Cyber Insurance: Everything You Need to Know for Readiness

Cyber insurance has moved from a nice-to-have to a near-standard requirement for businesses of nearly every size and industry. As ransomware, business email compromise, and data breaches grow more frequent and more expensive, more organizations are turning to cyber insurance to offset the financial fallout of an attack, and more insurers are tightening the bar to qualify for coverage in the first place.

The data backs up the urgency: according to At-Bay’s 2026 InsurSec Report, claim frequency rose 7% year-over-year in 2025 to its highest level since 2021, while average claim severity climbed to an all-time high of $221,000, the third consecutive year both figures have worsened.

For managed service providers, this shift matters twice over. MSPs need cyber insurance to protect their own business and are increasingly helping their clients meet the security requirements insurers now demand. The two are closely connected: the stronger an organization’s cybersecurity posture, the more insurable it becomes, and often the more affordable coverage is.

This guide walks through what cyber insurance is, who needs it, why it matters for MSPs specifically; the core security controls insurers look for during applications and renewals, and the steps to get (and stay) ready for coverage.

What is cyber insurance?

Cyber insurance is a policy that helps organizations cover the financial costs of a cyberattack or data breach, including expenses like incident response, legal fees, customer notification, and liability claims. What a policy actually covers, excludes, and caps varies significantly by insurer and policy, which is why two businesses in the same industry can end up with very different levels of protection.

Coverage generally falls into two categories: first-party coverage, which protects the policyholder’s own losses, and third-party coverage, which protects against claims brought by others affected by the incident. Since policies differ so widely, it’s worth reading the fine print on what cyber insurance does cover and what it does not before assuming a policy will respond to every scenario your business might face.

First-Party Coverage

First-party coverage addresses the organization’s own direct losses and expenses resulting from a covered cyber incident. It’s the coverage most people picture when they think about cyber insurance coverage, since it deals with the immediate costs of responding to and recovering from an attack.

Common examples include:

  • Forensic investigation and incident response costs
  • Business interruption and lost income during downtime
  • Ransomware payments and negotiation support
  • Data recovery and system restoration
  • Customer notification and credit monitoring services
  • Crisis communications and public relations support

Third-Party Coverage

Third-party coverage addresses claims or liabilities that arise when a covered cyber incident affects other people or organizations, such as customers, partners, or vendors whose data was compromised. This category of risk is growing quickly: third-party liability claims jumped 70% in 2025, the largest year-over-year increase of any incident type At-Bay tracks, driven in part by class-action lawsuits that often don’t surface until six to nine months after the original incident.

Common examples include:

  • Lawsuits from customers or partners affected by a breach
  • Regulatory fines and penalties
  • Payment card industry (PCI) assessments and fines
  • Media and intellectual property liability claims
  • Contractual liability owed to partners or vendors

Who Needs Cyber Insurance?

Any organization that stores sensitive data, processes payments, or depends on IT systems to operate needs cyber insurance, and today that describes nearly every business. Some organizations carry more exposure than others, but few are truly outside the risk pool anymore. A few profiles face particularly high exposure:

Regulated industries

Healthcare, finance, and legal organizations carry both data-breach liability and compliance exposure under frameworks like HIPAA and GLBA, making coverage effectively non-negotiable.

Small and mid-sized businesses

Cyber insurance for small business has become especially important because smaller organizations are increasingly targeted precisely because their defenses tend to be lighter, and a single incident can be financially existential without a policy to absorb the impact.

The trend is measurable: companies with under $25 million in revenue saw a 26% increase in average claim severity in 2025, the steepest jump of any segment, as attackers increasingly select victims by the technology they run rather than their size or industry.

Businesses handling customer or payment data

Any organization storing PII, PHI, or cardholder data takes on regulatory and contractual risk the moment that data is collected.

Organizations with contractual or vendor requirements

Many clients and partners now mandate proof of cyber insurance as a condition of doing business, regardless of the vendor’s size or industry.

MSPs sit in a unique position within this picture. They need their own coverage to protect against their own risk, and they increasingly need to help clients qualify for theirs, since a compromised MSP can cascade across every client environment it manages. Insurers are well aware of this concentration risk, which is part of why MSP relationships are drawing more scrutiny during underwriting.

Why is Cyber Insurance Important for MSPs?

MSPs face a compounding set of pressures around cyber insurance. Threats targeting MSPs directly have grown, since a single successful attack can provide access to dozens or hundreds of downstream client networks at once like when one animal gets sick, so does much of the herd. Cybercriminals have learned that this return on their investment is lucrative, and they’re exploiting it.

Insurers have responded with heightened scrutiny of MSPs and their clients alike, and application and renewal questionnaires have grown considerably more detailed as a result, often asking pointed questions about MFA enforcement, backup practices, endpoint coverage, and incident response readiness.

The scale of this shift shows clearly in the claims data. Per At-Bay’s 2026 InsurSec Report, the ransomware group Akira alone drove a 53% surge in ransomware frequency in the second half of 2025 and accounted for more than 40% of all ransomware claims At-Bay tracked that year, with 86% of those attacks exploiting remote access tools, exactly the kind of infrastructure many MSPs manage on behalf of their clients.

Many of the security requirements insurers ask about are ones MSPs are already responsible for managing on their clients’ behalf, which means gaps in an MSP’s own service delivery can directly affect whether a client’s application is approved, what it costs, or whether a renewal goes through cleanly. That makes visibility into clients’ security posture essential, not just to deliver good service, but to avoid being the reason a client’s coverage falls through.

The MSP’s role in cyber insurance readiness

It’s worth drawing a clear boundary here. MSPs help clients assess their environment, implement technical controls, monitor gaps and threats, and document that controls are operating effectively. Coverage decisions, policy terms, and pricing remain the responsibility of the client, their insurance broker, and the insurer itself.

An MSP’s job is to make sure the technical foundation is solid enough that those conversations go smoothly, not to make the coverage decisions.

10 Core Security Controls Required by Insurers

Cyber security insurance requirements have converged around a fairly consistent set of controls that insurers evaluate during both new applications and renewals. Meeting these doesn’t guarantee approval or a specific premium, but gaps in any of them are a common reason applications get delayed, denied, or come back with higher rates.

1. Multi-Factor Authentication

Insurers typically expect MFA across privileged accounts, remote access points, and cloud applications, not just on a handful of systems. Enforcement matters as much as availability; MFA that exists but isn’t consistently required offers little protection and little credibility on an application.

This isn’t theoretical: Akira ransomware, which accounted for over 40% of all ransomware claims in 2025, overwhelmingly targeted remote access appliances that lacked enterprise-wide MFA, with attacks in some cases moving from initial access to full deployment in hours. Strong MFA coverage is closely tied to broader identity threat detection, since compromised credentials remain one of the most common entry points for attackers.

2. Endpoint Detection & Response

Insurers want to see EDR deployed broadly across endpoints and servers, not just on a subset of high-value machines. Beyond deployment, they’re increasingly asking whether that coverage is actively monitored and whether there’s a real response capability behind it, which is where endpoint detection and response tools earn their keep; detection alone isn’t enough if nothing acts on what it finds.

The value of active, around-the-clock monitoring shows up starkly in the claims data: two-thirds of Akira ransomware attacks in 2025 struck on nights or weekends, when internal teams are least likely to be watching, and At-Bay reported that not a single one of its MDR customers filed an Akira claim that year.

3. Backup & Disaster Recovery

Regular backups are table stakes; insurers now look for offline or isolated backups that ransomware can’t reach during an attack, along with immutable backup options that can’t be altered or deleted. Just as important is proof that restores actually work, untested backups and undocumented recovery procedures are a common gap insurers flag.

The financial stakes here are significant. In 2025, one in three ransomware claims triggered business interruption coverage, and those claims averaged $510,000 in severity compared to $168,000 for ransomware claims without business interruption, roughly three times the cost, and about one in ten dragged on for more than 30 days of downtime.

Attackers routinely target backup systems deliberately, before deploying ransomware, specifically to pressure victims into paying once they realize recovery isn’t an option, which is exactly why isolated, immutable backups are treated as a baseline expectation rather than a nice-to-have.

4. Vulnerability & Patch Management

Applications and renewals typically ask about the cadence of vulnerability scanning, how quickly critical vulnerabilities get remediated, and whether unsupported or end-of-life systems are still in the environment. Consistent vulnerability management turns this from a periodic scramble before renewal into an ongoing, defensible practice.

5. Email Security

Since phishing and business email compromise remain leading causes of cyber claims, insurers scrutinize email filtering and anti-phishing protections closely, along with authentication standards like SPF, DKIM, and DMARC that make it harder for attackers to spoof a domain.

6. Identity & Access Management

This control covers whether access follows the principle of least privilege, whether privileged accounts are tightly controlled, and whether the organization conducts regular access reviews. Password policies and a defined user lifecycle process, provisioning, changes, and timely deprovisioning, round out what insurers expect to see.

7. Incident Response

A documented incident response plan with clear roles, responsibilities, and escalation paths is a near-universal requirement. Insurers also increasingly ask whether that plan has been tested through tabletop exercises, since a plan that’s never been exercised often fails in the moments it matters most. This is a natural extension of managed detection and response (MDR), which provides the monitoring and response capability an incident response plan depends on.

Speed matters most when funds are on the line. Financial fraud was the single most common cyber insurance claim type for the third year running in 2025, accounting for 30% of all claims, with an average of $285,000 stolen per incident.

According to At-Bay, organizations that reported an incident within three days recovered some stolen funds 70% of the time, a figure that drops sharply the longer the response is delayed. A tested, well-rehearsed incident response plan is what makes that three-day window realistic instead of aspirational.

8. Security Awareness Training

Insurers look for evidence of regular employee training, including phishing simulation programs, along with records showing who completed training and when. One-time onboarding training rarely satisfies this requirement, recurring, documented education is what insurers want to see.

9. Network & Data Security

This control spans firewalls, network segmentation to limit lateral movement, encryption of sensitive data at rest and in transit, and controls governing remote access into the environment.

10. Third-Party & Vendor Risk

Insurers are paying closer attention to the vendors and partners connected to an organization’s environment, including which vendors have system access, what that access is limited to, and whether the organization performs any third-party risk assessments on critical vendors.

Steps to Achieve Cyber Insurance Readiness

Getting ready for cyber insurance follows a fairly consistent pattern: evaluate your current posture, address the gaps that surface, and then maintain that posture over time so readiness doesn’t quietly erode between renewals.

Step 1: Review Insurance Requirements

Start by understanding the specific requirements tied to the insurer and policy in question, since expectations can vary meaningfully between carriers and policy types.

Step 2: Inventory Your Environment

Build a complete picture of what needs protecting: users, endpoints, servers, applications, cloud environments, critical data, remote access points, and connected third-party systems.

Step 3: Assess Existing Security Controls

Determine which of the required controls are already in place, and just as importantly, how effectively each one is actually being managed day to day.

Step 4: Identify & Prioritize Security Gaps

Compare your current posture against the applicable requirements and prioritize the highest-risk gaps first, rather than tackling issues in whatever order they’re discovered.

Step 5: Remediate Security Gaps

Implement the controls that are missing, correct misconfigurations, address critical vulnerabilities, and shore up the areas identified as weakest during the assessment.

Step 6: Test & Verify Controls

Confirm that controls actually work as intended by testing backups, recovery procedures, incident response plans, and other critical safeguards rather than assuming they’ll perform when needed.

Step 7: Document Security Controls & Evidence

Maintain the policies, reports, configurations, and testing records that demonstrate controls are operating effectively. Insurers increasingly expect documentation, not just assurances.

Step 8: Maintain Ongoing Readiness

Continuously monitor the environment, address new risks as they emerge, and review readiness well ahead of renewal rather than scrambling right before the deadline. Readiness isn’t a one-time project; environments change, new vulnerabilities emerge, users and devices get added, and configurations drift over time.

Cyber Insurance Readiness Checklist

Use this checklist to assess and track readiness across the areas insurers evaluate most closely. It’s built to be easy to scan during an internal review or ahead of an application or renewal.

Identity & Access

  • MFA enforced on privileged accounts
  • MFA enforced on remote access
  • MFA enforced on cloud applications
  • Least-privilege access model in place
  • Regular access reviews conducted
  • Formal password policy enforced
  • User lifecycle process (provisioning/deprovisioning) documented

Endpoint Security

  • EDR deployed across all endpoints
  • EDR deployed across all servers
  • Endpoint activity actively monitored
  • Response capability in place for detected threats

Backup & Recovery

  • Regular, scheduled backups in place
  • Offline or isolated backup copies maintained
  • Immutable backups configured
  • Restore procedures tested regularly
  • Recovery time/point objectives documented

Vulnerability Management

  • Regular vulnerability scanning performed
  • Critical vulnerabilities remediated on a defined timeline
  • Patch management process in place
  • Unsupported/end-of-life systems identified and addressed

Email Security

  • Email filtering and anti-phishing protection in place
  • SPF configured
  • DKIM configured
  • DMARC configured
  • Business email compromise protections in place

Incident Response

  • Documented incident response plan
  • Roles and responsibilities defined
  • Escalation procedures defined
  • Plan tested via tabletop exercise

Documentation

  • Security policies documented and current
  • Control evidence (reports, configs, logs) maintained
  • Exceptions to policy documented and tracked
  • Remediation tracking in place for open gaps

Cyber insurance readiness is an ongoing process

Cyber insurance readiness isn’t something to check off once and forget. Environments change constantly, new vulnerabilities emerge, users and devices get added, configurations drift, and vendors change. Continuous monitoring and regular control verification are what keep an organization ready for renewal instead of scrambling to catch up when it arrives.

Strengthen your cybersecurity readiness

Readiness starts with having the right controls in place, and knowing they actually work. Blackpoint helps MSPs strengthen and continuously monitor their clients’ security posture, so the gaps that jeopardize applications, renewals, and more importantly, the businesses themselves get caught before they become a claim.

Explore Blackpoint’s Managed Cybersecurity Solutions →

Sources

DATE PUBLISHEDOctober 5, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY