A few years ago, cyber insurance was a short form and a modest premium. Now it’s a detailed questionnaire with specific technical requirements, and the answers you give become part of the contract.
At the same time, larger customers have started pushing security requirements down to their suppliers. A regional distributor, a healthcare group, a general contractor: all increasingly send questionnaires to businesses that have never been asked before.
Most small businesses can meet these requirements. The problem is that few can prove they meet them, and proof is what’s being asked for.
The Gap That Voids Claims
This is the part worth understanding clearly.
Cyber insurance applications ask specific yes/no questions: Is MFA enforced for all users? Are backups tested? Is there an incident response plan? Someone fills the form in, usually in a hurry, and answers based on what they believe is true.
Then a claim gets filed, and the insurer investigates. If MFA was enabled for most users but not the three service accounts, or backups were configured but never tested, the answer on the application was inaccurate, and coverage can be reduced or denied entirely.
You paid the premium for years. The claim fails on a form question.
The lesson isn’t to answer conservatively. It’s to make the answers true and be able to demonstrate it.
What You’re Actually Being Asked For
The specifics vary by carrier and customer, but the same controls appear on nearly every questionnaire:
| Control | The Question Behind It | What Counts as Proof |
|---|---|---|
| Multi-factor authentication | Is it on for all users and admins? | A configuration report showing enforcement, not a policy document |
| Endpoint protection | Is EDR deployed everywhere? | Console showing coverage across all machines |
| Backup testing | When did you last restore successfully? | A dated log of test restores with results |
| Patch management | How fast do critical patches get applied? | Compliance reporting from your patching tool |
| Access reviews | Are departed employees’ accounts removed? | Dated records of quarterly reviews |
| Incident response plan | Do you have one, and has anyone read it? | The document, plus evidence of a tabletop exercise |
| Security awareness training | Is it ongoing or once a year? | Completion records and phishing simulation results |
| Vendor access | Who else can reach your systems? | A maintained list with review dates |
Notice the pattern: every row asks for evidence the control operates, not evidence it exists. A written policy nobody follows is worse than no policy; it establishes what you knew you should be doing.
The Five Mistakes That Cause Findings
1. The Policy Binder Problem
Policies written once, saved to a shared drive, never trained and never enforced. If your password policy says one thing and your actual system settings say another, that discrepancy is the finding.
Fix: every policy needs a named owner, a training record, and a system setting that enforces it.
2. No Asset Inventory
You can’t secure or attest to what you haven’t listed. This is the first thing nearly every framework asks for, and the thing small businesses most often lack.
Fix: a maintained spreadsheet is fine. Update it quarterly. Include cloud services and anything with network access.
3. Account Sprawl
People leave, roles change, contractors finish projects, and the accounts stay. Accumulated access is a chronic finding and a genuine risk.
Fix: a quarterly access review. Pull the account list, compare against current staff, remove what’s stale, and write down that you did it. That last step is what turns a good habit into evidence.
4. Untested Backups
“We have backups” is not an answer. “We restored a database on March 14th, it took 40 minutes, here’s the log” is.
Fix: schedule test restores quarterly. Record the date, what you restored, how long it took, and whether it worked.
5. Unreviewed Vendor Access
Your security posture includes everyone with a path into your systems: your software vendors, your bookkeeper, anyone with remote access. If they’re compromised, you’re compromised.
Fix: maintain a list of who has access to what. Review it annually. Ask for security documentation from anyone holding significant access.
Which Framework, If Any?
Small businesses often assume they need formal certification. Most don’t. Unless a contract specifically requires it, you’re better off using a framework as a checklist than pursuing certification.
- CIS Controls v8, Implementation Group 1: the most practical starting point for a small business. Around 55 concrete safeguards, written for organizations without security teams.
- NIST Cybersecurity Framework 2.0: a good organizing structure (Identify, Protect, Detect, Respond, Recover) that maps cleanly onto other frameworks if requirements arrive later.
- HIPAA: mandatory if you handle protected health information, which catches more businesses than expected, including some that only handle it incidentally.
- PCI DSS: applies if you take card payments; largely handled by your payment processor if you’ve set it up correctly, but not entirely.
Start with CIS IG1. It’s free, it’s specific, and working through it will answer most insurance questions as a side effect.
A Year-Round Rhythm
The goal is distributing the work so there’s never a scramble.
Monthly Check that backups completed. Review security alerts. Confirm patching is current.
Quarterly Run the access review and document it. Test a restore and log it. Check for new vendors with system access. Review your asset inventory.
Twice a year Walk through your incident response plan with the people named in it; 90 minutes around a table is enough. Refresh security awareness training.
Annually Review and re-sign policies. Re-read your insurance requirements, since they change. Do a full gap check against your chosen framework. Confirm vendor security documentation is current.
None of this requires a compliance officer. It requires a calendar and someone whose job it is.
Making It Affordable
Use what you already have. Microsoft 365 Business Premium includes endpoint protection, device management, and identity controls, three of the pillars in one license many businesses already pay for and underuse.
Let the tools generate the evidence. Audit logging, patch compliance reports, and MFA registration reports all produce documentation automatically. The auditor wants logs showing controls operate; automated logging provides exactly that without manual effort.
Document as you go. The highest-return habit here is recording work when you do it. Changed a firewall rule, onboarded a vendor, ran a restore, log it. Two minutes each time builds the evidence library that would otherwise take weeks to reconstruct.
A 90-Day Start
Days 1–30, see where you are. Complete an asset inventory. Work through the CIS IG1 list and mark what’s in place. Pull out your actual insurance application and check whether the answers are still true.
Days 31–60, close the top gaps. Enforce MFA everywhere including service accounts. Confirm automated patching covers everything. Run a restore test. Document all of it.
Days 61–90, build the rhythm. Assign owners. Put the quarterly reviews on the calendar with names attached. Create somewhere to keep evidence; a SharePoint folder is entirely adequate. Brief leadership on where you stand.
The Real Payoff
Compliance work has a reputation as pure overhead, and treated as an annual scramble that’s exactly what it is. Treated as an operating rhythm, it produces three things worth having: insurance that pays out when you need it, the ability to answer customer questionnaires without panic, and, not incidentally, a security posture that actually matches what your policies claim.
We don’t perform formal compliance audits or certifications. What we do run is the Manufacturing Technology Efficiency Review, a fixed-fee on-site engagement that finds where your plant is losing hours to manual work and tells you plainly what’s worth fixing. It starts with a free 20-minute fit call.