In the spring of 2022, a small electronics manufacturer in Decatur, Illinois bought a cyber insurance policy. A few weeks later, ransomware hit one of their servers. They filed a claim expecting their insurer to step in.
Instead, the insurer sued them.
The company, International Control Services, had told its insurer that multi-factor authentication was in place across its administrative and privileged accounts. When investigators looked at what actually happened, they found MFA protecting exactly one thing: the firewall. Not the servers. Not the remote access points. Not the system the ransomware walked through. The insurer argued that the application itself was the problem, since the coverage had been issued based on a security posture that didn't exist. A federal court agreed, and the policy was voided from the day it was signed, as reported by Insurance Journal's coverage of the case. The business walked away with no coverage for a loss that had already happened.
Nobody at that company set out to defraud their insurer. Most likely, someone answered a questionnaire based on what they believed was true, or what they hoped was close enough. That gap between "we have MFA" and "we have MFA everywhere it needs to be" is exactly where a lot of small business cyber policies quietly fail, and it's becoming more common as insurers dig deeper before they pay a claim.
Cyber Insurance Isn't a Form Anymore
It used to be simple. A business answered a short questionnaire, signed it, and paid a premium. That era is over. Insurers spent several years absorbing enormous ransomware losses, and they responded by tightening underwriting and asking much harder questions before writing a policy.
The numbers explain why. According to the National Association of Insurance Commissioners' 2025 report on the cyber insurance market, the number of claims filed in the U.S. rose nearly 40% in 2024, reaching close to 50,000. Business email compromise alone drove over $2.77 billion in losses that year, and the same report notes that human error, social engineering, or privilege misuse played a role in roughly 60% of all breaches. Insurers are paying out more often, on more incidents, tied more directly to gaps in basic security hygiene rather than exotic attacks. That's why the questionnaire got longer and the follow-up investigation got sharper.
The practical result for a small business is this: the policy you sign is a promise about your security posture, not just a payment for coverage. If that promise turns out to be inaccurate, even by accident, it can undo the entire policy.
What Insurers Are Actually Looking For
Every carrier's questionnaire looks a little different, but a handful of controls show up almost everywhere. These aren't arbitrary. They map closely to how most claims actually happen.
- Multi-factor authentication, and specifically where it's enforced. Email, VPN and remote access, and privileged or administrator accounts are the ones insurers ask about most closely. Partial coverage, MFA on some systems but not others, is one of the most common gaps found after a breach.
- Endpoint detection and response (EDR) on workstations and servers. Traditional antivirus alone increasingly fails to meet the bar carriers set.
- Backups that are encrypted, isolated from the main network, and actually tested. A backup that hasn't been restored recently is a theoretical backup, not a working one.
- A written incident response plan that names who does what in the first hours of an incident, rather than something drafted once and never looked at again.
- Patch management for operating systems, firewalls, and business-critical software.
- Documented employee security training, since human error remains involved in the majority of breaches.
Any of these gaps can raise your premium, add exclusions, or, as the case above shows, become the reason a claim gets denied entirely. The FTC's small business cybersecurity guidance lays out what a policy should cover in return, including first-party coverage for your own recovery costs and third-party coverage if a client or customer sues over the incident. It's worth reading both sides of that equation before you sign anything, since what you owe your insurer in accuracy is matched by what they owe you in coverage.
Why Claims Get Denied More Often Than People Expect
Denial rarely comes from a dramatic policy loophole. It usually comes from a mismatch between what was written on the application and what an investigator finds after the fact. A "yes" answer to "do you use MFA" often turns out to mean "yes, for some accounts," and that distinction only surfaces once forensics gets involved.
Ransomware itself is still evolving in ways that make this scrutiny sharper. CISA has documented how affiliated ransomware groups increasingly use double-extortion tactics, encrypting systems while also stealing data to pressure victims into paying twice over. When an incident like that happens, insurers and their forensic teams reconstruct exactly how the attacker got in, and that reconstruction is what exposes whether the controls on your application were real.
Business email compromise adds another layer. It doesn't always involve malware at all, just a convincing email and a wire transfer that shouldn't have gone through. The FBI's Internet Crime Complaint Center has tracked BEC losses in the billions of dollars over the past decade, and many cyber policies require a documented, separate-channel verification step for large wire transfers as a condition of coverage. Skipping that step, even once, can matter more at claim time than most business owners expect.
Getting Ready Before You Apply or Renew
The good news is that everything insurers ask about is knowable and fixable well before renewal season puts you under pressure. A few weeks of preparation goes a long way.
- Confirm MFA is enforced on every account that touches business data, not just email. Check remote access, admin consoles, and financial software specifically, since those are the accounts underwriters ask about by name.
- Verify your backups have been restore-tested recently and document the date. "We have backups" and "we know they work" are different claims.
- Put your incident response plan in writing if it only exists as institutional knowledge. It doesn't need to be long. It needs to be accurate and something your team has actually seen.
- Review exactly what your current policy excludes. Many carriers include a "failure to maintain security" clause that limits coverage if you can't show the controls you attested to were kept up over time, not just on day one.
- Have whoever fills out the questionnaire double-check technical answers with whoever manages your actual systems. The ICS case above happened partly because the person signing the attestation didn't have a precise picture of where MFA was and wasn't deployed.
If your business works with a managed IT provider, this is exactly the kind of prep they should be able to document for you quickly. If you're evaluating that gap yourself, our backup and disaster recovery guide is a useful next stop for understanding what "tested backups" should actually look like, and our piece on a real business email compromise attempt we caught and stopped shows what these attacks look like in practice, not just in a claims report.
Frequently Asked Questions
Does cyber insurance replace the need for security tools like EDR or MFA?
No. Insurers increasingly require those controls as a condition of coverage rather than as an alternative to it. Cyber insurance is meant to help absorb the financial impact of an incident, not prevent one.
What happens if my controls were accurate when I applied but changed later?
This is where the "failure to maintain security" exclusion comes in. Many policies expect the controls you attested to remain in place for the life of the policy, not just at signing. If a tool lapses or a setting gets reversed, document when and why, and consider notifying your broker if the gap is significant.
Is partial MFA coverage enough to satisfy most insurers?
Generally not for privileged or administrative accounts. Carriers have moved toward expecting full coverage across email, remote access, and admin accounts specifically, since those are the accounts most often used as an entry point.
Who should fill out the cyber insurance application?
Whoever signs it should verify technical answers with the person or team who actually manages your systems day to day. A well-intentioned guess from someone without hands-on visibility is exactly the kind of gap that leads to denied claims later.
How often should we revisit our cyber insurance readiness?
At minimum, before every renewal. Given how quickly requirements and threats are changing, a lot of businesses find it worth a lighter check-in every six months as well.
About ITGuys
ITGuys is a Managed IT Support company that has been helping businesses solve technology problems since 2009. We work with companies of all sizes to provide reliable, practical IT solutions that keep teams productive and secure.
Our services include managed IT support, network cabling, office onboarding and offboarding, email migration, IT consulting, wireless networking, infrastructure upgrades, and ongoing technical support for businesses across the United States.
We believe technology should make business easier, not more frustrating. Our goal is to provide straightforward IT guidance that helps businesses avoid downtime, improve reliability, and make smarter technology decisions.
Recent Comments