The moment the rules changed
A renewal email arrives from the cyber-insurance broker. The questionnaire that used to be a page of tick-boxes is now several pages long. It asks whether MFA is enabled on every mailbox, whether backups are immutable, whether there's a documented patch management policy, and when the last restore test was run.
Answer honestly, and the broker comes back with one of three outcomes: a large premium increase, a ransomware coverage exclusion, or a flat refusal to renew.
That's not a fringe scenario any more. Cyber insurers have spent several years paying out heavily on ransomware claims, and they've responded the way any insurer responds to a bad loss ratio: by tightening what they'll cover and checking harder before they pay. The carriers' own numbers explain it: Coalition's annual claims report puts email compromise and ransomware at the head of small-business claims[1], and Marsh's cyber market analysis describes the same control expectations hardening across the market rather than at one insurer[2][3]. In the renewals we've helped small businesses through, the businesses that pass are not the bigger or better-funded ones. They're the ones that treated the questionnaire as a checklist and prepared for it in advance, not the week it landed.
What insurers actually check now
The exact wording varies by carrier, but the pattern across the market is consistent. Six controls come up on almost every serious questionnaire:
They are not carrier inventions either - the same set is close to CISA's Cyber Essentials baseline for small organisations[4][5], which is why preparing for one tends to satisfy the other.
- MFA on every mailbox, every admin account, and every remote access path - not most accounts, all of them. Microsoft's own research on Entra ID accounts found MFA cuts the risk of compromise by 99.22% across the general population, and by 98.56% even on accounts whose password had already leaked[6]. That's the reason insurers treat it as close to non-negotiable rather than a nice-to-have. Verizon's breach data makes the same case from the attacker's side, where credential abuse remains the most pervasive technique across breach chains[7][8].
- Endpoint detection and response (EDR), not just antivirus. Antivirus blocks known threats by signature. EDR watches behaviour and catches threats nobody has seen before, automatically detecting, investigating and remediating incidents rather than just flagging a file[9].
- Immutable, offsite backups with a recent, tested restore. A backup an administrator, or an attacker holding admin credentials, can delete is not the backup an insurer is underwriting against. Sophos' annual ransomware research is the reason the restore test matters more than the backup job: recovery, not payment, is what a working backup buys you[10].
- A documented patch management policy, not "we update when we remember to."
- Annual security training with phishing-simulation results on file, not a single video shown on someone's first day.
- A written, reviewed incident response plan that says who gets called, what gets shut down, and how the business communicates.
What this costs to fix, for a 10-person business
The gap between what insurers want and what most small businesses have is rarely expensive to close. It's a matter of knowing what to configure and doing it before the renewal, not after.
If the business already runs Microsoft 365 Business Premium, most of the technical controls are already paid for and sitting unconfigured:
- MFA everywhere - included in Business Premium through Entra ID's identity and access management[11]. No extra cost.
- EDR - Microsoft Defender for Business is bundled into Business Premium[9]. No extra cost, but it has to be switched on and configured, not just licensed.
- Patch management and device policy - Microsoft Intune handles update rings, compliance policies and encryption enforcement across the fleet[12], and is part of the same Premium licence. No extra cost.
- Immutable, tested backup - this sits outside the M365 licence. Budget roughly €100-200 a month for a 10-person business, plus the time for a quarterly restore test, based on what we see running this for clients.
- Security training with phishing simulation - roughly €50-150 a month for a small team.
- Incident response plan - a one-off cost to write and review it properly, typically a few hundred euros up to around €1,500 depending on how much of the business's process it has to capture.
Add it up and a 10-person business already on Business Premium is usually looking at somewhere in the €150-350 a month range on top of the licence, mostly for backup and training, not for anything new to buy.
The five reasons businesses actually fail
MFA on most accounts, not all of them. This is the single most common failure we see. Insurers check every admin account and every remote access path specifically because that's where it's most often skipped. One unsecured admin account is enough to fail the assessment even if everyone else has MFA switched on.
Backups that exist but have never been tested. Insurers ask for the date of the last restore test, not whether backups run. "We have backups" doesn't answer that question, and a backup nobody has restored from is, for underwriting purposes, treated as a backup that doesn't work.
No documented policies. Plenty of small businesses have genuinely good practices with nothing written down. The assessment is as much a paperwork exercise as a technical one - a policy that exists only as a habit in someone's head does not exist for the purposes of the form.
Antivirus mistaken for EDR. Free or basic antivirus is not what insurers mean by endpoint protection any more. Microsoft Defender for Business, included in Business Premium, does qualify[9] - but only once it's actually enabled and configured, which is the step that gets skipped when a licence is bought and left alone.
Shadow IT the owner doesn't know about. Personal cloud storage, unapproved apps, or personal email used for business communication. A carrier's scan finds these regardless of what the business owner believes is true, and if the owner didn't know about them, the assessment fails on accuracy before it fails on security.
The timeline: when to actually start
Most businesses start preparing 30 days before renewal. That's too late - insurers want to see controls that have been in place and documented for a while, not switched on the week before the questionnaire goes in.
For a business renewing in January, a realistic run looks like this:
- Three months out - audit current controls against the insurer's questionnaire and list every gap.
- Two months out - close the gaps: MFA everywhere, EDR configured, immutable backups live, policies written.
- One month out - test a backup restore, run a phishing simulation, and build the evidence pack: a screenshot, a policy document or a test log behind every "yes" on the form.
- Renewal month - submit with the evidence ready rather than promised.
For a 10-person business with the right licence already in place, this is genuinely 2-3 weeks of focused work plus ongoing maintenance, not a large project. The alternative is a policy that looks fine on paper and doesn't pay out when it's actually needed.
Outside the biggest markets, the paperwork looks a little different
The six controls above are consistent everywhere, but the surrounding compliance layer varies. In Israel, some international carriers are less familiar with local regulatory requirements, which can slow underwriting even when the technical controls are solid. In the EU, a business already doing NIS2-driven documentation work usually finds it satisfies most of what an insurer's questionnaire is asking for in writing, since both are pointing at the same written policies. In Spain specifically, businesses handling EU citizen data at meaningful scale tend to see extra questionnaire sections on data classification and breach notification, reflecting AEPD's separate enforcement layer on top of the insurer's own checks.
None of this changes the six controls above. It changes how much extra documentation sits alongside them.
What this actually means for your business
A cyber-insurance policy you can't successfully claim against is worse than no policy at all - it's the belief that you're covered, right up until the moment you find out you're not. The fix isn't complicated or expensive if you're already on the right Microsoft 365 licence. It's making sure the controls you're already paying for are actually switched on, documented, and tested before the renewal, not after a claim.
