For a small firm, cyber insurance can feel like a tax: the application grows longer, the questions get tougher, and the quote may jump even though nothing seems to have changed. Insurers have tightened underwriting over the years, and many now expect specific controls before they will offer coverage at all. The good news is that the same steps that satisfy underwriters also reduce your actual risk, and a prepared firm usually gets better treatment than an unprepared one.
This post is general information, not insurance advice. Work with a licensed broker who understands professional-services firms.
Understand what drives price and eligibility
While every carrier is different, underwriters generally look at:
- Firm size and revenue
- The type of data held and the practice areas
- The security controls described on the application
- Claims history
- Whether the firm handles large funds transfers
- Any outside scan results of your internet-facing systems
Because controls are among the few factors you can change, investing there can influence both availability and cost.
Controls that insurers commonly ask about
Prioritize these, roughly in order of impact and cost-effectiveness.
- Multifactor authentication on email, remote access, and administrator accounts. This is frequently a gating requirement.
- Endpoint detection and response on all computers and servers, with monitoring.
- Backups that are separate from the main network, protected from deletion, and tested.
- Email filtering and protection against impersonation.
- Patching of operating systems and internet-facing systems on a schedule.
- Security awareness training with simulated phishing and records.
- Written incident response plan that has been reviewed.
- Call-back verification for payment changes.
- Limits on administrative accounts.
Getting these right is usually cheaper than paying a large premium increase year after year.
Prepare a clean application
Answer precisely
Every statement should be accurate and provable. If a control is partial, say so. Overstating invites trouble at claim time.
Use a broker as a translator
A good broker can explain what each question is really asking and how to present your environment truthfully and favorably. Give them documentation, such as MFA reports and backup test logs.
Fix visible problems first
Many carriers run an outside scan of your public IT footprint. Exposed remote desktop, expired certificates, outdated systems, and missing email authentication records can raise flags. Ask your IT provider to run the same kind of scan and clean up before applying.
Choose limits and retentions deliberately
- Limits: think in terms of realistic loss scenarios, including forensic investigation, notification, legal counsel, restoration, and business interruption. Ask your broker to model a few.
- Retention (deductible): a higher retention can lower the premium, but be sure the firm can actually pay it on a bad day.
- Sublimits: examine those for social engineering and ransomware. If fraud losses are capped low, consider whether you need to adjust.
- Coordination: understand how your cyber policy interacts with your professional liability and crime policies.
Ways to control cost without cutting corners
- Shop through a broker, but avoid applying to many carriers inconsistently, which can create confusion.
- Bundle information into a tidy submission with a short summary of your security program.
- Show improvement over time. A year-over-year list of controls added is persuasive.
- Reduce data you hold. Retention and purging policies lower exposure.
- Segment risk. Isolating accounting and trust systems can reduce the blast radius.
- Train and test. Evidence of drills and training suggests a lower likelihood of claims.
Do not buy coverage you cannot use
A policy with conditions you cannot meet is worth less than it looks. Read the conditions on required controls, notice, and vendor use. Ask what happens if a condition lapses mid-term.
Budget for the controls, not just the premium
Consider the total cost of risk: premium, retention, the cost of the controls that make you insurable, and the cost of downtime. Many managed security services bundle several of the listed controls at a predictable monthly price.
Review annually
Meet with your broker and IT provider about 90 days before renewal. Review changes in staff, systems, and practice areas, plus any incidents or near-misses.
Our role
Counsel Cyber does not sell insurance. We help firms implement the controls insurers ask about, gather evidence, and answer technical application questions accurately. If renewal is coming, we are happy to run a pre-renewal readiness review.