as if it never existed. This is not a rare technicality; it is how the product works. The worst position available is paying premiums for years and discovering at claim time that a checkbox answered optimistically in twenty minutes made the coverage worthless.
The rule is simple: answer what is true today, not what you intend to fix soon. A higher premium on honest answers is real coverage. A low premium on hopeful answers is an expensive placebo.
How to actually meet the requirements
The good news: for a typical small business this list is weeks of work, not months, and the costs are modest.
MFA is usually free. Business email platforms include it; the cost is an hour of setup and a week of staff grumbling. Start with email and anything that touches money.
EDR runs roughly 3 to 10 dollars per computer per month from mainstream vendors, and it replaces old-style antivirus rather than adding to it.
Backups worth attesting to means copies that a ransomware attack on your network cannot reach, typically a cloud backup service with version history, often 10 to 50 dollars a month at small scale, plus a calendar reminder to test a restore quarterly and write down the result.
Training can be as simple as a short quarterly session on spotting fake emails and verifying any payment-change request by phone. Keep attendance notes, because documentation is half the value.
As a Security+ certified practitioner this is the exact checklist I work through with HashWhales clients, and the honest summary is that meeting it usually costs less per year than the premium itself.
Next steps
- Get a current questionnaire from your broker, or pull the application you already signed, and reread your own answers as if you were the claims adjuster.
- Audit each answer against reality. Every yes needs evidence you could show after an incident: a settings screenshot, an invoice, a training note.
- Fix gaps in order of claim impact: MFA on email and finance first, then EDR, then backup separation and a tested restore, then the patching routine and training.
- Correct any answer that was wrong. Telling your broker mid-policy is an awkward conversation; a denied claim after a loss is a catastrophic one.
- Recheck once a year at renewal, because the questions get stricter each cycle.
Done in this order, you get the only outcome that matters: insurance that actually pays, protecting a business that has become far less likely to need it.
