Skip to content
Back to Blog
Cybersecurity

Cyber Insurance IT Requirements: What Your Business Actually Needs to Qualify and Stay Covered

Barry SinghAugust 20, 20269 min readUpdated August 20, 2026
Business owner reviewing cyber insurance IT requirements on a laptop at a desk

/ Key takeaways

  • How Cyber Insurance Changed
  • What Insurers Are Actually Checking
  • The Gap That Shows Up at Claim Time

Cyber insurers now require multi-factor authentication enforced across every account, endpoint detection and response software on every device, encrypted backups tested for actual restoration, documented patch management, and a written incident response plan before they will write or renew a policy for a small business. The important word in that sentence is enforced, not enabled. Having MFA switched on for some accounts is not the same as having it enforced across all of them, and the difference matters when a claim is filed. This guide explains what insurers are actually checking, where businesses most commonly fail, and why the gap between your application answers and your actual security posture is the most expensive mistake in cyber insurance today.

How Cyber Insurance Changed

For most of its early history, cyber insurance worked on a simple model. A business filled out a questionnaire, answered yes or no to a series of security questions, and received a premium based on those self-reported answers. The process relied almost entirely on trust.

That model collapsed under the weight of ransomware claims. Insurers paid out enormous sums across thousands of incidents, audited the affected businesses, and found a consistent pattern: the controls businesses said they had in place were frequently incomplete, misconfigured, or simply not functioning the way the application implied.

Carriers have pivoted from passive underwriters to aggressive technical gatekeepers. They no longer take an SMB's word for it. They demand proof of digital hygiene before they even quote a premium.

The practical consequence is that cyber insurance now functions less like a financial product and more like a security audit. The application is the starting point, not the finish line. What matters is whether the controls described in that application can be evidenced and verified if a claim ever needs to be paid.

What Insurers Are Actually Checking

Self-attestation is no longer enough. Carriers want screenshots, exports from your RMM or PSA, and evidence of tested controls, not just a checked box. Here is what that means for the five controls that appear in almost every carrier questionnaire.

96%
of cyber insurers now mandate enforced MFA across email, VPN, RDP, and admin accounts
73%
of SMBs fail cyber insurance assessments due to weak controls or missing documentation
14 days
the critical-patch window many carriers now expect, down from 30

Multi-Factor Authentication

96% of cyber insurers now mandate enforced MFA across email, VPN, RDP, cloud applications, and all admin accounts. The critical word is enforced. MFA that is available but optional doesn't satisfy most underwriters.

The trap most businesses fall into is straightforward. Someone on the IT team enabled MFA for the Microsoft 365 environment. The business genuinely believes MFA is in place. The application gets a tick in the yes column. But enabled is not the same as enforced. If staff can bypass MFA, or if it was configured for standard accounts but not administrator accounts, or if legacy authentication protocols are still active that allow sign-in without MFA at all, the control exists on paper and not in practice.

Underwriters now look specifically for Conditional Access policies, meaning your IT environment evaluates the login context: is the user on a known company device, are they logging in from a high-risk location. Basic MFA alone is no longer sufficient for most carriers.

Endpoint Detection and Response

Standard antivirus software, the kind that checks files against a list of known threats, does not satisfy the endpoint detection requirement for most policies today. Insurers look for behaviour-based detection platforms that provide visibility, alerting, and response capabilities across all endpoints. Tools like Microsoft Defender for Endpoint, CrowdStrike, or SentinelOne are commonly accepted. A legacy antivirus product is not.

The second issue is coverage. A single unmanaged machine can be a disqualifying gap. If EDR is deployed on company laptops but not on servers, or if a handful of remote staff are using personal devices that don't have the tool installed, the insurer's definition of "all endpoints" is not met even if the application implies otherwise.

Tested Backups

Having a backup solution running is not the same as having a backup that works. Insurers want to know that you can recover without paying a ransom. That requires evidence of tested restoration, not just evidence that backup software is active.

The specific question underwriters now ask is whether backups have been tested and whether the restoration time has been documented. A backup that has never been restored from is an assumption, not a control. If a claim involves ransomware and the insurer finds that the backup had not been tested in 18 months, or that the backup was stored on a system reachable through the same credentials as the production environment, the claim outcome changes significantly.

Patch Management

Cyber insurance companies want to see software upgrades and evidence that known vulnerabilities are patched in a timely manner through a vulnerability management system. The key word is evidence. A business that patches regularly but has no logs, no records, and no documented process has nothing to show an underwriter that a business with a formal patch management process does.

The window insurers consider acceptable has also shortened. Patching critical vulnerabilities within 30 days was once a reasonable standard. Following high-profile exploitation campaigns like the SharePoint and Certighost incidents, many carriers now expect critical patches within 14 days or fewer, with evidence.

Incident Response Plan

A written incident response plan does not need to be elaborate. It does need to exist, be dated, and reflect how the business would actually respond to a breach, including who is notified, in what order, and what external resources are available. A complete, documented response plan also speeds up forensic investigation and customer notification if a claim is ever filed. Carriers who see an undocumented or stale response plan treat it as evidence of a reactive security posture, which affects both the premium and the coverage terms.

The Gap That Shows Up at Claim Time

73% of SMBs fail cyber insurance assessments due to weak controls, missing documentation, and reactive security, leading to denied coverage, 100 to 300% premium increases, or full financial exposure to cyber incidents.

Most of those failures do not involve deliberate misrepresentation. They involve businesses that answered application questions in good faith, genuinely believing the controls described were in place, without realising that their version of "we have MFA" and the underwriter's version of the same phrase referred to different things.

The gap closes at claim time. An adjuster is sent in. Logs are reviewed. Configurations are checked. The difference between what was checked yes on the application and what actually existed becomes the basis for whether the claim is paid, partially paid, or denied on the grounds that the policy was written based on inaccurate information.

The Documentation Problem

Companies that can produce documentation qualify faster, avoid sublimits and exclusions, and routinely save 20 to 40% on premiums compared to peers who cannot.

The practical implication is that the IT controls themselves and the records of those controls are both requirements. A business running EDR on every endpoint with no centralised logging, no monthly reports, and no exported configuration evidence is in a weaker position than a business with identical controls and clean documentation to support them.

This is where the relationship between managed IT and insurance readiness becomes concrete. An MSP or managed IT provider that runs monthly patch reports, maintains backup restoration logs, exports MFA configuration records, and generates regular security posture documentation is producing exactly what an underwriter will ask for at renewal and what an adjuster will check at claim time.

What to Do Before Your Next Renewal

Start at least 60 days before the renewal date rather than the week before. Pull the evidence for each required control before the application is completed.

  • Confirm MFA is enforced, not just enabled, across every account including admin accounts
  • Verify EDR is deployed on every device that connects to the business network
  • Run a test restoration from your most recent backup and document the result
  • Check when patches were last applied and whether records satisfy a 14-day window for critical vulnerabilities
  • Review your incident response plan and update the date

If any of those checks reveal a gap, the right time to address it is before the application is submitted, not after a claim makes the gap relevant.

Not sure your controls would pass a carrier review?

BPro Technologies can review your current MFA, EDR, backup, and patch evidence against what underwriters are actually asking for, and flag the gaps before your next renewal, not after a claim.

Get Free IT Assessment

Frequently Asked Questions

What IT controls do cyber insurers require?

The controls most carriers require as a baseline are enforced multi-factor authentication across all accounts and devices, endpoint detection and response software on every endpoint, encrypted backups with documented and tested restoration, a formal patch management process with evidence, security awareness training with completion records, and a written incident response plan.

What is the difference between MFA enabled and MFA enforced?

MFA enabled means the feature is turned on and available for staff to use. MFA enforced means staff cannot log in without completing MFA, regardless of device or location, and no exceptions exist. Insurers require enforced MFA. Enabled but optional MFA does not satisfy most underwriter requirements.

Can my cyber insurance claim be denied if my application was inaccurate?

Yes. If an adjuster finds that controls described as in place were not functioning as the application implied, insurers can deny a claim on the basis that the policy was written on inaccurate information. This is why documentation of actual controls, not just self-attestation, has become critical.

What counts as a tested backup for cyber insurance purposes?

A tested backup is one where an actual restoration was performed and the result documented. The documentation should include the date of the test, what was restored, how long it took, and whether the restoration was successful. Backup software that is running without a documented restoration test does not satisfy most underwriter requirements.

Does standard antivirus software satisfy the EDR requirement?

No. Most cyber insurers today specifically require behaviour-based endpoint detection and response tools rather than traditional antivirus software. Products like Microsoft Defender for Endpoint, CrowdStrike Falcon, or SentinelOne are commonly accepted. Legacy antivirus tools that rely on signature matching are not.

How does having a managed IT provider help with cyber insurance?

A managed IT provider that generates monthly patch reports, maintains backup restoration logs, runs regular security posture assessments, and can export configuration evidence gives a business exactly the documentation that underwriters request at renewal and adjusters check at claim time. The controls and the records of those controls are both requirements.

/ Choose the next step

Move from article guidance to a practical review path.

Pick the route that best matches the issue behind the article so the next conversation starts with the right scope.

Security path

Use the assessment to review exposure first

The free assessment is the right first move when identity, endpoint protection, backup readiness, email security, or Microsoft Defender coverage needs review.

Use this when you want a clearer starting point before work is scoped.

Service path

See cybersecurity coverage in practice

Review how BPro Technologies handles access hardening, endpoint protection, visibility, remediation, and evidence without using scare tactics or vague promises.

Use this when you want a clearer starting point before work is scoped.

Team path

Send the current security concern

If the issue is urgent, share what changed, what tools you have, and what is already protected so the team can review the safest next step.

Use this when you want a clearer starting point before work is scoped.