You bought the policy and checked the box that said you have security measures in place. Then a ransomware attack hits. You file a claim, and the insurer denies it because the multi-factor authentication wasn’t actually enforced on every account.
This scenario is playing out for more organizations every year, and it’s rarely because anyone lied on their application. More often, it happens because the gap between “we have security tools” and “we can prove exactly how they’re configured and monitored” is wider than most leadership teams realize.
Small and medium organizations are far from immune to this risk. In fact, SMBs experience ransomware-related breaches at a rate of 88 percent, compared to 39 percent for larger organizations, according to Verizon’s Data Breach Investigations Report. Insurers know this, and their underwriting has evolved accordingly. Cyber insurance used to be a fairly simple purchase: fill out a questionnaire, pay a premium, and move on. Today, it functions more like a technical audit, one that continues well past the day you sign the policy.
For a long time, cyber insurance felt like a formality. A business filled out a short application, answered a handful of yes-or-no questions about its security setup, and received a policy that sat in a drawer until it was needed. That approach doesn’t hold up anymore. As ransomware losses and business email compromise claims have climbed, insurers have gotten far more precise about what they’ll cover, and far less forgiving when a policyholder’s actual environment doesn’t match what was described on the application.
That shift catches a lot of organizations off guard, particularly growing businesses and non-profits that assumed their existing tools were “good enough” to satisfy an insurer. In many cases they’re close, but close isn’t the same as compliant, and the difference tends to surface at the worst possible moment: during a claim.
In this blog, we’ll break down what insurers actually require before they’ll cover you, why partial compliance can be more dangerous than obvious gaps, and how TenisiTech helps clients meet and maintain the standards that keep coverage intact.
The Fine Print Got Sharper: Why Underwriting Changed
For years, cyber insurance applications leaned heavily on self-reported answers. If an organization said it had antivirus software and backups, that was often enough to secure a policy. Ransomware claims and business email compromise losses changed that calculus for carriers.
As claims volume and severity climbed, insurers started paying closer attention to what happens after a breach, specifically, whether the security controls an organization claimed to have were actually in place and functioning at the time of the incident. When forensic investigators found gaps between what was attested and what was real, insurers began denying claims and, in some cases, rescinding coverage entirely.
The result is a market where underwriting reviews go much deeper than a checklist. Applications now ask pointed questions about where multi-factor authentication is enforced, what endpoint protection covers, how often backups are tested, and whether an incident response plan has ever actually been run through a tabletop exercise, a simulated walkthrough where the team practices their response to a mock breach scenario, step by step, without any real systems being affected. Some carriers verify these answers with external scans of an organization’s network before ever issuing a quote.
None of this means coverage is out of reach. It means the organizations that get approved and stay approved are the ones that can back up their answers with evidence.
This also explains why premiums and coverage terms vary so widely between organizations that look similar on the surface. Two businesses of the same size and industry can end up with very different outcomes at renewal, one seeing a modest increase and the other facing a significant premium hike or a coverage exclusion, based entirely on how well each can document its controls.
What Insurers Actually Require: The Controls That Matter
While specific requirements vary by carrier and coverage level, insurers are underwriting for the same basic outcomes. Boiled down, here’s what they want to see:
- Your employees have an extra layer of protection when signing in. Login credentials get stolen and leaked more often than people realize, and a password alone is rarely enough to keep an attacker out. Insurers want confirmation that a second step is required to sign in everywhere it matters, not just on the systems that are easiest to secure.
- Your computer and business systems are protected. Traditional antivirus catches known threats, but attackers have moved past what it can detect. Insurers want to know your devices, including the servers running in the background, are being actively watched for suspicious activity.
- Your backups actually work. A backup that’s never been tested is a backup you’re hoping works, not one you know works. Insurers want proof that if your systems went down tomorrow, you could get your data back.
- You have a plan if something goes wrong. Confusion costs time, and time costs money during a breach. Insurers want to see that your team knows who does what, who to call, and how recovery actually happens, before an incident forces you to figure it out in the moment.
- Your team knows how to spot a threat before it becomes a problem. Most breaches start with a person, not a piece of software. A convincing email, a spoofed login page, a moment of not thinking twice. Insurers want to see that employees are trained regularly to recognize these attempts, not just once during onboarding.
None of these requirements require deep technical knowledge on your part. It just requires knowing what to look for so you can ask the right questions, whether that’s of your internal team or an outsourced provider.
Here’s how TenisiTech turns each of these outcomes into something concrete, documented, and ready to hold up when the insurer asks for proof.
Why “We Have It” Isn’t the Same as “We Can Prove It”
The most common way organizations run into trouble isn’t outright noncompliance. It’s partial compliance that looks fine on paper but doesn’t hold up under scrutiny.
An organization might enforce MFA on email but not on its VPN. It might have EDR installed on employee laptops, but not on the file server sitting in the back office. It might have backups running automatically, but has never actually tested whether they restore correctly. These gaps are common, and they’re exactly what underwriters and forensic investigators after a breach are trained to find.
Business email compromise and funds transfer fraud together account for 60 percent of all cyber insurance claims, according to Coalition’s 2025 Cyber Claims Report. That single statistic explains why insurers scrutinize email security and access controls so closely.
This is why the industry has shifted toward what’s often called an “evidence packet”: documentation that shows controls working, not just descriptions of what’s technically installed. Screenshots of MFA enforcement settings, EDR console reports showing full device coverage, dated backup restore logs, and a signed-off incident response plan all serve as proof that holds up if a claim is ever filed.
The organizations that struggle most at renewal time are usually the ones that treated their initial application as a one-time formality rather than an ongoing standard to maintain.
Want more insights like this? Subscribe to the TenisiTech newsletter for monthly guidance on cybersecurity, compliance, and IT strategy tailored to growing businesses and non-profits.
Why This Falls Through the Cracks for Growing Organizations
Lean IT teams, or a single person wearing multiple hats, don’t always have the time to track evolving underwriting standards across every carrier. Security controls often get implemented piecemeal over time: MFA gets turned on for one system during a software migration, EDR gets deployed during a laptop refresh, and nobody ever steps back to confirm the full picture adds up to what an insurance application is asking for.
By the time a renewal questionnaire lands in someone’s inbox, the answers require pulling together information from several different systems and vendors, often under a tight deadline. That’s when gaps get missed, or worse, get answered with a “yes” that isn’t fully accurate.
The cost of getting this wrong can mean higher premiums, coverage exclusions, or non-renewal at the point when an organization needs that protection the most.
This is especially true for non-profits and mission-driven organizations, where budgets are tight and every dollar is expected to go toward the work itself. It’s tempting to treat cyber insurance as a line item to renew quickly and move past. But an organization that handles sensitive client data, whether that’s health records, donor information, or personal details tied to the people it serves, carries real exposure if a breach occurs. A denied claim can mean absorbing the full cost of recovery, notification, and remediation out of an operating budget that was never built to withstand it.
The TenisiTech Difference: Built for Insurability, Not Just Security
At TenisiTech, we don’t treat security and insurability as separate conversations. The same proactive security posture that protects your organization from an attack is what makes you insurable and keeps you insurable at renewal.
Here’s how we help clients close the gap between having controls and proving them:
- MFA enforcement audits across every access point. We don’t just confirm MFA is turned on somewhere. We map every system, including VPN, remote access, and admin accounts, to make sure enforcement is complete and documented.
- EDR deployment with active monitoring. Our approach to foundational security includes full endpoint coverage, servers included, with monitoring built into our ongoing support model rather than treated as a separate add-on.
- Backup architecture reviews with tested restores. We help clients move beyond “we have backups” to a documented, regularly tested recovery process that holds up under an underwriter’s questions.
- Incident response planning and tabletop exercises. A plan that’s actually been walked through carries far more weight, both for your team’s readiness and for your insurer, than one sitting untouched in a folder.
- Ongoing evidence collection. Rather than scrambling to assemble documentation right before a renewal deadline, we help clients build a standing record of their controls so each renewal cycle becomes routine instead of a fire drill.
This work fits naturally into the strategic IT roadmapping and vCIO advisory TenisiTech already provides. Cyber insurance readiness is a natural outcome of doing IT strategically in the first place.
Coverage You Can Count On
Cyber insurance exists to protect your organization when something goes wrong. But a policy is only as good as the evidence behind it. Insurers have made that clear through tighter underwriting, more detailed questionnaires, and a growing willingness to deny claims when attested controls don’t match reality.
The good news is that this is entirely fixable, and it doesn’t require a massive overhaul to get there. It requires knowing exactly what your insurer expects, closing the gaps between what you have and what you can prove, and keeping that evidence current year over year.
If you’re not confident your organization could produce that proof today, now is the time to find out, before a claim depends on it. A quick internal check now, walking through where MFA is enforced, whether EDR covers every device, and when your backups were last restored, can save weeks of scrambling later and, more importantly, make sure the coverage you’re paying for actually does what it’s meant to do.
Ready to see where you stand? Schedule a free IT review with TenisiTech to assess your cyber insurance readiness and identify any gaps before your next renewal.
