Cybersecurity · Cyber insurance
The controls that decide coverage, why your application answers must be accurate, and a checklist to get ready before renewal.
MFA, EDR and tested backups first
Answers on applications must be true
Keep evidence for every control
30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.
As of 2026, most cyber insurers expect a small business to have multi-factor authentication (MFA) on email, remote access and admin accounts; endpoint detection and response (EDR) on computers and servers; backups that are protected from tampering and have been test-restored; timely patching; and regular security awareness training. Many also ask about email filtering, an incident response plan and how you handle wire transfers. Gaps in the first three can mean a decline, higher premiums or lower limits.
Every carrier’s application is different. Treat this as general information and confirm the exact requirements with your broker or insurer.
A few years ago, a cyber policy came with a short questionnaire. Today the application reads like a security audit. Marsh, one of the largest insurance brokers, says insurers now ask more questions than ever about an applicant’s controls, and that “the adoption of certain controls has now become a minimum requirement of insurers.”
The reason is claims data. Coalition’s 2026 Cyber Claims Report, covering 2025, found that business email compromise and funds transfer fraud made up 58% of the incidents it observed, and that ransomware was the most expensive claim type, averaging $269,000. Insurers have learned which controls reduce those losses, and they now price and underwrite around them.
Insurers also check. Many run external scans of your internet-facing systems and ask for evidence, not just a checked box.
Marsh’s list of twelve key controls is a useful map, because it lines up with most carrier applications. Here they are in plain English, grouped by how often they decide whether you get coverage.
Because funds transfer fraud is so common, many applications ask whether you confirm new or changed payment instructions by phone to a known number, and whether two people approve large transfers. These are cheap to put in place and worth doing even without insurance.
Wording varies by carrier, but these questions show up on most small business applications. Here is what they usually mean and what to have ready.
If you can’t produce the evidence in a day, treat that as a gap to fix before renewal.
The application is part of the policy. If an answer is wrong, the insurer may refuse a claim or rescind the policy. In a 2022 case, Travelers asked a federal court to void a cyber policy after a ransomware attack, saying the insured had stated MFA protected its systems when it covered only the firewall. According to Lockton, the case ended with a judgment rescinding the policy.
Practical rules for filling out the form:
Want to know how your answers would look today? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report on your cybersecurity, backups and continuity, rated controlled, needs attention, significant exposure or unknown, with next steps in order. No obligation. Request your assessment.
We won’t quote numbers here, because they vary widely. The cost drivers are predictable: number of users and devices, whether you already have Microsoft 365 or Google Workspace licenses that include security features, how many servers and locations you run, how much data you back up, and whether someone is watching alerts. Many small businesses find the biggest cost is not software but the time to set things up properly and keep them running.
Timing matters too. Start three to four months before renewal. That leaves room to roll out MFA or EDR, run a restore test and collect evidence without rushing, and it gives your broker time to shop the application if your controls have improved since last year.
Compare that with the alternative. A declined application, a sublimit on ransomware, or a disputed claim usually costs far more than closing the gaps.
JLB USA provides cybersecurity and managed IT for businesses with roughly 25 to 100 employees. That includes MFA, access reviews, same-day removal of people who leave, endpoint protection, updates, encryption, email security, monitored backups with tested restores and a written recovery plan. We also help you work through cyber-insurance questionnaires, so the technical answers match what is actually in place.
We are not an insurance broker and don’t give legal or coverage advice. Your broker and insurer decide what a policy requires. Our job is to help you meet it and prove it. If you’re in Atlanta, see our Atlanta cybersecurity services; everywhere else we work remotely.
Book it now
Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.
Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.
MFA on email, remote access and admin accounts, endpoint detection and response on all computers and servers, and protected backups with recent restore tests. Patching, email filtering, staff training and an incident response plan are also commonly asked about. Confirm specifics with your broker or insurer.
It can happen. Applications are typically part of the policy, and inaccurate answers can lead to disputes or rescission. In one 2022 case a court rescinded a cyber policy after MFA turned out to cover far less than the application stated. Ask counsel or your broker about your policy.
Often not. Many insurers ask specifically about endpoint detection and response, which monitors behavior and can isolate an infected device, rather than signature-based antivirus alone.
Many run external scans of internet-facing systems and may ask for evidence such as MFA reports, EDR coverage lists and backup test records, especially at renewal or after a claim.
We help you answer the technical questions accurately and gather evidence. You, your broker and your insurer remain responsible for the application and coverage decisions.