Elecrics logoElecricsManaged IT Services
ServicesIndustriesHow It WorksAboutClient Support
(617) 982-2325Book an IT Fit CallSign in
Elecrics logoElecrics

The complete outsourced IT department for growing Massachusetts businesses.

530 West St, Braintree, MA 02184

Mon–Fri, 10 AM–6 PM ET

(617) 982-2325support@elecrics.com

Services

Complete Managed ITHelpdesk & Employee SupportMicrosoft 365 & Google WorkspaceCybersecurity & Data ProtectionDevice & Endpoint ManagementNetworks & Workplace TechnologyDevice Procurement & LifecycleIT Projects & Deployments

Company

How It WorksIndustriesProperty Management ITIT Insights (Blog)About ElecricsContactClient Support

Get Started

A free 20-minute call to see whether Elecrics is the right IT department for your team.

Book an IT Fit Call

Windows · Mac · Chromebook · Microsoft 365 · Google Workspace

© 2026 Elecrics LLC. All rights reserved.

Terms of ServicePrivacy PolicyCCPA/CPRA
    All articles

    Cyber Insurance IT Requirements: A Small-Business Guide

    August 26, 2026 · Elecrics Team

    Why cyber insurance got harder to get

    A few years ago, buying cyber insurance was easy. You filled out a short form, paid a modest premium, and moved on. That's over. After a wave of ransomware claims (attacks where criminals lock your files and demand payment), insurers started losing money — so they tightened the rules.

    Today, when you apply or renew, you'll fill out a detailed questionnaire about your IT setup. Answer wrong, and you'll either be denied, charged much more, or — worst of all — have a claim rejected later because you said you had protections you didn't actually have.

    This guide explains what insurers ask for, in plain English, so you can walk into your renewal prepared. It's written for owners and office managers at 5–50 person companies here on the South Shore and across Massachusetts who don't have IT staff on hand.

    The core controls almost every insurer now requires

    Think of these as the price of admission. Most carriers won't quote you without them.

    1. Multi-factor authentication (MFA)

    MFA means logging in requires two things: your password and a second step, like a code from an app on your phone. This is the single most-asked-about control on cyber applications.

    Insurers typically want MFA on:

    • Email (Microsoft 365 or Google Workspace)
    • Remote access — any way employees log in from outside the office
    • VPNs (secure remote connections into your network)
    • Administrator accounts (the accounts that can change settings for everyone)

    If you check "yes" for MFA, make sure it's actually turned on everywhere, not just for a few people.

    2. Endpoint detection and response (EDR)

    Regular antivirus is no longer enough for many carriers. They increasingly ask for EDR — software that not only blocks known viruses but watches for suspicious behavior and can isolate an infected computer before it spreads. On your application it may be called "EDR," "managed detection," or "next-gen antivirus."

    3. Backups — and specifically, offline or immutable ones

    Insurers want proof you can recover without paying a ransom. The key questions are:

    • Are backups separated from your main network so ransomware can't reach them?
    • Are they immutable (can't be changed or deleted once written)?
    • Do you test that backups actually restore?

    A backup you've never tested is a guess, not a safety net. This ties directly to the 3-2-1 approach many businesses already follow.

    4. Security awareness training

    Because most breaches start with a person clicking something they shouldn't, carriers ask whether you train employees to spot phishing (fake emails designed to trick them into giving up passwords or money). Many want to see this done regularly, not once at hiring.

    5. Email filtering

    A spam and phishing filter that screens messages before they reach inboxes. Microsoft 365 and Google Workspace include baseline versions; some carriers want more robust filtering on top.

    The controls that are becoming standard

    Depending on the carrier and your size, you may also see questions about:

    • Patch management — keeping Windows, Mac, and software updated on a schedule, not whenever someone gets around to it.
    • Least-privilege access — employees only have access to what their job needs. The bookkeeper doesn't need admin rights to the whole network.
    • A written incident response plan — a simple document that says who does what if you get breached.
    • Encryption — scrambling data on laptops and backups so it's useless if a device is stolen.
    • Separate admin accounts — IT tasks done from a dedicated account, not someone's everyday login.
    • End-of-life systems — carriers may ask if you're still running unsupported software like old Windows versions. These are a red flag.

    The trap: answering "yes" when the real answer is "sort of"

    Here's the part that trips up small businesses. The application is a legal document. If you attest that all your admin accounts use MFA, and a claim later reveals one didn't — and that's how the attacker got in — the insurer can deny the claim. You'd have paid premiums for coverage that evaporates when you need it.

    So before you sign:

    • Don't guess. If you're unsure whether MFA is on for every account, find out.
    • Don't let a well-meaning employee fill it out from memory.
    • Keep evidence — screenshots or reports showing controls are actually in place.

    This is where a managed IT provider earns its keep. An MSP like Elecrics can review the questionnaire with you, confirm what's genuinely in place, and put missing pieces in place before you attest to them.

    A pre-renewal checklist

    Run through this a few weeks before your policy renews:

    • [ ] MFA is on for email, remote access, VPN, and all admin accounts
    • [ ] EDR or next-gen antivirus is installed on every computer and server
    • [ ] Backups are automated, separated from the network, and tested within the last 90 days
    • [ ] Employees have had phishing/security training in the past year
    • [ ] Email filtering is active
    • [ ] Windows, Mac, and key software are patched on a regular schedule
    • [ ] No one is running unsupported/end-of-life operating systems
    • [ ] Admin rights are limited to people who truly need them
    • [ ] You have a basic written plan for what to do after a breach
    • [ ] You have documentation to back up every "yes" on the application

    What this means for your budget

    Good news: the controls insurers demand are the same ones that actually protect your business. You're not spending money to satisfy a form — you're reducing the odds you ever file a claim. In general terms, meeting these requirements often means modest recurring costs for tools like MFA, EDR, and backup, plus training. For most small businesses that's a fraction of what a single ransomware incident or a week of downtime would cost.

    And many carriers reward stronger controls with lower premiums, so improving your security posture can partly pay for itself.

    Where to start if you're behind

    If reading this list made you nervous, you're not alone — most 5-to-50-person companies without dedicated IT are missing at least a couple of these. Start with the highest-impact, lowest-effort wins: turn on MFA everywhere and confirm your backups actually restore. From there, work down the checklist.

    If you'd rather not sort through the questionnaire alone, we're happy to help. Book a free 20-minute IT Fit Call at https://elecrics.com/book, and we'll walk through your cyber insurance requirements, tell you honestly where you stand, and outline what it would take to answer every question truthfully. No pressure, no jargon.

    Questions about your own IT?

    Book a free 20-minute IT Fit Call — a no-pressure conversation about your team, your technology, and what would actually help.

    Book a Free IT Fit Call

    Elecrics LLC

    530 West St, Braintree, MA 02184

    (617) 982-2325 · support@elecrics.com

    Monday–Friday, 10:00 AM–6:00 PM ET