
Navigating Cyber Insurance for Small Businesses
Article Summary: Cyber insurance forms are longer now because insurers lost big on MOVEit, Change Healthcare, and Arup deepfake fraud. New questions target the exact controls that failed. Understanding them makes renewal more manageable.
If your cyber insurance renewal application looks longer than last time, you're not imagining it. Three major incidents in 2023 and 2024 produced significant losses for insurance carriers, and the industry responded by adding more specific questions before issuing coverage. Each new section traces back to one of these events:
The MOVEit supply-chain breach (2023) exploited a vulnerability in widely used file-transfer software, affecting more than 2,650 organizations and over 66 million individuals.
The Change Healthcare ransomware attack (February 2024) froze healthcare claims processing nationwide for weeks, with estimated insurance losses exceeding $250 million from that single event.
The Arup deepfake wire fraud (early 2024) showed that a finance employee could be convinced to wire $25.6 million after a video call with AI-generated versions of company executives that appeared completely real.
The more your business handles payments, client funds, medical records, or other sensitive data, the more carefully your application will be reviewed.
What the Application Is Really Asking
You don't need to be a technical expert to fill out a cyber insurance application well. You do need to know what you actually have in place, and most of these questions are answerable if you take the time to look.
Your Backup Setup
Your form will likely include the terms "immutable backup" and possibly "air-gapped." Here's what those mean in plain terms:
Immutable backup: A backup that cannot be deleted or changed during a set period of time, even if someone gains access to your systems.
Air-gapped: A backup copy stored somewhere with no connection to your main network, so it cannot be reached or wiped out in an attack.
The form will also ask when your backups were last tested with a successful restore. I've seen this catch business owners off guard, especially those who assumed that having a backup set up was the same as having it protected. Pull up your backup system and look for two things: how your backups are stored, and when a restore was last confirmed to work. If you're not sure of either answer, it's worth verifying before renewal.
Multi-Factor Authentication
Multi-factor authentication, or MFA, is the extra verification step when you log in, like a code from your phone after entering your password. Your form will ask whether MFA is active in each of these places:
Email accounts
Remote access tools used when logging in from outside the office
Owner or administrator-level accounts
Any accounts used to manage your business systems
Business owners often find that MFA is on in some places but not others. Logging into each account and checking for yourself is more reliable than assuming it's covered. Note anywhere it's missing before you fill out the form.
Wire Transfers and Payment Approvals
Carriers now ask whether your business has a written process for verifying wire transfers before they go out. What they're looking for is a requirement to call a known phone number before any large transfer is sent, rather than approving a payment based on an email alone.
A one-page wire transfer policy is enough to satisfy most carriers. It should include:
The dollar amount that triggers a verification call
A requirement to call a number already on file, not one included in the request
Who in your organization is authorized to approve transfers
A sign-off from everyone who handles payments
Several applications now also ask whether your team has received training on AI-generated voice and video fraud. A brief team conversation covering what deepfake scams look like, with a note of the date it happened, is a reasonable place to start.
Your Security Tools and Software Vendors
Your form will likely ask about the security monitoring running on your business computers and servers, and may use the term "EDR," which stands for endpoint detection and response. Unlike basic antivirus that scans files against a list of known threats, EDR monitors what's actually happening on your devices in real time. Many carriers ask about this specifically because antivirus alone is no longer considered sufficient. You can check what's installed on your devices through your system settings, and knowing the product name gives you something specific to put on the form.
The form will also ask about your key software vendors. You may see the term "SOC 2," which refers to an independent review confirming a vendor has had their security practices examined by a third party. The practical step here is simple:
List the platforms your business depends on most
Email each vendor asking whether a SOC 2 report is available
Keep a record of who responds and what they provide
The Most Important Thing to Get Right
The most consequential mistake on a cyber insurance application is claiming you have something in place that you don't. These applications are legal documents. If a claim is filed and an investigation finds that your environment didn't match what you declared, the carrier can void the policy as if it never existed. The claim is denied, and you absorb the full cost of the incident yourself. That outcome is considerably worse than a higher premium for disclosing a gap honestly.
If you're not certain something is in place, say so. If there's a known gap, note it with a plan and a target date. Carriers respond better to honesty with a timeline than to polished answers that fall apart during a claim review.
What to Do in the 30 Days Before You Submit
Most of this preparation is within reach for any business owner willing to set aside focused time. Here's a practical order to work through:
1. Check your accounts for MFA.
Log in to your email, remote access tools, and any admin-level accounts. Confirm whether multi-factor authentication is active on each one and note any gaps.
2. Review your backup setup.
Find out what system your business is using, whether it's configured to protect against tampering, and when it was last tested with a successful restore.
3. Write a wire transfer policy.
Draft a one-page document outlining the steps required before any payment above a set amount is sent. Include who has approval authority and get it signed by anyone who can authorize transfers.
4. Identify your key vendors and request SOC 2 reports.
List the software platforms your business depends on most and email each one asking whether a SOC 2 report is available. Keep track of who responds.
5. Review your incident response plan.
If you have one, walk through it with your leadership team and keep notes. If you don't, write a short outline covering who handles what if your systems go down. That document, and the conversation around it, is what most carriers are looking for.
6. Sit down with the application and answer honestly.
Fill it out based on what you actually have. Flag anything unresolved with a specific date for when it will be addressed. That's the approach that holds up.
Know Where You Stand Before Your Renewal Goes In
Cyber insurers have raised their requirements significantly. What qualified your business for coverage a year or two ago may not meet the bar today, and most businesses don't find that out until the application is already in.
If your renewal is coming up and you're not confident your current setup will hold up to the new requirements, that's exactly the time to take a closer look.
At qnectU, we help you get ahead of the application by assessing your current controls, closing the gaps insurers are flagging, and getting you to renewal with confidence.
Click here to schedule a quick 26-minute call today, and we'll show you exactly where you stand before your renewal goes in.
Article FAQs
What does rescission mean on a cyber insurance policy?
Rescission means the carrier voids the policy from inception after discovering material misrepresentation on the application. The policy is treated as if it never existed, the current claim is denied, and any prior payouts under the same policy term can be clawed back. Courts have generally found that the carrier does not need to prove a causal link between the misrepresentation and the specific incident that triggered the claim.
Will my cyber insurance be affected if I don't have MFA on every system?
It might not necessarily be denied outright, but expect a meaningful impact on your coverage and pricing. Gaps in MFA coverage typically trigger significant premium increases, sub-limits on ransomware coverage, or exclusions for incidents that trace back to the unprotected entry point. The most common gap that carriers flag is MFA on privileged or service accounts, which tend to be overlooked in initial deployments.
