Cyber Insurance IT Requirements: A Small-Business Guide
July 27, 2026 · Elecrics Team
Why your insurer suddenly cares about your IT
A few years ago, buying cyber insurance meant filling out a short form and writing a check. Those days are gone. Today, insurers ask detailed questions about your technology and security — and if your answers don't measure up, they'll either deny coverage, raise your premium, or quietly leave you uncovered when you actually file a claim.
If you run a 5–50 person business here on the South Shore and you don't have an IT person on staff, this can feel overwhelming. The good news: most of what insurers want is standard, achievable security hygiene. This guide walks you through the common requirements in plain English so you can answer the application honestly and keep your coverage valid.
Cyber insurance is a policy that helps cover the costs of a cyberattack — things like ransomware payments, data recovery, legal fees, notifying affected customers, and lost income while you're down.
The trap most small businesses fall into
Here's the risk nobody warns you about: you answer "yes" to every question on the application to get the best rate, then a claim gets denied because you didn't actually have those controls in place.
Insurers increasingly check. If your application says you require multi-factor authentication everywhere but the breach happened through an account that didn't have it, they can refuse to pay. Answer the questions truthfully — and if the answer is "no," fix it before you sign.
The controls insurers commonly require
Most application questionnaires cluster around the same set of security measures. Here are the big ones, what they mean, and roughly how hard they are to put in place.
1. Multi-factor authentication (MFA)
MFA means logging in requires a second step beyond your password — usually a code from an app on your phone or a tap to approve. This is the single most requested control, and often a hard requirement.
Insurers typically want MFA on:
- Email (Microsoft 365 or Google Workspace)
- Remote access to your network (VPN or remote desktop)
- Any administrator accounts
- Cloud applications that hold sensitive data
MFA is inexpensive and dramatically reduces the odds a stolen password leads to a breach. If you do only one thing on this list, do this.
2. Regular, tested backups
A backup is a saved copy of your data you can restore if the originals are lost, encrypted by ransomware, or deleted. Insurers want to know:
- Do you back up regularly (ideally daily)?
- Is at least one copy stored offline or otherwise separated so ransomware can't reach it?
- Have you actually tested that you can restore from it?
That last point trips people up. A backup you've never tested is a guess, not a safety net.
3. Endpoint protection
Endpoints are the devices your team uses — laptops, desktops, servers. Insurers expect modern protection, often specifically EDR (endpoint detection and response), which is a step up from traditional antivirus. Where old antivirus just blocked known threats, EDR watches for suspicious behavior and can isolate a device that's been compromised.
4. Patching and updates
Patching means installing the security updates software vendors release to fix newly discovered holes. Attackers actively hunt for machines that haven't been updated. Insurers want to see that you apply critical updates promptly — not months later.
5. Email security and phishing training
Phishing is a fake email designed to trick someone into clicking a bad link or handing over a password. Because most breaches start with email, insurers ask about:
- Email filtering to catch spam and malicious messages
- Regular security awareness training for staff
- Sometimes, simulated phishing tests
6. Access controls and offboarding
Insurers want assurance that people only have access to what they need, and that access is removed immediately when someone leaves. For a small office, that means having an actual process — not just "we'll get to it."
7. An incident response plan
An incident response plan is a simple written document that says who does what when something goes wrong: who to call, how to isolate affected systems, and how to notify your insurer. It doesn't need to be long. It needs to exist.
A pre-application checklist
Before you fill out (or renew) a cyber insurance application, walk through this:
- [ ] MFA is turned on for email, remote access, and admin accounts
- [ ] Backups run automatically, are stored separately, and have been test-restored
- [ ] Every computer has current endpoint protection or EDR
- [ ] Security updates are applied promptly across all devices
- [ ] Email filtering is in place and staff have had recent phishing training
- [ ] Former employees' accounts are disabled the day they leave
- [ ] You have a written incident response plan with contact info
- [ ] Someone can honestly vouch for each "yes" on the application
If you can't check a box, that's your to-do list — and it's a lot cheaper to close those gaps than to have a claim denied.
How to actually answer the questionnaire
A few practical tips:
- Don't guess. If you're unsure whether MFA is enabled everywhere, verify it before answering.
- Keep evidence. Screenshots, reports, or a summary from whoever manages your IT can prove you had controls in place if a claim is ever questioned.
- Involve whoever handles your technology. These questions are technical, and a wrong answer has real consequences.
This is one area where working with a managed IT provider (MSP) — a company that handles your technology for a flat monthly fee — genuinely helps. Most of these controls are things an MSP sets up and maintains as part of normal service, and they can help you answer the application accurately.
What this costs, roughly
We won't quote prices, because they vary widely. But in general terms: MFA is nearly free, phishing training and email filtering are modest monthly costs, and endpoint protection and backups are ongoing subscriptions priced per device or per user. The total is almost always far less than a single denied ransomware claim would cost your business.
Many South Shore business owners find that meeting insurance requirements and having solid day-to-day IT support end up being the same project — because the controls insurers want are simply good practice.
The bottom line
Cyber insurance is still worth having. But the policy is only as good as the security behind your answers. Put the core controls in place, answer the application truthfully, keep proof, and revisit it all at renewal time.
If you'd like a second set of eyes before you sign or renew, Elecrics is a managed IT provider based in Braintree serving businesses across Massachusetts. We're happy to help you understand where you stand — you can book a free 20-minute IT Fit Call at https://elecrics.com/book. No pressure, just a straight answer.