There's a story circulating in MSP communities that should make every IT admin and small business owner uncomfortable: a managed service provider lost their cyber insurance policy after 11 years — not because of a breach, not because they filed too many claims, but because of a minor service scope discrepancy the insurer decided violated policy terms at renewal. Eleven years of premiums. Gone.
If you think your long-standing relationship with your insurer protects you, think again. The cyber insurance market has fundamentally changed, and the consequences of getting caught without coverage during an incident are severe.
The Threat Landscape Is Forcing Insurers to Tighten Controls
Insurers aren't tightening requirements arbitrarily. They're responding to a measurable increase in claim frequency and severity driven by increasingly professional threat actors.
According to The Hacker News, the DevMan Ransomware-as-a-Service portal now centralizes payload builds, victim management, and affiliate payouts — essentially a turnkey ransomware business that lowers the barrier to entry for attackers and dramatically increases the volume of incidents hitting small businesses. When more businesses file claims, insurers respond by scrutinizing what controls were in place before they pay out.
The operational damage is real. A ransomware attack recently disrupted a Japanese frozen-food chain, halting logistics and production — exactly the kind of business continuity catastrophe cyber insurance is designed to cover. But coverage only pays when the policy requirements were met before the incident occurred.
And the threat vectors keep expanding. According to The Hacker News, Cl0p affiliates are actively targeting internet-exposed PTC Windchill and FlexPLM installations with unauthenticated remote code execution. If your policy requires you to maintain patched, non-internet-exposed systems and you haven't done that, you may be handing your insurer a reason to deny your claim.
Even the act of filing a claim has become dangerous. The Hacker News reports that CTM360 research has uncovered how insurance-sector phishing has evolved into real-time account hijacking operations — attackers are now intercepting insurance interactions to steal credentials and redirect claim payments. The entire insurance process, from application to claim, is now an attack surface.
What Insurers Are Actually Checking at Renewal
Most small business owners signed their cyber policy during a 20-minute application process and haven't looked at it since. That was fine in 2019. It's not fine now.
Here's what modern cyber liability policies increasingly require — and what underwriters are verifying:
Multi-Factor Authentication (MFA) — Not just on email, but on remote access tools, VPNs, and privileged accounts. Policies that previously accepted SMS-based MFA are now specifying app-based or phishing-resistant MFA. If you haven't addressed this yet, our post on SMS MFA deprecation and what small businesses need to do before Microsoft's September 2026 deadline is required reading before your next renewal.
Endpoint Detection and Response (EDR) — Basic antivirus is no longer sufficient. Many policies now explicitly require EDR on all endpoints. "We have Windows Defender" may not satisfy this requirement depending on how your policy defines EDR.
Patching and Vulnerability Management — Policies increasingly include language requiring timely patching of critical vulnerabilities. If Cl0p is exploiting unpatched business software and your insurer finds out you were running a vulnerable version at the time of your incident, expect a coverage dispute.
Backup and Recovery Controls — Offline or immutable backups are frequently specified. A backup that ransomware can reach and encrypt won't satisfy this requirement.
Incident Response Plan — Some policies now require a documented IR plan. "We'd call our IT guy" is not a plan.
Access Controls and Privilege Management — Least-privilege access, separation of duties, and offboarding procedures. If a former employee's credentials were used in a breach, insurers will ask whether you had proper offboarding controls. Our employee offboarding security checklist walks through exactly what needs to happen when someone leaves.
The Renewal Trap: Attestation Without Verification
Here's where small businesses get hurt. Most renewal applications ask you to attest that controls are in place. You check the boxes based on your best understanding. But if you haven't actually verified your environment recently, you may be attesting to controls that have drifted, been misconfigured, or were never fully implemented.
This is called a material misrepresentation, and it gives insurers grounds to deny claims even after you've paid premiums for years.
The fix is to verify before you attest — not after an incident. That means running an actual scan of your external attack surface, auditing your MFA enrollment, confirming your EDR is deployed and reporting, and testing your backup restores. As we covered in our guide to vulnerability scanning vs penetration testing, a vulnerability scan is often the right starting point for exactly this kind of pre-renewal verification.
A Pre-Renewal Checklist for IT Admins
Before you sign your next renewal application, work through this list:
- Pull your current policy and read the security controls section — not the summary, the actual policy language.
- Inventory your MFA coverage — every user, every application, every remote access point.
- Run a vulnerability scan on your internet-facing systems and review open findings against your policy's patching requirements.
- Audit EDR deployment — confirm every endpoint has a reporting agent and that alerts are being reviewed.
- Test a backup restore — not just confirm backups are running, but actually restore a file or system.
- Review your offboarding log — confirm all departed employees and contractors have had access revoked.
- Document your IR plan — even a one-page procedure satisfies most policy requirements.
- Talk to your broker — ask specifically what the underwriter will verify this year that they didn't verify last year.
Don't wait until the renewal form arrives. By then you have days, not weeks, to remediate findings.
Take Action
Cyber insurers are now enforcing the controls they've been listing in policies for years. The businesses that get caught are the ones that assumed nothing had changed.
Before your next renewal, run a scan. Know what your external attack surface looks like. Know what a motivated attacker — or a motivated underwriter — would find.
Oscar Six Security's Radar gives small businesses and IT admins an affordable, straightforward way to verify their security posture before renewal season. At $99 per scan, it's a fraction of what a denied claim or a lapsed policy will cost you.
Focus Forward. We've Got Your Six.