Cyber insurers in 2026 require multi-factor authentication almost universally, endpoint detection or response tools on every device, and immutable, regularly tested backups before they'll issue or renew a policy — and 41% of small business applications still get denied on first submission because one of these controls is missing (Beancount.io, 2026). Even businesses that do get covered aren't guaranteed a payout: more than 40% of small business cyber claims end with no payout at all.
What Do Insurers Actually Check For?
Ninety-nine percent of cyber insurance applications now include detailed MFA questions, and MFA has to be enforced everywhere — email, VPN, cloud platforms, admin accounts, accounting software, and backup tools, not just the most obvious systems (Beancount.io, 2026). Beyond MFA, 88% of carriers require endpoint detection and response (EDR) or managed detection and response (MDR) across every endpoint — a single unmanaged laptop can disqualify the whole application. Underwriters also expect offsite or air-gapped immutable backups with documented quarterly restore tests, a written incident response plan with named roles, annual phishing-simulation training, and patching of critical vulnerabilities within 14-30 days.
Why Do So Many Small Business Claims Get Denied?
Claims get denied for the same reasons applications do — missing controls, but also misrepresentation on the application, missed notice deadlines after an incident, excluded loss types, and sublimit exhaustion (Beancount.io, 2026). A business that answered "yes, we have MFA" broadly on the application but never enforced it on a specific system that later got breached is a textbook misrepresentation denial — insurers can and do audit the actual environment after a claim, not just take the application at its word.
How Much Does Cyber Insurance Actually Cost?
For businesses under $5 million in revenue, $1 million in coverage typically runs $3,000-$7,500 annually, (Beancount.io, 2026). High-risk industries pay 2-4 times the baseline, while businesses that can demonstrate strong security controls typically see 15-30% discounts. For context, the average cost of an incident with no insurance behind it runs over $79,000 — often well above a year or more of premiums.
Is It Worth Getting Cyber Insurance If a Claim Might Get Denied?
Yes, but only if the controls behind the application are real, documented, and actually enforced — insurance priced and sold on an inaccurate application isn't really coverage, it's a liability waiting to be discovered during a claim review. The businesses getting real value from cyber insurance are the ones treating the application's control requirements as a baseline security standard to actually meet, not a checklist to get through.
Frequently Asked Questions
What security controls do I need before applying for cyber insurance?
At minimum: multi-factor authentication enforced across all systems (not just email), endpoint detection or response on every device, immutable offsite backups with tested restores, a written incident response plan, and regular phishing-awareness training.
Why do cyber insurance claims get denied?
The most common reasons are misrepresenting security controls on the application, missing a notice deadline after discovering an incident, the loss type being excluded from the policy, or the claim exceeding a sublimit — missing controls that were claimed on the application is a frequent and preventable cause.
How much does cyber insurance cost for a small business?
For $1 million in coverage, small businesses under $5 million in revenue typically pay $3,000-$7,500 a year, with strong security controls earning a 15-30% discount and high-risk industries paying 2-4 times as much.
Does having EDR on most devices satisfy insurer requirements?
Usually not. Most carriers require EDR or MDR across every endpoint, and a single unmanaged or excluded device can be enough to void coverage or trigger a denial if that device is involved in the incident.
Not sure your current setup would survive an insurer's post-claim audit? Infortech helps Bay Area businesses put the real controls in place before you need the policy to pay out. Book a discovery call to get a fit assessment to see where the gaps are.
