cover image background
Our Blog
24 Hourtek cybersecurity and businesses, tips and best practices
cover image background
Our Blog
24 Hourtek cybersecurity and businesses, tips and best practices
cover image background
Our Blog
24 Hourtek cybersecurity and businesses, tips and best practices

Small Business

Cyber Insurance Readiness: What Small Businesses Need Before Applying or Renewing

Todd Moss

Todd Moss

CEO, Co-Founder

Cyber Insurance Readiness: What Small Businesses Need hero image

Cyber Insurance Readiness: What Small Businesses Need Before Applying or Renewing by Todd Moss

Applying for cyber insurance can feel like an IT exam that landed on the desk of someone in finance or operations. The questions may cover authentication, backups, devices, cloud systems, employee training, vendors, and incident response, sometimes in language that does not match the way your team normally talks about technology.

A better way to approach the process is to treat it as a review of how your business actually manages risk. That is also the foundation of a practical cybersecurity approach: understand what needs protection, control access, build reasonable safeguards, prepare for problems, and keep improving the environment over time.

Cyber insurance can help transfer some financial risk. It cannot replace those operating practices. The goal before applying or renewing is not to make your business look perfect. It is to know what is true, understand where the meaningful gaps are, and answer the insurer accurately.

What do small businesses need before applying for cyber insurance?

Before applying for or renewing cyber insurance, a small business should understand its systems and sensitive data, know who has access to them, verify important security controls such as multi-factor authentication and backups, maintain basic incident response procedures, and gather evidence showing how those controls operate. Requirements vary by insurer, so the application itself should guide the final review.

That sounds straightforward, but the difficult part is usually not buying technology. It is answering seemingly simple questions precisely.

If an application asks whether multi-factor authentication is enabled, does that mean email? Remote access? Administrators? Contractors? Cloud applications? All of them?

If it asks whether data is backed up, knowing that a backup job runs every night may not tell you whether that backup can actually restore the systems the business needs.

The preparation process is therefore less about finding the “right” answer and more about establishing a reliable picture of the organization.

Cyber insurance readiness is really a risk-management exercise

Insurance and cybersecurity solve different parts of the same business problem.

Cybersecurity controls are intended to reduce the likelihood or impact of incidents. Insurance is intended to transfer certain financial consequences when an event covered by the policy occurs. Neither eliminates risk.

A business with insurance but weak security may still experience significant disruption, lost productivity, damaged data, or costs that fall outside the policy. A business with strong security can still have an incident because no reasonable security program can remove every possibility of error, technical failure, fraud, or attack.

Readiness means understanding both sides.

From the cybersecurity side, you want to know whether the controls you rely on actually work. From the insurance side, you want to know what the policy covers, what it excludes, what conditions apply, and whether your application accurately represents the environment.

The NIST Cybersecurity Framework 2.0 Small Business Quick Start Guide provides a useful way to organize that thinking. It groups cybersecurity risk management into six broad functions: Govern, Identify, Protect, Detect, Respond, and Recover.

You do not have to formally adopt the entire framework before buying insurance. Its structure simply highlights why insurance readiness goes beyond installing antivirus software. Leadership, asset visibility, prevention, monitoring, response, and recovery all matter.

Why the application can be harder than expected

Small businesses often have perfectly reasonable technology arrangements that developed gradually.

A company starts with email and laptops. Later it adds cloud storage, accounting software, remote access, collaboration tools, a CRM, online banking, contractors, mobile devices, and perhaps several specialized applications.

Each addition makes sense on its own. The challenge appears when someone asks for a single, accurate description of the whole environment.

One manager may believe MFA is required because everyone on their team uses it. IT may know that two older service accounts cannot use the same authentication method. Finance may assume backups include a SaaS platform that is actually outside the existing backup system.

None of those misunderstandings requires negligence. They usually point to something more ordinary: ownership and documentation have not kept pace with the technology.

A cyber insurance application brings those assumptions into the same room.

That can be useful even if some answers are uncomfortable. A documented “not yet” gives leadership something concrete to evaluate. An incorrect “yes” leaves the underlying weakness in place while creating a misleading picture of the organization.

What insurers may ask about

Applications vary by carrier, business type, coverage, and risk profile. You should therefore work from the actual questionnaire supplied by your insurer or broker rather than assuming every application will be identical.

Still, several areas regularly make sense from a cybersecurity risk perspective:

  • Identity and access: MFA, administrator privileges, remote access, password practices, user onboarding and offboarding, and access reviews.

  • Devices and systems: Endpoint protection, supported operating systems, software updates, vulnerability management, and monitoring.

  • Backups and recovery: Backup frequency, separation from production systems, access protection, retention, and restore testing.

  • Email and employee security: Phishing protection, employee cybersecurity training, reporting procedures, and financial verification processes.

  • Cloud services and vendors: Cloud account controls, sensitive-data access, third-party connections, privileged vendor access, and responsibility for configurations.

  • Incident response: Who makes decisions during an incident, how systems are isolated, who contacts the insurer, and how essential operations continue.

  • Data protection: What sensitive information the company keeps, where it lives, who needs it, and how it is protected.

  • Governance and documentation: Written policies, ownership, review schedules, previous incidents, and evidence supporting questionnaire answers.

You may not need the most sophisticated version of every control. A ten-person professional services company has different operational needs from a larger organization running complex infrastructure.

The important question is whether the safeguards make sense for the systems, data, people, and dependencies your business actually has.

Close-up of a laptop and smartphone

Cyber insurance applications often ask where MFA and other access controls are in place. Verifying actual coverage across important accounts and systems helps businesses answer accurately.

Start with identity and access

For many businesses, identity has become one of the most important security boundaries.

Employees may access email, files, accounting systems, project platforms, cloud infrastructure, and client portals from different locations and devices. If someone obtains a valid username and password, the attacker may not need to “break into” a traditional network at all. They may simply sign in.

Multi-factor authentication, or MFA, reduces that risk by requiring another form of verification in addition to a password.

The detail that matters during insurance preparation is not simply whether your company “uses MFA.” You need to know where it is actually required.

Check coverage, not just availability

A platform can support MFA without every relevant account being protected by it.

Review email accounts, administrator accounts, remote-access systems, major cloud services, backup consoles, financial applications, and other systems containing important business data.

Look for exceptions too. Old accounts, shared accounts, service accounts, temporary users, and administrators sometimes operate differently from ordinary employee accounts.

An insurer's question may distinguish between those categories. Your answer should too.

Review privileged access separately

Administrative accounts deserve special attention because they can change configurations, create users, access large amounts of information, or disable security controls.

Ask who has administrative privileges and why. Someone who needed temporary admin access six months ago may still have it simply because nobody removed it.

This is the principle of least privilege in practical terms: people should have the access they need to do their jobs, without keeping unnecessary additional permissions indefinitely.

That does not eliminate the possibility of account compromise. It limits what one compromised account can potentially do.

Treat backups as a recovery capability

“Do you have backups?” sounds like an easy question.

A more useful question is: “What could we restore if tomorrow's working copy were unavailable?”

Those questions are not always equivalent.

A backup can exist but still fail to meet the business's recovery needs. Perhaps only some systems are included. Perhaps an administrator account that controls normal production systems can also delete the backups. Perhaps the backup has run successfully for months, but nobody has tested whether the data can be restored.

Insurance readiness is a good reason to work through those details.

For each important system, know what gets backed up, how frequently it happens, where the copies are stored, who can access them, how long they are retained, and when a meaningful restore was last tested.

A successful backup notification proves that a process ran. A restore test gives you better evidence that the recovery process works.

It also forces a business question: how long could the organization realistically operate without that system?

Accounting may tolerate a different recovery window from a customer-facing application. A nonprofit may care most about donor records and operational files. A startup may be more dependent on source code, cloud infrastructure, and SaaS applications.

Recovery priorities should follow the business, not an arbitrary technology checklist.

Know what endpoint protection actually covers

Endpoints are the laptops, desktops, servers, and similar devices people use to interact with business systems.

Traditional antivirus primarily looks for known malicious software. Modern endpoint detection and response, often shortened to EDR, adds more visibility into suspicious behavior and gives administrators additional ways to investigate or contain activity.

You do not need to turn the insurance application into a product comparison exercise. You do need to know what is deployed and where.

An endpoint security platform that protects 45 laptops is not necessarily protecting the whole company if there are 52 laptops, five servers, and several unmanaged devices connecting to business applications.

Inventory matters here.

It is difficult to confidently say systems are protected, updated, or monitored when nobody has a reasonably current list of those systems.

This is one reason basic asset management remains an important cybersecurity practice even when more sophisticated security tools are available.

Patching is about reducing known exposure

Software vendors routinely fix vulnerabilities and other security problems through updates.

A small business does not need to interrupt everyone every time an update appears. It does need a reasonable process for keeping operating systems, browsers, applications, network equipment, and other important systems supported and current.

During insurance preparation, look for two problems.

The first is delayed updating. Systems may technically receive patches, but only when someone remembers.

The second is unsupported technology. Older software can remain operational long after the vendor has stopped providing normal security updates.

Replacing a legacy application may be expensive or operationally difficult. That does not mean leadership should pretend the risk is absent.

Document the system, understand why it remains in use, reduce exposure where practical, and create a realistic plan for replacing or isolating it.

That is better risk management than claiming every system is current when it is not.

Cloud security belongs in the same review

Many small businesses no longer have one clearly defined “network.” Their technology environment is spread across Microsoft 365 or Google Workspace, SaaS applications, file-sharing platforms, cloud infrastructure, mobile devices, and third-party services.

The cloud provider may secure the underlying platform, but your business still controls important things such as users, permissions, sharing, administrators, and many configuration choices.

That is why insurance preparation should include a cloud access review.

Ask who has administrator rights, whether MFA is enforced, which outside users still have access, whether old accounts have been disabled, and whether important files or resources have broader sharing permissions than intended.

Our guide to cloud security across AWS, Azure, and Google Cloud goes deeper into this issue, including access reviews, least-privilege permissions, centralized identity, monitoring, and backup testing.

The underlying lesson applies beyond those three platforms. Cloud security needs ongoing ownership.

A system can be configured sensibly today and become less controlled over time as people join, leave, share information, install integrations, and create exceptions.

Employee security practices matter too

A cyber insurance questionnaire may ask about employee cybersecurity training, but the useful goal is not simply being able to check a training box.

Employees make security decisions while doing ordinary work. They receive unexpected attachments. Vendors request changes to payment information. Someone sends a file-sharing link. A new employee needs access quickly. A manager gets a login notification while rushing between meetings.

Good security awareness gives people a practical response to those moments.

Training should explain what employees are likely to encounter, how to verify unusual requests, where business information should be stored, how to report suspicious activity, and what to do after a mistake.

Just as importantly, the secure process has to be usable.

If the official method for sharing a large client file is so cumbersome that employees routinely use personal storage accounts instead, the company does not really have a file-sharing policy. It has a policy on paper and a different workflow in practice.

We have written separately about building a security culture without slowing productivity. That balance matters here because insurer readiness works best when security controls are part of normal operations rather than temporary rules introduced before renewal.

At 24hourtek, this is one reason we tend to look at security alongside the rest of the IT environment. Identity, devices, cloud tools, people, access, and support processes affect one another.

Have an incident response plan people can actually use

An incident response plan answers a basic question: if something serious happens, who does what?

It does not need to be a hundred-page manual.

For a small business, a useful plan may identify who can make decisions, who has authority to disable accounts or systems, how employees report suspicious activity, who contacts the insurer or broker, which outside specialists may need to be involved, and how critical business functions continue during disruption.

The plan should also distinguish technical recovery from business decision-making.

IT may investigate a compromised account. Leadership may need to decide whether certain services should be taken offline. Legal counsel may need to evaluate notification or contractual obligations. The insurer may have specific reporting requirements or preferred incident-response resources.

Those roles should not be invented while everyone is already dealing with an incident.

A tabletop exercise can help. Walk through a hypothetical situation with the people who would actually participate.

For example, imagine that several employee accounts appear to be compromised on a Monday morning. Who notices? Who disables access? How does the company communicate if email itself cannot be trusted? Who determines whether client information may have been affected? Who checks the policy's reporting requirements?

The exercise will usually reveal small operational gaps that are easier to fix before a real problem.

Business team reviewing documents

Cyber insurance readiness works best as a shared review across leadership, operations, finance, and IT. Verifying controls and documenting accurate answers before renewal helps reduce guesswork and makes future reviews easier.

Build evidence while you review the controls

One of the most useful things a business can do before completing a cyber insurance application is create a simple evidence folder.

The purpose is not to produce an enormous compliance archive. It is to make sure someone can support important answers without relying on memory.

Useful documentation might include:

  • An inventory of important systems, devices, cloud platforms, and responsible owners.

  • A summary of where MFA is enforced and any documented exceptions.

  • Current endpoint protection or device-management coverage.

  • Backup configurations, retention information, and the date and result of recent restore testing.

  • Written onboarding and offboarding procedures.

  • Relevant cybersecurity policies and employee training records.

  • The incident response plan and contact information for key participants.

  • Records of important security reviews, such as administrator access or critical vendor access.

The exact evidence will depend on what the application asks.

Documentation also has value after the insurance form is complete. It reduces dependence on institutional memory.

If the person who configured your backups leaves next month, the company should still know how those backups work. If a finance manager changes roles, someone else should be able to find the incident reporting information.

That is operational resilience, not paperwork for its own sake.

Do not guess when answering the questionnaire

Insurance applications often move between several people.

Finance may coordinate with the broker. Operations may answer process questions. IT may provide technical details. Leadership may approve the final application.

That is reasonable, but it creates room for answers to become simplified as they move between teams.

Suppose the insurer asks, “Is MFA required for all remote access?”

An employee remembers using MFA when working remotely and says yes. The answer reaches finance and goes onto the application.

Meanwhile, an older remote-access system still permits one administrator to sign in differently.

The better process is to verify what the question means, check the actual configuration, and answer based on the environment as it exists.

If a control is only partially implemented, describe the reality accurately when the form provides space to do so. If the wording is unclear, ask the broker or insurer what they mean rather than interpreting the question in whichever way produces the most favorable answer.

Application accuracy matters because policy terms, underwriting decisions, and claim handling can depend on the information supplied. The legal consequences of an inaccurate statement vary with the circumstances, policy language, and applicable law, so material questions should not be treated casually.

Fix meaningful gaps before cosmetic ones

An insurance questionnaire can create an understandable temptation to treat every “no” as a problem that must immediately become “yes.”

That is not always the smartest use of limited money or time.

First identify controls that reduce meaningful business risk regardless of insurance.

Broad MFA coverage is a good example because stolen credentials are a practical problem across email, cloud applications, and remote access.

Reliable backups and tested recovery matter because many different events can make data unavailable, including cyber incidents, technical failures, accidental deletion, and administrative mistakes.

Removing unnecessary administrator rights is useful because it limits what one account can change.

Supported software and consistent patching reduce exposure to known vulnerabilities.

A clear incident response process helps people make better decisions when something goes wrong.

These controls have operational value even if an insurer never asks about them.

More specialized investments should follow the organization's actual risk and the insurer's requirements. A company should not buy an expensive security platform simply because the product appears on someone else's insurance-readiness checklist.

Understand the policy, not just the application

Passing underwriting is only part of the decision.

Business leaders should also understand what they are buying.

The FTC's guidance on cyber insurance recommends discussing with the insurance professional whether the company needs first-party coverage, third-party coverage, or both.

First-party coverage generally concerns losses experienced directly by the insured business, while third-party coverage concerns certain liabilities or claims brought by others. Exact coverage depends on the policy.

Look closely at the events covered, exclusions, sublimits, deductibles or retentions, notification requirements, business interruption provisions, data-restoration coverage, incident-response resources, and treatment of third-party systems or vendors.

Do not assume the label “cyber insurance” tells you what a particular policy will pay for.

Two policies can use similar names while handling specific events differently.

The right policy is therefore not simply the one with the easiest application or lowest premium. It is the one whose terms make sense for the losses your organization is actually trying to transfer.

Your broker or insurance adviser should explain those terms. Technical staff can help leadership understand whether policy conditions match how systems are actually configured and operated.

Pay attention to third parties

A small business may have limited internal infrastructure while depending heavily on outside platforms.

Payroll, accounting, customer relationship management, file storage, email, payment processing, cloud hosting, and industry-specific applications may all be operated by vendors.

Insurance preparation is a good time to map those dependencies.

Start with the vendors that can access sensitive information, connect directly to business systems, administer technology, or support functions that would be difficult to operate without.

Ask what access each vendor has and whether that access is still required.

A former implementation consultant does not need permanent administrator rights because they might be useful again someday.

Vendor management does not mean auditing every software company as if you were a large enterprise procurement department. Small businesses can prioritize the handful of providers whose failure or compromise would have the greatest effect.

This also helps when evaluating insurance coverage for incidents involving third-party systems.

Renewal should not be the first security review of the year

Cyber insurance readiness becomes much easier when the organization does not recreate its cybersecurity picture once every twelve months.

Systems change too quickly.

Employees join and leave. New SaaS tools appear. Vendors get replaced. Administrators receive temporary privileges. New devices arrive. Old devices stop reporting into management tools. Backups change. Business processes move.

A quarterly or semiannual review of a few high-value areas can prevent those changes from accumulating unnoticed.

For example, review administrator access, major cloud accounts, security-tool coverage, critical vendors, and backup status on a regular schedule.

Then test the incident response plan periodically and document meaningful changes to the environment.

This turns insurance renewal from an investigation into a confirmation exercise.

Instead of asking, “Do we still have MFA everywhere?” you already have a record of the latest access review.

Instead of asking, “Has anyone ever restored that backup?” you know when the last recovery test occurred.

Security becomes quieter when ownership is clear.

What should you do 60 to 90 days before renewal?

Starting before the application deadline gives the business room to investigate discrepancies and make thoughtful improvements rather than rushing changes into production.

A practical sequence looks like this:

  1. Get the current application or renewal questionnaire. Ask the broker for it early if possible, and compare it with the previous version rather than assuming the questions are unchanged.

  2. Bring the right people together. Finance or operations can coordinate, but technical questions should be verified by whoever manages the relevant systems.

  3. Review last year's answers. Confirm that controls previously represented as being in place still operate as described.

  4. Verify the environment. Check MFA, administrators, remote access, endpoints, software support, backups, cloud accounts, employee practices, vendors, and incident response.

  5. Identify meaningful gaps. Separate straightforward fixes from changes that require planning, testing, budgeting, or policy decisions.

  6. Document evidence. Keep enough information to explain important answers and make next year's review easier.

  7. Review policy terms alongside security requirements. Cybersecurity readiness and insurance coverage are related, but they are not the same decision.

  8. Complete the application accurately. Do not turn partial implementation into a blanket “yes” simply to make the form look cleaner.

This timeline is not a rule. Some organizations may need more time, while simpler environments may need less.

The principle is to leave enough room to make good operational decisions.

What if your business cannot meet every requirement?

That is possible.

A small business may have a legacy application that cannot support the preferred authentication method. A specialized system may require administrator privileges. A security upgrade may need to wait until a planned migration.

The right response is not to hide the limitation.

Understand the risk, determine whether another control can reduce it, document the reason for the exception, and discuss the situation with the broker or insurer.

For example, if a legacy system cannot support modern MFA, perhaps access to it can be restricted through another authenticated gateway while the system is scheduled for replacement.

That does not make the old application risk-free. It shows that the business understands the limitation and is managing it deliberately.

Sometimes the insurer may require a particular control before offering certain coverage or terms. Sometimes there may be alternative arrangements. Those are underwriting decisions, not something an IT provider should promise in advance.

Cyber insurance should reinforce good security, not define it

There is a useful side effect to the insurance process when it is handled well.

It forces leadership, finance, operations, and IT to discuss the same risks.

Which systems actually matter to the business? What information would be difficult to replace? Who has powerful access? How quickly could operations recover? Who makes decisions during an incident? Which vendors are critical?

Those are worthwhile questions even if the company decides not to purchase a policy.

The mistake is allowing the questionnaire to become the entire cybersecurity strategy.

An insurer's application reflects underwriting needs. Your cybersecurity program has a broader job: keeping systems dependable, protecting information, limiting unnecessary access, supporting employees, detecting problems, and recovering when something fails.

There will always be controls that matter to your business even if they never appear on an insurance form.

About 24hourtek

24hourtek, Inc is a forward thinking managed service provider that offers ongoing IT support and strategic guidance to businesses. We meet with our clients at least once a month to review strategy, security posture, and provide guidance on future-proofing your IT.

📅 Let us help you, book a call with us today

Frequently Asked Questions

Can't find the answer you're looking for?

What security controls are commonly reviewed for cyber insurance?

Do small businesses need cyber insurance if they already have cybersecurity protections?

How should a small business prepare for a cyber insurance renewal?

Frequently Asked Questions

Can't find the answer you're looking for?

What security controls are commonly reviewed for cyber insurance?

Do small businesses need cyber insurance if they already have cybersecurity protections?

How should a small business prepare for a cyber insurance renewal?

Frequently Asked Questions

Can't find the answer you're looking for?

What security controls are commonly reviewed for cyber insurance?

Do small businesses need cyber insurance if they already have cybersecurity protections?

How should a small business prepare for a cyber insurance renewal?

Looking for a managed IT services provider?

Contact us today to explore the possibilities.

Learn how our team will future-proof your IT.

The Forward Thinking IT Company.

24HourTek serves businesses across the San Francisco Bay Area with managed IT support, cybersecurity, Microsoft 365 management, and IT consulting. Our clients are located throughout San Francisco, Oakland, San Jose, Fremont, Berkeley, Walnut Creek, Palo Alto, Redwood City, Santa Clara, and the broader Bay Area region, including Alameda County, Santa Clara County, and San Mateo County. We support companies of all sizes with both on-site and remote IT services across Northern California.

© 2024 All Rights Preserved by 24hourtek, LLC.

We focus on user experience as IT service partners.

24HourTek serves businesses across the San Francisco Bay Area with managed IT support, cybersecurity, Microsoft 365 management, and IT consulting. Our clients are located throughout San Francisco, Oakland, San Jose, Fremont, Berkeley, Walnut Creek, Palo Alto, Redwood City, Santa Clara, and the broader Bay Area region, including Alameda County, Santa Clara County, and San Mateo County. We support companies of all sizes with both on-site and remote IT services across Northern California.

© 2024 All Rights Preserved by 24hourtek, LLC.

The Forward Thinking IT Company.

24HourTek serves businesses across the San Francisco Bay Area with managed IT support, cybersecurity, Microsoft 365 management, and IT consulting. Our clients are located throughout San Francisco, Oakland, San Jose, Fremont, Berkeley, Walnut Creek, Palo Alto, Redwood City, Santa Clara, and the broader Bay Area region, including Alameda County, Santa Clara County, and San Mateo County. We support companies of all sizes with both on-site and remote IT services across Northern California.

24hourtek, LLC © 2024 All Rights Reserved.