Cyber Insurance Requirements and Coverage Gaps for Mid Market Businesses

Luke Johnson

A cyber insurance renewal brings IT, finance, and business leadership into the same conversation. What controls are actually in place? How much downtime could the organization absorb? Who should the team call if something looks wrong?

Cyber insurance requirements often center on multi-factor authentication, endpoint detection and response, monitoring, tested backups, and incident response planning. But preparing for coverage also means understanding the policy’s reporting requirements, approved response providers, exclusions, and financial limits.

In Cyber Insurance: What’s Actually Changing, Katalyst CTO Steve Rattacasa spoke with Dena Cusick, Executive Vice President and ProEx South Region Practice Leader at HUB International. Their conversation offered practical guidance for mid-market organizations preparing to buy, renew, or use cyber insurance.

What does cyber insurance cover

Dena began by distinguishing first-party coverage, which addresses an organization’s own covered losses, from liability coverage involving claims by others. Depending on the policy, coverage may include incident investigation, data restoration, business interruption, notification expenses, and certain regulatory or third-party claims.

Some policies also address social engineering fraud, invoice manipulation, or other electronic crime. The details matter: whose money was lost, how the transfer happened, and which account was affected can change the coverage analysis.

A cyber policy does not cover every loss involving technology. Ask your broker to walk through specific scenarios involving your operations and explain how cyber, crime, property, and other policies fit together. Review sublimits, exclusions, retentions, and waiting periods alongside the headline coverage limit. A retention is the amount your organization must absorb before applicable insurance payments begin. A business interruption waiting period is a time threshold defined by the policy.

Which security controls do cyber insurers look for

Dena highlighted several controls that shape underwriting conversations. Requirements and their effect on terms vary by carrier, policy, industry, and the organization’s exposure.

Multi factor authentication

Expect detailed questions about where MFA is enforced, including remote access and privileged accounts. A general statement that the business has MFA may leave important gaps unexplained. Document systems where it is missing and discuss exceptions and compensating controls with your broker.

Endpoint detection and response with active monitoring

Endpoint detection and response, or EDR, needs an operational response behind it. Dena emphasized the importance of monitoring and sufficient staffing or outside support. A single IT employee cannot personally provide continuous coverage.

Organizations should be able to explain who investigates alerts, what coverage exists after hours, and how an incident is escalated. Managed security and MDR can help support that work when an internal team needs additional capacity.

Protected backups and tested restores

The discussion covered immutable backups and the importance of testing recovery. Steve noted a recurring gap: teams confirm that backups completed but have not demonstrated that they can restore the data or systems they need.

Prepare evidence of restoration tests, including what was recovered, how long it took, and what problems remain. That evidence supports both underwriting conversations and your own backup and disaster recovery planning.

A current and practiced incident response plan

A plan needs current contacts, clear responsibilities, and a workable process. Practice it through a tabletop exercise and update it when systems, personnel, or insurance arrangements change.

Have IT validate the technical answers on insurance applications. If a control is partly deployed, explain its actual scope. Application responses should describe the environment the organization operates today.

How much cyber insurance does your organization need

Dena cautioned against choosing limits solely by benchmarking what similar organizations buy. If peers are underinsured, matching their limits does not solve the problem.

Start with scenarios that could materially disrupt your business. Estimate the potential costs of response, downtime, restoration, and affected data. Then discuss those scenarios with your broker alongside the risk the organization can retain.

Different industries need different questions:

  • Credit unions and financial services firms should examine fraud involving member or customer funds and how cyber coverage coordinates with crime coverage.
  • Manufacturers should consider production downtime and the relationship between IT and operational technology. Segmentation and recovery dependencies belong in the discussion.
  • Healthcare organizations should examine sensitive data exposure, system availability, and regulatory coverage, including limitations on fines and penalties.
  • Local governments and education organizations should assess public-service disruption, sensitive records, and reliance on outside providers. Extra expense may matter even where lost revenue is less relevant.
  • Professional services firms should consider confidential client data and how cyber coverage interacts with their other liability policies.

Ask about dependent business interruption as well. If a critical vendor experiences an incident, your organization may incur costs even when its own systems are unaffected. Whether those costs are covered depends on the policy’s triggers and wording.

Why cyber insurance claims can run into problems

One of the most practical parts of the webinar focused on response procedures. Dena described problems that can arise when an organization engages outside specialists without the insurer’s required consent or uses providers outside the approved panel.

That does not automatically mean the entire claim will be denied. As she clarified, reimbursement for particular expenses may be affected. The lesson is to understand the process before an emergency and incorporate it into the response plan.

Keep an accessible offline copy containing:

  • The carrier’s incident hotline and the policy’s notice instructions.
  • Broker and claims contacts.
  • Approved legal and incident response providers, plus any required consent process.
  • Internal decision-makers, their backups, and escalation responsibilities.

Ask your broker how your existing IT or security partner fits into that process. Coordinate technical containment with the policy’s requirements so urgent response work and insurance notifications can proceed together.

Report suspected incidents according to your policy

Steve asked about incidents that seem small enough to handle internally. Dena advised engaging the broker because an event that appears minor can later become more significant. Late reporting can create coverage problems, particularly around policy renewals or changes.

Know whether your policy addresses suspected events and what notice it requires. Contacting a broker should not be assumed to satisfy a separate requirement to notify the carrier.

Describe known facts accurately and involve qualified counsel when needed. Counsel can advise on notification obligations and the handling of sensitive communications; simply involving a lawyer does not automatically make every investigation document privileged.

Ask what is changing in your renewal terms

During the October 2026 webinar, Dena described a market in which some organizations had seen pricing corrections, while others faced different outcomes based on their industry, losses, or exposure. Her advice was to have an active conversation with the broker about why a particular renewal looks the way it does.

If your team has improved MFA coverage, monitoring, or recovery capability, provide documentation. Ask whether those changes support better coverage, a different retention, or an improved business interruption waiting period. Stronger controls do not guarantee a lower premium, but they give the broker a more complete picture to present.

Dena also discussed war exclusions and the significance of their wording. Ask your broker to explain the exclusion in your specific policy, including how attribution is addressed. Broad assumptions about nation-state attacks will not tell you how your contract responds.

Use the resources included with your policy

Some carriers offer services such as tabletop exercises or incident response plan reviews. Dena encouraged organizations to find out what is available and use it.

Confirm eligibility, scope, and whether findings are shared with underwriting. A policy-supported exercise can be a useful opportunity to test the handoff among executives, IT, legal counsel, the broker, and approved response providers.

Frequently asked questions

Does having MFA mean a business qualifies for cyber insurance

MFA is a significant underwriting consideration, but it does not establish eligibility by itself. Carriers may also assess endpoint protection, monitoring, recovery, incident response, industry exposure, and other factors. Requirements vary.

Can a business use its existing IT provider during a cyber incident

Check the policy and confirm the process with your broker before an incident. Some work or expenses may require carrier approval or a panel provider. Define how the existing IT team will coordinate with approved specialists.

Should a business report a small suspected cyber incident

Follow the policy’s notice requirements and promptly discuss suspected incidents with the broker or designated claims contact. An initially small event may develop into a larger issue, and late notice can complicate coverage.

Does cyber insurance cover ransomware and business interruption

Policies may cover certain ransomware-related costs and business interruption, subject to their terms. Review exclusions, sublimits, waiting periods, retentions, and consent requirements with your broker to understand the protection you have.

Align your controls and response plan before renewal

Bring your broker, IT leader, and business decision-makers together before the next application or renewal. Validate the controls you will describe, review coverage against realistic disruption scenarios, and practice the response process the policy expects.

As a Digital Operations Partner, Katalyst helps mid-market organizations strengthen the security and recovery practices behind those conversations. Schedule a conversation with Katalyst to discuss control gaps, recovery testing, and response readiness. Work with your insurance broker on policy selection, interpretation, and coverage decisions.

Visit the full cyber insurance session for more from Steve and Dena, and explore the Cybersecurity Awareness Month series.

Picture of Luke Johnson

Luke Johnson

Luke Johnson is the CEO of Katalyst and a proven leader in IT and cybersecurity who is passionate about helping organizations solve complex problems with clarity and confidence. As an entrepreneur and lifelong learner, Luke brings a strategic, forward-thinking approach to modern managed services, aligning secure infrastructure, risk reduction, and business outcomes. Known for his curiosity and decisive leadership style, he focuses on building high-performing teams and delivering practical solutions that enable clients to operate smarter, move faster, and stay protected.

Helping You Go Further, Faster, Safer

Learn about the services Katalyst offers to keep your organization and its data safe with a tailored cybersecurity solution.

Sign up for our newsletter to get insights sent directly to your inbox.

Related Content