Cyber insurance for small teams: the 12 controls the application actually checks
Small teams get denied cyber insurance for one reason more than any other: the answers on the application contradict each other or contradict reality. Not the headcount, not the revenue — the controls. An underwriter reading "yes to MFA" next to "no to offboarding checklist" next to "backups: yes" (untested) reads a team that filled in the form optimistically, and optimistic forms are exactly what claims adjusters subpoena later. The checklist below is the twelve controls that actually appear on small-business applications, in roughly the order the forms ask, with the evidence you should have before you apply — because the cheapest premium is the one you get when your answers are true.
1. Why the application is a security audit in disguise
- The form is the underwriting. For small accounts, nobody visits your office. The application is the risk assessment — and it is written to be defensible in court. Every "yes" you tick is a representation you are making about your business.
- Claims are paid or denied on those answers. The ransomware claim gets denied not because you lacked backups but because the backups were never tested, and the application said "regularly tested backups: yes." Regularly was doing a lot of work.
- Contradictions cost more than gaps. "We enforce MFA" plus "one shared admin login for the billing portal" is worse than honestly saying "MFA is rolling out next quarter." Underwriters price honesty; adjusters punish fiction.
2. The twelve controls, in the order the form asks
- MFA on email and admin accounts. The first question on nearly every form. Email first — business email compromise is the #1 small-business claim. Hardware keys or authenticator apps count; SMS is accepted but noted. MFA rollout checklist →
- Backups — tested, offsite, and disconnected. Three copies, one offsite, at least one offline or immutable. The word underwriters look for is tested: a restore you have run, not a job that says "successful." Backup / restore test checklist →
- Endpoint protection (EDR/AV) on all laptops and servers. "All" is the operative word — the one unmanaged laptop the founder's spouse uses for invoicing is the gap the application asks about indirectly.
- Patching cadence with a documented window. Critical patches within 14 days is the common line. You need a cadence and a record, not perfection. Patch management checklist →
- No end-of-life systems touching the internet. The 2012 Windows Server still running the file share is a denial on its own if it's exposed. Retire, isolate, or disclose it.
- Access reviews and a real offboarding process. "How do you remove access when someone leaves?" has a right answer ("same day, checklist, verified") and a wrong one ("we ask them to hand over their laptop"). Offboarding checklist →
- Unique accounts, no shared logins. Shared admin passwords make every other control unfalsifiable — you can't prove who did what, so insurers assume the worst.
- A written incident-response plan. One page counts. Who calls whom in the first hour, who talks to the insurer, who decides on ransom (answer: nobody, pre-decided). IR plan template →
- Log retention long enough to investigate. Thirty days of auth and email logs is the practical floor; sixty to ninety is comfortable. Log retention policy →
- Disk encryption on laptops. BitLocker or FileVault, default-on. This is the cheapest "yes" on the form — a stolen unencrypted laptop is the classic small claim.
- A password manager. It signals the rest of the hygiene, and it makes MFA and unique accounts sustainable. "Passwords in a spreadsheet" is an answer that raises the rate.
- Security awareness / phishing training. Annual training plus a way to report a suspicious email. The underwriter wants evidence the humans are part of the control set. Phishing response checklist →
3. The answers that quietly void a claim
- "Tested backups" with no test date. If challenged, you need a date, a system restored, and ideally a person's name. A dashboard status is not evidence — run the restore test and write down when you ran it.
- "MFA enforced" on an account with a shared service login. Service accounts and scripts don't carry phones; scope them deliberately and document the exceptions before the form asks.
- "We have an incident-response plan" that exists only in someone's head. If it isn't written down, it doesn't exist to an adjuster. A one-page plan beats a ten-page intention.
- "No known incidents" when there was one. The "known" standard is broad. Prior incidents disclosed honestly usually cost a small rate adjustment; prior incidents discovered by the insurer cost the policy.
- Answers from memory. The person filling the form should be able to point at the thing behind each answer. If nobody can, the answer isn't yes yet.
4. Evidence to assemble before you apply (one folder, one afternoon)
- MFA: a screenshot of the enforcement setting per critical app, and the list of documented exceptions with expiry dates.
- Backups: the date and output of your last restore test — what was restored, where it was restored, how long it took.
- Patching: your patch window policy and the last two cycles' records (even a simple sheet).
- Offboarding: the checklist and the last two departures' completion dates.
- IR: the one-page plan itself, with names and phone numbers current enough to survive a real call.
- Encryption: the MDM or settings export showing FileVault/BitLocker coverage across laptops.
5. If you can't meet a control yet
- Answer truthfully with a date. "MFA enforcement completes 30 Sep; authenticator app, break-glass accounts documented" reads as a managed roadmap, not a gap.
- Sequence by claim likelihood. Email MFA and laptop encryption close the two most common small claims; do those first if the list is long.
- Don't let the broker pre-fill. Some applications arrive pre-ticked. Read every line — you are signing representations, and the broker's optimistic defaults are your representations once bound.
- Ask what evidence a claim would need. Underwriters will tell you. "What would you ask for if we filed?" is the single best question in the process — it converts the checklist from abstract to exact.
6. After binding: the annual attestation trap
- Renewals re-ask the questions. The controls must stay true all year, because the renewal application re-certifies them. A control that decayed quietly in month four becomes next year's misrepresentation.
- Attach the checklist to a calendar. Quarterly: MFA exceptions review, restore test, patch records, offboarding audit. Annual: the full twelve, evidenced, before the renewal form arrives. Daily ops checklist →
- When something changes, change the story. New ERP, new laptops, new offshore contractor — each is a control change. Ten minutes of updating the evidence folder beats a denied claim over a stale answer.
The pattern across all twelve: insurers don't buy your intentions, they buy your evidence. A small team that runs the restore test, enforces MFA properly, and keeps a one-page IR plan answers every question on the form with a document, not a hope — and gets the rate that reflects it.