
Most owners buy a cyber insurance policy expecting it to make a breach disappear. It won't. A policy is a financial safety net that helps cover certain losses and gives you fast access to the specialists you'll need after something goes wrong — legal, forensic, breach notification, recovery. What it does not do is stop the attack or replace the security controls that would have prevented it. Getting that distinction right is the difference between a policy that pays and a policy that fights you at claim time.
What the policy actually pays for
When people picture cyber coverage, they picture a ransom payment. That's a small slice. The bigger value is everything that follows an incident: forensic investigators to work out what happened, attorneys to tell you your legal obligations, notification costs when customer data is exposed, lost income while you're down, and the labor to rebuild. Those costs stack up fast, and most of them land whether or not a ransom is ever paid.
It's also worth knowing where small-business claims actually come from. The headlines are all ransomware, but a large share of the claims I see start with a fraudulent wire or a business email compromise — someone tricked into sending money or credentials, no encryption involved. A policy that's strong on ransomware but weak on funds-transfer fraud can leave you exposed on the thing most likely to hit you. Read what's covered, not just the limit on the front page.
And coverage is conditional. What you actually collect depends on the policy limits, the exclusions in the fine print, and — critically — whether the answers on your application matched reality. A policy is a contract, not a guarantee. Treat it like one.
Why the application got so hard
A few years ago you could get a cyber policy by checking a couple of boxes. Now the questionnaire wants proof of multi-factor authentication everywhere, endpoint detection and response, monitored and tested backups, a patching cadence, and employee security training. Owners ask me whether this is a cash grab.
It isn't. The industry is finally forcing businesses to put in place the controls they should have had all along. None of those requirements are exotic — they're the basics. An insurer doesn't want to write a policy on a building with no locks on the doors, and cyber insurance has caught up to the same logic. The uncomfortable part for a lot of businesses is that the application now doubles as a security audit, and it surfaces gaps the owner didn't know were there.
So do you actually need it?
This is a business decision, not a moral one. The honest way to answer it: figure out what a serious incident would cost you, then ask whether you could absorb that out of pocket. Forensic investigators, attorneys, customer notifications, weeks of lost income, recovery labor, and possibly a ransom or a fraud loss — added together, for most small businesses that number is well past what they could write a check for.
For a growing number of businesses the decision is already made for them. Clients are writing proof of cyber coverage into contracts, and some lenders and larger partners now ask for it before they'll work with you. If that's your situation, the question isn't whether to carry a policy — it's whether your security can support the one you're being asked to hold.
When the answer is “no, we couldn't eat that,” appropriate coverage is worth carrying. Not as a substitute for security — alongside it. The businesses that come out of an incident in one piece are the ones that had both.
Why businesses get denied or stuck at renewal
The most common reason a renewal goes sideways: the security controls didn't keep pace with what the application demands. MFA isn't turned on everywhere. Endpoint protection is thin. Backups exist but were never tested. There's no documented offboarding process, so a terminated employee's access lingers for weeks. Insurers price risk around the safeguards you actually have — thin controls mean a higher premium, a lower limit, or a decline.
The other trap is answering the questionnaire based on what the owner assumes is happening rather than what can be verified. If you attest to MFA everywhere and a breach investigation later shows it wasn't, that's not just an awkward conversation — it can void the claim. Answer the application against what you can prove, not what you hope is true. If you're not sure, that uncertainty is itself the finding, and it's better to know now.
Where it's oversold, and where it earns its keep
Cyber insurance gets oversold when someone pitches it as protection against having an incident. It isn't. It won't stop a phishing email, ransomware, or an account takeover. Anyone selling it as prevention is selling the wrong thing.
Where it genuinely earns its place is the morning after — when a real incident hits and you suddenly need specialists, legal guidance, funding for recovery, and someone to help manage the response while you're trying to keep the business running. The strongest setup is simple: strong security to cut the odds of an incident, and insurance to cut the financial damage when those controls fail. One reduces the chance; the other reduces the cost. You want both.
If you're not sure your current security would stand up to your insurer's questionnaire — or you'd rather find the gaps now than during a claim — that's a conversation worth having before your next renewal.
