Cyber insurance for SMBs: what insurers require before covering you
By the QuantumSec team
It's increasingly common for an insurer to reject a cyber insurance claim, or refuse to issue the policy at all, because the company hadn't implemented the minimum controls it declared on the application questionnaire. Cyber insurance is no longer a blank check: it's a contract with concrete technical conditions that must be met before, during and at the moment of the incident. This guide explains what controls are required today and how to avoid surprises.
The minimum controls almost every insurer requires
Two-factor authentication (MFA) on email, VPN and administrative access; regular, tested backups, ideally with at least one offline or immutable copy; managed antivirus/EDR on every device; a documented incident response plan; and anti-phishing staff training. Without these five, many insurers simply won't issue the policy, or will issue it with exclusions that hollow out the coverage.
Why a claim can be denied even with a policy in place
The application questionnaire you filled in when contracting the insurance is a binding declaration. If you stated MFA was enabled on all systems and the attack came through an account without it, the insurer can claim a material misrepresentation and deny the entire claim, not just the related portion. It's the most common reason for cyber insurance claim denial among SMBs.
How to verify you meet what you declared
Before renewing or contracting, it's worth a quick review of the controls you're about to declare: is MFA active on ALL critical systems, not just some? Are backups actually tested, or just generated? Is the asset inventory you give the insurer up to date? A basic vulnerability assessment before renewal catches these gaps before the insurer finds them during a claim.
How to lower the premium without lowering coverage
The more controls you can prove, not just declare, with documented evidence, the better premium you get. A recent pentest or vulnerability assessment report, a documented security policy and an anti-phishing training log usually translate into real discounts at renewal, because they lower the perceived risk for the insurer.
FAQ
Does cyber insurance replace having security measures?
No, it's complementary. It covers part of the financial impact of an incident (forensics, notification, potential fines, business loss), but it doesn't prevent the incident or exempt you from basic controls.
What if I don't have any of the required controls?
You can often still get coverage, but at a much higher premium or with specific exclusions for scenarios tied to the missing control. It pays off to implement them before contracting, not after.
Do I need a vulnerability assessment before buying the insurance?
It's not mandatory, but it's the fastest way to know whether what you're about to declare on the questionnaire is actually true, and to catch gaps before the insurer finds them during a claim.