08/31/2026
Your cyber insurance might not pay out, and you'd only find that out after an attack.
Insurers have spent the last few years tightening what they require. The application you sign is basically a security audit, and if you claim to have controls you don't have, the insurer can reduce your payout or deny the claim when something happens.
Most policies now expect:
β’ MFA on email, remote access, and every admin account. Missing or misconfigured MFA is one of the most common reasons claims get disputed.
β’ Real endpoint detection (EDR) on every machine, not just basic antivirus.
β’ Backups that are offline or immutable, and tested.
β’ Security awareness training you can show records for.
Plenty of businesses sign the renewal form, tick boxes they can't back up, and assume they're covered. The day you file a claim is the worst possible time to learn you weren't.
Pull your policy this week and read the conditions section. If it lists controls, you're not sure you have, close that gap now, before you ever need to file.
.com