The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means
Identity Access   Aug 10, 2026

The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means

Last year, 63% of small businesses watched their cyber insurance premiums jump 200% or more. This year, the carriers are not just charging more. They are sending applications with a checklist that looks a lot like a security audit. For a lot of small business owners, that checklist is the first time anyone has told them, in writing, what the minimum actually is.

That is the real story right now. Attackers have always known small businesses are softer targets. What is new is that insurance companies have started pricing it that way too, and they are not willing to write checks to companies that cannot prove they are doing the basics.

The numbers have stopped being abstract

A few data points that explain why this is happening:

  • Verizon’s 2025 Data Breach Investigations Report logged 2,842 confirmed breaches at small and medium businesses — roughly four times the rate of large organizations.
  • 88% of SMB breaches now involve ransomware, per Verizon’s dataset.
  • 40% of small businesses say a $100,000 incident would put them out of business, according to VikingCloud’s 2025 research.
  • 47% of companies under 50 employees still have no cybersecurity budget at all (StrongDM).
  • Only 17% of SMBs carry cyber insurance (StrongDM). Most of the ones that do not are gambling, not budgeting.

These are not theoretical numbers. The $100,000 figure is not a worst-case scenario — it is closer to a median. Average ransomware payments from US small businesses last year ran about $115,000. Add forensic investigation, customer notification, legal fees, and the cost of downtime, and the real bill is usually two or three times the ransom itself.

The companies that survive these events are not the ones with the best security in their peer group. They are the ones that had enough working controls that an underwriter was willing to back them.

What insurers are now actually checking

Cyber insurance used to be closer to a credit-card application. “Do you have a firewall? Yes. Approved.” That era is over. In 2026, carriers verify the answers. They ask for screenshots, logs, and configuration exports. The Coalition and Fisch Solutions renewal checklists for 2026 spell it out:

  1. Multi-factor authentication everywhere — including VPN, email, and any admin interface. SMS-based MFA is increasingly treated as insufficient. Phishing-resistant MFA (hardware keys, platform passkeys, or push-based authenticator apps) is becoming the default ask.
  1. Endpoint detection and response (EDR) on every device, not just antivirus. Carriers want to see that someone is monitoring alerts, not just collecting them.
  1. Tested, offline, or immutable backups, with a documented recovery test in the last 12 months. A backup that has never been restored is not a backup. It is a hope.
  1. A documented incident response plan, with names, numbers, and a tested escalation. The 24-to-72-hour breach-notification window is real and tight.
  1. Email security beyond the basics: DMARC, anti-spoofing, and link rewriting at the gateway. Business email compromise is still the most common way small businesses get hit.

If a small business cannot produce those five items, the carrier either declines the policy, charges a deductible that makes the coverage almost pointless, or excludes ransomware from the policy entirely.

Small business owner reviewing cyber insurance requirements
The 2026 cyber insurance application looks less like paperwork and more like a security audit.

The gap is the message

The frustrating part is that almost none of these controls are expensive or exotic. Phishing-resistant MFA is free with Microsoft 365 or Google Workspace for most companies. EDR tools from companies like CrowdStrike, SentinelOne, or even Microsoft Defender for Business run in the low double digits per endpoint per month. Backups to an immutable cloud target with quarterly restore tests are a weekend project, not a quarter-long engagement.

So why is the gap so wide? A few reasons, all familiar:

  • The owner is busy and the IT person is also the owner’s nephew.
  • The “we passed our audit” trap — compliance frameworks (HIPAA, PCI, SOC 2) measure different things than insurer checklists. Passing one does not automatically satisfy the other.
  • Security is invisible until it isn’t, and until recently the consequences were also invisible to most owners because they had not yet been hit.
  • Many MSPs sell “managed security” that is mostly antivirus and patching, and the customer has no way to tell the difference.

What to do about it this quarter

If you are a small business owner, here is the practical list. Not the long version, just the one that will get you through an insurance application and meaningfully reduce your real risk.

  1. Turn on MFA everywhere this week. Start with email, VPN, and any admin console. Push-based authenticators are fine; SMS is a stopgap.
  1. Move from antivirus to EDR. If you cannot tell whether alerts are being reviewed, you do not have EDR — you have antivirus on autopilot.
  1. Test a backup restore. Pick one important system, restore it to a clean environment, and time it. That single test will tell you whether your backup story is real.
  1. Write a one-page incident response plan. Who calls the insurer, who calls legal, who talks to customers, who restores systems. Print it. Tape it to the wall next to the fire escape plan.
  1. Ask your MSP or IT provider for a written security summary. What is deployed, what is monitored, what is tested. If they cannot produce it in a week, that answer is itself the report.

None of these are fun projects. All of them are cheaper than a bad week.

Cybersecurity controls checklist
The five controls carriers now verify — none of them exotic, all of them expected.

The honest take

For most of the last decade, small businesses have been told that cybersecurity is “important” in the same vague way flossing is important. The insurance market has finally done what the awareness campaigns could not: it has attached a dollar amount to the gap, and it has started refusing to insure the gap.

That is a painful adjustment, but it is also the first honest market signal small business owners have ever gotten about what the minimum looks like. The companies that take the checklist seriously, even the ones doing it grudgingly while filling out a renewal form, will end up safer than the ones that wait for an incident to teach the lesson.

The 40% who cannot survive a six-figure attack are not going to learn it from a magazine article. They are going to learn it from the next invoice, the next claim denial, or the next morning when a workstation shows a ransom note instead of a desktop. The good news is that the checklist to avoid all three of those mornings fits on one page, costs less than a part-time hire, and does not require a security team to operate.

It just requires the decision to start.

Sources

  • Verizon, 2025 Data Breach Investigations Report (DBIR): https://www.verizon.com/business/resources/reports/dbir/
  • VikingCloud, Small Business Cybersecurity Statistics 2025
  • StrongDM, Small Business Cyber Security Statistics 2025: https://www.strongdm.com/blog/small-business-cyber-security-statistics
  • Coalition, 5 Essential Cyber Insurance Requirements: https://www.coalitioninc.com/topics/5-essential-cyber-insurance-requirements
  • Fisch Solutions, Cyber Insurance Requirements 2026: MFA, Renewal & Compliance: https://fischsolutions.com/cyber-insurance-requirements-2026/
  • Hiscox, Cyber Readiness Report 2025
The Cyber Insurance Squeeze Just Told Small Businesses What “Secure Enough” Means
~/other/posts

Keep Reading

The Network Is the Control Plane Now. Small Businesses Need to Treat It That Way.
Aug 3, 2026 Identity Access

The Network Is the Control Plane Now. Small Businesses Need to Treat It That Way.

Last week’s article looked at management consoles as the new front door. This week, the same idea is showing up in a different place: the network itself. In July, more than 30 Minnesota water systems were targeted in a coordinated cyberattack. One plant went offline. Around the same time, The Hacker News reported that attackers […]

Your Management Console Is the New Front Door. Stop Treating It Like a Back Room.
Jul 28, 2026 Uncategorized

Your Management Console Is the New Front Door. Stop Treating It Like a Back Room.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, the tools those teams are *not* flying blind on (legitimate admin consoles, automation platforms, and self-hosted developer tools) are getting hit with pre-authentication exploits at a pace that should reset every CISO’s priorities. On July 23, Check Point […]

Healthcare Cyberattacks Just Doubled. The Hospitals Aren’t Even the Soft Target Anymore.
Jul 20, 2026 Network Security

Healthcare Cyberattacks Just Doubled. The Hospitals Aren’t Even the Soft Target Anymore.

Last week we wrote about the 47.4% of IT teams flying blind on Shadow AI. This week, Comparitech and Dark Reading put a number on the target that’s getting hit hardest because of that gap: healthcare. In February, a ransomware attack on the University of Mississippi Medical Center (UMMC) disrupted operations for more than two […]

Shadow AI Is Already Inside Your Company. The Hard Part Is Finding It.
Jul 14, 2026 Uncategorized

Shadow AI Is Already Inside Your Company. The Hard Part Is Finding It.

Last week’s Bitdefender numbers said 47.4% of IT teams have only partial or no visibility into the AI tools their employees are using. That is the polite version of the problem. A sales rep pastes a contract into ChatGPT to “summarize the legalese.” An engineer feeds a production stack trace into a chatbot to debug […]