Is Your Business Ready for a Cyber Insurance Audit?

Getting cyber insurance used to be simple. You filled out a short form, got good coverage, and paid reasonable prices. That changed around 2021 when ransomware attacks cost insurance companies billions of dollars. Now they check everything carefully before they cover you.

Today’s applications ask for detailed proof of your security. Insurance companies want to see that you use two-step verification, keep your software up to date, test your backups regularly, protect your email from hackers, monitor your computers for threats, and have a plan for handling attacks.

If you can’t prove you have these protections in place, you’ll pay more for insurance, get less coverage, or get rejected completely. This guide explains what insurance companies look for and how to get ready without spending months on it.

Why Requirements Tightened

Three factors led insurance companies to start checking security so carefully.

Loss Ratios Exploded

Between 2019 and 2022, ransomware and email scams cost insurance companies billions of dollars. Small and medium businesses got hit the hardest because they didn’t have basic security in place. Insurance companies were paying out more in claims than they collected in premiums. They couldn’t stay in business that way.

Reinsurers Demanded Proof

Insurance companies buy reinsurance (insurance for insurance companies) to protect against large losses. Those reinsurance companies started demanding proof that businesses actually had working security, not just policies on paper. That requirement got passed down to you.

Commodity Attack Tools

Hacking tools became cheap and easy to use. Criminals could rent ransomware or buy password-guessing tools. The same security problems kept appearing in every attack: no two-factor authentication, remote access left wide open, old, unpatched software, and backups that didn’t work. Insurance companies realized they could prevent losses by checking for these problems before selling coverage.

What Carriers Actually Require

Now that you understand why insurance companies tightened their requirements, here’s exactly what they’re checking for. Almost all cyber insurance companies now ask for the same basic security measures. Here’s what you need:

Multi-Factor Authentication (MFA)

Two-step login (also called MFA) requires you to enter both a password and a code from your phone to log in. You must use it for:

  • Email accounts
  • Remote access to your company network
  • Administrator accounts
  • Cloud services like Microsoft 365 or Google Workspace

For your most important accounts, insurance companies prefer hardware keys or fingerprint readers instead of text message codes.

What to show them: Take screenshots of your two-step login settings. Print reports showing which users have it turned on. Export your security settings from Microsoft 365 or Google Workspace.

Backup and Recovery

Your backups must be protected from ransomware. This means storing them somewhere ransomware can’t reach, either offline or in a separate system that ransomware can’t encrypt. Keep backup copies for 30 to 90 days. This protects you even if an attack goes unnoticed for weeks.

The most important question: Do your backups actually work? Test them every 3 months and record the results. You also need to know:

  • How much data can you afford to lose (Recovery Point Objective)
  • How long can you be offline before it seriously hurts your business (Recovery Time Objective)

What to show them: A simple diagram of where your backups are stored, proof they’re protected from ransomware, records of your test restores with dates, and logs showing your last successful backup.

Patch and Vulnerability Management

Insurance companies want proof that you install security updates quickly. Most want you to install critical updates within 30 days. You also need a plan for old software that no longer gets security updates.

What to show them: Reports from your update management system showing when you installed updates. Security scan results showing which problems you’ve fixed. Records of your maintenance schedule.

Email Security

Email is how most hackers break into businesses. Insurance companies expect you to have spam filters and email authentication. Email authentication uses three technical standards (SPF, DKIM, and DMARC) to verify that your emails are really from you and help block fake emails pretending to be from your company.

Protecting your domain: Start by setting up DMARC in monitoring mode to see what’s happening. Then move to blocking mode, which significantly reduces email scams according to NIST guidance on trustworthy email.

Protecting your employees: You also need defenses against phishing attacks and malicious emails targeting your staff. This includes:

  • Email filters that block suspicious attachments and dangerous links
  • Warning banners on emails from outside your organization
  • Link scanning that checks websites before employees click them
  • Attachment sandboxing that opens suspicious files in a safe environment first

What to show them: Reports from your DMARC setup showing it’s working. Your SPF and DKIM records from your domain settings. Screenshots of your email security settings, including anti-phishing protections and malicious link/attachment blocking.

Incident Response Planning

You need a written plan that explains what to do if you get hacked. The plan should say who does what, whom to call, and what decisions to make. Insurance companies want proof you’ve practiced this plan, not just written it.

What to show them: Your written plan. Records showing when you practiced it and who participated. Notes about what you learned and what you improved.

Endpoint Detection and Response (EDR)

Basic antivirus software isn’t enough anymore. You need security software that watches for suspicious behavior and can stop attacks in progress. Endpoint protection is an important requirement for cyber insurance, although it typically falls under your IT provider or managed security partner rather than your website hosting provider. 

What to show them: Reports showing which devices are protected. Examples of security alerts you received. Proof that your security software is active and up to date. For help setting this up, see our guide to essential website security practices.

Security Awareness Training

Your employees need regular training on how to spot scams and avoid clicking dangerous links. This is especially important for people who handle money, personal information, or have access to important systems. Some insurance companies want proof that you test your employees with fake phishing emails to see if they’d fall for them.

What to show them: Records showing who completed training and when. Results from fake phishing tests. Signed forms showing employees understand your security policies.

What Non-Compliance Costs

Knowing what insurance companies require is important, but understanding the real cost of gaps in your security makes it urgent. Security gaps don’t just slow down your application; they compromise it. They cost you real money.

Higher Premiums and Retention: You might still be able to get insurance, but you’ll pay a lot more. You’ll also have higher deductibles, meaning you pay more out of pocket before insurance helps.

Coverage Exclusions: Specific security gaps can exclude you from coverage. For example, if you don’t have two-step verification and someone steals your password, your claim might be denied for “not meeting minimum security requirements.”

Outright Denial: Some insurance companies won’t sell you a policy at all without proof of basic security. If you can’t show two-step login, working backups, or regular updates, they’ll say no.

Claims Friction: Even when insurance covers your claim, poor records cause problems. Insurance companies might pay less or deny claims if you can’t prove your security was actually working when the attack happened. This delays or reduces the money you get when you need it most.

A Five-Question Self-Check

Ready to see where you stand? Answer these five questions to see if you’re ready. This takes about ten minutes:

  1. Can you show that MFA is enforced for all admin accounts and remote access? Take a screenshot of your settings. If any admin accounts don’t require two-step login, that’s a problem you need to fix.
  2. Do you have DMARC configured for your primary domain? Check your domain settings. Even basic monitoring is better than nothing, but insurance companies prefer full blocking mode.
  3. When was your last successful test restore, and do you have documentation for it? If you can’t remember or don’t have written proof, insurance companies will assume your backups don’t work. If your website is hosted with us, our hosting platform includes automated website backups to help protect your site and support recovery when needed. 
  4. Are there old user accounts, shared admin logins, or “temporary” exceptions still active? Print a list of admin accounts and compare it to your current employees. Old accounts that should have been deleted are among the most common problems insurance companies encounter.
  5. Is RDP or SSH exposed directly to the internet? Check if you can connect to your network remotely without using a VPN. If yes, that’s dangerous, and insurance companies will reject you immediately.

If you answered “no” or “I’m not sure” to more than one question, you need to fix things. The good news is that most problems can be fixed quickly if you focus. If you’ve already been hacked, our incident response playbook shows you exactly what to do.

What Comes Next

Knowing what insurance companies want is just the beginning. The next article in this series shows you where security problems actually hide in small businesses. You’ll learn how to identify issues with user accounts, email protection, backups, and your website before insurance companies do.

Getting ready for cyber insurance isn’t about being perfect. It’s about proving you’ve fixed the problems that lead to the most common and expensive attacks. Start with the basics, write down what you’ve done, and test that it works. This protects your business and helps you get affordable insurance.

Many of these security requirements involve multiple parts of your technology environment. While some controls are managed by your IT provider, Beacon Web focuses on helping secure the websites and business email services we host and manage for our clients.

Need Help Strengthening Your Website and Email Security?

If this checklist uncovered gaps in your website hosting or business email security, Beacon Web can help with the areas we manage for our clients.
We can assist with security features for hosted websites, business email accounts, backups, website updates, and email authentication (SPF, DKIM, and DMARC) where applicable. These measures can support your overall cybersecurity efforts and help you prepare for conversations with your cyber insurance provider.
While we don’t provide cyber insurance consulting or compliance services, we do help ensure that the websites and email environments we host follow current security best practices.
Contact us to learn more about securing your hosted website and business email.

Free Gift! 🎁

Learn how the right keywords can help your business rank higher on Google, attract more qualified leads, and generate more sales.

We don’t spam! Read our privacy policy for more info.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Secret Link