OmniTech Mega Menu Block
Schedule Consultation →
Cyber liability insurance requirements, an OmniTech article

Cyber Liability Insurance: What Carriers Require and How to Prove It

The renewal packet lands on the owner’s desk in March. Last year the cyber liability application was two pages. This year it is twelve, and it is asking whether multi factor authentication is enforced on all privileged accounts, what your endpoint detection coverage is, and when you last tested a restore from backup.

Nobody in the building knows the answers with certainty. The deadline is Friday. So somebody checks yes to most of it, because the answers feel roughly true and the policy has to be bound.

That moment is a bigger risk than most business owners realize.

Why the questions got harder

Cyber insurance used to be easy to buy. Carriers wrote broad coverage without much underwriting, then spent several years paying claims that were far larger than anyone had priced for. The response was predictable: fewer questions about your revenue, many more about your controls.

The claims data explains the shift. In Coalition’s 2025 report, covering 2024 claims, business email compromise and funds transfer fraud together made up 60 percent of all claims. Ransomware accounted for 21 percent, with an average loss of 292,000 dollars and initial ransom demands averaging 1.1 million dollars. Forty four percent of affected policyholders paid something. (Source)

Read that first number again. The majority of cyber claims are not sophisticated intrusions. They are email. Someone gets phished, an attacker sits in a mailbox reading the accounts payable thread, and a wire goes to the wrong account. That is why so much of the application is about email security, MFA and user training rather than firewalls.

What carriers are actually asking for

Specific wording varies by carrier and broker, but the underlying list has converged. Expect questions covering:

  • Multi factor authentication, and not just whether you have it. Carriers ask about scope: email, remote access, VPN, and administrative accounts specifically. Partial coverage is where a lot of applications come apart.
  • Endpoint detection and response, meaning behavior based protection with monitoring, not traditional signature antivirus.
  • Backups that are tested, with offline or immutable copies, a defined retention period, and a documented recovery objective.
  • Patch management with a defined timeline for critical vulnerabilities, and a policy on end of life software still running in production.
  • Email security including filtering, quarantine handling, and a way for users to report suspicious messages.
  • Security awareness training with completion records and phishing simulation results, not just an annual video nobody watched.
  • An incident response plan that exists in writing and ideally has been exercised.
  • Logging and privileged access controls, and increasingly some review of your own vendors’ security.

The part that should worry you

Misrepresentation on the application is a leading cause of denied claims. (Source)

This is worth being blunt about. If you attest that MFA is enforced across all administrative accounts, and an attacker later compromises an admin account that did not have it, you have a coverage problem on top of a breach. The claim is the moment your answers get examined, by people whose job is to examine them, with the incident forensics in hand.

The gap is rarely dishonesty. It is that the person signing the form does not have visibility into the environment and is answering in good faith based on what they believe is true. “We have MFA” and “MFA is enforced on 100 percent of privileged accounts” are different statements, and only one of them is a defensible answer.

Before you sign anything, someone should be able to produce the evidence behind each yes.

How our monthly plans line up with the application

We did not design our service tiers around insurance questionnaires, but there is heavy overlap, because carriers are asking for the controls that actually prevent claims.

Every OmniTech plan, including Core at 50 dollars per user per month, includes endpoint detection and response, enterprise antivirus, Microsoft and third party patching, email security and encryption, content filtering, identity threat detection and response, 24/7 remote monitoring, network and firewall monitoring, online file backup, end user security training with simulated phishing campaigns, and documented IT asset inventory.

That covers a large share of a typical application on its own. Two things are worth calling out honestly:

  • MFA is an add on, not a default. Managed Duo two factor and single sign on runs 3 dollars per employee per month. Given that MFA is the single control carriers ask about most aggressively, and given that 60 percent of claims start in email, this is the cheapest meaningful thing most businesses can do this quarter.
  • Server and workstation backup is separate from online file backup. If your application asks about full system recovery rather than file recovery, that distinction matters and we should talk about it before you answer.

Managed detection and response with a security operations center is available at 35 dollars per employee per month. Some carriers now ask specifically about 24/7 monitored detection, and a few price for it.

Our Support plan at 125 dollars per user adds unlimited help desk and guaranteed response times. Omni at 150 dollars per user adds quarterly business reviews, full virtual CIO service, roadmap planning and vendor management, which is where the documentation side gets handled deliberately rather than incidentally.

The documentation is half the value

Having a control and being able to evidence it are separate problems, and the second one is what turns a renewal from a scramble into a form you fill out in an afternoon.

Because we monitor and manage these environments continuously, we can produce patch compliance reporting, training completion and phishing simulation results, backup status and restore test records, endpoint coverage figures, and a current asset inventory. When your broker asks what percentage of endpoints are covered by EDR, that is a number we can answer rather than estimate.

Clients on the Omni plan get this reviewed in their quarterly business review, which means the answers exist before the renewal packet arrives rather than being assembled under deadline.

A few honest caveats

We are not insurance brokers and this is not insurance advice. Carriers differ, policy language differs, and what satisfies one underwriter may not satisfy another. Your broker should be the one telling you what your specific carrier requires, and you should read your exclusions.

What we can tell you is whether the answers you are about to give are accurate, and what it would take to make the ones that are not true today true by renewal.

If your renewal is coming up

Send us the application before you fill it out. We will go through it question by question against your actual environment and tell you where you stand, including the places where the honest answer is no.

A no you can fix in sixty days is a much better position than a yes you cannot defend after an incident.

Scroll to Top