← Back to Blog

Cyber Insurance and IT Compliance: What Small Businesses Are Being Asked to Prove

A few years ago, cyber insurance was a short form and a modest premium. Now it’s a detailed questionnaire with specific technical requirements, and the answers you give become part of the contract.

At the same time, larger customers have started pushing security requirements down to their suppliers. A regional distributor, a healthcare group, a general contractor: all increasingly send questionnaires to businesses that have never been asked before.

Most small businesses can meet these requirements. The problem is that few can prove they meet them, and proof is what’s being asked for.

The Gap That Voids Claims

This is the part worth understanding clearly.

Cyber insurance applications ask specific yes/no questions: Is MFA enforced for all users? Are backups tested? Is there an incident response plan? Someone fills the form in, usually in a hurry, and answers based on what they believe is true.

Then a claim gets filed, and the insurer investigates. If MFA was enabled for most users but not the three service accounts, or backups were configured but never tested, the answer on the application was inaccurate, and coverage can be reduced or denied entirely.

You paid the premium for years. The claim fails on a form question.

The lesson isn’t to answer conservatively. It’s to make the answers true and be able to demonstrate it.

What You’re Actually Being Asked For

The specifics vary by carrier and customer, but the same controls appear on nearly every questionnaire:

ControlThe Question Behind ItWhat Counts as Proof
Multi-factor authenticationIs it on for all users and admins?A configuration report showing enforcement, not a policy document
Endpoint protectionIs EDR deployed everywhere?Console showing coverage across all machines
Backup testingWhen did you last restore successfully?A dated log of test restores with results
Patch managementHow fast do critical patches get applied?Compliance reporting from your patching tool
Access reviewsAre departed employees’ accounts removed?Dated records of quarterly reviews
Incident response planDo you have one, and has anyone read it?The document, plus evidence of a tabletop exercise
Security awareness trainingIs it ongoing or once a year?Completion records and phishing simulation results
Vendor accessWho else can reach your systems?A maintained list with review dates

Notice the pattern: every row asks for evidence the control operates, not evidence it exists. A written policy nobody follows is worse than no policy; it establishes what you knew you should be doing.

The Five Mistakes That Cause Findings

1. The Policy Binder Problem

Policies written once, saved to a shared drive, never trained and never enforced. If your password policy says one thing and your actual system settings say another, that discrepancy is the finding.

Fix: every policy needs a named owner, a training record, and a system setting that enforces it.

2. No Asset Inventory

You can’t secure or attest to what you haven’t listed. This is the first thing nearly every framework asks for, and the thing small businesses most often lack.

Fix: a maintained spreadsheet is fine. Update it quarterly. Include cloud services and anything with network access.

3. Account Sprawl

People leave, roles change, contractors finish projects, and the accounts stay. Accumulated access is a chronic finding and a genuine risk.

Fix: a quarterly access review. Pull the account list, compare against current staff, remove what’s stale, and write down that you did it. That last step is what turns a good habit into evidence.

4. Untested Backups

“We have backups” is not an answer. “We restored a database on March 14th, it took 40 minutes, here’s the log” is.

Fix: schedule test restores quarterly. Record the date, what you restored, how long it took, and whether it worked.

5. Unreviewed Vendor Access

Your security posture includes everyone with a path into your systems: your software vendors, your bookkeeper, anyone with remote access. If they’re compromised, you’re compromised.

Fix: maintain a list of who has access to what. Review it annually. Ask for security documentation from anyone holding significant access.

Which Framework, If Any?

Small businesses often assume they need formal certification. Most don’t. Unless a contract specifically requires it, you’re better off using a framework as a checklist than pursuing certification.

  • CIS Controls v8, Implementation Group 1: the most practical starting point for a small business. Around 55 concrete safeguards, written for organizations without security teams.
  • NIST Cybersecurity Framework 2.0: a good organizing structure (Identify, Protect, Detect, Respond, Recover) that maps cleanly onto other frameworks if requirements arrive later.
  • HIPAA: mandatory if you handle protected health information, which catches more businesses than expected, including some that only handle it incidentally.
  • PCI DSS: applies if you take card payments; largely handled by your payment processor if you’ve set it up correctly, but not entirely.

Start with CIS IG1. It’s free, it’s specific, and working through it will answer most insurance questions as a side effect.

A Year-Round Rhythm

The goal is distributing the work so there’s never a scramble.

Monthly Check that backups completed. Review security alerts. Confirm patching is current.

Quarterly Run the access review and document it. Test a restore and log it. Check for new vendors with system access. Review your asset inventory.

Twice a year Walk through your incident response plan with the people named in it; 90 minutes around a table is enough. Refresh security awareness training.

Annually Review and re-sign policies. Re-read your insurance requirements, since they change. Do a full gap check against your chosen framework. Confirm vendor security documentation is current.

None of this requires a compliance officer. It requires a calendar and someone whose job it is.

Making It Affordable

Use what you already have. Microsoft 365 Business Premium includes endpoint protection, device management, and identity controls, three of the pillars in one license many businesses already pay for and underuse.

Let the tools generate the evidence. Audit logging, patch compliance reports, and MFA registration reports all produce documentation automatically. The auditor wants logs showing controls operate; automated logging provides exactly that without manual effort.

Document as you go. The highest-return habit here is recording work when you do it. Changed a firewall rule, onboarded a vendor, ran a restore, log it. Two minutes each time builds the evidence library that would otherwise take weeks to reconstruct.

A 90-Day Start

Days 1–30, see where you are. Complete an asset inventory. Work through the CIS IG1 list and mark what’s in place. Pull out your actual insurance application and check whether the answers are still true.

Days 31–60, close the top gaps. Enforce MFA everywhere including service accounts. Confirm automated patching covers everything. Run a restore test. Document all of it.

Days 61–90, build the rhythm. Assign owners. Put the quarterly reviews on the calendar with names attached. Create somewhere to keep evidence; a SharePoint folder is entirely adequate. Brief leadership on where you stand.

The Real Payoff

Compliance work has a reputation as pure overhead, and treated as an annual scramble that’s exactly what it is. Treated as an operating rhythm, it produces three things worth having: insurance that pays out when you need it, the ability to answer customer questionnaires without panic, and, not incidentally, a security posture that actually matches what your policies claim.

If you’d like a clear read on where you stand against what insurers and customers are asking, our free Technology & Growth Review covers cybersecurity, technology, and AI readiness in 60 minutes and leaves you with a written action plan.