Why the insurance form feels like a foreign language

Your cyber insurance renewal arrives with a questionnaire. It asks about multi-factor authentication, endpoint protection, backups, email filtering, privileged access, and “security awareness.” You run a real business—appointments, invoices, trucks, patients, jobs—not a security department. The form still has to get answered, or the quote jumps, coverage shrinks, or the application stalls.

Insurers are not trying to trick you. They are asking, in their words, whether the basics that stop common losses are actually in place. This article translates the usual checklist into plain English for local owners in Henderson and across the Southwest: computers, email, passwords, backups, Wi‑Fi, viruses, and who handles IT when something breaks.

If you already work with a managed IT provider or a managed cybersecurity team, many of these answers should be easy. If nobody owns the setup, the form is a useful wake-up call—not just paperwork.

What they usually mean by “multi-factor authentication” (MFA)

They mean a second step at sign-in for important accounts—especially Microsoft 365 / Outlook email, remote access, and admin logins. A password alone is not enough. The second step is often a phone prompt, an authenticator app, or a hardware key.

What insurers care about in practice:

  • MFA is on for company email (not “we talked about it”)
  • Admin accounts require MFA
  • Former employees cannot still sign in
  • You can say who turned it on and who checks that it stays on

If half the staff still logs in with only a password, the honest answer is “partial”—and that is better than claiming “yes” and inventing details later.

Antivirus / “endpoint protection” on each computer

They want protection installed and current on the machines people use for work—laptops, desktops, and any small servers. A free consumer trial that expired last year does not count. Neither does “Windows Defender is probably on.”

A usable answer sounds like: every business computer has company-managed protection, updates are applied, and someone can show a list of devices. When insurance asks “do you have antivirus?” you want a yes you can prove. That proof is part of everyday managed IT, not a special project.

Email security and phishing

Most small-business money loss still starts in the inbox: fake invoices, fake “CEO” wire requests, links that steal Microsoft 365 passwords. Insurers ask about email filtering, spam controls, and whether people get any training on spotting scams.

Plain-language translation:

  • Business email is not a personal Gmail free-for-all for company money
  • Basic filtering is on (Microsoft 365 has tools; someone must turn them on and keep them sane)
  • Staff know to slow down on money moves and password resets
  • You have a plan when Outlook starts sending weird messages

You do not need a corporate training portal with badges. You do need habits and settings that cut the easy wins for attackers. For the Microsoft side of that work, see our notes on Microsoft 365 security.

Backups (and the question they really care about)

The form often asks: Do you back up critical data? How often? Are backups tested? Can you restore after ransomware?

“Files are in OneDrive” is not automatically a complete answer. Cloud sync helps collaboration. A tested backup is what you use when a computer dies, someone deletes a folder, or ransomware encrypts files. Insurers want to know you can get back to work without paying a criminal.

Be ready to say what is backed up (email, shared files, accounting, line-of-business data), how often, where copies live, and when you last tried a restore. If you have never tested a restore, say so—then schedule one. Untested backups are hopes, not plans.

Passwords, admin access, and “privileged accounts”

Fancy wording aside, they want to know that not everyone is an admin, that shared passwords are rare, and that the person who left last month is not still in the Microsoft 365 admin center. Sticky notes on monitors and one shared Outlook login for the whole office are the opposite of what underwriters like.

Practical picture they are looking for:

  • Each person has their own account
  • Admin rights are limited
  • Password changes happen when someone leaves
  • You know who can change billing, domains, and user access

Updates, Wi‑Fi, and the office network

Questions about “patch management” mean: do Windows and apps get updated on a schedule, or only when something already broke? Questions about firewalls and Wi‑Fi mean: is guest Wi‑Fi separate from business Wi‑Fi, and did anyone change the router password from the factory default?

Local shops get burned by old routers, open guest networks mixed with business traffic, and machines months behind on updates. You do not need a network diagram for the board. You need someone who owns the office Wi‑Fi, printers, and updates as part of normal support.

Who manages IT—and can you prove it?

Insurers increasingly ask who provides IT and security support. “My cousin” or “we figure it out” raises eyebrows. A named provider with a phone number, a written scope, and records of MFA, protection, and backups makes the application smoother.

Keep a one-page snapshot: users, computers, MFA status, backup summary, protection status, and who to call. That is the same packet that helps with picky customers and bank questionnaires. Our companion piece on what a small business actually needs from an IT company covers that day-to-day picture.

Training and “policies” without the binder theater

When they ask about security awareness training or written policies, they usually want evidence that people have been told not to wire money from a surprise email, and that you have a few simple rules: how passwords work, who approves money moves, what to do if email looks hacked.

A short written set of rules beats a 40-page policy nobody reads. If you have neither, start with money-move verification and MFA—then expand.

How to answer without guessing

Walk the form with whoever actually manages your computers and Microsoft 365. Answer honestly. If a control is missing, note the plan and date. Underwriters prefer a clear gap with a fix over a confident fiction. If you need help translating the form into a real setup, contact us—PrimeTech helps Southwest owners turn insurance questions into a checklist that matches how the shop actually runs.

FAQ

Will cyber insurance pay if we skipped MFA?

Every policy is different, and we are not your broker or lawyer. Many carriers expect MFA and other basics. Weak controls can mean higher premiums, exclusions, or fights after a claim. Ask your broker what your application promised—and make the setup match.

Is OneDrive enough for the backup question?

Sometimes it is part of the answer; rarely is it the whole answer. Say what is protected, how versions work, and whether you have tested getting files back after a bad day. If accounting data or a line-of-business system sits elsewhere, include that too.

Do we need overnight monitoring to get coverage?

Most small shops do not. Insurers care more about MFA, email safety, protection on each computer, updates, and backups you can restore. Fancy monitoring language without those basics is not a substitute.

Who should fill out the form—the owner or IT?

The owner (or office manager) should own the answers, with IT providing facts. Sign only what you believe is true. If IT cannot show MFA or backups, that is the finding—not a reason to invent a yes.

How often should we revisit the checklist?

At each renewal, after a big hire wave, after a ransomware scare, and whenever you change IT providers. The form is a snapshot. Your setup should stay true between snapshots.

Need help turning the insurance form into a real checklist?

PrimeTech helps local businesses in Henderson and across the Southwest answer cyber insurance questions with plain-English IT: MFA, email, backups, protection on each computer, and clear ownership—no buzzword theater.

Book a 15-Minute Call →  Managed IT  Managed Cybersecurity  More Insights