AI & AUTOMATION MASTER CLASS WORKSHOP
 SEP 10 | SEP 24 | OCT 8
The Mandatory Cyber Insurance Checklist Every Small Business Needs

The Mandatory Cyber Insurance Checklist Every Small Business Needs

Lorenzo Ciambotti

Cyber insurance used to be a straightforward purchase. Answer a few questions, pay the premium, get the policy. That era is over. 

Insurers have spent the last three years absorbing massive losses from ransomware claims, supply chain breaches, and business email compromise. In response, they have completely overhauled how they underwrite small business policies. In 2026, getting covered at a reasonable rate requires demonstrating real security controls, not just checking a box on an application. 

At eMazzanti Technologies, we work with SMBs across the NY/NJ metro area who are navigating this shift. Whether you are applying for the first time or renewing an existing policy, here is what insurers are looking for and what you can do to prepare. Our managed cybersecurity services are built around exactly the controls underwriters now require. 

Why Have Cyber Insurance Requirements Changed So Much? 

Cyber insurers tightened requirements after years of mounting claims. Today they require proof of specific security controls before issuing coverage, and businesses that cannot demonstrate those controls face higher premiums, reduced limits, or outright denial. 

Ransomware payouts alone cost insurers billions annually. In response, the industry has shifted from a trust-based model to a verify-first model. Underwriters now send detailed questionnaires, require third-party security assessments, and in some cases conduct their own scans of your external attack surface before quoting a policy. 

A policy that cost $5,000 two years ago may now cost three times that, or come with a much higher deductible, if you cannot show the right controls are in place. 

The good news is that the controls insurers require are the same ones that actually reduce your risk. Getting your security posture in order to qualify for insurance makes your business genuinely safer at the same time. 

What Security Controls Do Cyber Insurers Require in 2026? 

In 2026, cyber insurers commonly require multi-factor authentication, endpoint detection and response, email security, regular backups with tested recovery, privileged access controls, employee training, an incident response plan, and vulnerability patching. Missing any of these can affect your coverage or premium. 

While requirements vary by insurer and policy size, the following controls appear on nearly every underwriting questionnaire today. 

Multi-Factor Authentication 

This is the single most commonly required control. Insurers want MFA enabled on email, remote access, cloud applications, and any system with administrative privileges. Policies that previously covered businesses without MFA now either exclude certain breach types or require it as a condition of coverage. 

Endpoint Detection and Response 

Basic antivirus is no longer sufficient. Underwriters want to see EDR tools deployed across all endpoints, with active monitoring and response capabilities. Many now ask specifically whether EDR coverage extends to servers, not just workstations. 

Email Security and Anti-Phishing Controls 

Business email compromise remains the most common trigger for cyber claims. Insurers look for anti-phishing filters, SPF, DKIM, and DMARC authentication, and in many cases, advanced email security tools beyond what comes standard with your mail platform. Solid email security configuration is one of the most direct ways to improve your insurability. 

Privileged Access Management 

Underwriters want to know that administrative credentials are tightly controlled. This includes limiting who has admin access, using separate accounts for privileged tasks, and logging all privileged activity. Unrestricted admin access is a significant red flag in underwriting reviews. 

Backup and Recovery 

Insurers require documented backup procedures with offsite or cloud storage, regular testing to confirm backups actually restore, and in many cases, immutable backups that ransomware cannot encrypt. They also want to know your recovery time objective, meaning how quickly you can get back online after an incident. 

Security Awareness Training 

Annual training is the minimum. Many underwriters now ask how frequently phishing simulations are run and whether employees who fail receive additional coaching. A documented training program with measurable completion rates carries more weight than self-reported compliance. 

Incident Response Plan 

Having a written plan is table stakes. Insurers increasingly ask whether the plan has been tested in the past 12 months and whether employees know their roles. An untested plan is treated with the same skepticism as no plan at all.

Vulnerability and Patch Management 

Underwriters want to see a defined process for identifying and patching vulnerabilities, with critical patches applied within a documented timeframe. Unpatched systems with known vulnerabilities are one of the most common reasons for claim denial after a breach. 

The SMB Cyber Insurance Readiness Checklist 

Use this checklist to assess your readiness before applying for or renewing cyber insurance. Each item corresponds to a control underwriters commonly require. Gaps identified here are also your highest-priority security investments. 

 

IDENTITY AND ACCESS 

  • MFA is enabled on all email accounts 

  • MFA is enabled on all remote access tools and VPNs 

  • MFA is enabled on all cloud applications with business data 

  • Administrative accounts are separate from standard user accounts 

  • Privileged access is limited to employees who require it for their role 

  • All admin activity is logged and reviewed 

 

ENDPOINT AND NETWORK SECURITY 

  • EDR tools are deployed on all workstations and servers 

  • EDR alerts are actively monitored (by internal staff or a managed SOC) 

  • Firewall and network segmentation are in place 

  • Remote desktop protocol (RDP) is disabled or restricted where not needed 

  • All devices are enrolled in a patch management program 

  • Critical patches are applied within 14 days of release 

 

EMAIL AND PHISHING PROTECTION 

  • SPF, DKIM, and DMARC records are properly configured 

  • Advanced email filtering is in place beyond default platform settings 

  • Anti-phishing and anti-spoofing controls are active 

  • Employees receive phishing simulation training at least quarterly 

 

BACKUP AND RECOVERY 

  • All critical data is backed up daily 

  • Backups are stored offsite or in an air-gapped cloud environment 

  • Immutable backups are in place to protect against ransomware encryption 

  • Backup restoration has been tested successfully in the past 6 months 

  • Recovery time and recovery point objectives are documented 

 

INCIDENT RESPONSE AND GOVERNANCE 

  • A written incident response plan exists and is current 

  • The plan has been tested or tabletop-exercised in the past 12 months 

  • Key employees know their roles in the event of a breach 

  • A documented security awareness training program is in place 

  • Training completion rates are tracked and on record 

  • A vulnerability assessment has been completed in the past 12 months 

 

VENDOR AND SUPPLY CHAIN 

  • Third-party vendors with access to your systems or data are inventoried 

  • Vendor security practices are reviewed before granting access 

  • Contracts with vendors include data protection and breach notification requirements 

 

What Happens If You Cannot Meet All the Requirements? 

If your business cannot meet all cyber insurance requirements, you may still qualify for coverage with higher premiums, lower limits, or exclusions for certain breach types. The priority is to close the most critical gaps first, particularly MFA and EDR, before applying. 

Not every SMB will check every box before their renewal date, and that is okay. The key is to demonstrate a credible, documented improvement plan. Insurers respond better to a business that can show concrete progress than one that simply says the controls are coming soon. 

Start with the highest-impact items. MFA and EDR, in particular, have an outsized effect on both your risk profile and your insurability. Many insurers will decline to quote at all without these two controls in place. 

A Security Operations Center (SOC) also carries significant weight with underwriters. Around-the-clock monitoring signals that your business takes security seriously and reduces the likelihood of a claim going undetected for an extended period. 

How Should You Document Your Security Controls for Underwriters? 

Underwriters want written evidence of your security controls, not verbal assurances. Policies, procedures, training records, vulnerability scan reports, and backup test logs all support your application and can reduce your premium. 

Documentation is what separates a strong insurance application from a weak one. For each control you have in place, be prepared to show: 

  • Written policies describing how the control is implemented and maintained 

  • Configuration screenshots or reports from your security tools 

  • Training completion records with dates and employee names 

  • Vulnerability scan results from the past 12 months 

  • Backup test logs confirming successful restoration 

  • Your incident response plan, signed and dated 

 

If you work with a managed IT provider, ask them to prepare a security posture summary on your behalf. A well-organized package of documentation can meaningfully reduce your premium and accelerate the underwriting process. 

How Much Can Strong Security Controls Actually Reduce Your Premium? 

Businesses with documented, mature security controls consistently pay lower cyber insurance premiums than those without. MFA adoption alone has been associated with premium reductions of 20 to 40 percent in some markets. The investment in security pays off in coverage costs as well as reduced breach risk. 

Cyber insurance pricing is directly tied to perceived risk. The more controls you can demonstrate, the lower the probability of a claim in the insurer's model, and the lower your premium. In 2025, cyber insurance shifted from a safety net to a competitive differentiator, with businesses that had strong security postures securing better rates and contract advantages. That trend has only accelerated into 2026. 

Beyond the premium itself, strong security documentation can help you negotiate better terms: higher limits, lower deductibles, and broader coverage for incident types like social engineering fraud that are often excluded from standard policies. 

Where Should You Start If Your Policy Renewal Is Coming Up? 

If your cyber insurance renewal is approaching, start with a gap assessment against your insurer's questionnaire. Prioritize MFA, EDR, and email security first, then document what you have in place. A managed IT partner can help you close gaps quickly and prepare the documentation underwriters need. 

Here is a practical sequence to follow in the 90 days before renewal: 

  • Pull last year's insurance questionnaire and map your current controls against each requirement 

  • Identify gaps and rank them by severity, starting with MFA and EDR if either is missing 

  • Engage your IT provider to implement missing controls and produce supporting documentation 

  • Run a vulnerability assessment to identify and address any open exposures 

  • Test your backup restoration process and document the results 

  • Review and update your incident response plan, then schedule a tabletop exercise 

  • Compile your documentation package before the insurer's questionnaire arrives 

 Starting this process early gives you time to close gaps without rushing, and gives your insurer confidence that your controls are mature rather than last-minute. 

 eMazzanti Technologies offers complimentary cybersecurity gap assessments for SMBs across the NY/NJ metro area. We can help you identify where you stand against current insurance requirements and build a practical plan to get there.