Cyber Insurance Coverage Checklist
A cyber insurance policy should cover data breach response, ransomware and cyber extortion, business interruption, third-party liability, regulatory fines, and social-engineering fraud. Insurers now also require you to have core security controls, MFA, EDR, backups, patching, and training, before they will cover you or pay out. Use this checklist to confirm both your coverage and the controls needed to qualify.

- Good cyber insurance covers breach response, ransomware, business interruption, liability, fines, and fraud.
- Insurers now require security controls like MFA, EDR, tested backups, and training to qualify and to pay out.
- Read the exclusions: missing controls or misrepresented security can void a claim.
- Cyber insurance is a backstop, not a substitute for actually securing your business.
- Match coverage limits to your real exposure, since the average breach costs millions.
Why cyber insurance, and why a checklist
Cyber insurance (also called cyber liability insurance) helps cover the costs of a cyberattack or data breach, the investigation, recovery, legal fees, notifications, and more. As attacks have become routine and expensive, with the average data breach reaching $4.88 million and reported cybercrime losses topping $12.5 billion in a single year, cyber insurance has shifted from a nice-to-have to a core part of risk management for most businesses. But two things make it tricky: policies vary widely in what they actually cover, and insurers now demand specific security controls before they will insure you or pay a claim. A checklist helps you get both right.
This guide is a two-part checklist: the coverage your policy should include, and the security controls you need to qualify and to ensure a claim is actually paid. Used together, they help you buy insurance that will be there when you need it. It pairs with our cybersecurity services and IT compliance services overviews, and our guide on how much cyber insurance costs.
Part 1: The coverage checklist
A strong cyber insurance policy should include both first-party coverage (your own costs) and third-party coverage (claims others bring against you). Check that your policy addresses each of these:
- Data breach response. The costs of investigating a breach, notifying affected people, credit monitoring, and public relations.
- Ransomware and cyber extortion. Coverage for ransom demands and the cost of recovery, a leading and growing threat.
- Business interruption. Lost income while systems are down, which matters because an hour of downtime costs most organizations more than $100,000.
- Third-party liability. Claims and lawsuits from customers or partners whose data was exposed in your breach.
- Regulatory fines and defense. Costs related to regulatory investigations and penalties under privacy and data-protection laws.
- Social engineering and funds-transfer fraud. Losses from phishing and business-email-compromise scams that trick staff into sending money, often excluded unless specifically added.
Pay special attention to that last item: social-engineering fraud is common and is frequently excluded or sub-limited, so confirm it is covered. Read what is excluded as carefully as what is included.
Part 2: The security controls insurers require
This is where many businesses get caught out. Insurers have tightened requirements dramatically, because they were paying out too often. To qualify for coverage at a reasonable price, and crucially, to have a claim paid, you typically must demonstrate a set of baseline security controls:

- Multi-factor authentication (MFA). Required almost universally now, especially for email, remote access, and admin accounts.
- Endpoint detection and response (EDR). Modern endpoint protection beyond basic antivirus.
- Tested backups. Regular, secured, and tested backups so you can recover from ransomware without paying.
- Prompt patching. A process to keep systems updated against known vulnerabilities.
- Security awareness training. Ongoing training to reduce phishing success, since the human element features in 68 percent of breaches.
- Email security and access controls. Filtering, least-privilege access, and often a documented incident response plan.
The critical point: if you claim to have these controls on your application but do not actually have them, the insurer can deny your claim. Misrepresenting your security is the fastest way to pay premiums for years and then be left uncovered when it matters most.
Match coverage to your real exposure
Cyber insurance is priced and sized around risk, so the right coverage limits depend on your exposure: how much sensitive data you hold, your revenue, your industry, and your compliance obligations. Under-insuring leaves you exposed to the very costs the policy was meant to absorb, and those costs are large and slow to resolve, with the average breach running into the millions and taking about 258 days to identify and contain, during which expenses keep mounting.

The good news is that coverage is affordable relative to that exposure. Small businesses pay an average of about $129 a month for cyber insurance, though premiums range widely with risk and coverage. Better security often lowers your premium, because insurers price the controls above into the rate, so investing in security and buying insurance reinforce each other rather than competing for budget.

Insurance is a backstop, not a strategy
The most important thing to understand about cyber insurance is what it is not: it is not a substitute for actually securing your business. Insurance helps you recover financially after an incident, but it does not prevent the attack, the disruption, the reputational damage, or the loss of customer trust, and it will not pay out if you lacked the controls you claimed. The right mindset is that insurance is the backstop behind strong security, not a replacement for it. The same controls insurers require, MFA, EDR, backups, patching, training, are exactly what reduce your chance of a claim in the first place, which is why building security and buying insurance go hand in hand.
How to get cyber insurance right
Getting cyber insurance right means doing two things well: implementing the security controls insurers require (which also genuinely protect you), and choosing a policy whose coverage matches your real risks. Both take expertise, and security talent is scarce amid a global shortfall of about 4.8 million cybersecurity professionals. Many businesses work with a managed IT or security provider to put the required controls in place and document them for the insurance application, which both improves the chance of approval and often lowers the premium. It is part of why the managed services market is projected to grow to about $879 billion over the next decade.
If you are buying or renewing cyber insurance, a provider can help you meet the requirements and avoid the gaps that void claims. To find one, browse vetted, merit-ranked firms by city in the Best IT MSP directory, where ranking is earned on rating and verified data. (This guide is general information, not insurance or legal advice; confirm details with a licensed broker.)
Frequently asked questions
What should a cyber insurance policy cover?
A strong policy should cover data breach response (investigation, notification, credit monitoring, PR), ransomware and cyber extortion, business interruption (lost income during downtime), third-party liability from affected customers, regulatory fines and defense, and social-engineering and funds-transfer fraud. The last is often excluded or sub-limited, so confirm it is included, and read exclusions carefully.
What security controls do cyber insurers require?
Insurers now typically require multi-factor authentication (especially on email, remote access, and admin accounts), endpoint detection and response, regular tested backups, prompt patching, security awareness training, and email security with access controls, often plus an incident response plan. These are needed both to qualify for coverage and to have a claim actually paid.
Can a cyber insurance claim be denied?
Yes. If you claimed to have required security controls on your application but did not actually have them, the insurer can deny the claim. Claims can also be denied for excluded events, such as social-engineering fraud if it was not specifically covered. Misrepresenting your security is the fastest way to pay premiums and then be left uncovered.
How much does cyber insurance cost?
Small businesses pay an average of roughly $129 a month, though premiums range widely, often from a few hundred to several thousand dollars a year, depending on revenue, data held, industry, and coverage limits. Stronger security controls often lower the premium, because insurers price those controls into the rate, so security and insurance reinforce each other.
Is cyber insurance worth it?
For most businesses, yes, given that the average breach costs $4.88 million and reported cybercrime losses topped $12.5 billion in a year. Insurance absorbs costs that could otherwise be catastrophic. But it is a backstop, not a strategy: it does not prevent attacks or pay out if you lacked the controls you claimed, so it works alongside, not instead of, strong security.
Does cyber insurance replace good security?
No. Insurance helps you recover financially after an incident, but it does not prevent the attack, disruption, reputational damage, or loss of trust, and it will not pay if you lacked required controls. The same controls insurers require, MFA, EDR, backups, patching, and training, are what reduce your chance of a claim, so security and insurance go hand in hand.
Related reading
Meet cyber insurance requirements and close the gaps
Best IT MSP is the independent directory of vetted managed IT and security providers across North America. Compare merit-ranked firms in your city that implement the controls insurers require. No pay-to-play.
Best IT MSP is an independent directory that connects you with vetted managed IT providers. Browse the directory city by city:
- Managed IT Services in Houston
- Managed IT Services in Dallas
- Managed IT Services in Phoenix
- Managed IT Services in Atlanta
- Managed IT Services in San Diego
- Managed IT Services in San Fernando
- Managed IT Services in San Francisco
- Managed IT Services in San Jose
- Managed IT Services in Santa Ana
- Managed IT Services in Savannah