Cyber Insurance IT Requirements: A Small-Business Guide
September 25, 2026 · Elecrics Team
Why Cyber Insurance Now Comes With Homework
A few years ago, buying cyber insurance was almost as simple as buying a policy for your building. You filled out a short form, paid your premium, and you were covered. Those days are gone.
Today, insurers ask detailed questions about how your business handles technology and security. If your answers don't measure up, you'll either be denied coverage, charged a much higher premium, or — worst of all — approved but later denied a claim because you said you had protections you didn't actually have.
For a 5–50 person business in Braintree, Quincy, or anywhere on the South Shore without a dedicated IT person, that application can feel like a pop quiz in a language you don't speak. This guide walks you through what insurers are really asking for, in plain English, and how to get your business ready.
First, What Is Cyber Insurance?
Cyber insurance is a policy that helps cover the costs when your business suffers a cyberattack or data breach. That can include things like:
- Recovering data after a ransomware attack (where criminals lock your files and demand payment)
- Notifying customers whose information was exposed
- Legal fees and regulatory fines
- Lost income while your systems are down
- Hiring experts to investigate and clean up
Massachusetts has a strict data protection law (201 CMR 17.00) that requires businesses holding residents' personal information to have a written security program. Cyber insurance won't replace that obligation — but many of the same controls overlap.
The Controls Insurers Ask About
Most cyber insurance applications now boil down to a checklist of security "controls" — specific protections you either have or don't. Here are the ones that come up again and again.
1. Multi-Factor Authentication (MFA)
MFA means logging in requires more than just a password — usually a code from your phone or an app. This is the single most requested control on cyber insurance forms today.
Insurers typically want MFA on:
- Email accounts (especially Microsoft 365 or Google Workspace)
- Remote access to your network (like VPN or remote desktop)
- Any administrator or "admin" accounts that can change settings
If you answer "no" to MFA, expect to be denied or heavily surcharged. The good news: for most small offices, turning on MFA is free and can be done in an afternoon.
2. Reliable, Tested Backups
Insurers want to know your data is backed up — and that the backups are protected from attackers. A common standard is the 3-2-1 rule: three copies of your data, on two different types of storage, with one copy stored offsite or in the cloud.
The key word insurers focus on is tested. A backup you've never restored from is a guess, not a safety net. Be ready to answer:
- How often do you back up?
- Are backups stored separately from your main network?
- When did you last test a restore?
3. Endpoint Protection
Endpoints are the devices your team uses — laptops, desktops, servers. Insurers ask whether you have modern security software on them. Increasingly they want EDR (Endpoint Detection and Response), which is a smarter version of antivirus that watches for suspicious behavior, not just known viruses.
Basic free antivirus may not check the box on newer applications.
4. Regular Software Updates (Patching)
Patching means installing updates that fix security holes in your software and operating systems. Attackers love out-of-date systems. Insurers want to know you apply updates promptly — ideally automatically — across all your devices.
5. Email Filtering and Phishing Protection
Most attacks start with a phishing email — a fake message designed to trick someone into clicking a link or handing over a password. Insurers ask whether you filter incoming email for spam and threats, and whether you train staff to spot phishing.
6. Employee Security Training
Many applications now ask if you provide regular security awareness training. This doesn't have to be elaborate — short, periodic sessions that teach staff to recognize scams and report suspicious messages are what insurers want to see.
7. Access Controls and Admin Accounts
Insurers want to know that not everyone has the keys to everything. That means:
- Employees only have access to what they need
- Admin accounts are limited and separate from everyday accounts
- Former employees' accounts are shut off promptly when they leave
A Pre-Application Checklist
Before you fill out (or renew) a cyber insurance application, walk through this list:
- [ ] MFA is on for email, remote access, and admin accounts
- [ ] Backups follow the 3-2-1 rule and have been tested recently
- [ ] Every computer has current endpoint protection
- [ ] Software and operating systems update automatically
- [ ] Incoming email is filtered for spam and threats
- [ ] Staff receive periodic phishing and security training
- [ ] Access is limited by role, and departed employees are removed quickly
- [ ] You have a written incident response plan (basic steps for who to call and what to do)
If you can honestly check most of these, you're in strong shape. If several are blank, that's your to-do list — and doing them lowers your real-world risk, not just your premium.
Answer the Application Honestly
This matters more than anything: do not overstate your protections. If you claim you have MFA everywhere and a claim later reveals you didn't, the insurer can deny the claim entirely. You'd be paying premiums for coverage that evaporates when you need it.
If you're unsure how to answer a question, that uncertainty is itself the answer — it means you need to verify before you sign. It's far better to fix a gap now than to discover it during a crisis.
A Realistic Example
Imagine a 20-person accounting firm in Weymouth renewing its policy. The new application asks about MFA on email and EDR on every laptop. The office manager isn't sure, so she checks with whoever set up their systems. They discover MFA is on for some accounts but not the shared reception inbox, and three older laptops have only basic antivirus.
Rather than guessing "yes," they spend a week closing those gaps — enabling MFA everywhere and upgrading protection on the laptops. When they submit the application, every answer is truthful and favorable. Their coverage is solid and their actual risk is lower.
Where a Managed IT Provider Fits In
Many of these controls are things a managed IT services provider handles as part of ongoing support — turning on MFA, running tested backups, keeping software patched, and documenting what's in place so you can answer the application confidently. If you don't have internal IT staff, that documentation alone can save you hours of guesswork at renewal time.
Getting Started
Cyber insurance requirements will keep tightening, but the underlying message is a healthy one: the steps that make you insurable are the same steps that keep your business running when something goes wrong.
If you'd like a second set of eyes on your setup before your next renewal, Elecrics offers a free 20-minute IT Fit Call. We serve small and mid-sized businesses across Braintree, Quincy, Weymouth, and the greater South Shore. You can book one at https://elecrics.com/book — no pressure, just a straight answer on where you stand.