The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means
Identity Access   Aug 10, 2026

The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means

Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told them, in writing, what the minimum actually is.

That is the real story right now. Attackers have always known small businesses are softer targets. What is new is that insurance companies have started pricing it that way too, and they are not willing to write checks to companies that cannot prove they are doing the basics.

The numbers have stopped being abstract

A few data points that explain why this is happening:

  • Verizon’s 2025 Data Breach Investigations Report logged 2,842 confirmed breaches at small and medium businesses — roughly four times the rate of large organizations.
  • 88% of SMB breaches now involve ransomware, per Verizon’s dataset.
  • 40% of small businesses say a $100,000 incident would put them out of business, according to VikingCloud’s 2025 research.
  • 47% of companies under 50 employees still have no cybersecurity budget at all (StrongDM).
  • Only 17% of SMBs carry cyber insurance (StrongDM). Most of the ones that do not are gambling, not budgeting.

These are not theoretical numbers. The $100,000 figure is not a worst-case scenario — it is closer to a median. Average ransomware payments from US small businesses last year ran about $115,000. Add forensic investigation, customer notification, legal fees, and the cost of downtime, and the real bill is usually two or three times the ransom itself.

The companies that survive these events are not the ones with the best security in their peer group. They are the ones that had enough working controls that an underwriter was willing to back them.

What insurers are now actually checking

Cyber insurance used to be closer to a credit-card application. “Do you have a firewall? Yes. Approved.” That era is over. In 2026, carriers verify the answers. They ask for screenshots, logs, and configuration exports. The Coalition and Fisch Solutions renewal checklists for 2026 spell it out:

  1. Multi-factor authentication everywhere — including VPN, email, and any admin interface. SMS-based MFA is increasingly treated as insufficient. Phishing-resistant MFA (hardware keys, platform passkeys, or push-based authenticator apps) is becoming the default ask.
  1. Endpoint detection and response (EDR) on every device, not just antivirus. Carriers want to see that someone is monitoring alerts, not just collecting them.
  1. Tested, offline, or immutable backups, with a documented recovery test in the last 12 months. A backup that has never been restored is not a backup. It is a hope.
  1. A documented incident response plan, with names, numbers, and a tested escalation. The 24-to-72-hour breach-notification window is real and tight.
  1. Email security beyond the basics: DMARC, anti-spoofing, and link rewriting at the gateway. Business email compromise is still the most common way small businesses get hit.

If a small business cannot produce those five items, the carrier either declines the policy, charges a deductible that makes the coverage almost pointless, or excludes ransomware from the policy entirely.

Small business owner reviewing cyber insurance requirements
The 2026 cyber insurance application looks less like paperwork and more like a security audit.

The gap is the message

The frustrating part is that almost none of these controls are expensive or exotic. Phishing-resistant MFA is free with Microsoft 365 or Google Workspace for most companies. EDR tools from companies like CrowdStrike, SentinelOne, or even Microsoft Defender for Business run in the low double digits per endpoint per month. Backups to an immutable cloud target with quarterly restore tests are a weekend project, not a quarter-long engagement.

So why is the gap so wide? A few reasons, all familiar:

  • The owner is busy and the IT person is also the owner’s nephew.
  • The “we passed our audit” trap — compliance frameworks (HIPAA, PCI, SOC 2) measure different things than insurer checklists. Passing one does not automatically satisfy the other.
  • Security is invisible until it isn’t, and until recently the consequences were also invisible to most owners because they had not yet been hit.
  • Many MSPs sell “managed security” that is mostly antivirus and patching, and the customer has no way to tell the difference.

What to do about it this quarter

If you are a small business owner, here is the practical list. Not the long version, just the one that will get you through an insurance application and meaningfully reduce your real risk.

  1. Turn on MFA everywhere this week. Start with email, VPN, and any admin console. Push-based authenticators are fine; SMS is a stopgap.
  1. Move from antivirus to EDR. If you cannot tell whether alerts are being reviewed, you do not have EDR — you have antivirus on autopilot.
  1. Test a backup restore. Pick one important system, restore it to a clean environment, and time it. That single test will tell you whether your backup story is real.
  1. Write a one-page incident response plan. Who calls the insurer, who calls legal, who talks to customers, who restores systems. Print it. Tape it to the wall next to the fire escape plan.
  1. Ask your MSP or IT provider for a written security summary. What is deployed, what is monitored, what is tested. If they cannot produce it in a week, that answer is itself the report.

None of these are fun projects. All of them are cheaper than a bad week.

Cybersecurity controls checklist
The five controls carriers now verify — none of them exotic, all of them expected.

The honest take

For most of the last decade, small businesses have been told that cybersecurity is “important” in the same vague way flossing is important. The insurance market has finally done what the awareness campaigns could not: it has attached a dollar amount to the gap, and it has started refusing to insure the gap.

That is a painful adjustment, but it is also the first honest market signal small business owners have ever gotten about what the minimum looks like. The companies that take the checklist seriously, even the ones doing it grudgingly while filling out a renewal form, will end up safer than the ones that wait for an incident to teach the lesson.

The 40% who cannot survive a six-figure attack are not going to learn it from a magazine article. They are going to learn it from the next invoice, the next claim denial, or the next morning when a workstation shows a ransom note instead of a desktop. The good news is that the checklist to avoid all three of those mornings fits on one page, costs less than a part-time hire, and does not require a security team to operate.

It just requires the decision to start.

Sources

  • Verizon, 2025 Data Breach Investigations Report (DBIR): https://www.verizon.com/business/resources/reports/dbir/
  • VikingCloud, Small Business Cybersecurity Statistics 2025
  • StrongDM, Small Business Cyber Security Statistics 2025: https://www.strongdm.com/blog/small-business-cyber-security-statistics
  • Coalition, 5 Essential Cyber Insurance Requirements: https://www.coalitioninc.com/topics/5-essential-cyber-insurance-requirements
  • Fisch Solutions, Cyber Insurance Requirements 2026: MFA, Renewal & Compliance: https://fischsolutions.com/cyber-insurance-requirements-2026/
  • Hiscox, Cyber Readiness Report 2025
The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means
~/other/posts

Keep Reading

AI Is Now Both Sides of the Fight, and Your SMB Is Caught in the Middle
Sep 28, 2026 Identity Access

AI Is Now Both Sides of the Fight, and Your SMB Is Caught in the Middle

A finance worker in Hong Kong thought he was on a video call with his company’s CFO. Every face in the meeting was real except none of them were. He authorized 15 wire transfers that day totaling about $25.6 million. The “CFO” was a deepfake. The other participants were deepfakes. The whole thing was a […]

The Network Management Plane Just Became the Most Exploitable Surface You Own
Sep 21, 2026 Identity Access

The Network Management Plane Just Became the Most Exploitable Surface You Own

The Network Management Plane Just Became the Most Exploitable Surface You Own Between Tuesday and Thursday of last week, three vendors told the world that the systems meant to control your network are now the easiest way into it. Cisco disclosed a CVSS 10.0 authentication bypass in Identity Services Engine that attackers are using right […]

The Patch Is Out. You Are Probably Still Exposed.
Sep 14, 2026 Identity Access

The Patch Is Out. You Are Probably Still Exposed.

The Patch Is Out. You Are Probably Still Exposed. Last Tuesday, Microsoft patched 974 vulnerabilities in one go. It was the largest Patch Tuesday in history: 723 flaws in Windows, 111 in Office, 62 in SQL, 22 in developer tools, and over 110 rated critical. Two of those flaws were already being exploited before the […]

When the CFO on the Video Call Isn’t Your CFO
Sep 7, 2026 Identity Access

When the CFO on the Video Call Isn’t Your CFO

A finance employee at a multinational engineering firm joined a video call last year expecting to see his company’s UK-based CFO and a handful of other colleagues. Every face on that call looked right.