2026 Updated · SMB Guide

Cyber Insurance Readiness:
Are You Actually Coverable?

Most small businesses apply for cyber insurance and get declined — not because they're high-risk, but because they don't know what insurers actually require. Here's the exact checklist.

80%
of breaches involve compromised credentials (MFA blocks this)
2–4 weeks
to implement all 5 required controls from scratch
40–60%
lower premium for companies with documented controls

What "Cyber Insurance Ready" Actually Means

"Cyber insurance readiness" isn't a buzzword — it's a specific set of documented security controls that underwriters check before binding coverage. Without them, your application gets declined. With them, you pay significantly less and get broader coverage.

For small businesses, the five controls insurers almost always require are the same five controls that stop the majority of ransomware and breach attacks. They're not bureaucracy — they're genuinely good security hygiene. This guide walks through each one, explains what counts as compliant, and shows you how to prove it to an underwriter.

The 5 Controls Every SMB Needs to Qualify

Insurers call these the "minimum required controls" or MRCs. Here's what each one actually means in practice.

1
🔐

Multi-Factor Authentication (MFA)

Required on: remote access (VPN, RDP), admin/privilege accounts, email, and any cloud console (AWS, Azure, Google Cloud). Authenticator app or hardware key preferred — SMS-based MFA is increasingly rejected by insurers (Coalition cites 82% of denied claims involve MFA failures).

SOC 2 CC6.1 · Required for all remote access + admin accounts
2
🛡️

Endpoint Detection & Response (EDR)

Software that monitors every device (laptop, server, workstation) for suspicious behavior and can alert or isolate in real-time. Carrier-accepted examples: SentinelOne, CrowdStrike, Microsoft Defender for Business. Basic antivirus does not qualify — it relies on signatures after the fact.

SOC 2 CC7.1 · Must cover all employee devices + servers
3
💾

Immutable / Verified Backups

Backups that ransomware cannot encrypt or delete. This means: air-gapped/offline backups, cloud backups with write-once / object-lock vault policy, or hardware with write-blocker. Your nightly backup to a mapped network drive? Not compliant — and the carrier will ask for last-restore test date (≤90 days).

SOC 2 A1.2 / CC7.5 · 3-2-1 rule + tested restore ≤90 days
4
🗝️

Privileged Access Management (PAM)

Every admin/root account behind just-in-time elevation, hardware-key MFA, separate credentials from standard users, session recording for production access, and a documented quarterly access review. Most modern ransomware campaigns begin with privilege escalation from a compromised standard account.

SOC 2 CC6.2 / CC6.3 · Inventory + 90-day access review cadence
5
📋

Written Incident Response Plan (IRP)

A documented IRP that names who does what during a cyber incident: key contacts, isolation steps, communication templates, and recovery sequence. Must be dated, reviewed within the last 12 months, and tabletop-tested — carriers increasingly reject template-only IRPs without a documented exercise.

SOC 2 CC7.4 · Written + tabletop-tested within last 12 months
6
🔗

Vendor / Supply Chain Risk Management

62% of SMB cyber claims now involve a third-party breach (Coalition 2024). Carriers expect: a maintained subprocessor inventory, annual SOC 2 Type II report review for every critical vendor (hosting, payments, identity, data warehouse, primary SaaS), and a written vendor onboarding security review.

SOC 2 CC9.2 · Annual SOC 2 review for critical subprocessors
7
🎓

Security Awareness Training

Annual security awareness training for every employee with documented completion records, plus quarterly phishing simulations with click-rate tracking and remedial training for clickers. Carrier-accepted platforms: KnowBe4, Proofpoint Security Awareness, Hoxhunt, Curricula.

SOC 2 CC1.4 / CC2.1 · Annual training + quarterly phishing sim

SOC 2 Crosswalk: Each Carrier Control → Trust Services Criteria

Every control on a carrier questionnaire maps to a SOC 2 Trust Services Criteria (TSC) point — and the crosswalk is the single best evidence shortcut. An auditor will pull the same artifacts your carrier will request. If you have evidence that satisfies SOC 2, you almost always have evidence that satisfies the carrier questionnaire.

Carrier Control SOC 2 TSC Mapping Evidence an Auditor Will Pull Sources
Multi-Factor Authentication (MFA) CC6.1 SSO/IdP screenshot with MFA policy enforced on every group; authenticator-app / hardware-key factor configuration; conditional-access policy export. Coalition 2024 (82% denial rate tied to MFA)
Endpoint Detection & Response (EDR) CC7.1, CC7.2 EDR console screenshot showing coverage ≥95% of fleet; documented detection rule set; 90-day alert retention; named incident response owner. AICPA TSC CC7 System Operations
Immutable / Verified Backups A1.2, CC7.5 Backup configuration export (object-lock, air-gap, or write-blocker); dated restore-test report from the last 90 days; RTO/RPO documentation. AICPA TSC Availability A1
Privileged Access Management (PAM) CC6.2, CC6.3 Privileged-account inventory with named owners; just-in-time elevation policy; quarterly access-review screenshots; termination-of-access SLAs. AICPA TSC CC6 Logical Access
Written Incident Response Plan CC7.4, CC7.5 Dated IRP document; tabletop exercise record from the last 12 months; external DFIR / breach-counsel retainer; named on-call rotation. IBM 2024 (tested IRP cuts cost by $2.66M)
Vendor / Supply Chain Risk CC9.2 Subprocessor inventory; annual SOC 2 Type II review file for each critical vendor; vendor onboarding security-review procedure. /vendor-risk-management framework hub
Security Awareness Training CC1.4, CC2.1 Annual completion records per employee (KnowBe4 / Proofpoint / Hoxhunt / Curricula export); quarterly phishing simulation results with click rates. AICPA TSC CC1 / CC2

The full TSC breakdown — CC1 Control Environment through CC9 Risk Mitigation plus Availability, with SMB control mappings — lives in the /soc-2-checklist framework hub. If your controls satisfy SOC 2 above, the carrier questionnaire is mostly a checkbox exercise.

What "Self-Attestation" Actually Means on a Carrier Application

A cyber insurance application is not a survey. Every answer is a self-attestation made under penalty of the carrier's misrepresentation exclusion — meaning the carrier can deny a claim if the answer turns out to be wrong.

Four things to know before you check the boxes

1
Self-attestation vs audit. A SOC 2 attestation is issued by a licensed CPA firm after reviewing evidence over a 6–12 month observation window. A cyber insurance application is a self-attested representation by you, the applicant — neither a broker nor a carrier independently verifies your answers until a claim is filed.
2
The misrepresentation exclusion. Every cyber policy contains a misrepresentation / concealment exclusion. If "Is MFA enforced?" was answered yes and a claim investigation reveals admin accounts without MFA, the carrier can void the policy or deny that specific claim — even if the controls are otherwise in place.
3
Evidence the carrier will request when a claim is filed. Forensic investigators will pull: IdP MFA enforcement logs, EDR telemetry from affected endpoints, backup configuration exports, IRP activation records, vendor SOC 2 reports for any third-party breach. If you can't produce the artifact, the claim is denied regardless of what the application said.
4
How the SOC 2 crosswalk shortens the review. If you have a SOC 2 Type II report covering CC6, CC7, CC9, A1 — or a CyberStackHub SOC 2 Readiness Check that maps every questionnaire line item to a TSC artifact — you can attach it as evidence. Carriers with trust but verify workflows (Coalition, At-Bay, Cowbell) let AI-native underwriting skip drill-down questions when artifact-style evidence is on file.

Sample Carrier Application Questions & How to Answer Them

Six typical SMB carrier questionnaire items — with the model-yes answer that satisfies underwriting, and the model-no answer that produces a denial or a 2–5x premium surcharge.

Carrier Question Model-Yes Answer (Application Approved) Model-No Answer (Denial or Surcharge)
Do you enforce multi-factor authentication on all remote access and admin accounts? Yes — MFA enforced on all remote access (VPN, RDP, SSO), all admin/privilege accounts, all email accounts, and all cloud consoles. Factor type: authenticator app (Authy / Microsoft / Google Authenticator) for staff; hardware key (YubiKey) for admins. SOC 2 CC6.1. Partial — MFA on SSO only, SMS-only factor, or admin accounts excluded. Triggers Coalition's typical 40–60% MFA-failure surcharge or non-renewal.
What endpoint protection is deployed on every employee device? EDR on every endpoint — [SentinelOne / CrowdStrike / Microsoft Defender for Business] with 24×7 monitoring, central console, 90-day alert retention, and named incident response owner. SOC 2 CC7.1. Basic antivirus (Windows Defender passive, consumer-grade Avast / McAfee / Norton). Common denial path under SMB cyber carriers — antivirus misses fileless / signature-evasion ransomware.
Describe your immutable backup strategy and last restore test date. 3-2-1 backup with one immutable copy: AWS S3 Object Lock / Azure Immutable Blob / Wasabi Vault / rotating air-gapped external drives. Last tested restore: [date within last 90 days]. RTO 4 hours, RPO 1 hour. SOC 2 A1.2 / CC7.5. Mapped network drive backup, nightly sync to Dropbox / OneDrive, last restore test >12 months old, or single backup copy in same datacenter as production. Most common backup-related denial.
Is privileged access inventoried and reviewed at least quarterly? Yes — privileged-account inventory maintained in [Okta / Entra / AWS IAM Identity Center]. Quarterly access review with screenshots on file, deprovisioning within 24 hours of termination documented, just-in-time elevation enabled for production. SOC 2 CC6.2 / CC6.3. No — standing admin access on legacy accounts, no formal review cadence, or admin credentials shared across employees. Carriers increasingly require evidence of PAM tooling or compensating controls.
Attach your written Incident Response Plan (PDF). IRP attached — dated within last 12 months, tabletop-tested [date], names roles / contacts / isolation steps / external DFIR retainer / breach counsel. SOC 2 CC7.4. No IRP, or template-only IRP with no tabletop exercise record. Coalition 2024: claims without tabletop-tested IRP have materially higher containment times and denial rates.
Do you maintain a subprocessor inventory with annual SOC 2 review? Yes — subprocessor inventory maintained; annual SOC 2 Type II review on file for [AWS / Stripe / data warehouse / identity provider / primary SaaS]. Vendor onboarding security review procedure documented. SOC 2 CC9.2. No subprocessor inventory or no annual vendor SOC 2 review. 62% of 2024 SMB cyber claims involved a third-party breach — carriers treat this as a primary exposure factor. Detailed guidance: /vendor-risk-management.

Premium-Impacting Control Gaps

Six gaps that carriers treat as material — each one is documented in Coalition, At-Bay, and Cowbell SMB underwriting guidance. The carrier publishes the denominator; the gap determines whether you're in the lowest premium tier or the highest.

1
No MFA on any account — premium multiplier 2.0–5.0x (or outright denial). Coalition cites 82% of denied claims involve MFA failures. This is the single most impactful control.
2
SMS-only MFA — 40–60% surcharge per Coalition data, with several major carriers now refusing to bind. SIM-swap and SS7 attacks defeat SMS MFA without compromising credentials.
3
Legacy antivirus instead of EDR — denial common on SMB cyber policies. AV matches signatures after the fact; EDR detects the behavior. Underwriters want behavior-detection coverage on every endpoint.
4
Mapped network drive "backup" — denial or specific exclusion. Ransomware encrypts everything with admin access, including mapped drives. An immutable / air-gapped copy is the only carrier-acceptable backup posture.
5
No IRP (or template-only) — denial or specific exclusion. IBM 2024 Cost of a Data Breach: companies with tested IRPs save $2.66M per incident. Carriers increasingly require evidence of tabletop testing within the last 12 months.
6
No vendor SOC 2 review — denial or sub-limit reduction. 62% of 2024 SMB claims involved a third-party breach. Carriers treat missing subprocessor SOC 2 as a primary exposure — see /vendor-risk-management.

Pre-Submit Readiness Checklist (Do This Before Applying)

Fourteen items — seven essential, seven strengthening. Run through the essentials first; carriers can't bind without them. Then layer in the strengthening items for the lowest premium tier.

⚡ Essentials — Without These You Will Be Denied

  • MFA enforced on remote access, admin accounts, and email — authenticator app or hardware key (no SMS-only)
  • EDR deployed on every employee device and server (SentinelOne / CrowdStrike / Microsoft Defender for Business)
  • Immutable backups configured — write-once / air-gapped — with a tested restore report from within the last 90 days
  • Privileged Access Management in place — admin inventory maintained, JIT elevation enabled, quarterly access review documented
  • Incident Response Plan written, dated, and tabletop-tested within the last 12 months (with named external DFIR / breach counsel)
  • Subprocessor inventory maintained with annual SOC 2 review for every critical vendor (VRM framework)
  • Email filtering and anti-phishing enabled on all company email (Microsoft 365 / Google Workspace built-in or Advanced)

🛡 Strengthening — Lowers Your Premium Tier

  • SOC 2 quarterly access review screenshots on file (CC6.2 / CC6.3) — see /soc-2-checklist
  • Tabletop-tested IRP with dated exercise record (CC7.4) — outside counsel + DFIR retainer documented
  • Written security awareness training records with annual completion and quarterly phishing-simulation click rates (CC1.4 / CC2.1)
  • Encrypted laptop posture with documented disk disposal (BitLocker / FileVault + KMS) — covers CC6.7
  • Tested backup restore in the last 90 days with RTO / RPO documented — covers A1.2 / CC7.5
  • Vendor SOC 2 review for top 5 subprocessors completed in the last 12 months — covers CC9.2
  • Corgi consultation booked via /cyber-insurance for same-day binding if you want to skip the broker middleman

⚡ Quick Readiness Checklist — Do You Have These in Place?

  • MFA enforced on all remote access, admin accounts, and email (no SMS-only MFA)
  • EDR deployed on all employee devices and servers — not just basic antivirus
  • Immutable backups configured — write-once or air-gapped; tested in the last 90 days
  • Incident Response Plan written, signed, dated, and distributed to key staff
  • Email filtering enabled on all company email — no exceptions
  • Patch management process documented — critical patches applied within 72 hours of release
  • Security awareness training conducted for all employees in the last 12 months
  • Vendor risk assessment completed for any third party with access to your data or systems

Cyber Insurance: DIY vs. Partner vs. Traditional Broker

Getting cyber insurance isn't just about having a policy — it's about having the right controls and choosing the right platform to bind fast.

Criteria No Controls (DIY) Traditional Broker Corgi Insurance (YC-backed)
Time to first quote N/A — declined without controls 2–4 weeks <10 minutes
Same-day binding
Requires all 5 controls upfront Must self-implement first Usually requires full audit AI-native — shows gaps vs. requires perfection
Cyber + Tech E&O + AI Liability Cyber only Usually separate policies All in one
Premium discount for documented controls Up to 30% Up to 60%
No broker middleman ✓ — direct carrier access
Valuation / backing N/A Established but slow $1.3B YC-backed

Don't Guess — Know Where You Stand

Run CyberStackHub's free cyber insurance readiness assessment. In under 10 minutes, you'll know exactly which controls you have in place and which ones you need to address before applying.

1 Answer 20 questions about your current security setup
2 Get a scored readiness report (0–100)
3 See exactly which controls are missing
Start Free Readiness Assessment →

Ready to Get Covered?

Once your controls are in place, get a cyber insurance quote in under 10 minutes — with same-day binding. CyberStackHub partners with Corgi Insurance, YC-backed at $1.3B valuation, to offer SMBs fast, AI-native cyber coverage with no broker middleman.

✓ Cyber Liability
✓ Tech E&O / Prof Liab
✓ AI Liability Coverage
✓ D&O Coverage
✓ Same-Day Binding
Book a Free Cyber Insurance Consultation →

Get a quote in minutes · No broker middleman · YC-backed · $1.3B valuation

Frequently Asked Questions

What do I need to qualify for cyber insurance as an SMB?
Most insurers require five controls: Multi-Factor Authentication (MFA), Endpoint Detection & Response (EDR), immutable/verified backups, a written Incident Response Plan (IRP), and email filtering/spam protection. Without all five, your application will be declined or you'll pay significantly higher premiums.
Why do most SMBs get denied cyber insurance coverage?
The most common reasons: no MFA on remote access or admin accounts, no EDR deployed, backups that aren't immutable (ransomware can encrypt them), no documented IRP, and no email security stack. Insurers see these gaps as unacceptable risk and either decline the application or charge 2–5x the standard premium.
How long does it take to become cyber insurance ready?
For most SMBs with basic IT infrastructure: 2–4 weeks to implement the five required controls and document them. With CyberStackHub's tools you can run a self-assessment in under 10 minutes, generate the required Incident Response Plan, and have documented evidence of each control — ready to submit to an insurer.
What is MFA and why do insurers require it?
MFA (Multi-Factor Authentication) requires a second verification step beyond your password — usually a text message, authenticator app, or hardware key. 80%+ of breaches involve compromised credentials. MFA blocks the most common attack vector, which is why every cyber insurer now makes it mandatory for coverage.
What counts as an acceptable backup for cyber insurance?
Insurers require immutable backups — meaning the backup cannot be overwritten or encrypted by ransomware. This typically means: air-gapped backups (disconnected from the network), cloud backups with versioned write-once policies, or hardware with write-blocker protection. A regular scheduled backup to a mapped network drive does NOT qualify.
Do I need a written Incident Response Plan for cyber insurance?
Yes. Every cyber insurer requires a written Incident Response Plan. This documents who does what during a breach: who is contacted, how systems are isolated, what communication goes out, and how recovery is sequenced. A generic template is fine for initial underwriting — but it must be documented and dated. CyberStackHub generates a customized IRP for your team.
How much does cyber insurance cost for an SMB?
For small businesses (under $10M revenue), cyber insurance typically runs $500–$3,000/year depending on industry, revenue, and your security posture. Companies with documented controls (MFA, EDR, backup, IRP) consistently pay 40–60% less than those without. YC-backed insurtech Corgi offers same-day binding with AI-native underwriting — no traditional broker middleman required.
What's the difference between a traditional insurance broker and an insurtech like Corgi?
Traditional brokers take 2–4 weeks, require a detailed application, and may decline you after the full review. Insurtech platforms like Corgi use AI-native underwriting to give you a quote in under 10 minutes. They don't require a full application upfront — they start with basic company info, and binding can happen same-day. Corgi is YC-backed with a $1.3B valuation and covers cyber, Tech E&O, AI Liability, D&O, and General Liability.

Continue Learning

📋

SOC 2 Trust Services Criteria Checklist

The CC1–CC9 + Availability framework hub — the same TSCs the carrier questionnaire evidence maps to. Includes Sprinto / Drata / Defendify / Vanta platform comparison.

Read the SOC 2 checklist →
🔗

Vendor Risk Management Guide

62% of SMB cyber claims now involve a third-party breach — and CC9.2 is the carrier line item. Full VRM framework, 14-point checklist, and platform comparison.

Read the VRM guide →
🛡️

NIST CSF 2.0 Guide

The Govern / Identify / Protect / Detect / Respond / Recover functions crosswalk directly to the carrier questionnaire controls and to SOC 2 CC1–CC9.

Read the NIST CSF guide →
🛡

Cyber Insurance Partner (Corgi)

Once your controls are in place, get a quote in under 10 minutes via YC-backed Corgi — same-day binding, AI-native underwriting, no broker middleman.

Get a quote →