Cyber insurance for small teams: the 12 controls the application actually checks

Small teams get denied cyber insurance for one reason more than any other: the answers on the application contradict each other or contradict reality. Not the headcount, not the revenue — the controls. An underwriter reading "yes to MFA" next to "no to offboarding checklist" next to "backups: yes" (untested) reads a team that filled in the form optimistically, and optimistic forms are exactly what claims adjusters subpoena later. The checklist below is the twelve controls that actually appear on small-business applications, in roughly the order the forms ask, with the evidence you should have before you apply — because the cheapest premium is the one you get when your answers are true.

1. Why the application is a security audit in disguise

2. The twelve controls, in the order the form asks

  1. MFA on email and admin accounts. The first question on nearly every form. Email first — business email compromise is the #1 small-business claim. Hardware keys or authenticator apps count; SMS is accepted but noted. MFA rollout checklist →
  2. Backups — tested, offsite, and disconnected. Three copies, one offsite, at least one offline or immutable. The word underwriters look for is tested: a restore you have run, not a job that says "successful." Backup / restore test checklist →
  3. Endpoint protection (EDR/AV) on all laptops and servers. "All" is the operative word — the one unmanaged laptop the founder's spouse uses for invoicing is the gap the application asks about indirectly.
  4. Patching cadence with a documented window. Critical patches within 14 days is the common line. You need a cadence and a record, not perfection. Patch management checklist →
  5. No end-of-life systems touching the internet. The 2012 Windows Server still running the file share is a denial on its own if it's exposed. Retire, isolate, or disclose it.
  6. Access reviews and a real offboarding process. "How do you remove access when someone leaves?" has a right answer ("same day, checklist, verified") and a wrong one ("we ask them to hand over their laptop"). Offboarding checklist →
  7. Unique accounts, no shared logins. Shared admin passwords make every other control unfalsifiable — you can't prove who did what, so insurers assume the worst.
  8. A written incident-response plan. One page counts. Who calls whom in the first hour, who talks to the insurer, who decides on ransom (answer: nobody, pre-decided). IR plan template →
  9. Log retention long enough to investigate. Thirty days of auth and email logs is the practical floor; sixty to ninety is comfortable. Log retention policy →
  10. Disk encryption on laptops. BitLocker or FileVault, default-on. This is the cheapest "yes" on the form — a stolen unencrypted laptop is the classic small claim.
  11. A password manager. It signals the rest of the hygiene, and it makes MFA and unique accounts sustainable. "Passwords in a spreadsheet" is an answer that raises the rate.
  12. Security awareness / phishing training. Annual training plus a way to report a suspicious email. The underwriter wants evidence the humans are part of the control set. Phishing response checklist →

3. The answers that quietly void a claim

4. Evidence to assemble before you apply (one folder, one afternoon)

5. If you can't meet a control yet

6. After binding: the annual attestation trap

The pattern across all twelve: insurers don't buy your intentions, they buy your evidence. A small team that runs the restore test, enforces MFA properly, and keeps a one-page IR plan answers every question on the form with a document, not a hope — and gets the rate that reflects it.