
Cyber insurers now require MFA, EDR, tested backups, and email security before issuing policies. Here's what Albuquerque businesses must have to qualify.
Cyber insurance is no longer a rubber stamp for any business willing to pay the premium. After years of catastrophic ransomware losses, underwriters rewrote the rules. Small businesses applying for or renewing cyber liability policies in 2026 face detailed questionnaires asking about specific technical controls. The controls are not suggestions — missing critical items results in application denial, policy exclusions, or claims rejection after an incident. For Albuquerque and Santa Fe small businesses, understanding what insurers require is now an IT planning prerequisite, not an afterthought.
The Controls That Determine Coverage
Multi-factor authentication is the single control that appears on every cyber insurance questionnaire without exception. Insurers require MFA on email (especially Microsoft 365 and Google Workspace), VPN and remote access, cloud services and admin portals, and financial and banking applications. In recent years, insurers added specific questions asking not just whether MFA is enabled but whether it is enforced for all users or only some. Policies with exceptions — shared accounts, executives who declined to enroll, or legacy applications that bypass MFA — face exclusions or denial. If any accounts operate without MFA, that is the first remediation priority before applying for coverage.
Endpoint detection and response (EDR) has replaced traditional antivirus as the minimum standard insurers accept. Traditional signature-based antivirus cannot detect behavior-based attacks, fileless malware, or living-off-the-land techniques commonly used in ransomware intrusions. Insurers ask specifically whether you use EDR with behavioral detection, whether all endpoints including servers are covered, and whether EDR alerts are actively monitored. For small businesses without internal security staff, a managed EDR solution monitored by your MSP satisfies this requirement and provides the documentation trail insurers want.
Backups with offline or immutable copies are required because ransomware operators specifically target and delete network-accessible backups before triggering encryption. Insurers verify that at least one backup copy cannot be altered or deleted by ransomware: cloud backups with immutable storage, air-gapped tape, or offline drives. They also ask whether backups are tested — a backup that has never been verified is a risk, not a recovery capability. Document your backup solution, retention policy, and test restore schedule. This documentation is routinely requested during claims.
Email security beyond basic spam filtering is now standard in underwriter requirements. Specifically, insurers ask whether you have configured DMARC on your domain, whether you use an email security gateway with attachment sandboxing and URL rewrite, and whether anti-phishing policies are enabled in Microsoft 365 or equivalent. DMARC records protect your domain from being spoofed in phishing campaigns targeting your clients. They cost nothing to implement and are quick to configure. Insurers view an absent DMARC record as a fundamental oversight, not a minor gap.
The Questionnaire and Audit Process
The insurance application process now commonly includes a technical questionnaire covering 20 to 50 questions about your IT environment, security controls, and incident history. Some insurers add an automated external security scan of your public-facing assets to verify answers. Common questionnaire sections include: MFA coverage and enforcement scope; patch management cadence and documented vulnerability management; backup architecture and restoration testing frequency; email security gateway and authentication records; whether an incident response plan exists and whether staff have participated in tabletop exercises; and vendor and third-party access controls. Providing accurate answers is essential — misrepresentation in the application is the most common reason for claims denial after an incident.
An incident response plan is increasingly required documentation, not just a recommended best practice. Insurers want evidence that your business knows what to do when an incident occurs: who to call, how to isolate compromised systems, how to communicate with clients and staff if email is down, and when to engage a forensics firm. Your insurer may have preferred vendors for incident response that you must use to qualify for coverage. Review your policy carefully for breach coach or incident response vendor requirements. A one-page IRP that addresses these basics satisfies most underwriter requirements for small businesses.
Qualifying and Maintaining Coverage
Patch management and vulnerability management appear in detail on modern questionnaires. Insurers ask how quickly critical patches are applied — the acceptable answer is within 30 days for critical OS and application patches — whether you use automated patch management tools, and whether you have a process for tracking known vulnerabilities. For businesses using a managed IT provider, your MSP should be able to provide a patching compliance report. This report serves as evidence that patch obligations are being met. Keep it on file and update it quarterly as ongoing proof of diligence.
Security awareness training is asked about on most questionnaires. Insurers want to know whether employees receive annual training covering phishing and social engineering, whether you run simulated phishing campaigns, and whether training completion is documented. Platforms like KnowBe4, Proofpoint Security Awareness, or Microsoft's built-in security training modules all produce completion reports. Keep these as part of your compliance documentation package alongside MFA reports, patch logs, and backup test records.
Claims, Premiums, and Getting Coverage Right
If you have an incident and need to file a claim, expect the insurer to review questionnaire answers against your actual security posture at the time of the incident. If the investigation finds that controls were misrepresented — for example, you answered yes to MFA being enforced but it was not — the insurer can deny the claim for material misrepresentation. The post-incident investigation is thorough and forensically detailed. Ensure that your questionnaire answers reflect actual implemented controls, not intended future state.
Businesses that can demonstrate strong security posture through documentation typically receive better premium rates than those providing the same answers without supporting evidence. Working with an MSP that systematically documents your security controls creates the paper trail that supports better coverage terms and faster claims processing. Some insurers now offer formal security attestation programs through preferred MSP partners that result in direct premium discounts.
If you need help preparing for a cyber insurance application, implementing missing technical controls, or documenting your existing security posture for underwriting purposes, HelpTek can assess your environment against current insurer requirements and remediate gaps. We regularly help Albuquerque and Santa Fe businesses qualify for and maintain cyber insurance coverage through practical, documented security implementations.


