Cyber Insurance Claims Are Rising—and Small Businesses Are Increasingly at Risk
Nearly 50,000 Cyber Insurance Claims Were Reported in 2024 as Ransomware Continues to Hit SMBs Hardest
Nearly 50,000 cyber insurance claims were reported by U.S.-domiciled insurers in 2024—an increase of almost 40% in just one year, according to the National Association of Insurance Commissioners (NAIC). Even more striking, the number of cyber insurance policies in force remained essentially unchanged, meaning the sharp increase in claims occurred without a comparable increase in the number of policies.
At the same time, the cybersecurity threat facing businesses continues to grow. Verizon’s 2026 Data Breach Investigations Report (DBIR) analyzed more than 31,000 real-world security incidents across 145 countries, including more than 22,000 confirmed data breaches.
Ransomware was involved in 48% of all breaches analyzed, up from 44% the previous year.
And attackers are finding new ways into business networks. For the first time in the DBIR’s 19-year history, exploiting software vulnerabilities surpassed stolen credentials as the leading initial access method. 31% of breaches now begin with vulnerability exploitation—a 55% increase from the previous year.
For small business owners, the message is difficult to ignore:
Cyberattacks aren’t just a big-business problem, and having cyber insurance doesn’t eliminate the risk.
Cyber insurance can provide an important layer of financial protection following a covered cyber incident. But insurers also need to understand the risk they’re being asked to insure.
That means your cyber insurance application or renewal may include detailed questions about multi-factor authentication, endpoint protection, backups, email security, employee security training, patch management, network security, administrative access, and incident response.
Which raises an important question:
If your cyber insurance carrier reviewed your cybersecurity protections today, would your business be ready?
Why Cyber Insurance Companies Care About Your Cybersecurity
Your Insurance Application Is Really a Measure of Your Company’s Cyber Risk
Cyber insurance transfers some of the financial risk associated with a cyberattack to an insurance carrier. Before accepting that risk, the insurer needs to understand how your business is protecting itself.
That’s why today’s cyber insurance applications can look surprisingly similar to cybersecurity assessments.
The questions insurers ask aren’t arbitrary. Many directly address the techniques cybercriminals are currently using to compromise businesses.
The 2026 Verizon DBIR provides a good example.
31% of breaches now begin with exploitation of a software vulnerability. At the same time, the median time required to fully resolve a critical vulnerability was 43 days.
That means something as routine as patch management—keeping computers, servers, firewalls, VPNs, applications, and other technology current—can have a direct impact on your company’s cyber risk.
And patching is only one part of the equation.
An insurer may want to know:
- Is MFA protecting company email and critical accounts?
- Are computers and servers protected by modern endpoint security?
- Are security alerts actively monitored?
- Are critical business systems backed up?
- Are backups protected against ransomware?
- Are employees receiving cybersecurity awareness training?
- Are critical security updates being installed?
- Does the business have an incident response plan?
There’s also an important distinction between having a security product and having an effective security control.
A company might have MFA but discover that some accounts aren’t protected. It might have endpoint protection installed on most computers while several devices remain unprotected. Or backups may run every night without anyone knowing whether those backups can successfully restore the business.
Cyber insurance readiness isn’t simply about being able to check “Yes.”
It’s about being able to say:
“Yes. It’s in place. We know it’s working. And we can verify it.”
Small Business Cyber Insurance Readiness Checklist
1. Multi-Factor Authentication (MFA)
A Password Alone Is No Longer Enough
One of the first questions you may encounter on a cyber insurance application is whether your business uses multi-factor authentication (MFA).
MFA adds another layer of security beyond a username and password. That’s important because compromised credentials continue to play a significant role in cyberattacks.
But simply having MFA somewhere in your organization isn’t enough.
Employees may use MFA for Microsoft 365 while administrator accounts, remote access, cloud applications, or other critical systems remain protected by passwords alone.
Ask your IT provider:
- Is MFA required for every Microsoft 365 user?
- Is it enforced for administrator and privileged accounts?
- Does remote access require MFA?
- Which critical cloud applications are protected?
- Are there any accounts capable of bypassing MFA?
- Can you show me exactly which accounts are—and aren’t—protected?
Cyber Insurance Readiness Check
Can you verify that MFA is properly configured and enforced across your email, administrative accounts, remote access, and other critical systems?
2. Endpoint Protection, Detection and Response
Having Antivirus Doesn’t Necessarily Mean Your Computers Are Fully Protected
Every desktop, laptop, and server connected to your business represents a potential entry point for an attacker.
Traditional antivirus remains an important security layer, but modern threats can require greater visibility into what’s actually happening on a device.
Endpoint Detection and Response (EDR) continuously monitors protected computers and servers for suspicious activity that could indicate ransomware, malware, credential theft, or other malicious behavior.
But detection creates another important question:
Who is watching the alerts?
Managed Detection and Response (MDR) combines security technology with people and processes that monitor, investigate, and respond to potential threats.
Detecting suspicious activity at 2:00 a.m. isn’t very helpful if nobody sees the alert until the next morning.
Ask your IT provider:
- Is every desktop, laptop, and server protected?
- Are we using traditional antivirus, EDR, or another advanced endpoint security solution?
- Is protection centrally managed?
- Who receives and investigates security alerts?
- Is anyone monitoring threats outside normal business hours?
- Can we verify which devices are currently protected?
Cyber Insurance Readiness Check
Can you identify every device that should be protected and explain exactly what happens when suspicious activity is detected?
3. Data Backup and Recovery
Having a Backup Is Not the Same as Knowing Your Business Can Recover
Ask most small business owners whether their company’s data is backed up and they’ll probably answer:
“Yes, we have backups.”
But that’s only the beginning.
The more important question is:
“If ransomware encrypted our systems tonight, how quickly could we actually get the business running again?”
A backup is valuable only if it’s available, protected from the attack, and capable of being successfully restored.
Ransomware can actively search for accessible backups and attempt to encrypt or delete them. That’s why a strong backup strategy should include appropriate isolation, security, monitoring, retention, and regular recovery testing.
Businesses should know:
- What is being backed up?
- How frequently?
- Where are backups stored?
- How long are they retained?
- Are they protected from ransomware?
- Who monitors backup failures?
- When were they last tested?
- How long would a recovery actually take?
Microsoft 365 deserves attention too. Email, OneDrive, SharePoint, and Teams can contain years of critical business information. Businesses should understand what recovery capabilities their cloud services provide and whether additional backup protection is appropriate.
Then ask your IT provider one particularly revealing question:
“Can you show me the results of our most recent successful recovery test?”
Cyber Insurance Readiness Check
Do you know what is backed up, how it’s protected, when it was last tested, and how long it would take to recover your business?
If not, you may have backups—but you don’t yet know whether you have a recovery strategy.
4. Microsoft 365 and Email Security
Your Email Account May Be One of the Most Valuable Targets in Your Business
Think about how much information flows through your email.
Customer communications. Invoices. Contracts. Financial information. Password resets. Vendor relationships. Employee information. Wire instructions. Microsoft 365 documents.
Access to an employee’s email account can provide a cybercriminal with an extraordinary amount of information.
An attacker may impersonate a Microsoft 365 login page, pose as an executive requesting payment, send a fraudulent invoice, or compromise a legitimate mailbox and quietly monitor conversations until the right financial opportunity appears.
This is why Business Email Compromise (BEC) can be so dangerous.
There may be no obvious virus, ransomware screen, or computer failure to warn you that something is wrong.
Microsoft 365 provides important built-in security capabilities, but simply subscribing to Microsoft 365 doesn’t mean every available security control is appropriately configured for your organization.
Ask your IT provider:
- Is MFA enforced for every appropriate Microsoft 365 account?
- How are administrator accounts protected?
- What anti-phishing and anti-malware protections are enabled?
- Are we protected against impersonation and domain spoofing?
- Who monitors suspicious sign-ins and account activity?
- What happens if an employee’s Microsoft 365 account is compromised?
- When was our Microsoft 365 security configuration last reviewed?
Then ask:
“If an employee gave their Microsoft 365 password to an attacker today, what would stop that attacker from getting into the account?”
Cyber Insurance Readiness Check
Can you explain how your Microsoft 365 environment is protected and who is responsible for responding to suspicious activity?
5. Other Cybersecurity Controls Your Business Should Be Ready to Verify
Cyber Insurance Readiness Goes Beyond MFA, Backups and Endpoint Protection
The controls above are important, but they’re not the only areas your business should review.
Employee Security Awareness Training
Employees should know how to recognize phishing, fake login pages, fraudulent payment requests, suspicious links, and other common attacks.
Ask: Do employees receive ongoing cybersecurity awareness training, and can we document that it occurred?
Patch and Vulnerability Management
The 2026 Verizon DBIR found that 31% of breaches begin with vulnerability exploitation—a 55% increase from the previous year.
Ask: Do we have a documented process for identifying and installing critical security updates, and can we verify our systems are current?
Firewall and Network Security
Simply owning a firewall doesn’t mean your network is secure. Configuration, firmware, security services, remote access, VPNs, and wireless networks all require attention.
Ask: When was our firewall and network security configuration last professionally reviewed?
Administrative Access and User Controls
Not every employee should have administrator privileges. Access should also be promptly changed or removed when employees leave or change roles.
Ask: Can we identify everyone with administrative access and explain why they need it?
Incident Response Planning
If a cyberattack happens tomorrow morning, who calls your IT provider? Who contacts your insurance carrier? Who contacts legal counsel? Who manages recovery?
Ask: Do we have a written cyber incident response plan—and do the people responsible know what they’re supposed to do?
Cybersecurity Policies and Documentation
Your business may have good cybersecurity technology but little documentation explaining how that technology and the associated processes are managed.
Ask: If our cyber insurance carrier asked us to document our cybersecurity practices today, what could we actually provide?
The Most Important Question: Can You Prove It?
There’s a difference between saying:
“Yes, we have MFA.”
and demonstrating that MFA is properly enforced.
There’s a difference between saying:
“Yes, we have backups.”
and knowing those backups are protected, monitored, tested, and capable of restoring the business.
And there’s a difference between saying:
“Yes, our computers are protected.”
and verifying that every endpoint is protected and someone is monitoring the alerts.
Cyber insurance readiness isn’t about checking boxes. It’s about knowing that your cybersecurity controls are in place, properly configured, monitored, maintained—and verifiable.
You should be able to confidently answer three questions:
What cybersecurity protections do we have?
Are they actually working?
Can we prove it?
Cyber Insurance Readiness Requires More Than Technology
JK Technology Solutions Helps Identify the Gaps—and Document the Controls
This is where cybersecurity and compliance come together.
Your business may be asked to provide policies, procedures, assessments, training records, incident response documentation, or other evidence demonstrating how cybersecurity risk is managed.
JK Technology Solutions can help identify potential technical security gaps through our cybersecurity services.
But through our Compliance as a Service, we can also help businesses establish and maintain the policies, procedures, assessments, and supporting documentation needed to demonstrate their cybersecurity and compliance practices.
Depending on your organization’s requirements, that may include:
- Cybersecurity policies and procedures
- Security risk assessments and gap analyses
- Documentation of cybersecurity controls
- Incident response planning
- Employee security awareness documentation
- Risk remediation planning
- Ongoing compliance reviews
- Evidence supporting cyber insurance requirements
- Documentation supporting applicable regulatory and compliance frameworks
Instead of scrambling for documentation when an insurance application, customer, auditor, regulator, or contractual requirement demands it, your business can maintain an organized compliance program that evolves with your cybersecurity environment.
ONE PARTNER. THREE LAYERS OF PROTECTION.
Manage the technology. Protect the business. Document the controls.
MANAGED IT — MANAGE IT
Your technology is properly configured, monitored, maintained, patched, supported, and kept up to date.
CYBERSECURITY — PROTECT IT
Your users, devices, email, network, cloud environment, and data are protected with multiple layers of security designed to prevent, detect, and respond to cyber threats.
COMPLIANCE AS A SERVICE — DOCUMENT IT
Your cybersecurity policies, procedures, assessments, controls, remediation efforts, and supporting evidence are organized and documented so your business can demonstrate the protections and processes it has in place.
Would Your Business Pass a Cyber Insurance Readiness Review?
Find the Gaps Before Your Insurance Carrier—or a Cybercriminal—Does
Cyber insurance requirements vary by insurance carrier, policy, industry, and organization. No cybersecurity assessment or compliance program can guarantee that an insurer will issue coverage or that a future claim will be paid.
But your business can be better prepared.
JK Technology Solutions helps small and midsize businesses evaluate their cybersecurity environment, identify potential gaps, strengthen security controls, and develop the documentation needed to demonstrate the protections they have in place.
Our Complimentary Cyber Insurance Readiness Review can help evaluate:
- Multi-factor authentication
- Endpoint security and monitoring
- Microsoft 365 and email security
- Backup and disaster recovery
- Patch and vulnerability management
- Firewall and network security
- Employee security awareness
- Administrative access
- Incident response preparedness
- Cybersecurity policies and documentation
Don’t wait until you’re completing your next cyber insurance application—or responding to a cyberattack—to discover what’s missing.
Request Your Complimentary Cyber Insurance Readiness Review
Let’s find out where your business stands today—and what you may need to address before your next cyber insurance application or renewal.
[Schedule My Complimentary Cyber Insurance Readiness Review]
Cyber insurance coverage, underwriting requirements, and claim decisions vary by insurer and policy. JK Technology Solutions does not provide insurance or legal advice and does not guarantee eligibility for coverage or payment of a claim.