Cyber Insurance for Small Business: What Carriers Ask
What cyber insurance covers for a small business, the security questions on real applications (MFA, backups, patching), and how to read the exclusions.
Cyber insurance pays for the costs of a security incident: investigators, legal advice, customer notification, lost income, and claims made against you. To get a quote, a small business answers a security questionnaire. Expect questions about multi-factor authentication on email and remote access, tested backups, patching, endpoint protection, and an incident response plan. Answer accurately, because the application becomes part of the policy.
This post explains what the coverage includes, what applications ask, and how to read the exclusions. It is general information, not insurance or legal advice. A licensed broker should guide the actual purchase.
What Does Cyber Insurance Cover?
Policies usually combine two kinds of cover. The FTC and the National Association of Insurance Commissioners describe them in a joint cyber insurance guide for small businesses:
| First-party cover | Third-party cover | |
|---|---|---|
| Who it protects | Your own business and its costs | You, when someone else brings a claim against you |
| Typical items | Legal counsel on notification duties, forensic investigation, recovering or replacing data, customer notification, lost income from business interruption, crisis management and public relations, cyber extortion and fraud, fees and fines related to the incident | Payments to affected consumers, litigation and regulatory response costs, settlements, damages and judgments, accounting costs |
| Example | Ransomware locks your files and the office cannot work for a week | Customers whose records were exposed file a lawsuit |
The same guide suggests confirming that a policy covers data breaches, attacks on your own network, attacks on your data held by vendors, and attacks that happen anywhere in the world. It also suggests asking whether the insurer will defend you in a lawsuit or regulatory investigation (look for “duty to defend” wording) and whether it offers a breach hotline.
A point that is easy to miss: many small businesses keep their data with vendors, such as a practice management system, a payroll service, or Microsoft 365. Ask specifically how the policy treats an incident at a vendor.
What Do Carriers Ask on the Application?
Questionnaires vary, but public application forms show the pattern. The Travelers CyberRisk applications, which include a short form for businesses with revenue of $50 million and below, ask whether the applicant has the following in place:
| Application question | What it means in practice | How to show it |
|---|---|---|
| Multi-factor authentication (MFA) for remote access to email | Every mailbox needs a second sign-in step, not only administrators | A Conditional Access policy or security defaults in Microsoft 365, or 2-Step Verification enforcement in Google Workspace |
| MFA for remote network access and for administrative accounts | VPN, remote desktop tools, and admin consoles all require MFA | Screenshots of the enforcement settings |
| Up-to-date anti-virus on all computers | Managed endpoint protection on every device, with someone reviewing alerts | A device list from the management console |
| A process to regularly install patches (the full form asks whether critical patches are installed within 30 days) | Operating system and software updates on a schedule | A patch management report |
| Backup and recovery procedures (the full form asks whether they are tested annually) | Backups of all important data, with a restore test on record | A dated restore test note. See our backup guide |
| An incident response plan | A written plan with roles and contacts | The plan itself. Here is a template |
| Encryption of sensitive data at rest, in transit, and on mobile devices | BitLocker or FileVault on laptops, encrypted email where needed | Device compliance report |
| Annual security training for employees | Short, regular security awareness training | Completion records |
| Payment verification procedures (on the social engineering fraud supplement) | Confirming changes to vendor bank details using a phone number already on file, and dual authorization for large transfers | A written procedure staff follow |
Why MFA Gets Its Own Form
Travelers publishes a separate MFA supplement. It explains the reasoning plainly: MFA on administrative access “can prevent an intruder from gaining the level of access necessary to successfully deploy ransomware across the network,” and MFA on email reduces account compromise from lost or stolen passwords. If your business has one item to fix before applying, this is it. Our post on why multi-factor authentication matters covers the setup.
What About EDR?
EDR stands for endpoint detection and response: security software that records what happens on each computer and can isolate a machine that behaves suspiciously. MDR is the same tooling with people monitoring it. Application forms still often say “anti-virus,” but expectations are moving. Coalition, a cyber insurer, wrote in January 2024 that insurers are “increasingly encouraging businesses to implement MDR” in the way they once did with MFA. If you use Microsoft 365 Business Premium, Microsoft Defender for Business is an EDR product that is already included in the license.
How Do You Read the Exclusions?
Read the policy form itself, not the summary. These are the clauses worth finding and asking your broker about:
- Claims-made wording and the retroactive date. The Travelers forms state that the policy applies “only to claims first made during the policy period.” Ask what happens if an intrusion began before the policy started but is discovered later.
- Known circumstances. Applications ask whether you are aware of any circumstance that could give rise to a claim. An incident you knew about and did not disclose is unlikely to be covered.
- Defense within limits. Some policies state that legal defense costs reduce the limit of liability. A $1 million limit then has to cover both the lawyers and any settlement.
- War and state-backed attacks. Lloyd’s of London has required its syndicates to include a state-backed cyber-attack exclusion in standalone cyber policies starting or renewing from March 31, 2023. Ask how your policy defines such an attack and who decides attribution.
- Social engineering and funds transfer fraud. Being tricked into wiring money is often a separate coverage with its own lower limit, and it may depend on following a verification procedure. Check the sublimit and the conditions. Our post on business email compromise explains the fraud itself.
- Sublimits and waiting periods. Ransomware payments, business interruption, and regulatory fines may each have a smaller limit than the headline figure. Business interruption cover may begin only after a waiting period, so check how long it is.
- Conditions on response. Look for requirements to report promptly and to use the carrier’s approved forensic and legal firms.
- Statements in the application. The signed application is part of the contract. If it says MFA is enforced for all users and it is not, that discrepancy can become an issue at claim time.
How Much Does It Cost?
There is no reliable single number, and we will not invent one. Premiums depend on your revenue, industry, the type and volume of records you hold, your claims history, the limit and deductible you choose, and your answers to the security questions. The practical approach is to have a broker collect quotes from two or three carriers using the same limit and deductible, then compare sublimits and exclusions side by side, not only price.
Security controls can affect terms as well as eligibility. Ask each carrier whether it attaches any credits, deductible changes, or conditions to specific controls such as MFA on email, and get the answer in writing.
When You May Not Need a Standalone Policy
A business that holds almost no personal or financial data, takes payments only through a hosted processor, and could operate on paper for a week has less at stake. Some business owner policies offer a small cyber endorsement, which may be enough in that case. Ask your broker what the endorsement actually covers and what its limit is.
On the other side, a standalone policy deserves serious consideration if you hold patient records, tax or financial records, or Social Security numbers, if customers or contracts require it, or if a week of downtime would threaten the business. Medical and dental practices and legal and accounting firms usually fall into this group.
Insurance is also not a security control. It pays for some costs after an incident. It does not restore data without backups, and it does not remove your duty to notify people under laws such as California’s breach notification statute.
Common Mistakes
- Answering the questionnaire from memory. Check each control before you answer. Confirm that “we have MFA” means every user and every administrator, with no exceptions left over from setup.
- Comparing only the premium. Two policies with the same limit can differ widely in sublimits for ransomware and fraud.
- Not knowing the claims process. Put the carrier’s hotline and policy number in your incident response plan, on paper.
- Letting the application go stale. Renewals ask the same questions again. If you changed email platforms or added remote staff, the answers may have changed too.
- Treating the application as paperwork. It is a useful free security checklist. Every “no” is a project worth considering regardless of insurance.
Common Questions
Is MFA required to get cyber insurance?
Many carriers expect it. Application forms commonly ask whether MFA is required for all employees on email, for remote network access, and for administrative accounts, and some carriers use a dedicated MFA form. On the Travelers MFA supplement, any “no” answer requires a written explanation. Ask your broker how a “no” would affect the quote.
What is the difference between first-party and third-party cyber coverage?
First-party coverage pays your own costs after an incident: investigation, legal advice on notification, restoring data, notifying customers, and income lost while systems are down. Third-party coverage pays when someone else brings a claim against you, including legal defense, settlements, and the cost of responding to a regulator. Most cyber policies sold to small businesses include both.
Does cyber insurance cover a wire transfer sent to a scammer?
Only if the policy includes social engineering or funds transfer fraud coverage, which is often a separate section with its own limit. Carriers may ask about your payment verification procedures when you apply. Check the sublimit and any conditions before you rely on it, and ask your bank what protections apply on its side.
Will a general liability or business owner policy cover a breach?
Do not assume so. Ask your broker to show you the wording, including any exclusion for data-related losses and the limit on any cyber endorsement. A standalone cyber policy is written specifically for these costs, and the FTC suggests asking whether it comes with a breach hotline that is available at all times.
Can an insurer deny a claim because of the security setup?
An insurer can contest a claim when the application contained inaccurate statements, when the loss falls under an exclusion, or when policy conditions such as prompt reporting were not met. The best protection is an accurate application, a record showing that the controls you listed were in place, and a response process that follows the policy’s requirements.
How Coastal Growth Co. Can Help
We can go through a cyber insurance application with you line by line, check each answer against how your systems are actually configured, and fix the gaps: MFA for every user, managed endpoint protection, patching, tested backups, and a written incident response plan. We can also prepare the screenshots and reports that document those controls for your broker. This is part of our managed IT support and is also available as a one-time project, with scope and price agreed first. Reach us through the contact page.
- cyber insurance
- MFA
- risk management
- small business
Need a hand with this?
I offer IT support across Orange County, with on-site work in Los Angeles and nearby areas by arrangement.
Let's talk arrow_forward