Cyber Insurance Requirements: What Insurers Want | Catalyst IT

Cyber Insurance: What Insurers Actually Want to See

The fastest-growing forcing function in SMB cybersecurity — what carriers now require, what they don’t tell you, and how to pass the application without scrambling.

Cyber insurance has changed substantially over the past five years. What used to be a routine line item is now a meaningful annual review with detailed questionnaires, escalating requirements, and sharp consequences for misrepresenting your security posture.

For most SMBs, cyber insurance is the single largest external force pushing them toward better security practices. Insurers know exactly which controls correlate with claims. They are increasingly willing to deny coverage, raise premiums, or refuse renewal for businesses that don’t have those controls in place.

This is what insurers are actually looking for in 2026, and how to position your business to pass.

CYBER INSURANCE FOR SMBs

  • What Cyber Insurance Actually Covers
  • Why the Application Questionnaire Matters So Much
  • The Controls Insurers Now Require
  • The Controls They Reward
  • The Honesty Problem
  • Preparing for Renewal

What Cyber Insurance Actually Covers

Coverage varies by carrier and policy, but typically includes some combination of:

  • First-party costs: incident response, forensic investigation, data recovery, system restoration, business interruption losses
  • Third-party costs: legal liability, regulatory fines, notification expenses, credit monitoring for affected individuals
  • Cyber extortion: ransom payments and negotiation costs, where permitted
  • Social engineering / wire fraud: business email compromise losses, under specific conditions

What it typically doesn’t cover: pre-existing breaches, attacks resulting from misrepresented controls on the application, certain nation-state actors, and infrastructure that was end-of-life or out of support.

Reading the policy matters. Two policies with similar premiums can have substantially different practical coverage.

Why the Application Questionnaire Matters So Much

Modern cyber insurance applications are not formalities. They are detailed security questionnaires — sometimes dozens of questions covering MFA, EDR, backups, patching, training, incident response, and more.

The answers determine whether you’re insurable, at what premium, and with what exclusions. Misrepresenting answers — even unintentionally — can void coverage at the moment you need it.

This is the part most owners discover only when something goes wrong. The right time to verify your answers match reality is before you submit the application, not after a claim is denied.

The Controls Insurers Now Require

The current baseline for most carriers — controls that are increasingly non-negotiable for any meaningful coverage:

  • MFA on email, remote access, and admin accounts
  • EDR (Endpoint Detection and Response) on every device
  • Email security with anti-phishing and impersonation protection
  • Backups with off-network or immutable copies, tested regularly
  • Patching of operating systems and applications
  • Security awareness training for employees
  • An incident response plan

A business without all of these — or that can’t credibly document having them — should expect either denial of coverage or significantly higher premiums.

The Controls They Reward

Beyond the baseline, several controls increasingly produce favourable premium and coverage outcomes:

  • Network segmentation, particularly separating critical systems
  • Privileged access management
  • Vendor risk management — what controls your I.T. and software vendors maintain
  • Twenty-four-seven security operations or monitored detection and response
  • An established managed I.T. relationship with documented procedures
  • Ransomware-specific defences, including immutable backups and rehearsed recovery

Insurers see these as predictive of better outcomes when an incident occurs. The premium difference can be meaningful.

The Honesty Problem

A pattern we see at renewal time: a business has been answering yes to questions like “do you require MFA for all remote access” when the answer is actually “yes for most accounts, with a few exceptions for convenience.”

When that business has an incident, and the forensic investigation reveals the gap, the carrier denies the claim on grounds of material misrepresentation. Coverage that the business has paid premiums on for years evaporates.

The right approach is to answer applications honestly, and if your honest answers fall short of insurer expectations, fix the gaps before renewal — not at claim time.

Preparing for Renewal

A practical approach to cyber insurance renewal:

  • Start the process sixty to ninety days before the renewal date, not thirty
  • Review the previous year’s questionnaire against your current state — what has changed
  • Identify any gaps between insurer expectations and your actual posture
  • Plan and implement remediation for material gaps before submitting
  • Document your controls clearly — most carriers ask for evidence at this point, not just yes/no answers
  • Get a second set of eyes on the application, ideally from someone with current managed services experience

A managed I.T. partner who actually understands your environment can usually identify gaps quickly and help close them in time for renewal. This is one of the more concrete value-adds in a partnership relationship.

Cyber insurance is doing more to push SMB security forward than almost any other single force right now. The businesses that treat the questionnaire as a strategic exercise — rather than a form to fill out — get better premiums, better coverage, and better security as a side effect.

If your next renewal is approaching and you haven’t reviewed your answers against current reality, that’s worth a structured walkthrough.

Scroll to Top