Cyber insurance helps cover the cost of a security incident, but only if your IT environment matches what you told the insurer. Carriers now expect specific controls like MFA, EDR and tested backups before they write a policy, and they check for them when you file a claim.
Most business owners think of cyber insurance like any other policy: pay the premium, file a claim if something goes wrong. After several years of heavy ransomware losses, underwriters have become much more specific about what they require up front and much more careful when a claim comes in. In practice, your policy works like a compliance framework with its own checklist. Here's what's usually on it, why claims get reduced or denied, and how to keep your coverage solid.
Requirements vary by carrier and coverage level, but these controls appear on nearly every underwriting questionnaire.
The most commonly required control. Carriers want MFA on email, remote access (VPN and remote desktop), cloud applications and administrator accounts, and some require it everywhere. Missing MFA can raise your premium, limit coverage for attacks that start with stolen passwords, or prevent a policy from being written. See our MFA dictionary entry.
Many underwriters no longer accept traditional antivirus on its own. They want endpoint detection and response, which watches for suspicious behavior instead of only matching known malware signatures. Some policies limit ransomware coverage when EDR is missing. Our EDR article explains the difference.
"We have backups" isn't enough. Carriers want backups that are separated from your production network, protected from tampering (for example with immutable or WORM storage), and restored on a test basis so you know they work.
A documented process for who does what, in what order, when something happens. A general security policy doesn't count. See What is a cybersecurity incident response plan?
Recurring training with completion records, and often phishing simulations. Security awareness training is a standard part of NerdSquad cybersecurity plans.
Evidence that operating systems and software are kept current, and that unsupported systems (Windows 10 reached end of support in October 2025, for example) have been replaced or isolated.
Controls on who has administrator rights, separate admin accounts, and logs that show when those accounts were used. Some carriers ask specifically about shared and service accounts.
Underwriters increasingly ask how you evaluate the security of your technology vendors. A simple, documented review process is usually enough to answer the question.
Claim problems tend to follow the same few patterns.
After a claim, the carrier usually assigns a forensic team. Their job is to understand the incident and confirm that policy conditions were met. Expect them to check whether the controls on your application were actually in place, whether backups were isolated and working, your patch history, your access logs, your incident timeline and when you notified the carrier. The firms that fare best are the ones whose day-to-day IT already matches the application, so the evidence is there without a scramble.
The controls carriers ask for are the same ones that make your business harder to attack and that frameworks like HIPAA, GLBA, PCI DSS and SOC 2 expect. You don't need separate programs for security, compliance and insurance. You need one well-run environment that satisfies all three and records that prove it.
Requirements vary by carrier, so no IT provider can promise you'll qualify for a particular policy. What we do:
For the wider picture, see How do you help businesses protect against cyber threats?
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.