← All Blogs

Cyber Insurance Coverage Checklist

A cyber insurance policy should cover data breach response, ransomware and cyber extortion, business interruption, third-party liability, regulatory fines, and social-engineering fraud. Insurers now also require you to have core security controls, MFA, EDR, backups, patching, and training, before they will cover you or pay out. Use this checklist to confirm both your coverage and the controls needed to qualify.

What a cyber insurance policy should cover
What a cyber insurance policy should cover
Key takeaways
  • Good cyber insurance covers breach response, ransomware, business interruption, liability, fines, and fraud.
  • Insurers now require security controls like MFA, EDR, tested backups, and training to qualify and to pay out.
  • Read the exclusions: missing controls or misrepresented security can void a claim.
  • Cyber insurance is a backstop, not a substitute for actually securing your business.
  • Match coverage limits to your real exposure, since the average breach costs millions.

Why cyber insurance, and why a checklist

Cyber insurance (also called cyber liability insurance) helps cover the costs of a cyberattack or data breach, the investigation, recovery, legal fees, notifications, and more. As attacks have become routine and expensive, with the average data breach reaching $4.88 million and reported cybercrime losses topping $12.5 billion in a single year, cyber insurance has shifted from a nice-to-have to a core part of risk management for most businesses. But two things make it tricky: policies vary widely in what they actually cover, and insurers now demand specific security controls before they will insure you or pay a claim. A checklist helps you get both right.

This guide is a two-part checklist: the coverage your policy should include, and the security controls you need to qualify and to ensure a claim is actually paid. Used together, they help you buy insurance that will be there when you need it. It pairs with our cybersecurity services and IT compliance services overviews, and our guide on how much cyber insurance costs.

Part 1: The coverage checklist

A strong cyber insurance policy should include both first-party coverage (your own costs) and third-party coverage (claims others bring against you). Check that your policy addresses each of these:

Pay special attention to that last item: social-engineering fraud is common and is frequently excluded or sub-limited, so confirm it is covered. Read what is excluded as carefully as what is included.

Part 2: The security controls insurers require

This is where many businesses get caught out. Insurers have tightened requirements dramatically, because they were paying out too often. To qualify for coverage at a reasonable price, and crucially, to have a claim paid, you typically must demonstrate a set of baseline security controls:

Security controls insurers require
Security controls insurers require

The critical point: if you claim to have these controls on your application but do not actually have them, the insurer can deny your claim. Misrepresenting your security is the fastest way to pay premiums for years and then be left uncovered when it matters most.

Match coverage to your real exposure

Cyber insurance is priced and sized around risk, so the right coverage limits depend on your exposure: how much sensitive data you hold, your revenue, your industry, and your compliance obligations. Under-insuring leaves you exposed to the very costs the policy was meant to absorb, and those costs are large and slow to resolve, with the average breach running into the millions and taking about 258 days to identify and contain, during which expenses keep mounting.

The average data breach cost 4.88 million dollars in 2024
The average data breach cost 4.88 million dollars in 2024

The good news is that coverage is affordable relative to that exposure. Small businesses pay an average of about $129 a month for cyber insurance, though premiums range widely with risk and coverage. Better security often lowers your premium, because insurers price the controls above into the rate, so investing in security and buying insurance reinforce each other rather than competing for budget.

Cyber insurance averages about 129 dollars a month for small businesses
Cyber insurance averages about 129 dollars a month for small businesses

Insurance is a backstop, not a strategy

The most important thing to understand about cyber insurance is what it is not: it is not a substitute for actually securing your business. Insurance helps you recover financially after an incident, but it does not prevent the attack, the disruption, the reputational damage, or the loss of customer trust, and it will not pay out if you lacked the controls you claimed. The right mindset is that insurance is the backstop behind strong security, not a replacement for it. The same controls insurers require, MFA, EDR, backups, patching, training, are exactly what reduce your chance of a claim in the first place, which is why building security and buying insurance go hand in hand.

How to get cyber insurance right

Getting cyber insurance right means doing two things well: implementing the security controls insurers require (which also genuinely protect you), and choosing a policy whose coverage matches your real risks. Both take expertise, and security talent is scarce amid a global shortfall of about 4.8 million cybersecurity professionals. Many businesses work with a managed IT or security provider to put the required controls in place and document them for the insurance application, which both improves the chance of approval and often lowers the premium. It is part of why the managed services market is projected to grow to about $879 billion over the next decade.

If you are buying or renewing cyber insurance, a provider can help you meet the requirements and avoid the gaps that void claims. To find one, browse vetted, merit-ranked firms by city in the Best IT MSP directory, where ranking is earned on rating and verified data. (This guide is general information, not insurance or legal advice; confirm details with a licensed broker.)

Frequently asked questions

What should a cyber insurance policy cover?

A strong policy should cover data breach response (investigation, notification, credit monitoring, PR), ransomware and cyber extortion, business interruption (lost income during downtime), third-party liability from affected customers, regulatory fines and defense, and social-engineering and funds-transfer fraud. The last is often excluded or sub-limited, so confirm it is included, and read exclusions carefully.

What security controls do cyber insurers require?

Insurers now typically require multi-factor authentication (especially on email, remote access, and admin accounts), endpoint detection and response, regular tested backups, prompt patching, security awareness training, and email security with access controls, often plus an incident response plan. These are needed both to qualify for coverage and to have a claim actually paid.

Can a cyber insurance claim be denied?

Yes. If you claimed to have required security controls on your application but did not actually have them, the insurer can deny the claim. Claims can also be denied for excluded events, such as social-engineering fraud if it was not specifically covered. Misrepresenting your security is the fastest way to pay premiums and then be left uncovered.

How much does cyber insurance cost?

Small businesses pay an average of roughly $129 a month, though premiums range widely, often from a few hundred to several thousand dollars a year, depending on revenue, data held, industry, and coverage limits. Stronger security controls often lower the premium, because insurers price those controls into the rate, so security and insurance reinforce each other.

Is cyber insurance worth it?

For most businesses, yes, given that the average breach costs $4.88 million and reported cybercrime losses topped $12.5 billion in a year. Insurance absorbs costs that could otherwise be catastrophic. But it is a backstop, not a strategy: it does not prevent attacks or pay out if you lacked the controls you claimed, so it works alongside, not instead of, strong security.

Does cyber insurance replace good security?

No. Insurance helps you recover financially after an incident, but it does not prevent the attack, disruption, reputational damage, or loss of trust, and it will not pay if you lacked required controls. The same controls insurers require, MFA, EDR, backups, patching, and training, are what reduce your chance of a claim, so security and insurance go hand in hand.

Meet cyber insurance requirements and close the gaps

Best IT MSP is the independent directory of vetted managed IT and security providers across North America. Compare merit-ranked firms in your city that implement the controls insurers require. No pay-to-play.

▶ Browse Vetted Providers

← Back to all Blogs