Small business owner reviewing cyber insurance readiness checklist in their office

What Small Businesses Need Before Applying for Cyber Insurance

Cyber insurance applications have become more detailed, and many small businesses are surprised by how much security evidence they are expected to provide. The good news is that the usual requirements are not mysterious. In many cases, insurers are looking for a practical baseline: secure logins, protected devices, reliable backups, and a written plan for what happens if something goes wrong.

If you are trying to understand cyber insurance requirements for small business, it helps to think in terms of controls you can explain, document, and maintain. You do not need enterprise-level complexity to make progress, but you do need consistency.

This guide breaks down five controls that commonly show up in applications and renewals. It also focuses on what a small business should be ready to show, not just what it should say it has in place.

Use this quick preparation checklist before you start an application.

  • Confirm MFA is enabled on email, admin accounts, remote access, and cloud apps.
  • Verify endpoint protection includes EDR, not only basic antivirus.
  • Make sure backups are automated, separated from daily access, and tested for restore.
  • Write down who does what during a security incident.
  • Review email protections for spoofing, phishing, and attachment filtering.
  • Gather simple evidence such as screenshots, policy notes, device counts, and test logs.

That preparation will not guarantee approval or pricing outcomes, but it can make the process clearer and reduce avoidable gaps.

Multi-Factor Authentication (MFA): A Mandatory Control for Insurer Compliance

MFA is one of the most common controls insurers ask about because passwords alone are easy to steal, reuse, or guess. If an attacker gets into business email or an admin account, the damage can spread quickly through invoices, payroll, customer communications, and cloud systems.

For small businesses, the practical takeaway is simple: MFA should be turned on wherever access matters most. Guidance commonly emphasizes email, cloud platforms, administrative accounts, and remote access tools. Some applications ask whether MFA is merely available, while others ask whether it is fully enforced. That difference matters.

A useful way to think about MFA is not as a technical feature, but as a documented business rule.

  • Email accounts should require MFA.
  • Admin or privileged accounts should require MFA.
  • Remote access should require MFA.
  • Cloud file storage and business apps should require MFA where supported.

App-based authentication is often the most realistic option for small teams because it is easier to roll out than more specialized hardware. The goal is not to adopt the most complex method. The goal is to make sure the control is actually used by everyone who needs it.

When preparing a cyber insurance application checklist, gather proof that MFA is enforced, not just mentioned in a policy. That may include admin settings, a short written access policy, and a list of systems covered.

A common mistake is enabling MFA for only the owner or only the Microsoft 365 or Google Workspace admin account while leaving regular inboxes unprotected. Insurers often care about both privileged access and day-to-day accounts because business email compromise frequently starts with ordinary user access.

Endpoint Detection and Response (EDR): Replacing Legacy Antivirus as a Standard

Many small businesses still think of device protection as "having antivirus installed." Insurer expectations have moved beyond that. EDR is increasingly treated as a baseline because it is designed to detect suspicious behavior on laptops and desktops, not just known malware files.

In plain English, EDR helps you do two things basic antivirus may not do well enough on its own:

  • Notice unusual activity on a device.
  • Investigate or respond before one infected computer becomes a larger incident.

This does not mean every insurer uses the same wording, and it does not mean every business needs the same setup. But if your current protection is limited to old-style antivirus with no monitoring or response visibility, that can become a problem during underwriting.

For a small team, the most important issue is coverage. If you say you have endpoint protection, you should know which devices are included.

Use this simple review table.

Question Why it matters
Are all company laptops and desktops covered? Partial coverage can leave obvious gaps.
Are remote devices included? Many small teams work outside one office.
Can you show device status or reports? Insurers may want evidence, not just a yes/no answer.
Is the tool still active and updated? Old or inactive protection may not count as meaningful control.

If you are reviewing EDR requirements for cyber insurance, focus on clear records: a device inventory, confirmation that protection is deployed, and a simple process for checking that devices remain covered. You do not need to describe deep technical settings in the application unless specifically asked.

Another common issue is unmanaged personal devices used for business work. If staff access company email or files from personal computers, your answers about endpoint coverage may be incomplete unless you have a clear policy for that access.

Documented Incident Response Plan: Preparing for Insurer Questionnaires

A documented incident response plan sounds formal, but for a small business it can be short and practical. Insurers often want to know that if ransomware, email fraud, or happens, your team will not be improvising under pressure.

Your plan does not need legal language or enterprise complexity. It should answer basic operational questions.

  • Who decides whether an incident is serious?
  • Who contacts your IT provider, security vendor, lawyer, or insurance contact?
  • Who can approve account lockouts, password resets, or device isolation?
  • How will you communicate if email is unavailable?
  • Where are key vendor contacts and policy details stored?

A simple incident response plan should usually include these sections.

  1. Purpose and scope.
  2. Key roles and backups for those roles.
  3. Steps for identifying and containing an incident.
  4. Internal and external communication contacts.
  5. Recovery steps, including restoring systems or data.
  6. Post-incident review and documentation.

Testing matters too. You do not need a full simulation lab. A short tabletop discussion can still show that the plan is real and understood. For example, walk through what your team would do if an employee reports a suspicious invoice change request or if shared files suddenly become inaccessible.

When insurers ask about a written plan, they are often looking for evidence that the business has thought through response responsibilities in advance. A one-page document that is reviewed periodically is usually more useful than a long template no one reads.

Be careful not to overstate what your plan covers. If you have not tested it, say it is documented and scheduled for review rather than implying mature response capability.

Backup and Recovery: Proving Data Protection to Insurers

Backups are not just about having copies of files. Insurers often care whether those backups are reliable, protected from tampering, and restorable within a reasonable business timeframe. That is why backup requirements for cyber insurance often go beyond a simple yes/no question.

For small businesses, the strongest backup story usually includes three elements:

  • Backups run automatically on a defined schedule.
  • Copies are stored in a way that reduces the chance they will be altered during an attack.
  • Restores are tested and logged.

A backup that has never been restored is hard to rely on. If you are asked to show readiness, a simple backup testing log can help more than a vague statement that backups exist.

Track items like these.

Item to document Example of useful evidence
What is backed up File shares, accounting data, email, line-of-business apps
Backup schedule Daily, hourly, or other defined frequency
Storage separation Offsite, cloud, or otherwise separated from daily user access
Encryption status Vendor setting or policy note
Last restore test Date, system tested, result, follow-up actions

A common weakness is backing up only documents while forgetting cloud application data, device settings, or specialized systems. Another is leaving backup access tied to the same compromised admin account that could be used in an attack.

You do not need to promise perfect recovery. What matters is being able to explain your process, show that it is active, and demonstrate that restore testing happens on purpose rather than by accident.

Email Security Controls: Mitigating Business Email Compromise Risks

Email remains one of the biggest practical risks for small businesses because it touches payments, customer communication, password resets, and vendor relationships. That is why insurers increasingly ask about both account security and message protection.

This section overlaps with MFA, but it goes further. Insurers may also look for controls that reduce spoofing and phishing risk, including SPF, DKIM, and DMARC. In plain English, those settings help receiving mail systems judge whether a message claiming to come from your domain is legitimate.

You do not need to turn this into a technical project description. What matters is knowing whether these controls are configured and who manages them.

Email security review should usually cover the following.

  • MFA on all business email accounts.
  • Filtering for malicious links, attachments, and spam.
  • Domain authentication settings such as SPF, DKIM, and DMARC.
  • Approval procedures for payment changes or sensitive data requests.
  • Limited admin access to email settings and forwarding rules.

This is especially important for business email compromise prevention and invoice fraud prevention. Many losses start with a fake payment request, mailbox takeover, or spoofed domain rather than a dramatic technical breach.

If your business relies heavily on Microsoft 365 or Google Workspace, keep a short checklist of the email-related settings you have reviewed. That gives you a cleaner way to answer application questions and supports broader access control policies.

A practical rule for small teams is to pair technical controls with a simple workflow rule: no banking change, invoice redirect, or sensitive request should be approved based on email alone. That kind of process control can reduce risk even when technical protections are not perfect.

Conclusion

Cyber insurance readiness is usually less about chasing every possible security feature and more about proving that your business has the basics in place and can maintain them. For many small teams, the most important starting points are multi-factor authentication (MFA), endpoint detection and response (EDR), tested backups, stronger email controls, and a documented incident response plan.

If you are preparing for a new application or renewal, start with evidence as well as implementation.

  • Write down which systems have MFA enforced.
  • Confirm which devices are covered by EDR.
  • Keep a backup testing log.
  • Store a current incident response plan where key staff can access it.
  • Review email authentication and payment approval procedures.

These steps will not guarantee coverage, approval, lower premiums, or claim outcomes. They can, however, help you answer insurer questions more accurately, reduce avoidable exclusions, and build a more defensible small business cybersecurity foundation.