Pumpkin
    Cyber Insurance Requirements, and What to Put in Place First
    Security

    Cyber Insurance Requirements, and What to Put in Place First

    By Aaron WatersOctober 8, 2024Updated August 15, 20265 min read

    Cyber insurance requirements have quietly become the strictest security standard most firms will ever face. To get covered at a sane premium, and to keep the coverage valid when it matters, you'll need MFA everywhere, endpoint detection someone actually watches, backups stored beyond ransomware's reach, patching discipline, documented training, and a written response plan. Overstate any of it on the application and the policy can evaporate exactly when you need it. That's the whole landscape. The rest is detail, and the detail is where firms get hurt.

    Why carriers got strict

    For years, cyber insurance was a short questionnaire and a modest premium. Then ransomware and wire-fraud losses hammered the carriers, and they responded the way insurers always respond: higher prices, narrower coverage, and applications that read like security audits. The change annoys everyone, and it contains a useful signal. The controls carriers now demand are a data-driven list of what actually reduces losses. They've seen the claims. They know what fails.

    What the losses look like at small-firm scale

    The reason to carry coverage at all is arithmetic. One documented case: a small accounting firm's ransomware recovery came to roughly $84,000 all-in, spread across the ransom itself, business interruption, client notifications, and rebuilding systems. Look at the composition, because it's instructive. The ransom is one line. The other lines keep arriving for months.

    Notice also that the bill is really a pile of vendors hired in a panic: forensics, counsel, a notification service, IT rebuild help. Firms that already run tidy vendor management at least hire calmly, know what they're signing, and can hand the insurer a clean paper trail. Firms that don't add panic pricing to every line item while the office is down.

    For a five-person practice, $84,000 lands during the exact weeks billing has stopped. That's the event insurance exists for. It's also the event carriers now make you prove you're guarding against before they'll take your premium.

    The requirements list

    **MFA, and they now ask which kind.** Multi-factor authentication on all email, all remote access, all admin accounts, all financial systems. Applications have grown pointed about method, with some carriers rejecting SMS codes for remote access outright. The distinction matters because MFA has known bypasses, and carriers price accordingly.

    **Detection someone watches.** Basic antivirus stopped satisfying underwriters a while ago. They want endpoint detection and response, centrally managed, with someone actually responding to alerts. For firms without an IT department, managed threat monitoring is how that box gets checked honestly, which is the only way worth checking it.

    **Backups ransomware can't reach.** Automated, stored separately from the main network, ideally immutable, and tested. Some applications now ask for the date of your last restore test. "We think it works" is not a date.

    **Patching with a deadline.** A documented process, critical patches applied within a defined window, and vulnerability scanning to catch what slipped.

    **Training with receipts.** Security awareness training on a schedule, phishing simulations, and completion records. Documentation is the operative word here, as you'll see.

    **A response plan that's been touched.** A written breach response plan with named roles, and increasingly, evidence of an annual tabletop exercise.

    The application is testimony

    Treat every answer as a statement the carrier will verify after a claim, because that's precisely what it is. If the application says MFA is everywhere and the forensics report finds one legacy system without it, the carrier has grounds to deny the claim or rescind the policy entirely. Firms don't usually lie; they answer optimistically, from memory, about systems nobody has audited. Same outcome.

    So involve whoever runs your IT in every technical answer, and where reality falls short of the question, fix reality before filing the application. A broker who specializes in cyber coverage for professional firms earns their keep here, both in matching you to carriers and in translating the questions.

    What the policy actually covers, and where it doesn't

    First-party coverage pays your own costs: forensics, restoration, business interruption, notifications, credit monitoring. Third-party coverage handles claims against you: client lawsuits, regulatory penalties, defense costs. And social engineering coverage, the part that pays when an employee is tricked into wiring money, is frequently a separate endorsement with a much lower sublimit than the headline number. For firms that move client money, that's the fine print most worth reading twice.

    Check the deductible against your cash reality, and read the exclusions. A policy that excludes losses from unpatched systems is quietly conditioning coverage on your patching discipline.

    Why claims get denied

    The patterns repeat. Controls that existed at application time but lapsed by breach time. Notification later than the policy's window, which is often 24 to 72 hours. Optimistic application answers contradicted by the forensics. And war exclusions applied to state-linked attacks, which is worth discussing with your broker rather than discovering in a denial letter.

    The common thread: the carrier relationship is ongoing, not annual. The controls you attest to have to stay true all year.

    Getting ready without drama

    Run a gap check against the requirements above before the application shows up, since insurers and regulators largely overlap in what they ask; closing your compliance gaps once serves both audiences. Implement what's missing, starting with MFA and backups. Document as you go, because carriers pay for evidence, not intentions.

    Here's the reframe that makes the whole exercise less annoying: everything on the carrier's list is something your firm should have wanted anyway. The premium is lower because the risk is lower, and the risk is lower because the controls work. The application is just the first audience for the security program described in our cybersecurity guide for firms. Build the program. The insurance follows.