You bought cyber insurance. You’ve been paying the premiums. And you’re telling yourself, “If something happens, we’re covered.” That’s exactly what hundreds of small business owners thought, right up until they filed a claim and got a denial letter.
Not because the damage wasn’t covered on paper. But because when the insurer’s team looked under the hood, the cybersecurity insurance requirements the business agreed to weren’t actually in place.
This isn’t a fringe situation anymore. It’s happening to businesses of every size, and especially, small businesses are taking the hardest hits by attackers. If you’re relying on your policy as a financial safety net, you need to know exactly what insurers check before they approve a claim, because the bar has moved significantly, and most business owners don’t realize it until it’s too late.
Working with businesses across industries through our MSP team in Jacksonville, we see this gap constantly, the space between what a business thinks their policy covers and what the insurer actually requires before cutting a check.
Why Insurers Have Raised the Requirements Bar, Suddenly
It didn’t happen overnight, but it did happen fast.
Between 2020 and 2022, ransomware attacks exploded. Insurers were paying out enormous claims and getting hammered financially. So they did what any business would when losses become unsustainable: they changed the rules.
The result: getting a policy is no longer the hard part. Keeping your claim from getting denied is important.
I’ve personally sat with business owners who were blindsided by this. One manufacturing client had a solid-looking policy, got hit by ransomware, and spent three weeks in claims limbo before the insurer’s forensic team flagged that remote access to their systems had no multi-factor authentication enabled. Partial payout. Months of operational disruption. All because of one missing control they didn’t know they needed to document.
So what exactly are insurers checking? Here are the 8 requirements that come up most consistently.
The 5 Cyber Insurance Requirements Insurers Actually Check
These aren’t suggestions buried in the fine print. They’re active checkboxes that underwriters and post-claim forensic teams verify. If one is missing or can’t be proven, your claim is at risk.
1. Multi-Factor Authentication (MFA) Across Critical Systems
MFA is the single biggest factor separating approved claims from denied ones. Coalition’s 2024 data found that 82% of denied claims involved organizations that did not have MFA in place.
But here’s what most business owners miss: insurers don’t just want to know if you have an MFA; they want to know where it’s applied. The systems they specifically look at include:
- Remote desktop and VPN access
- Business email accounts
- Cloud storage and file-sharing platforms
- Financial and payroll systems
- Admin and privileged accounts
A single system left without MFA can be enough to trigger a denial, because that’s often exactly where attackers find their way in.
2. Endpoint Detection & Response (EDR), Not Just Antivirus
Your old antivirus software does not count anymore. Insurers now specifically ask whether you’re running EDR tools, and they know the difference.
Antivirus works by recognizing threats it’s already seen before. EDR watches behavior, how programs are acting, and whether something is trying to move through your network or access files it shouldn’t. As we’ve broken down in our look at why traditional security tools fall short against modern threats, attackers have evolved well past what antivirus was built to catch.
Insurers understand this too. Many now explicitly exclude claims where only legacy antivirus was running at the time of the breach. Upgrading to EDR is both a security improvement and a claims protection move.
3. Regular, Tested, Offline Backups
Having backups isn’t enough. When a claim is filed, insurers look at three specific things:
| What They Check | What They’re Looking For |
|---|---|
| Backup frequency | Daily or near-daily backups, not weekly or monthly |
| Storage location | Offline/air-gapped copies, not just cloud or network-connected |
| Restore testing | Documented proof that backups have been successfully restored |
The reason offline storage matters: modern ransomware specifically targets network-connected backups first. Attackers know that if they encrypt your backups alongside your primary systems, you have no choice but to pay. Many businesses have discovered this the hard way: their backups existed but were encrypted right alongside everything else.
An untested backup is an assumption, not a recovery plan. Insurers have seen too many cases where backups existed on paper but failed completely in practice.
4. Incident Response Plan (Documented & Practiced)
When a breach happens, what does your business actually do in the first hour? The first day? Who gets notified, and in what order?
Insurers expect you to have a written incident response (IR) plan in place before anything goes wrong, not a general idea of who you’d call but a documented process. Many policies also require you to notify the insurer within a specific timeframe after discovering an incident. Miss that window, and a legitimate claim can be denied on procedural grounds alone.
A common mistake I’ve seen play out more than once: A business owner calls their IT person, spends two or three days trying to contain the situation internally, and only then notifies the insurer. That delay alone has been enough to trigger denials.
Your IR plan should cover, at minimum:
- Who is responsible for declaring an incident?
- Internal and external notification contacts (including your insurer)
- Steps to contain and preserve evidence
- How and when to engage external forensic support
5. Patch Management – With Proof
Keeping software up to date sounds basic. But insurers don’t just want to know that you try to patch regularly; they want logs proving it happened.
There’s a specific window forensic teams focus on: the time between when a vulnerability was publicly disclosed and when your systems received the fix. If attackers exploited a known flaw that had a patch available for 45 or 60 days prior, and your logs show you hadn’t applied it, that’s not an unknown threat; it’s a preventable one. Insurers treat it accordingly.
Patch management needs to be systematic, scheduled, and documented. That paper trail is what protects your claim when investigators start pulling records.
What Happens When One Requirement Is Missing
Here’s the honest version of what happens after a breach when one of these controls is absent or undocumented.
The insurer sends in a forensic team. These are not people who take your word for anything; they pull system logs, review configurations, check access records, and compare findings against what you stated in your application. If there’s a gap, it surfaces quickly.
The outcomes break down roughly like this:
| Scenario | Likely Outcome |
|---|---|
| One control missing but documented as in progress | Possible partial payout |
| Control missing and no documentation | High likelihood of full or partial denial |
| Application stated control was in place but it wasn’t | Risk of coverage rescission (policy voided retroactively) |
How to Know If You’re Actually Insurable Right Now
Most businesses can’t answer that with confidence, not because they haven’t tried, but because they’ve never run a structured assessment against what their specific policy actually requires.
Start here: pull out your current policy and read the conditions section, not the coverage page, but the part that lists security requirements. Then work through this quick self-check:
- MFA: Is it enabled on every system listed above, with logs to prove it?
- EDR: Are you running it, and is it actively monitored?
- Backups: When did you last successfully restore from an offline backup?
- IR plan: Is it written, current, and does your team know it exists?
- Patching: Do you have logs from the last 90 days?
If your policy is more than 12 months old and you haven’t had a detailed renewal conversation, that’s overdue.
This is exactly where working with an IT consulting partner becomes valuable before a crisis, not after. A proper controls gap assessment ahead of your next renewal gives you the chance to close what’s missing on your terms.
In Conclusion
Cyber insurance is only valuable if it actually pays out when you need it. And right now, that’s far from guaranteed for businesses that haven’t built their security practices around what insurers actually verify.
The 8 requirements above aren’t a wish list; they’re what stand between a covered claim and a six-figure loss you absorb on your own. Before your next renewal, before your next policy conversation, know exactly where you stand on each one. Not roughly. With documentation you could hand it to a forensic investigator without hesitation.
Because the insurer’s forensic team won’t take your word for it, and you shouldn’t expect them to.