This guide expands on OrbitalFire’s webinar “Cyber Insurance in the Age of Cyber Crime,” featuring cyber insurance expert Wes Spencer of FifthWall Solutions. Watch the recording below, or read the full guide.

The cyber insurance market has changed dramatically, and not in ways that favor buyers. Demand has surged, major claims have driven payouts to historic levels, and the industry’s response has been to raise premiums, tighten qualifications, lower coverage limits, and in some cases exit the market entirely. Meanwhile, smaller businesses are navigating renewal paperwork that looks increasingly like a security audit, and claims that get denied for reasons buried in fine print.

This guide covers what’s changed, what you need to qualify, what your policy actually covers, and the questions you must ask before you sign.

Why the Cyber Insurance Market Changed So Fast

For years, cyber insurance was relatively easy to obtain and relatively cheap. Insurers had limited loss history to price against, competition was fierce, and underwriters accepted applicants with few questions asked.

Then the claims started coming in at scale. Ransomware exploded. Business email compromise ballooned into a multi-billion dollar annual problem. Insurers that had priced policies based on pre-ransomware loss assumptions found themselves paying out far more than models predicted. The result was rapid, industry-wide repricing: premiums climbed sharply, exclusions multiplied, and underwriters began asking the kind of questions that used to only appear in enterprise security audits.

For smaller businesses, this created a real squeeze. The organizations that most need affordable cyber coverage are now the ones facing the steepest qualification hurdles.

What Cyber Insurance Actually Covers (and What It Doesn’t)

Understanding what your policy covers is the difference between a meaningful financial backstop and a false sense of security. Coverage typically falls into two categories.

First-party coverage protects your own organization’s losses: forensic investigation costs, system restoration, data recovery, business interruption losses, customer notification and credit monitoring, and sometimes ransom payments (with significant conditions attached). This is the coverage most smaller businesses think of when they think of cyber insurance.

Third-party liability coverage  protects you against claims from others: customers, partners, or patients whose data was compromised in an incident that originated with you. If a data breach in your systems affects a client’s information and they sue, third-party coverage responds. This matters more than many smaller businesses realize, particularly for healthcare vendors, financial service providers, and any organization that holds customer data under a contractual obligation to protect it.

Common exclusions that buyers miss until it’s too late:

Insufficient security controls. Most policies now require that specific controls be in place at the time of a claim, including MFA, endpoint detection, off-site backups, and email filtering. If you said you had them during underwriting and you didn’t, or if they lapsed between renewal and the incident, coverage can be denied.

Unencrypted data. Some policies exclude claims arising from breaches of data that was stored or transmitted without encryption. If your patient records, payment data, or employee files weren’t encrypted at rest, check your policy language carefully.

Nation-state or war exclusions.  Many policies contain exclusions for attacks attributed to nation-state actors. Given that major attacks (NotPetya, SolarWinds) have been attributed to state-sponsored groups, and given that these exclusions are increasingly litigated, this is language worth reviewing with your broker.

Employee-caused incidents. Some policies limit or exclude coverage for incidents caused by employee negligence or insider action. If an employee falls for a phishing email and triggers a ransomware infection, verify whether that scenario is covered under your specific policy.

Does Having Cyber Insurance Make You More of a Target?

This question comes up regularly, and it deserves a direct answer: the evidence doesn’t support the concern in any meaningful way.

Attackers generally don’t know whether a given target has cyber insurance before they attack. Ransomware groups in particular operate by deploying automated tools at scale to identify vulnerable systems. They’re not researching your insurance status before moving forward. The decision to attack is driven by opportunity (exploitable vulnerabilities, weak controls), not by insurance status.

What is true is that organizations that pay ransoms, whether or not they have insurance, can end up on lists that suggest they’re willing payers, which can invite repeat targeting. That’s a reason to be thoughtful about ransom payment decisions, not a reason to forgo insurance.

What Insurers Are Now Requiring to Qualify

Modern cyber insurance applications are effectively a security audit. Before your next renewal, expect underwriters to ask about, and verify, the following:

Multi-factor authentication. The single most common underwriting requirement. Insurers ask specifically whether MFA is deployed on email (especially Microsoft 365 or Google Workspace), remote access (VPN, RDP), and privileged administrator accounts. Absence of MFA on any of these is increasingly disqualifying for higher coverage tiers. MFA is complicated. For more, read The Problem with MFA (And Why You Can’t Ditch It)

Endpoint detection and response (EDR). Basic antivirus is no longer sufficient. Most insurers now ask whether you have active endpoint monitoring that can detect and respond to threats in real time, not just scan for known malware signatures.

Off-site and tested backups. Insurers ask whether you maintain backups, whether they’re stored off-site or in a separate cloud environment (not just on the same network that would be encrypted in a ransomware attack), and critically, whether you actually test restoration. An untested backup is worth very little.

Privileged access management. Whether administrator-level access is controlled, logged, and limited to those who genuinely need it.

Security Awareness Training. Evidence that employees receive regular training and that you conduct phishing simulations. Insurers have learned that the majority of incidents start with human error.

Incident response plan. Whether you have a documented plan and whether it’s been tested. Some underwriters now ask specifically about tabletop exercises.

If you answer “no” to several of these and your current policy is still in force, that’s a gap worth closing before your next renewal, not only for insurability, but because these controls genuinely reduce the risk of an incident requiring a claim.

 How to Use Cyber Insurance Strategically (Not Just Reactively)

The organizations that get the most value from cyber insurance treat the underwriting process as a security planning input, not just a compliance exercise.

When an insurer tells you they require MFA, endpoint detection, and tested backups, they’re not being bureaucratic. They’re telling you what the industry’s claims data says matters most. The controls that reduce claims are the controls that reduce incidents. Aligning your security roadmap with underwriting requirements is one of the most cost-effective ways to prioritize security investments.

Review your policy annually, ideally 90 days before renewal. Coverage limits that made sense two years ago may be inadequate given how your business has grown or how your threat exposure has changed. Bring your cybersecurity advisor into the renewal conversation so you’re answering underwriting questions accurately, and so any gaps in your controls are identified and addressed before the renewal date, not after a claim.

Work with a broker who specializes in cyber, not just a generalist who offers it as an add-on. Cyber policy language is technical and evolving. A specialist broker can translate the exclusions, compare carriers meaningfully, and advocate for you in a claim situation.

 Questions to Ask Before You Sign

Before renewing or purchasing a cyber policy, ask:

  • What controls are required for coverage to apply at the time of a claim, not just at renewal?
  • What are the exclusions for nation-state attacks, unencrypted data, and employee negligence?
  • What is the claims notification timeline? (Many policies require you to notify the insurer within 24 to 72 hours of discovering an incident.)
  • Does the policy include access to incident response services as part of the coverage, or is IR a separate cost?
  • What does the ransom payment process look like, and what conditions apply?
  • Is social engineering fraud (a fraudulent wire transfer triggered by a phishing email, for example) covered under this policy?

Want to discuss cyber insurance for your business, and see if your cybersecurity program is ready for a quote? Or if you have it, can you lower your rates with a plan that better meets their requirements? Reach Out to Chat

 Frequently Asked Questions About Cyber Insurance for Small Businesses

Is cyber insurance required for small businesses?

It’s not universally required by law, but it’s increasingly required by contract. Defense contractors under CMMC, healthcare vendors under Business Associate Agreements, and businesses working with financial institutions often face contractual cyber insurance requirements from their clients or partners. Beyond contractual requirements, the financial case for insurance has strengthened: the average cost of a small business cybersecurity incident now routinely exceeds what most smaller organizations can absorb without external support.

How much cyber insurance does a small business need?

Coverage limits vary based on your revenue, the sensitivity of data you hold, your contractual obligations, and your risk tolerance. A business holding limited customer data may find $500K to $1M of coverage appropriate. A healthcare vendor, financial services firm, or any business with significant volumes of sensitive data should likely carry $1M to $5M or more. Work with a cyber-specialist broker to model your exposure. The goal is matching your coverage limit to your realistic worst-case incident cost, not just picking a number.

What is the difference between first-party and third-party cyber insurance coverage?

First-party coverage protects your own organization’s losses: system restoration, business interruption, breach notification, and forensics. Third-party coverage protects you against claims from customers, partners, or patients whose data was affected by an incident originating with you. Most policies include both; verify the limits on each component separately.

Can my cyber insurance claim be denied?

Yes, and it’s more common than most buyers expect. The most frequent denial reasons are: security controls that were required at underwriting but weren’t actually in place at the time of the incident; incidents excluded under war or nation-state language; claims filed outside the notification window specified in the policy; and data that was required to be encrypted but wasn’t. Read your policy carefully, and ensure your controls actually match what you represented during underwriting.

Does paying a ransom affect my cyber insurance?

Most policies that cover ransom payments include conditions. Insurer pre-approval is often required before payment is made, and some policies exclude payments to sanctioned entities (including certain ransomware groups that have been sanctioned by the U.S. Treasury). If you experience a ransomware incident, notify your insurer immediately before making any payment decision.

Will my premium go down if I improve my security?

Often, yes. Some insurers offer explicit premium credits for specific controls, including EDR tools, MFA on all privileged accounts, and tested backups. Others will simply accept more applicants, at lower risk tiers, when controls are strong. The relationship between security posture and insurance cost has become much more direct as underwriting has matured. Improving your security before renewal is one of the highest-ROI activities you can do in the 90 days before your policy renews.

Watch the Webinar Recording HERE