Learn

Guide

Cyber Insurance for Small Businesses: What Underwriters Actually Check Before Approving a Policy in 2026

Cyber Insurance for Small Businesses: What Underwriters Actually Check Before Approving a Policy in 2026

Cyber Insurance for Small Businesses: What Underwriters Actually Check Before Approving a Policy in 2026

Underwriters verify controls now instead of trusting a questionnaire. What they check, why access control decides so many outcomes and how to prepare before you apply.

Underwriters verify controls now instead of trusting a questionnaire. What they check, why access control decides so many outcomes and how to prepare before you apply.

Julien Monguillot

Julien Monguillot

Julien Monguillot

Co-Founder

Co-Founder

Co-Founder

Created:

Created:

Created:

Learn

Cyber insurance underwriters in 2026 no longer approve small business policies on the strength of a questionnaire. They verify specific technical controls: multi-factor authentication (MFA) across all systems, endpoint detection and response (EDR) on company devices and backups that ransomware cannot encrypt or delete. If a business cannot produce evidence of those controls, the policy gets declined, the premium jumps or a claim gets denied later when it matters most.

That gap between what a business assumes it has and what it can actually prove is where most small businesses lose. This article breaks down exactly what underwriters check, why they check it and how to build the evidence trail before you ever submit an application.

TL;DR

  • Underwriters verify technical controls directly, mapped to frameworks like the CIS Controls and NIST, rather than relying on self-reported answers.

  • MFA is the single most scrutinized control, and partial deployment gets treated much like no deployment.

  • Pricing is driven by revenue, industry, the sensitivity of the records you hold and the limit and retention you choose. Verified controls are the input you can change fastest.

  • Exclusions bite hardest around sanctioned ransom payments, engaging an incident response firm before notifying the insurer and missed breach notification deadlines.

  • Having a documented incident response plan and access control system in place before you apply meaningfully improves both approval odds and pricing.

About the Author: This article is written by the team at ShiftControl, an IT operations platform purpose-built for Google Workspace by former ExpressVPN operators. ShiftControl’s technical co-founder ran IT operations at ExpressVPN, a remit that grew from 100 to more than 700 employees across 7 global offices. ShiftControl now helps small and mid-sized businesses maintain the access controls and incident response documentation that cyber insurance underwriters check, without requiring a dedicated IT hire.

What Do Cyber Insurance Underwriters Actually Verify in 2026?

Underwriting in 2026 works differently than it did five years ago. Insurers used to accept a signed attestation that a company had “reasonable security practices.” Today, underwriters request evidence. That shift happened because claims data showed a pattern: companies that said they had MFA often didn’t have it everywhere it counted, and insurers got tired of paying out on gaps that should have been caught at underwriting.

The specific controls underwriters check now include:

  • Multi-factor authentication (MFA) on all email accounts, remote access points, cloud services and administrative accounts

  • Endpoint detection and response (EDR) deployed across company devices

  • Immutable backups that ransomware cannot encrypt or delete

  • Role-based access control (RBAC) and privileged access management, so not every employee has admin-level reach into sensitive systems

  • Full-disk encryption for endpoints and mobile devices

  • Documented incident response plans, not just a verbal understanding of who calls whom

Underwriters map these controls to established frameworks, most commonly the CIS Controls and the NIST Cybersecurity Framework, which gives them a standardized way to compare one applicant’s security posture against another. That matters because the underwriting process rewards businesses that can demonstrate structured, repeatable access management over ones that simply “haven’t had a breach yet.”

Why Does MFA Carry So Much Weight in Underwriting Decisions?

MFA sits at the center of underwriting because it addresses the single most common entry point for attackers: stolen or guessed credentials. A password alone is a single point of failure. If an attacker gets it, whether through phishing, a data breach at another company or brute force, MFA is often the only thing standing between that stolen password and full account access.

Misrepresentation about security controls, MFA in particular, is a recurring basis for denial in litigated cyber claims. When an insurer investigates a breach after the fact, one of the first questions is whether MFA was enforced on the compromised account. If the answer is “we have MFA, but it wasn’t turned on for that admin account,” the claim can be denied even though the company technically owned an MFA tool.

This is why partial deployment is treated almost the same as no deployment. Underwriters aren’t asking “do you have MFA,” they’re asking “is MFA enforced everywhere it needs to be, with no exceptions for legacy accounts or convenience.” Small businesses that manage access manually across dozens of SaaS tools tend to have exactly these kinds of gaps, usually because nobody is tracking every account’s MFA status in one place.

What Drives Cyber Insurance Pricing for a Small Business?

Revenue and industry set the starting band. A healthcare or financial services business holding sensitive records is priced differently from a design studio with the same headcount, because the records it holds are worth more to an attacker and cost more to notify on. The volume of those records moves the price again.

Two structural choices on the policy itself matter as much: the coverage limit you buy and the retention you agree to absorb before coverage responds. A higher retention lowers the premium and shifts more of the first-dollar loss back onto the business, which is a real trade for a company without the cash to self-insure a bad week.

The input a business can change quickly is the strength of its documented controls. Since underwriters price risk against verified evidence, a business that can show enforced MFA, RBAC and a documented incident response plan is negotiating from a stronger position than one that cannot. This is also why getting a cyber liability insurance quote earlier in the process, before finalizing security tooling, tends to backfire: brokers can tell you what coverage costs, but they can’t retroactively fix the control gaps that drive the price up.

What Should Be on a Cyber Insurance Coverage Checklist?

A cyber insurance coverage checklist should cover both the technical controls underwriters verify and the policy terms that determine whether a claim actually pays out. The Federal Trade Commission recommends confirming that a policy covers data breaches involving stolen personal information as well as cyberattacks on data held by third-party vendors, since many small businesses store data with cloud providers rather than on their own servers.

Before comparing quotes, confirm you can document:

Control area

What underwriters want to see

Access management

MFA enforced on all accounts, RBAC in place, no shared admin logins

Endpoint security

EDR deployed, full-disk encryption on all devices

Backup strategy

Immutable backups, tested restore process

Incident response

Written IR plan with named responders and escalation steps

Vendor coverage

Policy explicitly covers breaches at third-party vendors

Each of these gaps costs money at renewal. Worse, any one of them can be the reason a claim gets denied after an incident, which is the outcome that actually hurts a small business.

Why Do Insurers Deny Small Business Claims?

Denials usually trace back to a gap between what was disclosed at underwriting and what was actually in place at the time of the incident. Beyond MFA and logging gaps, several policy-level triggers cause denials that have nothing to do with the technical breach itself.

Common exclusion triggers in 2026 include:

  • Making a ransom payment that violates OFAC sanctions rules

  • Hiring an outside incident response firm before notifying the insurer, which can void coverage for those response costs

  • Missing SEC or state-level breach notification deadlines

A business can have excellent technical controls and still lose a claim because it didn’t notify the insurer or regulators fast enough. This is part of why having a pre-arranged incident response relationship matters: it removes the guesswork about who to call and in what order, at the exact moment decisions need to happen quickly.

How Should a Startup Approach Cyber Insurance Differently?

Startups face a version of this problem with fewer resources to solve it. A five-person company evaluating cyber insurance for startups usually doesn’t have a security engineer on staff to build RBAC policies or audit MFA coverage across every SaaS tool. Cyber liability insurance underwriters generally evaluate a business’s operations, industry, revenue and the volume of sensitive records it handles, and startups often assume their small size makes them a low priority target.

The breach data says otherwise. Verizon’s 2025 Data Breach Investigations Report, which defines an SMB as an organization with fewer than 1,000 employees, found ransomware present in 88% of SMB breaches, against 39% of breaches at larger organizations.

The practical fix is a platform that enforces the same controls an enterprise IT department would, without the headcount. This is where ShiftControl fits into the underwriting conversation: automated provisioning and de-provisioning, role-based access control, app-permission visibility and SaaS spend visibility across Google Workspace and connected SaaS apps, set up in as little as ten minutes through a single Google Workspace login rather than a multi-week implementation project.

ShiftControl also includes cyber incident response (IR-1) through its partnership with Blackpanda as part of the subscription, rather than selling it as an add-on. Paired with documented access control, that covers the two areas underwriters scrutinize hardest: who has access to what, and what happens in the first hours after an incident.

Frequently Asked Questions

Does every small business need cyber insurance?

Not automatically. The starting point is evaluating your specific cyber risks, the type of data you hold and the threats most relevant to your industry. A business handling customer payment data or health records generally carries more exposure than one that doesn’t.

What’s the difference between cyber insurance pricing for a startup versus an established small business?

Pricing scales with revenue and risk profile rather than company age. A newer company with strong documented controls can price better than an older one with weak MFA coverage, since underwriters price the controls rather than the years in business.

Can I get cyber insurance without MFA?

Some insurers will still issue a policy, but expect a higher premium, narrower coverage or explicit exclusions tied to the accounts lacking MFA.

How do I compare cyber insurance quotes across providers?

Compare coverage first, then price. Confirm coverage for third-party vendor breaches and check for exclusions tied to sanctions or notification timelines before comparing price.

Does having an incident response plan lower my premium?

A documented, tested incident response plan is one of the specific controls underwriters verify, and it directly affects both approval odds and pricing.

What happens if I hire my own incident responders during a breach?

If you engage an outside incident response firm before notifying your insurer, you risk voiding coverage for those response costs. Always check notification requirements first.

About ShiftControl

ShiftControl is an IT operations and SaaS management platform purpose-built for Google Workspace, made for small and growing businesses that don’t have a dedicated IT team. It combines provisioning and access management, SaaS spend visibility, app-permission visibility and incident response in one platform, instead of four separate tools and a spreadsheet. Founded by former ExpressVPN operators, including a technical co-founder whose IT operations remit there grew from 100 to more than 700 employees across 7 global offices, ShiftControl gives smaller companies the same access control and response capabilities a large enterprise has, without the enterprise cost or complexity. Role-based access control and cyber incident response via Blackpanda come standard in the subscription rather than gated behind premium tiers.

If your business is preparing for a cyber insurance renewal or applying for the first time, get in touch with ShiftControl to see how the platform maps directly to what underwriters check in 2026.

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.

Get started

Experience SaaS management as it should be: straightforward management and robust security with ShiftControl.