Practical guideEN059

Cyber Insurance Questions: Essential Checklist for Small Businesses

Before signing a cyber insurance policy, small businesses must ask about coverage triggers, exclusions, required security controls, and incident response. Get a practical checklist.

Before you sign a cyber insurance policy, move past the premium and coverage limit. The real value lies in understanding when coverage starts, what it excludes, what security steps you must maintain, and how the insurer behaves after an incident. Cyber insurance is a financial backstop, not a replacement for solid security practices. Start with the NIST Cybersecurity Framework 2.0 Small Business Quick-Start Guide to build a security baseline, then use the questions below to compare policies thoroughly and avoid surprises when you file a claim.

What does the policy trigger and cover?

Policies differ in their triggers and scope. Some cover data breach response only, while others include business interruption and extortion costs. Ask the insurer to explain, in plain language, exactly which events start a claim: a stolen device, a phishing email that leads to a compromise, or a ransomware attack. Confirm that coverage includes customer notification, forensic investigation, legal defense, and any regulatory fines if applicable. Also clarify if the policy has sub-limits for specific costs, like extortion or forensic services, which may be lower than the overall limit.

  • First-party costs: your expenses like forensics, notification, and lost income
  • Third-party claims: lawsuits from customers or partners
  • Exact event that triggers coverage
  • Sub-limits that cap payouts for particular items like extortion
Sources and verification date: [2][1]

What exclusions should you examine?

Exclusions often catch small businesses off guard. Ask the insurer to list every exclusion, especially acts of war, state-sponsored attacks, and failures to maintain basic security. For example, if your business has unpatched vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog, some policies may deny coverage. Clarify what 'failure to maintain reasonable security' means. Vague language can be interpreted against you after a loss. Obtain written examples of excluded scenarios so you can compare offers with your actual risk profile.

  • List every exclusion that applies to your industry
  • Define 'reasonable security' and 'failure to maintain' in your policy
  • Check if ransomware extortion is explicitly covered or excluded
  • Understand how employee mistakes (like phishing clicks) are treated
Sources and verification date: [1][2]

Which security controls must you have in place?

Insurers increasingly require proof of cybersecurity before issuing a policy. You will likely need to demonstrate that you enforce multi-factor authentication, keep software updated, train staff on phishing, and maintain backups. CISA's small business resources recommend these four basics. Ask for a checklist of mandatory controls. If you do not meet them, ask whether the insurer offers a grace period or guidance. Be transparent about your current implementation, as false statements can void coverage later.

  • MFA required for email, VPN, and remote access
  • Vulnerability patching within a defined timeframe (e.g., 30 days)
  • Regular security awareness training for employees
  • Documented and tested incident response plan
Sources and verification date: [1][2]

How does the insurer respond to a claim?

After an incident, you do not want to discover that the insurer's process is confusing or delayed. Ask for the contact number and response time, typically a 24/7 hotline. Determine if you may choose your own forensic or legal experts or must use the insurer's approved vendor list-using their list can speed reimbursement but may limit flexibility. Clarify how they help meet legal notification duties and what documents you must provide. Confirm that you must report the incident promptly; most policies require notice within a specified period, so ask for the exact deadline.

  • 24/7 hotline and intended response time
  • Ability to select your own experts vs. using contracted vendors
  • How legal counsel is assigned or chosen
  • Process for notifying regulators and affected individuals
Sources and verification date: [2][1]

How are premium, deductibles, and limits structured?

Compare policies not only by premium but also by deductibles and limits. Ask if the deductible applies per claim or annually, and whether it splits between extortion and other losses. Clarify the aggregate (total) limit versus per-occurrence limit, and whether a retroactive date excludes incidents before a set date. Also ask if the premium increases after a claim and under what conditions. Use the NIST guide to document your security controls, as good hygiene may influence pricing or eligibility, but only if you present it clearly to the insurer.

  • Aggregate vs. per-occurrence limits
  • Deductible per claim vs. per policy period
  • Premium adjustment after a claim
  • Retroactive date and what it means for old incidents
Sources and verification date: [2]

What proof of controls does the application require?

Your application will likely include a risk questionnaire. Answer truthfully-overstating controls can lead to denial later. CISA provides fact sheets on phishing prevention, passwords, MFA, and updates; use them to document your baseline. Map your practices to NIST CSF functions: Identify, Protect, Detect, Respond, Recover. A simple table noting that you have MFA on email, patch within 30 days, and backup daily can suffice. Keep evidence like screenshots and logs to update the insurer after significant changes.

  • Fill the questionnaire accurately to avoid coverage disputes
  • Keep evidence of each control, such as MFA configuration and backup logs
  • Use NIST CSF as a common language to explain your posture
  • Reassess and update controls after major changes like moving to cloud or remote work
Sources and verification date: [1][2]

What gaps remain outside cyber insurance?

No policy covers everything. Nation-state attacks are often excluded or face high sub-limits, and business interruption from a cloud provider outage may not be covered unless separate coverage is added. Check whether the policy covers failure to implement the security controls you committed to. CISA offers no-cost services like vulnerability scanning and guides on logging and incident reporting. Use those to close gaps in your preparation so that insurance is only the last line of defense.

  • War and state-sponsored attack exclusions
  • Losses from unpatched known exploited vulnerabilities
  • Cloud service outages and system downtime
  • Your own intentional acts or fraud
Sources and verification date: [1]

What to verify

  • Policy terms vary by insurer and jurisdiction; you must verify with your provider.
  • Data breach notification laws differ by country and state; consult local legal counsel.
  • CISA and NIST resources are U.S.-based; other countries have their own authorities.
  • Insurers may require independent risk assessments; this guide is informational only.
  • Coverage and requirements change over time; confirm current details before purchase.

Questions and answers

What is a typical timeline for reporting an incident to the insurer?

Policies often require prompt notice, usually within a set time, such as 30 days after discovery, but this varies. Ask for the exact deadline and the required method of notification. Waiting too long can cause a denial. The NIST small business guide advises having an incident response plan so you know how to detect and report quickly. [2][1]

Does cyber insurance cover ransomware extortion payments?

Some policies include extortion payments, but not automatically. Ask if ransomware and extortion are explicitly covered, whether there are conditions such as reporting to authorities first, and if forensic investigation and data restoration are included. CISA's ransomware resources can help you understand the types of attacks and proper response. [1][2]

Can I get cyber insurance without MFA?

Yes, but coverage may exclude incidents that MFA would have prevented, or the premium may be higher. Some insurers require MFA as a condition for coverage. Be honest about your controls; CISA recommends MFA as a basic step. Ask which controls are mandatory and which improvements could lower your premium. [1][2]

Sources and verification date

  1. Official source: cisa.govcisa.gov · Checked
  2. Official source: csrc.nist.govcsrc.nist.gov · Checked
  3. Official source: trade.govtrade.gov · Checked

Related reading