The Cyber-Insurance Readiness Guide for Small Teams
The most common reason a small business finally fixes its security isn’t a breach — it’s a form. A cyber-insurance application, a renewal questionnaire, or a security addendum from a big client lands in your inbox, and suddenly “we should get around to MFA” becomes “we need this by Friday.”
Good news: the questionnaires are more consistent than they look, the controls they demand are the same foundations we recommend anyway, and almost all of them are achievable at your size without hiring anyone.
What this guide is not: insurance advice, a guarantee of coverage or approval, or legal advice. Carriers differ, applications are legal documents, and misstatements can void coverage — answer truthfully, and when unsure, ask your broker exactly what a question means.
The eight questions nearly every carrier asks
1. “Is multi-factor authentication enforced for email?”
The single most weighted question — several carriers decline outright without it. What satisfies it: MFA enforced (not just available) for all users on Google Workspace or Microsoft 365. Evidence: a screenshot of the enforcement policy in your admin console, plus the user list showing enrollment.
2. “Is MFA enforced for remote access and administrator accounts?”
If you have no VPN or servers, say so — “no remote-access infrastructure” is a legitimate answer. Admin accounts on every SaaS platform should have MFA regardless. Evidence: per-platform screenshots of admin accounts with MFA on.
3. “Do you use a password manager / enforce unique passwords?”
Carriers increasingly ask directly. A deployed team password manager answers it cleanly. Evidence: the member list in your password manager’s admin view.
4. “Are backups maintained, separated from production, and tested?”
Three sub-questions hiding in one. Cloud sync alone (Drive/OneDrive) usually does not satisfy the “separated” part — see why sync is not backup. Evidence: your backup service’s status page, and a dated note of your last restore test — which is why we tell everyone to test restores twice a year.
5. “Is endpoint protection deployed on all devices?”
At small scale, built-in protection (Microsoft Defender, macOS XProtect/Gatekeeper) plus auto-updates is a defensible baseline — but answer what the form asks. If it demands a managed EDR product by name and you don’t run one, don’t stretch; ask your broker whether the built-in stack qualifies or price a small-business endpoint product.
6. “Do you provide security-awareness / phishing training?”
Documented, informal training counts for many small-business policies: a short annual all-hands walkthrough plus a written one-pager beats “no.” Evidence: the dated agenda and the one-pager.
7. “Do you have a process for removing departed-employee access?”
They’re asking whether ex-employees can still log in. A written offboarding checklist is the answer — use the access teardown runbook as your template. (Or generate one for your exact stack with the offboarding checklist generator.) Evidence: the checklist itself, and audit-log entries from the last departure.
8. “Do you have an incident-response plan / contacts?”
At 1–25 people this means one page: who to call (IT help, broker/carrier hotline, bank), who decides, and where the backups are. Carriers often require you to call them first — check your policy’s notice requirements.
The order of operations (if the form is due Friday)
- Today: enforce MFA on email + admin accounts. It’s the pass/fail item.
- This week: deploy the password manager; write the offboarding checklist; write the one-page incident contacts sheet.
- This month: real backup with a documented restore test; a documented training session.
- Before signing: re-read every answer and make sure it’s true today, not aspirational. An accurate “no, planned for Q4” is safer than an optimistic “yes” — misstatements are the classic reason claims get denied.
Keep the evidence folder
Make a folder called insurance-evidence/ with dated screenshots for each control. We built a printable evidence-folder template that lists exactly what to capture for each of the eight controls. Renewal comes yearly; the folder turns next year’s questionnaire into a 30-minute job, and it’s exactly what a claims adjuster will ask for.
Where to start if you haven’t: the 10-Minute Security Check maps directly onto these eight questions.