Cyber Insurance Readiness for MSP Clients

Last updated

Underwriting became a technical audit

Five years ago a client got cyber insurance by answering six yes/no questions. After the 2020–22 ransomware loss cycle, carriers rewrote the process: multi-page applications, external scans of the applicant's attack surface, and a short list of controls without which they will not write the policy. That list – MFA everywhere, EDR on every endpoint, immutable or offline backups, a patching cadence, email security, privileged access controls, security awareness training, and an incident response plan – is now the de facto SMB security baseline, and the carrier enforces it better than any regulator. For a typical SMB, a clean application means a premium of roughly $1,500–5,000 per year for a $1M limit; a weak one means a 40–100% increase, a ransomware sublimit of $100–250K with co-insurance, or a declination. Typical 2026 figures.

That is a sales lever no ROI spreadsheet can match: the client's own carrier tells them, in writing, to buy what you sell.

How the questionnaire works – and why a wrong answer voids the claim

The application is not a survey. Its answers become part of the policy, as warranties or representations the carrier relied on. If a claim investigation finds a material misstatement, the carrier can rescind the policy from inception. In the canonical 2022 case the insured checked "yes" to MFA on email and servers when MFA covered only the firewall; after a ransomware loss the carrier sued to rescind the policy and the insured agreed to rescission.

So every "yes" must be true for every user, every device, and every system the question covers, on the date of signing. "Mostly" is a "no." The common false positives are MFA (most users, with legacy authentication or a service account left open), EDR (workstations but not servers, or not the owner's home PC), and backups (running, never restore-tested, reachable with domain admin credentials). Read each question literally; where the honest answer is "no" or "partially," say so and attach a remediation date. Carriers price partial controls far better than they treat a rescinded claim.

The checklist mapped to what you deliver

Every application line maps to a service you already deliver:

  • MFA on email, remote access, and privileged accounts – conditional access, legacy authentication disabled, phishing-resistant methods for admins. Evidence: the identity platform's enforcement report; see identity and access for SMB.
  • EDR on all endpoints and servers, 24/7 monitored – managed EDR with an MDR service behind it. Evidence: console coverage reconciled against the asset list.
  • Immutable or offline backups, tested – a BDR design with an immutable copy, credentials separate from the domain, and a dated restore test with a recovery time. See the backup and DR process.
  • Patching cadence – critical patches within 14 days under a patch management schedule, end-of-life systems isolated or replaced. Evidence: the RMM's monthly compliance report.
  • Email security – filtering, anti-phishing policies, SPF/DKIM/DMARC at enforcement. Evidence: DMARC report and policy export.
  • Privileged access controls – separate admin accounts, no standing local admin for users, a PAM tool or just-in-time elevation. Evidence: admin account inventory.
  • Security awareness training – quarterly at minimum, with phishing simulations. Evidence: completion and click rates.
  • Incident response plan – written, carrier contacts in it, exercised annually. Evidence: the plan and a tabletop date. See the incident response process.

Vendor choices for each line are in the client security stack guide. What matters here is the evidence column: a control you cannot document is, to an underwriter, a control you do not have.

Packaging readiness as a service

Two workable formats. The first is a fixed-price readiness assessment – typically $1,500–5,000 by client size – delivered 90 days before renewal: run the application line by line, mark each control green, amber, or red, collect evidence for the greens, and quote remediation for the rest. It is a gap assessment with a deadline, and the deadline is what closes it.

The second is to fold readiness into the managed agreement: every client on your baseline stack is insurance-ready by design, and the annual review becomes a scheduled QBR deliverable. This is the stronger model: controls are always on rather than stood up under pressure, and the baseline becomes non-negotiable for a reason the client's CFO already accepts.

Either way, require the client to carry cyber coverage in your MSA, and treat any declined control as a signed risk-acceptance letter – the document that later explains to their carrier, and your lawyer, why the control was absent. See MSP contracts and MSA.

Your own exposure

Three things put the MSP in the claim's blast radius. First, attestations. If you sign the application, or fill it in for the client to sign, and an answer is wrong, you made the misstatement – and the carrier's subrogation counsel and the client's lawyers will both look at you. The hard rule from broker guidance and channel consensus: supply the facts in writing, with evidence, and have the client's officer sign. Never sign, and never answer a question you have not verified in a console that day.

Second, the carrier increasingly asks about you: does the MSP enforce MFA on its own tools, is its remote access locked down, does it carry E&O and cyber coverage. A weak answer raises the client's premium and surfaces in their next vendor review; see securing your MSP.

Third, your own E&O and cyber coverage and the liability caps in your MSA stand between a rescinded client claim and your balance sheet; costs are in legal setup and insurance.

Running the annual renewal cycle

Renewal is predictable. Calendar every client's policy expiry the day you learn it, then work backwards:

  • T-120 days: re-run the checklist against the broker's current application – forms change every year. Quote and schedule remediation.
  • T-90 days: remediation complete, evidence pack assembled, restore test and IR tabletop done within the last twelve months.
  • T-60 days: sit with the client while they complete the application. Answer from evidence, not memory. The client signs.
  • T-30 days: the broker markets the risk. Answer underwriter follow-ups fast – an exposed RDP port on the carrier's scan can hold up binding.
  • Post-binding: file the policy, signed application, and evidence pack in the client's documentation. Put the carrier hotline, policy number, and mandatory panel vendors into the incident response plan.

Track one metric across the book: the share of clients with every control green 90 days before renewal. It predicts next year's security revenue and incident risk better than any other number you hold.

Bottom line

Cyber insurance underwriting is now the most effective security mandate your clients face, and its checklist is your baseline stack line for line. Map each question to a delivered control with dated evidence, package the review as a fixed-price assessment or a built-in annual deliverable, and run every renewal on a 120-day clock. Fill in the facts, never sign the form – a wrong answer voids the client's claim and puts you in the lawsuit – and keep your own shop clean enough for the vendor questions on the same form.