You bought the policy and checked the box that said you have security measures in place. Then a ransomware attack hits. You file a claim, and the insurer denies it because the multi-factor authentication wasn't actually enforced on every account. This scenario is playing out for more organizations every year, and it's rarely because anyone lied on their application.
More often, it happens because the gap between 'we have security tools' and 'we can prove exactly how they're configured and monitored' is wider than most leadership teams realize. SMBs experience ransomware-related breaches at a rate of 88 percent, compared to 39 percent for larger organizations, according to Verizon's Data Breach Investigations Report. Insurers know this, and their underwriting has evolved accordingly.
Cyber insurance used to be a fairly simple purchase: fill out a questionnaire, pay a premium, and move on. Today, it functions more like a technical audit — one that continues well past the day you sign the policy. As ransomware losses and business email compromise claims have climbed, insurers have gotten far more precise about what they'll cover, and far less forgiving when a policyholder's actual environment doesn't match what was described on the application.
What insurers actually require boils down to a few core controls. Multi-factor authentication is now table stakes — most insurers require MFA on email, remote access, and privileged accounts at minimum. Endpoint Detection and Response (EDR) has replaced basic antivirus as the expected standard. Traditional antivirus catches known threats; EDR monitors behavior continuously and can respond to threats that don't match known signatures.
Backup and recovery procedures need to be documented and tested. Having backups isn't enough. Insurers want to know that backups are isolated from your primary network (so ransomware can't encrypt them too), that they're tested regularly, and that you have a documented recovery process. Security awareness training is increasingly required as well — phishing remains the most common attack vector.
The most common way organizations run into trouble isn't outright noncompliance — it's partial compliance that looks fine on paper but doesn't hold up under scrutiny. An organization might enforce MFA on email but not on its VPN. It might have EDR installed on employee laptops, but not on the file server sitting in the back office. Business email compromise and funds transfer fraud together account for 60 percent of all cyber insurance claims, according to Coalition's 2025 Cyber Claims Report.
At TenisiTech, we don't treat security and insurability as separate conversations. The same proactive security posture that protects your organization from an attack is what makes you insurable and keeps you insurable at renewal. That includes MFA enforcement audits across every access point, EDR deployment with active monitoring, backup architecture reviews with tested restores, incident response planning and tabletop exercises, and ongoing evidence collection.
Cyber insurance exists to protect your organization when something goes wrong. But a policy is only as good as the evidence behind it. If you're not confident your organization could produce that proof today, now is the time to find out — before a claim depends on it.