Skip to content

What Cyber Liability Insurance Actually Requires From Your IT Setup

What does cyber liability insurance require of small business IT? Most policies now require specific, verifiable controls before an insurer will write or renew coverage, not just a general assurance that you take security seriously. Multi-factor authentication, tested backups, endpoint protection, and documented employee training show up on nearly every carrier’s checklist. Miss one, and you can find out during a claim, when it’s too late to fix, that your policy doesn’t pay out the way you thought it would.

Business email compromise and funds transfer fraud together account for roughly 60% of all cyber insurance claims, according to Coalition’s 2025 Cyber Claims Report, more than ransomware. That’s exactly the kind of everyday, low-tech incident the controls below are built to catch.

Our earlier post on decoding cyber insurance covers what a policy typically pays for. This one covers what you have to prove you already had in place before anything goes wrong.

What do insurers actually check before writing a policy?

Insurers ask applicants to fill out a security questionnaire before binding a policy, and increasingly, they follow up to verify the answers. Common questions cover multi-factor authentication, backup frequency and testing, endpoint detection tools, employee security training, and whether you have a written incident response plan. Answer those questions honestly and your premium reflects your actual risk. Answer them optimistically, and you may have a policy that looks fine on paper and falls apart during a claim.

Is multi-factor authentication really required for coverage?

For most carriers, yes, at least on email and remote access. This has become close to a baseline requirement rather than a nice-to-have, and JumpCloud’s 2025 review of cyber insurance trends notes that insurers increasingly require proof MFA is actually in place before they’ll offer coverage at all. If an attacker gets into your systems through a login that only needed a password, and your policy required multi-factor authentication that wasn’t actually turned on, the insurer has grounds to deny the claim. It’s one of the least expensive controls on this list and one of the most heavily weighted in underwriting.

Why do insurers care about backup testing, not just backups existing?

A policy that lists “regular backups” as a requirement isn’t satisfied by a backup job that runs automatically and nobody checks. Insurers are increasingly asking for evidence: when backups last ran, whether they’ve been tested with an actual restore, and how quickly you could recover if you needed to. This is exactly the gap covered in our guide to backup and recovery planning, which walks through what a tested, working plan actually looks like versus one that just runs quietly in the background.

What counts as security training in an insurer’s eyes?

A one-time onboarding video rarely qualifies anymore. Underwriters are looking for ongoing training, ideally with some form of tracking or completion record, plus evidence that your team can recognize phishing attempts specifically. Given how much claim volume traces back to business email compromise and funds transfer fraud rather than more technical attacks, this line item gets real scrutiny. Strong password habits and awareness training tend to get evaluated together. Our guide to strong passwords and authentication is a useful starting point for what that training should actually cover.

What happens if you don’t have a written incident response plan?

Some policies require one outright. Others don’t require it explicitly but pay out faster and with fewer disputes when one exists, because it demonstrates you had a plan for containing damage rather than reacting blind. A response plan doesn’t need to be long. It needs to name who makes decisions during an incident, who gets called first, and what the first hour looks like.

How do you find out what your specific policy actually requires?

Read the application questionnaire you originally submitted, not just the coverage summary. That questionnaire is often treated as a representation of fact, and gaps between what you told the insurer and what’s actually true on your network are where claims get denied. If you’re not sure whether your current setup lines up with what you represented, that’s worth checking before you need the policy, not after.

Cyber liability insurance is only as good as the accuracy behind it. Book your free on-site IT assessment, and we’ll help you see exactly where your current setup stands against what your policy actually requires.


Frequently Asked Questions

What does cyber liability insurance require of small business IT?

Most policies require multi-factor authentication, tested and verifiable backups, endpoint protection, documented employee training, and often a written incident response plan. Requirements vary by carrier, so your specific questionnaire is the real answer, not a generic checklist.

Is MFA mandatory for cyber insurance coverage?

For most carriers, yes, at minimum on email and remote access. It’s become close to a baseline requirement, and gaps between what you told an insurer and what’s actually configured are a common reason claims get denied.

Do insurers actually verify backups, or just ask if you have them?

Increasingly, they ask for evidence: when backups last ran, whether a restore has been tested, and how fast recovery would happen. A backup that has never been tested with an actual restore doesn’t satisfy that requirement even if it runs every night.

What kind of employee training satisfies a cyber insurance policy?

Ongoing training with some form of tracking or completion record, with specific attention to recognizing phishing attempts, tends to hold up better than a one-time onboarding video.

Can a cyber insurance claim be denied even if I have a policy?

Yes, most commonly when what you represented on your application questionnaire doesn’t match what was actually in place on your network at the time of the incident. Reviewing your questionnaire against your current setup before you need the policy is the way to avoid that gap.