Resource Guide

What Cyber Insurance Companies Expect From Small Businesses

Cyber insurance applications increasingly ask detailed questions about MFA, backups, endpoint security, email, employee access, and incident preparedness. Here's what those questions mean and how to determine whether your answers match what's actually happening in your environment.

Cyber insurance requirements vary by insurer and policy. This guide provides general cybersecurity information and is not insurance, legal, or coverage advice. Confirm specific requirements with your insurance professional and policy documents.

The Context

Why cyber insurance applications ask so many technical questions

Insurers are attempting to understand your organization's cyber risk and the controls being used to reduce that risk.

Identity securityMultifactor authenticationEndpoint protectionEDR / MDRBackupsEmail securityPatch managementRemote accessAdministrator privilegesSecurity awarenessIncident responseBusiness continuityData protectionVendor / third-party risk

The questionnaire is not simply an IT exercise. The answers can become representations made during the insurance application process, so businesses should understand what they are answering rather than automatically checking "Yes."

This guide does not provide legal conclusions about how an inaccurate answer will affect a specific claim or policy. Confirm specific requirements and consequences with your insurance professional and policy documents.

The Requirements

The most common cybersecurity controls insurers ask about

These are frequently evaluated areas. Whether any specific control is required depends on the insurer and policy.

1

Multifactor Authentication (MFA)

MFA requires a second form of verification beyond a password. Insurers may ask whether MFA protects Microsoft 365, remote access, VPN, administrative accounts, cloud applications, and privileged systems. 'We use MFA somewhere' is different from knowing exactly which users, systems, and access methods are protected by MFA.

Microsoft 365 Security Assessment
2

Endpoint Detection and Response (EDR)

Traditional antivirus looks for known threats. EDR is designed to detect suspicious behavior on devices and support investigation. Some insurers ask specifically about endpoint security capabilities rather than simply whether antivirus is installed. Managed Detection and Response (MDR) generally adds human monitoring, investigation, and response capabilities around security telemetry depending on the service. Not all EDR or MDR products provide identical capabilities.

3

Backup and Recovery

Insurers may ask what is backed up, how frequently, retention, whether backups are isolated or protected, whether restores are tested, whether Microsoft 365 or cloud data is protected, and who monitors backup failures. 'We have backups' is not the same as knowing whether the organization can recover.

Does Microsoft 365 Include Backup?
4

Email Security

Controls around phishing, malicious attachments and links, account compromise, email authentication, and Microsoft 365 security. Email is one of the most common entry points for business compromise.

What Is Business Email Compromise?
5

Patch & Vulnerability Management

Patch management is deploying available updates. Vulnerability management is identifying, evaluating, and addressing security weaknesses more broadly. An insurer may ask about frequency, critical vulnerabilities, or internet-facing systems. There is no universal patch deadline unless a specific insurer or applicable framework specifies one.

6

Remote Access Security

Controls around VPN, remote desktop, remote management, MFA, authorized remote-access tools, and access review. Poorly secured remote access is a frequently exploited entry point.

7

Privileged / Admin Access

Least privilege means giving people only the access they need. Insurers may ask about administrator accounts, local administrator rights, separate privileged accounts, former employees, and vendor access. A compromised privileged account can create greater risk than a compromised normal user account.

8

Security Awareness Training

Employee education may cover phishing awareness, business email compromise, reporting suspicious activity, payment verification, and password and account practices. Training alone does not prevent cyber incidents, but it is commonly evaluated.

9

Incident Response Plan

Insurers may want to understand whether the organization has considered what happens after an incident. A plan may address who gets called, who makes decisions, IT and security response, insurance notification, legal resources, communications, evidence preservation, and recovery.

10

Security Monitoring

There is a distinction between having security software and having someone actually reviewing and responding to meaningful alerts. Insurers may ask whether alerts are actively monitored and by whom.

The Risk

The dangerous checkbox problem

The insurance application asks: "Does your organization require multifactor authentication for remote access?" Someone remembers using a Microsoft Authenticator prompt and checks YES.

But nobody verifies whether MFA actually applies to every remote user, VPN access, administrator access, legacy access methods, or other remote systems.

The correct answer should come from verification, not assumption.

Don't answer what you think your IT environment does. Verify what it actually does.

This guide does not make legal claims about policy rescission, claim denial, or coverage. Those outcomes depend on the insurer, policy language, and circumstances. Work with a qualified insurance professional for coverage and policy questions.

Practical

Ask your IT provider before you submit the application

Copy these directly into your next review.

Is MFA enforced for all Microsoft 365 users?
Which administrator accounts are protected by MFA?
Is remote access protected by MFA?
What endpoint security platform is deployed?
Do we have EDR?
Is security actively monitored? By whom?
What data is backed up?
Are backups monitored?
When was the last successful restore test?
Is Microsoft 365 data backed up separately?
How quickly are critical vulnerabilities addressed?
Do users have local administrator rights?
Do we provide cybersecurity awareness training?
Do we have a written incident-response plan?
How are former employee accounts disabled and access removed?
Do we have documentation supporting these answers?

If your IT provider can't immediately answer every question, that doesn't automatically mean they're doing something wrong. But these are questions the business should ultimately be able to answer accurately.

The Distinction

Cyber insurance readiness vs. cybersecurity

Passing an insurance questionnaire is not the same thing as having a mature cybersecurity program. An organization can potentially satisfy individual questionnaire items while still having meaningful risk elsewhere.

Conversely, an organization may have strong controls that aren't specifically asked about on a particular application.

The goal shouldn't be to build cybersecurity around a questionnaire. The goal is to build a defensible security program and then accurately describe it on the questionnaire.

Interactive Self-Check

Cyber insurance readiness check

Answer honestly. No contact information is required to see your result, and this is not an insurance application.

Is MFA enforced for Microsoft 365?

Is MFA required for remote access?

Are administrator accounts protected appropriately?

Is EDR deployed on business endpoints?

Is someone monitoring security alerts?

Are backups monitored?

Have restores been tested?

Are critical systems centrally patched?

Do employees receive cybersecurity awareness training?

Does the business have an incident-response plan?

Are former employee accounts promptly disabled?

Can the business document these controls if asked?

Answer all 12 questions to see your readiness summary.

Documentation

What documentation should we keep?

Businesses should maintain reasonable evidence of important controls. Documentation helps the business know what is actually implemented rather than reconstructing the environment once an application or incident occurs.

MFA configuration
Security platform deployment
Backup reports
Restore testing records
Security awareness records
Patch-management reports
Incident-response plan
Access-control procedures
Employee onboarding and offboarding procedures
Security policies
Relevant vendor or service documentation

Do not store passwords, secrets, or private keys in these documents. Documentation should describe controls and procedures, not contain credentials.

The Process

What if the insurer requires something we don't have?

1

Understand exactly what the insurer is asking.

2

Verify the current technical state.

3

Identify the gap.

4

Determine whether configuration, licensing, new technology, or process changes are required.

5

Implement and verify the control.

6

Document the result.

7

Answer the application based on the verified state.

Do not simply change an answer to get through underwriting.

Glossary

Common cyber insurance terms business owners should understand

MFA

Multifactor Authentication. A second form of verification beyond a password.

EDR

Endpoint Detection and Response. Security software designed to detect and investigate suspicious activity on devices.

MDR

Managed Detection and Response. Generally adds human monitoring, investigation, and response around security telemetry.

Immutable Backup

A backup copy that cannot be altered or deleted during its retention period.

Offline / Isolated Backup

A backup stored separately from the production environment to reduce exposure to compromise.

Least Privilege

Giving users only the access they need to do their jobs.

Privileged Account

An account with elevated permissions, such as an administrator account.

Vulnerability Management

Identifying, evaluating, and addressing security weaknesses across systems.

Incident Response

The process for detecting, containing, and recovering from a security incident.

Business Continuity

Planning to keep critical operations running during and after a disruption.

Ransomware

Malicious software that encrypts or disrupts systems and demands payment, often combined with data theft.

Business Email Compromise

Fraud using a trusted business identity to manipulate payments, information, or access.

Planning

Before your next cyber insurance renewal

This is a practical planning recommendation, not an insurer-mandated requirement.

1

60 to 90 days before renewal

Review the previous application and current security requirements. Understand what has changed in your environment and what the insurer may ask this cycle.

2

Verify technical controls

Confirm MFA, EDR, backups, monitoring, remote access, and other relevant controls are actually in place and functioning as expected.

3

Address gaps

Do not wait until the application deadline to discover a security requirement. Identify and close gaps while there is time to do it properly.

4

Gather documentation

Have supporting information available so answers can be verified rather than reconstructed under pressure.

5

Complete the application carefully

Coordinate between business leadership, your IT or security provider, and your insurance professional where appropriate.

Transparency

What Titan can and cannot do

Titan CAN

  • Review technical cybersecurity controls
  • Verify security configurations within an agreed scope
  • Help identify technology gaps
  • Help implement appropriate controls
  • Help document the technical environment
  • Explain technical questionnaire terminology
  • Help businesses prepare technical information for discussions with their insurance professional

Titan DOES NOT

  • Sell cyber insurance unless Titan actually holds appropriate licensing and offers that service
  • Determine whether coverage will be issued
  • Interpret insurance contracts as legal advice
  • Guarantee a claim will be covered
  • Decide how an insurer will underwrite a business

Work with a qualified insurance professional for coverage and policy questions.

About Titan

How Titan helps with cyber insurance readiness

Titan IT Management helps small and midsized businesses build and verify the technical controls frequently encountered during cyber insurance readiness discussions, including MFA, Microsoft 365 security, endpoint security, EDR and MDR, email security, security monitoring, backup and recovery, patch management, identity and access management, incident preparedness, and documentation.

We serve businesses throughout Florida's Treasure Coast, including Stuart, Port St. Lucie, Jensen Beach, and Fort Pierce. Our role is to help you understand what is actually in place, verify it, document it, and describe it accurately, so your application reflects the real state of your environment.

FAQ

Common questions about cyber insurance requirements

Is MFA required for cyber insurance?

Many insurers ask about MFA, particularly for remote access, administrative accounts, and cloud applications like Microsoft 365. Whether it is required depends on the insurer and policy. MFA is one of the most commonly evaluated controls, so it is worth verifying exactly where it is and is not enforced before answering.

Do cyber insurance companies require EDR?

Some insurers ask specifically about endpoint detection and response capabilities rather than only whether antivirus is installed. Requirements vary by insurer and policy. If an application asks about EDR, confirm what is actually deployed and whether it is actively monitored.

Do I need backups for cyber insurance?

Insurers frequently ask about backups, including what is backed up, retention, whether backups are isolated, and whether restores have been tested. Specific requirements vary. 'We have backups' is usually not a sufficient answer; verify that recovery actually works.

What is a cyber insurance questionnaire?

A cyber insurance questionnaire is the set of technical and operational questions an insurer uses to understand an organization's cyber risk and security controls during application or renewal. The answers can become representations made during the underwriting process, so they should reflect the verified state of the environment.

Can my MSP help with a cyber insurance application?

An MSP or IT provider can help verify technical controls, explain questionnaire terminology, identify gaps, implement controls, and document the environment. They cannot determine coverage, interpret insurance contracts as legal advice, or guarantee a claim. Work with a qualified insurance professional for coverage and policy questions.

What happens if I don't have a security control the insurer asks about?

First understand exactly what the insurer is asking, then verify the current technical state and identify the gap. Determine whether configuration, licensing, new technology, or process changes are needed, implement and verify the control, document the result, and answer the application based on the verified state. Do not change an answer simply to get through underwriting.

Research & Sources

Sources & further reading

Cyber insurance underwriting requirements vary by insurer, policy, industry, organization size, coverage, and risk profile. The sources below support general cybersecurity guidance, not specific insurance requirements.

CISA

Cybersecurity Performance Goals (2024)

CISA's Cybersecurity Performance Goals outline practical security practices for small and medium businesses, including MFA, asset management, incident response, and data protection, many of which overlap with common cyber insurance expectations.

View source

Secure by Design (2024)

CISA guidance encouraging security to be built into products and services, relevant to understanding how insurers evaluate vendor and product security.

View source

NIST

Cybersecurity Framework (2024)

The NIST Cybersecurity Framework organizes cybersecurity activities across identify, protect, detect, respond, and recover, and is commonly referenced when describing the controls insurers evaluate.

View source

Small Business Cybersecurity Corner (2024)

NIST resources helping small businesses understand and implement fundamental cybersecurity controls, many of which align with insurance questionnaire topics.

View source

FBI / IC3

Internet Crime Report (2024)

The FBI Internet Crime Complaint Center annual report documents business email compromise, ransomware, and other cybercrime trends that influence how insurers assess risk.

View source

Microsoft

Microsoft 365 security documentation (2025)

Microsoft documentation covering MFA, conditional access, identity protection, and Microsoft 365 security configuration, relevant to verifying controls insurers frequently ask about.

View source

Know what you can verify before you sign.

Cyber insurance applications ask detailed technical questions for a reason. Titan helps Treasure Coast businesses verify, document, and accurately describe the controls insurers commonly evaluate, without fear-based marketing and without providing insurance or legal advice.