Cyber insurance is getting pickier: What MSPs need to know

A mainstay of American life is that after a disaster, insurance adjusters show up. Whether the damage is caused by wind, flooding, or hail, consumers simply want coverage. Insurers, however, examine the details, exceptions, and requirements before approving a claim.

The same is true in the era of cyber liability insurance. Following a cyber incident, insurers assess what security controls were actually in place and whether they can be verified. That makes it critical for MSPs to stay current on evolving underwriting standards.

The numbers explain why. Coalition’s 2024 data found that 82 percent of denied cyber insurance claims involved organizations that had not fully implemented multifactor authentication (MFA), making it the leading reason claims were rejected.

The new standard for coverage

“The issue with cyber liability insurance is the expanding ‘negligence baselines’ that companies face and may not even know it,” said Tom Cornelius of Secure Controls Framework.

Cornelius pointed to Texas SB 2610, which provides legal protections for organizations with fewer than 250 employees that can demonstrate compliance with recognized cybersecurity frameworks.

“While the intent was to shield companies from lawsuits, it also established clear expectations that cyber liability insurers can use to deny coverage,” Cornelius said. Organizations that cannot demonstrate compliance may find it more difficult to secure coverage after an incident.

The same principle applies to MSPs, MSSPs, and other service providers.

“When it comes to compliance, if the capability is not thoroughly documented, then it does not exist,” Cornelius said.

Dara Gibson of Cyberreadiness Advisors noted that organizations of every size remain targets for cyberattacks.

“If you collect customer information, payment data, or have intellectual property, you need cyber insurance,” Gibson said, adding that underwriting requirements are increasingly shaping cybersecurity standards.

The fine print behind cyber insurance

According to Kevin Walker, founder of Black Swan Cyber Security Solutions, cyber insurance applications have evolved from administrative paperwork into security assessments.

“A few years ago, many businesses seemed to view the proposal form largely as an administrative exercise,” Walker said. “Increasingly, the questions insurers are asking are really a mini cybersecurity assessment.”

MFA is a good example. Insurers often want evidence that MFA protects Microsoft 365, privileged accounts, remote access, and other critical systems, not simply that it exists somewhere in the environment.

The same scrutiny applies to endpoint protection, patch management, and backups. Many organizations answer questionnaires based on what they believe is in place rather than what they can prove is in place.

“Cyber insurance forms are increasingly becoming a test of whether your cybersecurity exists on paper or in practice,” Walker said.

Turning requirements into opportunity

That creates an opportunity for MSPs.

“This should not be about frightening a customer with the possibility that their insurer will refuse a claim,” Walker said. Instead, MSPs can help clients translate insurer questions into technical evidence.

That means validating MFA coverage, maintaining patching reports, documenting response processes for security alerts, and regularly testing backup recovery procedures. Businesses should be able to answer a simple question: Could they prove their security claims if an insurer asked tomorrow?

Taking that approach also transforms insurance renewals from a once-a-year scramble into an ongoing process. MSPs already have access to much of the information insurers value, including security controls, vulnerability reports, backup testing results, security awareness training records, and incident response documentation. Reviewing that evidence regularly helps clients strengthen their security posture throughout the year rather than uncovering gaps at renewal time.

Walker cautioned that MSPs should help customers understand insurer requirements and provide accurate evidence, but avoid advising clients on how to answer insurance applications.

Ultimately, tougher underwriting is creating better conversations about cyber risk. Organizations that can demonstrate effective controls and provide evidence those controls work will likely find the process much smoother.

As Walker put it: “Insurance should be the financial safety net after good cybersecurity has done everything it reasonably can. It shouldn’t be the cybersecurity strategy.”

 

Photo: SewCreamStudio / Shutterstock

This post originally appeared on Smarter MSP.