Cyber insurance requirements for small businesses now center on a short list of controls that insurers verify on the application: multi-factor authentication on email, remote access and admin accounts; endpoint detection and response on every device; tested offsite or immutable backups; email filtering; security awareness training; and a documented patching process. Answer no to the wrong question and the result is a declined application, a coverage exclusion or a premium that doubles.

We help Treasure Coast businesses complete these applications, and the pattern is consistent: the questions are technical, the deadline is short, and the honest answer is often somewhere between yes and no. This guide explains each control, why insurers ask, and how to close the gap before renewal.

Why do insurers ask about security controls?

Cyber insurers lost heavily to ransomware in recent years, and widely reported industry analysis showed that a handful of missing controls, above all MFA and offline backups, accounted for a large share of claims. The response was underwriting rigor: applications went from a page of checkboxes to detailed questionnaires, sometimes backed by external scans of your domain and follow-up calls. Answering inaccurately is worse than answering no, because a misrepresentation can void the policy after a claim.

What controls do cyber insurance applications require?

Multi-factor authentication

The single most important question. Insurers want MFA on all email accounts, on any remote access into the network (VPN, remote desktop), on administrative accounts, and increasingly on backup consoles and financial systems. Partial coverage, such as MFA for some staff but not the front desk, usually counts as no. Microsoft 365 conditional access makes tenant-wide enforcement straightforward; see our Microsoft 365 services for how we configure it.

Endpoint detection and response

Traditional antivirus no longer satisfies most carriers. They ask for EDR, a managed tool that detects behavior rather than signatures and can isolate an infected device, and many ask whether it is monitored 24x7 by a security operations team. They will often ask for the product name.

Backups: offsite, tested and protected

Expect questions about frequency, whether backups are stored offline or in immutable storage that ransomware cannot alter, whether they are separated from the production network with different credentials and MFA, and when you last tested a full restore. A backup drive attached to the server does not qualify. Our backup and disaster recovery service is designed to answer every one of these yes.

Email security

Advanced filtering for phishing and malicious attachments, plus domain protections such as SPF, DKIM and DMARC that stop attackers from spoofing your domain. Some carriers scan your domain records and know the answer before you do.

Security awareness training

Regular training for all staff, usually with simulated phishing, and records to prove it. Annual is the floor; quarterly is what underwriters like to see.

Patch management

A documented process for applying critical updates within a defined window, and confirmation that no unsupported operating systems are on the network. A single Windows 7 machine running an old lab instrument can be a problem; segmenting it is the usual fix.

Additional questions on larger policies

  • Privileged access management and separate admin accounts
  • Network segmentation and firewall configuration
  • Encryption of laptops and mobile devices
  • A written incident response plan, tested at least annually
  • Vendor and supply-chain risk controls
  • Funds transfer verification procedures, because wire fraud claims are frequent and often excluded without call-back verification

How do you close gaps before renewal?

  1. Get the application early. Ask your agent for the questionnaire 60 to 90 days ahead, not the week it is due.
  2. Run a gap assessment against the questions. Be honest about partial answers.
  3. Fix the cheap, high-impact items first: MFA everywhere, EDR on every device, DMARC, training enrollment. Most can be done in weeks.
  4. Address backups properly. Immutable offsite copies and a documented, tested restore. Keep the test report; underwriters accept evidence.
  5. Document what you have. Policies, training records, patch reports and an incident response plan. Documentation is what turns a real control into a yes on the form.
  6. Have your IT provider review the answers before submission. A wrong yes is the most expensive mistake on the form.

What happens if you cannot meet a requirement?

Options include a higher premium, a sublimit or exclusion for ransomware or social engineering, or a conditional binder giving you a set number of days to implement the control. Some businesses are declined outright, which is increasingly common for applicants without MFA. If you are between renewals, a conversation with your agent about what the carrier will accept as a remediation plan is worth having before the deadline.

Is cyber insurance worth it for a small business?

For most businesses that hold customer, patient or financial data, yes, provided the controls are in place to make it collectible. The policy funds incident response, forensics, legal notification, business interruption and, in some cases, ransom payments. The controls it requires are also exactly the ones that prevent most incidents in the first place, so the exercise pays off twice. Our compliance services handle the technical remediation and the evidence file together.

If your renewal is coming up or your application was declined, MainSail Data offers a free cyber-insurance readiness review for businesses across the Treasure Coast. Call (772) 794-1194 or request a consultation and we will go through the questionnaire with you line by line.