The cyber insurance bar just moved. Here's what Michigan small businesses need in their IT stack to qualify before renewal season finds them unprepared.
TL;DR: Cyber insurance has shifted, without fanfare, from a purchase to an audit. Insurers aren't asking whether you have security tools anymore; they're asking for documented proof that those tools are configured, enforced, and tested. The small businesses getting denied or facing premium increases of 300% or more aren't the ones who skipped security entirely. They're the ones who thought what they had was enough, and found out at renewal time that the definition of "enough" had moved on without them.
Cyber insurance used to feel like a formality. You filled out a questionnaire, checked some boxes, paid the premium, and moved on. The assumption was that you'd operate responsibly and the insurer would be there if something went wrong. Nobody asked for screenshots. Nobody wanted to see your patch logs.
That era is over. Think about how flood insurance works in high-risk zones: you don't just pay a premium and hope for the best. You have to demonstrate that the house meets certain standards, that the foundation is sound, and that the risk is manageable. Insurers started applying the same logic to cyber coverage after spending several years paying out massive claims on businesses that had almost no security controls in place. The questionnaire got longer. The documentation requirements got specific. The bar moved.
For a lot of Michigan small businesses, that shift happened without anyone sending a memo. The controls that satisfied an underwriter two years ago may not satisfy one today. Premiums are rising, coverage is narrowing, and the businesses getting hit hardest aren't the ones who ignored security entirely. They're the ones who assumed their existing setup was still sufficient.
More than 73% of small businesses fail their cyber insurance assessments in 2026, according to consolidated industry data from cyber insurance brokers, facing either outright denial or premium increases that can exceed 300%. That's not an edge case. That's the new normal for businesses that haven't kept pace with what underwriters now require.
Most business owners don't find out their IT stack doesn't qualify until they're already at the renewal table. This post tells you what to look for before you get there.
Table of Contents
- Why Cyber Insurance Requirements Tightened (and Kept Tightening)
- The Core Controls Underwriters Now Require
- Documentation: The Part Most Businesses Get Wrong
- Not Every Business Faces the Same Bar
- The Connection Between Security Controls and Premium Cost
- How a Managed IT Partner Helps You Qualify
- The Best Time to Find Out You Don't Qualify Is Before You Apply
- Key Takeaways
- Frequently Asked Questions
Why Cyber Insurance Requirements Tightened (and Kept Tightening)
Cyber insurers don't raise the bar because they enjoy paperwork. They raise it because their claims data told them to.
For several years, insurers wrote policies for businesses with almost no security controls in place, and then paid out when those businesses got hit. Ransomware claims alone surged. Average payouts climbed past $1.85 million per incident. At some point, the math stopped working, and the industry responded the way any rational business would: by requiring the controls that actually prevent claims before agreeing to cover you.
What changed most noticeably is the shift from "do you have security tools" to "prove they're working." A firewall that hasn't been updated in two years, antivirus that was installed and never touched, backups that run every night but have never actually been tested: those used to satisfy an underwriter. Most of them don't anymore. The questionnaire got longer, self-attestation gave way to documentation, and businesses that assumed their existing setup still qualified found out otherwise at renewal.
The other thing that happened: carriers that kept losing money on small business policies either tightened their standards significantly or stopped writing them altogether. The market got smaller and more selective. Getting coverage now means demonstrating an active, maintained security posture to a carrier that has every reason to look closely. That's the environment your renewal is walking into.
The Core Controls Underwriters Now Require
These aren't suggestions. They're the controls carriers treat as non-negotiable before they'll quote a policy in 2026. If your IT stack can't demonstrate these, the conversation with your insurer gets short very quickly.
Multi-Factor Authentication (MFA): The First Box They Check
MFA is mandatory across all business accounts: email, financial software, VPNs, remote access tools, cloud storage, and every admin account in your environment. Not available. Not optional for some users. Enforced, with configuration screenshots or policy exports to prove it. No MFA equals no policy at most carriers. It really is that binary.
Endpoint Detection and Response (EDR): Not Antivirus
Basic antivirus doesn't meet the bar anymore. Underwriters want modern EDR that uses behavioral analysis to catch threats rather than matching files against a known-bad list. They'll ask for a coverage report showing what percentage of your endpoints are protected. "Most of them" isn't a satisfying answer.
Tested Data Backups: The Word "Tested" Is Doing a Lot of Work
You need backups. You also need proof that they actually restore. A backup log showing the backup ran is not the same as a restoration test log showing your data came back intact. Underwriters increasingly ask for the latter. Offline or immutable backups are the expected standard.
Documented Patch Management
A defined, documented policy for how and when security updates are applied, plus evidence it's being followed. Unpatched software is one of the most common entry points for attackers, and carriers know it.
Security Awareness Training
Annual employee training with documentation: completion rates, dates, and ideally phishing simulation results. "We talk about this stuff" doesn't satisfy an underwriter in 2026.
Incident Response Plan
A written plan that spells out who does what when something goes wrong, and evidence that it's been tested. It doesn't have to be elaborate. It has to exist.
Privileged Access Management
Admin rights restricted to the people who genuinely need them, documented, and separate from everyday user accounts. Underwriters want a list of privileged accounts and how access is controlled.
Documentation: The Part Most Businesses Get Wrong
Here's the thing that trips up a lot of otherwise well-prepared businesses: it's not enough to have the controls in place. You have to be able to prove it.
Most small businesses have done some version of the right things. MFA is enabled somewhere. Backups are running. Someone installed endpoint protection last year. But when the underwriter asks for configuration screenshots, restore logs, and training completion records, the answer is often a long pause followed by "let me check on that." That pause is expensive.
Carriers have moved away from self-attestation in a significant way. They want exports from your monitoring tools, not your word that things are configured correctly. They want restoration test logs, not backup success notifications. They want phishing simulation completion records, not a general statement that your team does security training. The documentation gap is where a lot of businesses that thought they were prepared find out they weren't. If you're not yet sure which controls you should have in place before worrying about documenting them, The Cybersecurity Checklist Michigan Small Businesses Keep Putting Off is a good place to start.
This is also where working with a managed IT provider genuinely changes the outcome. A good provider maintains documentation of your controls as a matter of course, because managing those controls is their job. When renewal time comes, the evidence is already organized and ready. The businesses that walk into renewal conversations prepared consistently qualify faster and pay less than the ones scrambling to produce records they should have had all along.
If you've never been asked to produce this documentation before, now is the right time to find out what you actually have.
Not Every Business Faces the Same Bar
The 73% failure rate is an average. Your number depends heavily on what your business does and who it serves.
Regulated industries face stricter requirements, and the more sensitive data you handle, the more closely underwriters scrutinize your controls. A Michigan accounting firm handling client financial records under GLBA faces a different conversation than a landscaping company with a customer database. A healthcare practice managing protected health information under HIPAA faces a different conversation still. Same insurer, same renewal process, very different expectations.
The practical categories worth knowing:
Healthcare and behavioral health face HIPAA requirements around encryption, access controls, audit logging, and a documented incident response plan. Underwriters treat these as baseline, not bonus points.
Financial services and accounting firms fall under GLBA Safeguards Rule requirements regardless of size. If you collect financial data, you're required to have a comprehensive information security program. Carriers verify this.
Legal and professional services handle privileged client data that's increasingly targeted. Underwriters pay close attention to access controls, file sharing protocols, and how the firm handles data from third parties.
Businesses with government contracts may face CMMC or NIST framework requirements depending on the nature of the work. Those frameworks have specific, documented requirements that go well beyond standard small business underwriting.
Even businesses that aren't formally regulated but handle significant customer data face increased scrutiny around data loss prevention and breach notification procedures. The takeaway isn't that some businesses have it harder than others. It's that building your security to meet the standard relevant to your industry protects both your coverage and your clients.
The Connection Between Security Controls and Premium Cost
This is the part most businesses don't realize until they're already at the renewal table: your documented security posture doesn't just determine whether you qualify. It determines what you pay.
Carriers treat security controls the same way health insurers treat lifestyle factors. The businesses that can demonstrate strong, documented protection consistently receive better terms than peers who can't show their work. That means lower premiums, broader coverage, and fewer exclusions buried in the fine print. The businesses that can't demonstrate it get the opposite: higher rates, narrower coverage, and in some cases riders that exclude the exact scenarios they're most worried about.
The savings are real. Businesses that meet the full underwriting checklist routinely save 20 to 40% on premiums compared to those that can't produce the documentation. Over several years of coverage, that's meaningful money, and it's money that stays in your business instead of compensating for gaps you didn't know you had.
There's also a compounding effect worth understanding. A business that gets denied or hits a significant premium increase in one renewal cycle carries that history into the next one. Insurers share application data, and a prior denial or non-renewal follows you. Getting ahead of the requirements isn't just about this year's policy. It's about not creating a problem that makes next year's conversation harder before it even starts.
How a Managed IT Partner Helps You Qualify
Most small businesses don't have the internal capacity to implement, maintain, and document all of this on their own. That's not a criticism. Unless you're running an IT company, you didn't get into business to manage security controls and audit trails. You got into business to do the thing you actually do, and IT is supposed to support that, not consume it. The controls underwriters require aren't complicated in concept, but keeping them current, documented, and audit-ready takes ongoing attention that most owners genuinely don't have time for.
A managed IT partner changes that equation. Not by doing something exotic, but by handling the work that needs to happen continuously in the background: deploying and enforcing MFA across your environment, managing EDR and patch schedules, maintaining tested backups, running phishing simulations, and keeping the documentation that proves all of it is actually working. When renewal time comes, the evidence package is already built. You're not scrambling. You're ready.
The right partner also knows what underwriters are looking for right now, because the requirements shift. What satisfied a carrier last year may not satisfy one this year, and a provider who's paying attention to the insurance landscape can flag those changes before they show up as a surprise at renewal. That's the difference between a vendor who keeps your systems running and a partner who keeps your business protected.
Mann IT works with Michigan small businesses that want to get ahead of their cyber insurance requirements rather than react to them. We help you build and document the security posture that carriers want to see, so that renewal season feels like a formality rather than a reckoning. Reach out for a no-pressure conversation about where your current setup stands and what it would take to get it audit-ready.
The Best Time to Find Out You Don't Qualify Is Before You Apply
Cyber insurance requirements didn't get stricter overnight, but they got here faster than most Michigan small businesses noticed. The controls that satisfied an underwriter two years ago may not satisfy one today, and the businesses finding that out at renewal are in a significantly worse position than the ones who found out on their own terms, fixed the gaps, and walked into the conversation prepared.
The broader shift happening right now is real and it isn't slowing down. Insurers have more data than ever about what security postures actually prevent claims, and they're pricing accordingly. The businesses that can demonstrate active, maintained, documented protection are being rewarded for it. The ones that can't are paying for it, sometimes in premiums, sometimes in denied coverage, and occasionally in the kind of incident that makes the whole conversation moot.
That's exactly the conversation Mann IT has with Michigan small businesses before renewal season, not after. We're based in Ann Arbor and we've helped clients go from "I think we're covered" to actually knowing they're covered, with the documentation to prove it. If your renewal is coming up or you haven't reviewed your security posture against current underwriting standards recently, that's worth a conversation before your carrier does it for you.
Reach out to Mann IT for a no-pressure assessment. Let's find out where you stand before your insurer does.
Key Takeaways
- Cyber insurance has shifted without fanfare from a purchase to an audit. Insurers now require documented proof that your controls are configured, enforced, and tested, not just installed.
- More than 73% of small businesses fail their cyber insurance assessments in 2026, according to consolidated industry data from cyber insurance brokers, facing outright denial or premium increases exceeding 300%.
- The seven non-negotiable controls underwriters now require are: enforced MFA, modern EDR, tested backups, documented patch management, security awareness training with completion records, an incident response plan, and privileged access management.
- Documentation is as important as implementation. Carriers want configuration screenshots, restoration test logs, and training records, not self-attestation. The gap between having controls and proving them is where most businesses get surprised.
- Your industry and data type determine your bar. Healthcare, financial services, legal, and businesses with government contracts face stricter requirements than general commercial businesses.
- Businesses that meet the full underwriting checklist routinely save 20 to 40% on premiums compared to peers who can't show their work. Getting ahead of requirements isn't just about qualifying. It's about what you pay once you do.
Frequently Asked Questions
1. How far in advance should I start preparing for cyber insurance renewal?
At least 90 days out is a reasonable minimum. If your controls have gaps, remediating them takes time, and some carriers ask specifically when controls were implemented. "We just did this because you asked" is not the answer that gets you the best terms. Getting ahead of it by a quarter gives you time to close gaps, build the documentation, and walk into the conversation from a position of strength rather than catch-up.
2. What happens if I'm denied cyber insurance coverage?
You're fully exposed to the financial fallout of a breach: recovery costs, legal fees, regulatory fines, notification expenses, and business interruption losses with no safety net. Denial also tends to follow you, since insurers share application history and a prior denial makes the next conversation harder before it starts. That's the version of this story worth avoiding, and it's entirely avoidable with the right preparation.
3. My insurer accepted my policy last year with the same controls. Does that mean I'm fine?
Not necessarily. Insurers update their requirements at renewal, not mid-term. Last year's accepted application run through this year's underwriting standards may look very different. If you haven't reviewed your security posture against current requirements recently, it's worth doing before your carrier does it for you, which is exactly what renewal season is.
Thursday, Aug 6, 2026