News

Subscribe To Our Newsletter

Navigating Cyber Insurance for Small Businesses

Navigating Cyber Insurance for Small Businesses

July 07, 20267 min read

Article Summary: Cyber insurance forms are longer now because insurers lost big on MOVEit, Change Healthcare, and Arup deepfake fraud. New questions target the exact controls that failed. Understanding them makes renewal more manageable.


If your cyber insurance renewal application looks longer than last time, you're not imagining it. Three major incidents in 2023 and 2024 produced significant losses for insurance carriers, and the industry responded by adding more specific questions before issuing coverage. Each new section traces back to one of these events:

  • The MOVEit supply-chain breach (2023) exploited a vulnerability in widely used file-transfer software, affecting more than 2,650 organizations and over 66 million individuals.

  • The Change Healthcare ransomware attack (February 2024) froze healthcare claims processing nationwide for weeks, with estimated insurance losses exceeding $250 million from that single event.

  • The Arup deepfake wire fraud (early 2024) showed that a finance employee could be convinced to wire $25.6 million after a video call with AI-generated versions of company executives that appeared completely real.

The more your business handles payments, client funds, medical records, or other sensitive data, the more carefully your application will be reviewed.


What the Application Is Really Asking

You don't need to be a technical expert to fill out a cyber insurance application well. You do need to know what you actually have in place, and most of these questions are answerable if you take the time to look.

Your Backup Setup

Your form will likely include the terms "immutable backup" and possibly "air-gapped." Here's what those mean in plain terms:

  • Immutable backup: A backup that cannot be deleted or changed during a set period of time, even if someone gains access to your systems.

  • Air-gapped: A backup copy stored somewhere with no connection to your main network, so it cannot be reached or wiped out in an attack.

The form will also ask when your backups were last tested with a successful restore. I've seen this catch business owners off guard, especially those who assumed that having a backup set up was the same as having it protected. Pull up your backup system and look for two things: how your backups are stored, and when a restore was last confirmed to work. If you're not sure of either answer, it's worth verifying before renewal.

Multi-Factor Authentication

Multi-factor authentication, or MFA, is the extra verification step when you log in, like a code from your phone after entering your password. Your form will ask whether MFA is active in each of these places:

  • Email accounts

  • Remote access tools used when logging in from outside the office

  • Owner or administrator-level accounts

  • Any accounts used to manage your business systems

Business owners often find that MFA is on in some places but not others. Logging into each account and checking for yourself is more reliable than assuming it's covered. Note anywhere it's missing before you fill out the form.

Wire Transfers and Payment Approvals

Carriers now ask whether your business has a written process for verifying wire transfers before they go out. What they're looking for is a requirement to call a known phone number before any large transfer is sent, rather than approving a payment based on an email alone.

A one-page wire transfer policy is enough to satisfy most carriers. It should include:

  • The dollar amount that triggers a verification call

  • A requirement to call a number already on file, not one included in the request

  • Who in your organization is authorized to approve transfers

  • A sign-off from everyone who handles payments

Several applications now also ask whether your team has received training on AI-generated voice and video fraud. A brief team conversation covering what deepfake scams look like, with a note of the date it happened, is a reasonable place to start.

Your Security Tools and Software Vendors

Your form will likely ask about the security monitoring running on your business computers and servers, and may use the term "EDR," which stands for endpoint detection and response. Unlike basic antivirus that scans files against a list of known threats, EDR monitors what's actually happening on your devices in real time. Many carriers ask about this specifically because antivirus alone is no longer considered sufficient. You can check what's installed on your devices through your system settings, and knowing the product name gives you something specific to put on the form.

The form will also ask about your key software vendors. You may see the term "SOC 2," which refers to an independent review confirming a vendor has had their security practices examined by a third party. The practical step here is simple:

  • List the platforms your business depends on most

  • Email each vendor asking whether a SOC 2 report is available

  • Keep a record of who responds and what they provide


The Most Important Thing to Get Right

The most consequential mistake on a cyber insurance application is claiming you have something in place that you don't. These applications are legal documents. If a claim is filed and an investigation finds that your environment didn't match what you declared, the carrier can void the policy as if it never existed. The claim is denied, and you absorb the full cost of the incident yourself. That outcome is considerably worse than a higher premium for disclosing a gap honestly.

If you're not certain something is in place, say so. If there's a known gap, note it with a plan and a target date. Carriers respond better to honesty with a timeline than to polished answers that fall apart during a claim review.


What to Do in the 30 Days Before You Submit

Most of this preparation is within reach for any business owner willing to set aside focused time. Here's a practical order to work through:

1. Check your accounts for MFA.
Log in to your email, remote access tools, and any admin-level accounts. Confirm whether multi-factor authentication is active on each one and note any gaps.

2. Review your backup setup.
Find out what system your business is using, whether it's configured to protect against tampering, and when it was last tested with a successful restore.

3. Write a wire transfer policy.
Draft a one-page document outlining the steps required before any payment above a set amount is sent. Include who has approval authority and get it signed by anyone who can authorize transfers.

4. Identify your key vendors and request SOC 2 reports.
List the software platforms your business depends on most and email each one asking whether a SOC 2 report is available. Keep track of who responds.

5. Review your incident response plan.
If you have one, walk through it with your leadership team and keep notes. If you don't, write a short outline covering who handles what if your systems go down. That document, and the conversation around it, is what most carriers are looking for.

6. Sit down with the application and answer honestly.
Fill it out based on what you actually have. Flag anything unresolved with a specific date for when it will be addressed. That's the approach that holds up.


Know Where You Stand Before Your Renewal Goes In

Cyber insurers have raised their requirements significantly. What qualified your business for coverage a year or two ago may not meet the bar today, and most businesses don't find that out until the application is already in.

If your renewal is coming up and you're not confident your current setup will hold up to the new requirements, that's exactly the time to take a closer look.

At qnectU, we help you get ahead of the application by assessing your current controls, closing the gaps insurers are flagging, and getting you to renewal with confidence.

Click here to schedule a quick 26-minute call today, and we'll show you exactly where you stand before your renewal goes in.


Article FAQs

What does rescission mean on a cyber insurance policy?

Rescission means the carrier voids the policy from inception after discovering material misrepresentation on the application. The policy is treated as if it never existed, the current claim is denied, and any prior payouts under the same policy term can be clawed back. Courts have generally found that the carrier does not need to prove a causal link between the misrepresentation and the specific incident that triggered the claim.

Will my cyber insurance be affected if I don't have MFA on every system?

It might not necessarily be denied outright, but expect a meaningful impact on your coverage and pricing. Gaps in MFA coverage typically trigger significant premium increases, sub-limits on ransomware coverage, or exclusions for incidents that trace back to the unprotected entry point. The most common gap that carriers flag is MFA on privileged or service accounts, which tend to be overlooked in initial deployments.

InsuranceComplianceAccess Control
blog author image

Greg Mauer

Gregory Mauer is the founder and CEO of qnectU, a best-selling author, speaker, and cybersecurity & compliance expert. He has been on stage with the likes of the “Nice Shark,” Robert Herjavec, Siri co-founder Adam Cheyer, and business coach and author Mike Michalowicz.

Back to Blog

FREE GUIDE

Discover The Truth Nobody Is Telling You About IT Security And The New, Critical Threats That WILL Put Your Business At Risk

Answers To Common Questions

Frequently Asked Questions

Do you offer access to senior IT consultants or a vCSO for oversight and guidance? 

Yes, we offer access to senior IT consultants and provide vCSO(Virtual Chief Security Officer) as a service for our clients. Our vCSO service provides your organization with expert leadership and strategic direction tailored to your unique cybersecurity and legal compliance needs. We are here to help you navigate the complexities of cybersecurity and ensure that your security posture is robust, compliant, and capable of addressing evolving cyber threats. Book a call today to get expert help with your company’s cybersecurity and compliance.

Do you have a high level of confidence in your security posture? If so, can you explain why?

We have a high level of confidence in the security posture of our company and our clients. Our security stack includes several components to ensure strong and resilient cybersecurity measures. We provide comprehensive risk management, regular audits and assessments, advanced security technologies, employee training and awareness, and incident response planning. Our systems and solutions follow established industry standards and best practices to keep your company safe and your data secure. Since every company has different risks depending on the data, systems, utilization, and more, we can work with your team to develop a robust security plan and implement the proper measures as needed. Reach out today to strengthen your company’s security posture!

Do you have a Disaster Recovery (DR) plan? If so, what’s in place? Is it tested regularly?

We provide robust Disaster Recovery (DR) plans, covering preventative, detective, and corrective measures. Our DR strategies are tailored to each client’s specific needs and are designed to ensure rapid recovery and continuity of operations in the event of any disaster. These plans are regularly reviewed and tested to guarantee they function effectively and meet the highest standards of resilience and reliability. And if a disaster were to occur outside of regular business hours, we have you covered! At qnectU, we have a response time of mere minutes for emergency after-hours calls, ensuring a rapid response to implement your Disaster Recovery plan. Book a call today to protect your company in the event of a disaster.

Do you perform regular risk assessments?

Here at qnectU, we conduct regular risk assessments as a core part of our risk management strategy. Our process is comprehensive, involving identification, categorization, and response planning for potential security risks, including technical vulnerabilities, access controls, and more. These assessments help us understand, control, and mitigate all forms of cyber risk, ensuring that our security measures are effective and up-to-date. But most importantly, we provide continual risk assessments at pre-determined intervals based on your company’s risk level. This ensures that issues are corrected, new risks are identified, and compliance is properly documented. Want to see how our in-depth business risk assessments work? Book a consultation today to get an in-depth risk assessment of your company’s current network security.

Do you follow proven change management principles? 

We are committed to following proven change management principles. We understand the importance of structured and systematic processes in implementing changes that affect cybersecurity protocols and IT environments. Our approach is based on industry-recognized frameworks and methodologies that ensure changes are managed effectively, focusing on minimizing risks, enhancing security posture, and achieving strategic objectives.

Do you address all my compliance needs, including HIPAA?

We specialize in Compliance as a Service (CaaS), and our program is designed to meet a wide range of regulatory requirements to ensure that your business adheres to the highest standards of compliance. We demonstrate our compliance through detailed assessments, documentation, and third-party audits. Our expertise and ongoing support can give you confidence that your company’s sensitive information is managed securely and in full compliance with all regulations.

Is third-party auditing provided to ensure cybersecurity and compliance requirements are being met?

In today’s world a business can easily be compromised via a “supply chain hack.” There have been several instances where the IT company has exposed all of their clients to hacking due to their own lack of cybersecurity measures. In order to prevent this within our own company, we work closely with a third party for comprehensive auditing services to ensure that all cybersecurity and compliance requirements are met. Our rigorous audit process involves a thorough examination of our systems and practices against established industry standards and best practices. This collaboration provides an objective perspective and deep expertise to identify any potential vulnerabilities, ensuring that our cybersecurity measures are robust, up-to-date, and in full compliance with regulatory demands.

What is Compliance as a Service (Caas)? 

Compliance as a Service (Caas) means that our experts will give you specialized help in handling all the rules and regulations your business needs to follow. We do this by providing expert guidance to help you determine what rules apply to your business and how to follow them. All while giving ongoing support to monitor your compliance status and updates in regulations. This may also include any advanced tools to help manage compliance tasks and risk management surrounding compliance. CaaS takes the hassle out of compliance so you can focus on running your business with confidence.

Who is Greg Mauer? 

Gregory Mauer is the founder and CEO of our company, a best-selling author, speaker, and a cybersecurity & compliance expert. He has been on stage with the likes of the “Nice Shark”, Robert Herjavec, Siri co-founder Adam Cheyer, and business coach and author Mike Michalowicz.

Answers To Common Questions

Frequently Asked Questions

Do you offer access to senior IT consultants or a vCSO for oversight and guidance? 

Yes, we offer access to senior IT consultants and provide vCSO(Virtual Chief Security Officer) as a service for our clients. Our vCSO service provides your organization with expert leadership and strategic direction tailored to your unique cybersecurity and legal compliance needs. We are here to help you navigate the complexities of cybersecurity and ensure that your security posture is robust, compliant, and capable of addressing evolving cyber threats. Book a call today to get expert help with your company’s cybersecurity and compliance.

Do you have a high level of confidence in your security posture? If so, can you explain why?

We have a high level of confidence in the security posture of our company and our clients. Our security stack includes several components to ensure strong and resilient cybersecurity measures. We provide comprehensive risk management, regular audits and assessments, advanced security technologies, employee training and awareness, and incident response planning. Our systems and solutions follow established industry standards and best practices to keep your company safe and your data secure. Since every company has different risks depending on the data, systems, utilization, and more, we can work with your team to develop a robust security plan and implement the proper measures as needed. Reach out today to strengthen your company’s security posture!

Do you have a Disaster Recovery (DR) plan? If so, what’s in place? Is it tested regularly?

We provide robust Disaster Recovery (DR) plans, covering preventative, detective, and corrective measures. Our DR strategies are tailored to each client’s specific needs and are designed to ensure rapid recovery and continuity of operations in the event of any disaster. These plans are regularly reviewed and tested to guarantee they function effectively and meet the highest standards of resilience and reliability. And if a disaster were to occur outside of regular business hours, we have you covered! At qnectU, we have a response time of mere minutes for emergency after-hours calls, ensuring a rapid response to implement your Disaster Recovery plan. Book a call today to protect your company in the event of a disaster.

Do you perform regular risk assessments?

Here at qnectU, we conduct regular risk assessments as a core part of our risk management strategy. Our process is comprehensive, involving identification, categorization, and response planning for potential security risks, including technical vulnerabilities, access controls, and more. These assessments help us understand, control, and mitigate all forms of cyber risk, ensuring that our security measures are effective and up-to-date. But most importantly, we provide continual risk assessments at pre-determined intervals based on your company’s risk level. This ensures that issues are corrected, new risks are identified, and compliance is properly documented. Want to see how our in-depth business risk assessments work? Book a consultation today to get an in-depth risk assessment of your company’s current network security.

Do you follow proven change management principles? 

We are committed to following proven change management principles. We understand the importance of structured and systematic processes in implementing changes that affect cybersecurity protocols and IT environments. Our approach is based on industry-recognized frameworks and methodologies that ensure changes are managed effectively, focusing on minimizing risks, enhancing security posture, and achieving strategic objectives.

Do you address all my compliance needs, including HIPAA?

We specialize in Compliance as a Service (CaaS), and our program is designed to meet a wide range of regulatory requirements to ensure that your business adheres to the highest standards of compliance. We demonstrate our compliance through detailed assessments, documentation, and third-party audits. Our expertise and ongoing support can give you confidence that your company’s sensitive information is managed securely and in full compliance with all regulations.

Is third-party auditing provided to ensure cybersecurity and compliance requirements are being met?

In today’s world a business can easily be compromised via a “supply chain hack.” There have been several instances where the IT company has exposed all of their clients to hacking due to their own lack of cybersecurity measures. In order to prevent this within our own company, we work closely with a third party for comprehensive auditing services to ensure that all cybersecurity and compliance requirements are met. Our rigorous audit process involves a thorough examination of our systems and practices against established industry standards and best practices. This collaboration provides an objective perspective and deep expertise to identify any potential vulnerabilities, ensuring that our cybersecurity measures are robust, up-to-date, and in full compliance with regulatory demands.

What is Compliance as a Service (Caas)? 

Compliance as a Service (Caas) means that our experts will give you specialized help in handling all the rules and regulations your business needs to follow. We do this by providing expert guidance to help you determine what rules apply to your business and how to follow them. All while giving ongoing support to monitor your compliance status and updates in regulations. This may also include any advanced tools to help manage compliance tasks and risk management surrounding compliance. CaaS takes the hassle out of compliance so you can focus on running your business with confidence.

Who is Greg Mauer? 

Gregory Mauer is the founder and CEO of our company, a best-selling author, speaker, and a cybersecurity & compliance expert. He has been on stage with the likes of the “Nice Shark”, Robert Herjavec, Siri co-founder Adam Cheyer, and business coach and author Mike Michalowicz.

Image

Innovation

Fresh, creative solutions.

Image

Integrity

Honesty and transparency.

Excellence

Excellence

Top-notch services.

FOLLOW US

Subscribe to our newsletter!

© Copyright 2026 qnectU