Cyber Insurance IT Requirements: A Small-Business Guide
August 26, 2026 · Elecrics Team
Why cyber insurance got harder to get
A few years ago, buying cyber insurance was easy. You filled out a short form, paid a modest premium, and moved on. That's over. After a wave of ransomware claims (attacks where criminals lock your files and demand payment), insurers started losing money — so they tightened the rules.
Today, when you apply or renew, you'll fill out a detailed questionnaire about your IT setup. Answer wrong, and you'll either be denied, charged much more, or — worst of all — have a claim rejected later because you said you had protections you didn't actually have.
This guide explains what insurers ask for, in plain English, so you can walk into your renewal prepared. It's written for owners and office managers at 5–50 person companies here on the South Shore and across Massachusetts who don't have IT staff on hand.
The core controls almost every insurer now requires
Think of these as the price of admission. Most carriers won't quote you without them.
1. Multi-factor authentication (MFA)
MFA means logging in requires two things: your password and a second step, like a code from an app on your phone. This is the single most-asked-about control on cyber applications.
Insurers typically want MFA on:
- Email (Microsoft 365 or Google Workspace)
- Remote access — any way employees log in from outside the office
- VPNs (secure remote connections into your network)
- Administrator accounts (the accounts that can change settings for everyone)
If you check "yes" for MFA, make sure it's actually turned on everywhere, not just for a few people.
2. Endpoint detection and response (EDR)
Regular antivirus is no longer enough for many carriers. They increasingly ask for EDR — software that not only blocks known viruses but watches for suspicious behavior and can isolate an infected computer before it spreads. On your application it may be called "EDR," "managed detection," or "next-gen antivirus."
3. Backups — and specifically, offline or immutable ones
Insurers want proof you can recover without paying a ransom. The key questions are:
- Are backups separated from your main network so ransomware can't reach them?
- Are they immutable (can't be changed or deleted once written)?
- Do you test that backups actually restore?
A backup you've never tested is a guess, not a safety net. This ties directly to the 3-2-1 approach many businesses already follow.
4. Security awareness training
Because most breaches start with a person clicking something they shouldn't, carriers ask whether you train employees to spot phishing (fake emails designed to trick them into giving up passwords or money). Many want to see this done regularly, not once at hiring.
5. Email filtering
A spam and phishing filter that screens messages before they reach inboxes. Microsoft 365 and Google Workspace include baseline versions; some carriers want more robust filtering on top.
The controls that are becoming standard
Depending on the carrier and your size, you may also see questions about:
- Patch management — keeping Windows, Mac, and software updated on a schedule, not whenever someone gets around to it.
- Least-privilege access — employees only have access to what their job needs. The bookkeeper doesn't need admin rights to the whole network.
- A written incident response plan — a simple document that says who does what if you get breached.
- Encryption — scrambling data on laptops and backups so it's useless if a device is stolen.
- Separate admin accounts — IT tasks done from a dedicated account, not someone's everyday login.
- End-of-life systems — carriers may ask if you're still running unsupported software like old Windows versions. These are a red flag.
The trap: answering "yes" when the real answer is "sort of"
Here's the part that trips up small businesses. The application is a legal document. If you attest that all your admin accounts use MFA, and a claim later reveals one didn't — and that's how the attacker got in — the insurer can deny the claim. You'd have paid premiums for coverage that evaporates when you need it.
So before you sign:
- Don't guess. If you're unsure whether MFA is on for every account, find out.
- Don't let a well-meaning employee fill it out from memory.
- Keep evidence — screenshots or reports showing controls are actually in place.
This is where a managed IT provider earns its keep. An MSP like Elecrics can review the questionnaire with you, confirm what's genuinely in place, and put missing pieces in place before you attest to them.
A pre-renewal checklist
Run through this a few weeks before your policy renews:
- [ ] MFA is on for email, remote access, VPN, and all admin accounts
- [ ] EDR or next-gen antivirus is installed on every computer and server
- [ ] Backups are automated, separated from the network, and tested within the last 90 days
- [ ] Employees have had phishing/security training in the past year
- [ ] Email filtering is active
- [ ] Windows, Mac, and key software are patched on a regular schedule
- [ ] No one is running unsupported/end-of-life operating systems
- [ ] Admin rights are limited to people who truly need them
- [ ] You have a basic written plan for what to do after a breach
- [ ] You have documentation to back up every "yes" on the application
What this means for your budget
Good news: the controls insurers demand are the same ones that actually protect your business. You're not spending money to satisfy a form — you're reducing the odds you ever file a claim. In general terms, meeting these requirements often means modest recurring costs for tools like MFA, EDR, and backup, plus training. For most small businesses that's a fraction of what a single ransomware incident or a week of downtime would cost.
And many carriers reward stronger controls with lower premiums, so improving your security posture can partly pay for itself.
Where to start if you're behind
If reading this list made you nervous, you're not alone — most 5-to-50-person companies without dedicated IT are missing at least a couple of these. Start with the highest-impact, lowest-effort wins: turn on MFA everywhere and confirm your backups actually restore. From there, work down the checklist.
If you'd rather not sort through the questionnaire alone, we're happy to help. Book a free 20-minute IT Fit Call at https://elecrics.com/book, and we'll walk through your cyber insurance requirements, tell you honestly where you stand, and outline what it would take to answer every question truthfully. No pressure, no jargon.