Renewal season is producing a particular kind of conversation in smaller companies this year. The broker sends a questionnaire, the questionnaire runs to forty questions about controls nobody has formally implemented, and the quote that comes back is either substantially more expensive, substantially narrower, or simply absent. Rates in the wider market have eased from the peaks of two years ago. Underwriting requirements have not eased at all, and for companies below a few hundred employees that is the part that bites.
The questionnaire is now the product. The policy is just what you get if you pass it
Smaller organisations still treat cyber cover as a procurement task with a price attached. Underwriters stopped treating it that way some time ago.
Underwriting moved from revenue to controls
A decade ago, a small company's premium was largely a function of turnover, sector and the odd claims question. Today the rating is driven by a specific set of technical controls, and their absence is frequently a decline rather than a loading. Five show up in almost every submission. Multi-factor authentication, particularly on email and any remote access. Endpoint detection and response deployed across the estate. Backups that are tested, with at least one copy offline or immutable. Controlled privileged access, meaning administrators do not use their admin account for email. And a patching cadence with an inventory of anything past end of support. None of that is exotic. All of it is expensive to retrofit in the six weeks before a renewal date.
Where smaller companies actually fail
Not on intent. On the exception list. Multi-factor authentication is enabled, except for the shared finance mailbox because the system that reads it cannot handle a prompt, and except for two directors who found it inconvenient. Backups run nightly and have never been restored end to end, so nobody knows the restore takes nine hours or that one database was silently excluded in January. The endpoint agent has ninety-one licences against a hundred and forty devices, and nobody reconciles the difference. Every one of those is a truthful "yes" on the form and a genuine gap underneath it. Underwriters have learned to ask follow-up questions specifically about exceptions, and the follow-up is where submissions now fall apart.
Answers on the form are warranties
This is the part that should worry a finance director more than the premium. The application is not a survey. In most wordings the answers are representations the insurer relied on, and a materially inaccurate one is a defence against the claim at exactly the moment it matters. So the person completing it should be someone who can verify rather than someone who can recall. Attach the evidence — the coverage report, the restore test log, the exception register — and keep it with the policy file. If an exception exists, disclose it. A disclosed exception may cost a loading; an undisclosed one can cost the claim.
| Readiness area | Evidence to retain |
|---|---|
| Authentication | Document covered accounts and every remaining exception. |
| Backup recovery | Keep the end-to-end restore log and the scope tested. |
| Endpoint coverage | Reconcile installed protection against the device inventory. |
| Provider and response access | Record MSP access arrangements and test response-panel contact paths. |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Read the sub-limits before the limit
The headline aggregate is rarely the number that determines whether the policy helps. Funds transfer fraud and social engineering are usually carved out to a modest sub-limit, and for most small companies that is the single most likely loss they will ever suffer. Ransomware may carry co-insurance, so a portion of the cost stays with you regardless. Contingent business interruption — your loss when a supplier or platform goes down — is frequently excluded or tightly limited. There is usually a waiting period before business interruption engages at all, often long enough to exceed the entire duration of a typical incident. And the panel provision generally requires you to use the insurer's approved incident responder, or forfeit reimbursement.
What the policy is actually for
Not loss prevention, and for a small company not really indemnity either. The genuine value is access to capability you do not have and cannot assemble at two in the morning: forensic investigators, breach counsel, a negotiator if it comes to that, and notification support. Judge a policy on the quality and availability of that response machinery first, and on the limit second. A large limit attached to a response panel you cannot reach is a worse product than a modest limit attached to one you can.
Ninety days before renewal
A realistic programme for a small company: close the multi-factor exceptions and document what remains and why. Run a full restore test and keep the evidence. Reconcile endpoint agent coverage against the asset list. Inventory end-of-support software and produce a dated plan for it. Write a four-page incident response plan with names and phone numbers. Run one tabletop exercise. That is achievable and it changes the submission materially. Started three weeks out, none of it is.
Practical Guidance for Cyber Insurance Readiness Assessment
- Begin the renewal work ninety days out, not three weeks.
- Have the questionnaire answered by someone who can verify.
- Disclose every control exception rather than answering around it.
- Test a full restore and keep the log with the application.
- Reconcile endpoint coverage to your asset list before submitting.
- Read the social engineering sub-limit first; it is your likeliest loss.
- Check the response panel's reachability in your time zone and language.
- Keep the evidence pack with the policy for the whole period.
The Regional Angle
The first thing underwriters here now probe, and the thing most regional small companies answer badly, is the managed service provider relationship. A large share of businesses in this market outsource information technology entirely to a local provider who holds domain administrator credentials, manages the firewall, runs the backups and often hosts the server. That provider's security posture is, in substance, your answer to half the questionnaire — and you probably have no visibility of it. Ask for a written attestation covering their own multi-factor authentication, how their technicians access your environment, whether they use a shared administrative account across clients, and what monitoring sits over that access. Then read the liability cap in your service contract, which in most regional agreements is a small multiple of monthly fees and bears no relationship to the loss their compromise would cause you. Underwriters have started asking these questions directly; it is considerably better to have the answers before the form arrives. The second is what happens operationally at the moment of an incident. Cyber policies in this market are frequently fronted by a local insurer on an international wording with regional endorsements, and the response panel attached to that wording may have been assembled for another market entirely. Establish before binding whether the panel forensic firm has people who can be on site here, whether the breach counsel is admitted in the relevant jurisdiction, whether the hotline is staffed in your working week rather than a Monday-to-Friday one elsewhere, and whether anyone in the chain operates in Arabic. Negotiate the right to appoint your own responder with pre-approval if the answers are weak, and get that pre-approval in writing at inception. Discovering the limits of a panel during the first four hours of a ransomware event is the most expensive possible time to learn them. The third is the notification and penalty question, which has become considerably more complicated in the last two years. Data protection regimes across the Emirates, Saudi Arabia and the financial free zones each carry their own breach notification expectations and timelines, and sector regulators impose their own on top for regulated entities. The policy will separately require you to notify the insurer promptly, and those clocks are not aligned. Build the notification matrix before you need it — who must be told, by when, by whom, in what form — and put it in the incident plan rather than in somebody's memory. Then ask the broker a direct question in writing: are regulatory fines under the applicable local law insurable at all? In several jurisdictions penalties of that kind are not, and a policy summary that lists "regulatory defence and penalties" as a covered head can still deliver only the defence costs.
The objection worth taking seriously
The strongest objection is straightforward economics. Cyber insurance for a small company is a meaningful annual cost, the claims process is adversarial, the sub-limits mean the payout on the most likely loss is capped well below the actual exposure, and insurers have spent three years narrowing wordings. Spend the premium on controls instead — better backups, proper endpoint protection, security training — and you reduce the probability of the loss rather than arguing about it afterwards. For a company of forty people, that argument has real force. It is also partly correct: controls reduce expected loss and insurance does not, and anyone treating a policy as a substitute for the five basic controls has misunderstood what they bought. Where it breaks down is in the first forty-eight hours. A small company hit by a serious incident has no forensic capability, no relationship with breach counsel, no experience of regulatory notification, and no idea whether the attacker is still in the network. Those are not things the annual premium could have bought as a standing capability; they are only available as a call option, and the policy is the call option. There is a second, less comfortable point. The underwriting process is, in practice, the only external force that reliably makes small organisations close the multi-factor exceptions and test a restore. Companies that dropped their cover to fund controls very often did not fund the controls. The honest position is to buy the cover for the response capability, treat the questionnaire as the security roadmap it has effectively become, and stop expecting the indemnity to be the valuable part.
Common Questions
Will a claim be refused if we had a control gap?
Not automatically. It becomes a problem when the gap contradicts something stated on the application. Disclosed weaknesses are priced; undisclosed ones are disputed.
Is a sub-limit on funds transfer fraud negotiable?
Sometimes, for additional premium and usually with conditions attached such as documented callback verification on payment changes. It is worth asking, because that is where small companies actually lose money.
Do we need cover if our systems are all cloud based?
Yes. The common losses — compromised email, fraudulent payment instructions, a supplier outage — are entirely unaffected by who runs the server.
What should we expect over the next twelve months?
Expect underwriting questions about artificial intelligence tooling and about managed provider access to appear on standard forms during the year. Expect continued tightening around systemic and infrastructure-dependency exposures rather than around rates. Expect more insurers to bundle monitoring or assessment services into small business policies, which is a genuine benefit and also a data-gathering exercise. And expect the gap between companies that can evidence their controls and those that merely assert them to widen into a straightforward availability problem for the second group.
Cyber Insurance Readiness Assessment — we work the questionnaire ninety days out, close the exceptions that cause declines, and check the response panel can actually reach you.
