Skip to content
CONFIGLANE

Insurance · Smaller companies

What cyber insurers demand — and why half of it sits in the network

A cyber policy is not a substitute for technology but a bet on it. The questions in the application are the terms of that bet — and anyone no longer meeting them when a claim arrives may have paid for nothing.

By ConfiglanePublished 5 min readSmall Business

The short version

  • Insurers demand multi-factor authentication with no exceptions for email access, VPN and remote access, administrator accounts and privileged application access. SMS as a second factor is increasingly rejected.
  • For backups the 3-2-1 rule applies — three copies, two media, one off-site — with at least one copy offline or immutable, and documented restore tests.
  • Flat networks are considered no longer acceptable: VLAN separation between client and server networks is expected, along with blocking direct access such as SMB or RDP from client into server networks.
  • These points are ongoing obligations. If they are not met when a claim arises, the insurer can reduce or refuse payment.

A few years ago a cyber insurance application looked like a form. Today it looks like a technical audit — and that is no accident: insurers have learned which claims they had to pay and which gaps sat behind them.

Multi-factor authentication: the question it hangs on

MFA is where most applications fail or become expensive. It is required not selectively but across four areas: email access (Microsoft 365, Google Workspace, on-premises Exchange), VPN and remote access, administrator accounts and privileged application access. Exceptions are not envisaged.

There is also a tightening on method: SMS as a second factor is increasingly rejected in favour of app or hardware tokens. Anyone who introduced MFA three years ago using SMS may no longer meet the requirement today — without anything having changed on their own premises.

Backup: the word that matters is “tested”

The 3-2-1 standard is required: three copies, two different media, one off-site. At least one copy must be offline or immutable — an air gap, write-once media, or object lock in object storage. And restore tests must be documented regularly.

That last point is where most organisations stumble in practice. A backup whose restore has never been verified is a hope when a claim arrives. To the insurer it is an unmet obligation.

The points that sit in the network

Three of the required measures cannot be handled by software on the workstations. They are network work:

  1. Separation of client and server networks

    Flat networks are considered no longer acceptable. VLAN separation between workstations and servers is expected — and, where present, between office and production.

  2. Blocked direct access

    Direct SMB or RDP connections from the client into the server network should be prevented by firewall rule. Those two protocols are the usual path along which ransomware spreads.

  3. Controlled remote access

    Every path from outside — home office, IT provider, machine builder — needs MFA and a named authorisation. The forgotten maintenance link of a former supplier is the classic finding.

  4. Traceable patch management

    What gets asked is the process, the tools and the response times — with evidence of when which system was updated. Routers, firewalls and switches count; they are the most frequently forgotten.

Anyone with those four in place also answers much of the supply chain questionnaire customers now send — the requirements overlap almost entirely. More on that in the article about your customer's NIS2 questionnaire.

The order that makes sense

If everything cannot happen at once — and it rarely can — the order by effect per effort is: MFA on email and remote access first, then a tested restore run, then separation of client and server networks, then the rest. The first two steps cost little and cover the most common causes of loss.

One point often gets lost here: the answers in the application are assurances. Ticking what is about to be implemented moves the problem into the claim — where it is most expensive. How we build smaller networks so these questions are answerable is described on our page for smaller companies.

Sources

Every evidenced claim in this article can be traced here. The retrieval date shows how fresh the check is.

FAQ

Frequently asked questions about cyber insurance

Does cyber insurance replace technical measures?

No, it presupposes them. The policy covers the financial loss, not the risk itself — and only for as long as the agreed obligations are met. Insurance without the required measures is, in case of doubt, a premium without a counterpart.

What happens if we stop meeting a requirement later?

Obligations are ongoing duties, not conditions at signing. If MFA is switched off for an access path, patching slips, or backups stop being tested, the insurer can reduce or refuse payment when a claim arises. That is why checking these points belongs in regular operations, not in the application phase.

Is VLAN separation enough, or do we need a firewall between them?

VLANs separate the traffic but do not decide what is permitted between the areas. Both are required: the separation, and a rule preventing direct access from client into server networks — particularly SMB and RDP. In smaller networks the same firewall that already sits at the internet connection usually handles this.

We are small. Will insurers even take us?

Yes, the offering for smaller companies is broad. The questionnaires are barely shorter, though, and the minimum standards are the same. The difference is effort: in a network with fifty workstations, MFA, a backup test and network separation are questions of days, not months.

Next step

Does this hold for your network?

An assessment answers the question against your infrastructure rather than an example — ending in a first dependable change.

Request an assessment

Assessment → first dependable change