Buying the Policy Is Only Half the Job
Cyber insurance is one of the fastest-growing lines a business owner buys, and that growth makes sense. Roughly 49 percent of small businesses reported a cyberattack in 2026, and the average breach now costs about $254,000. The math is clear, and more owners are responding by adding a cyber policy to their coverage. That is the right move. But here is the part that gets far less attention: in 2026, more than 40 percent of businesses that filed a cyber claim walked away with no payout at all.
The number one reason is not buried in fine print. It is missing security controls. One analysis found that 82 percent of denied claims involved organizations that had not fully implemented multi-factor authentication. Not a complicated firewall configuration, not an obscure compliance standard. Multi-factor authentication, the kind where you confirm a login with your phone. For a lot of businesses, the difference between a paid claim and a denied one comes down to a setting that takes less than an hour to turn on.
What Carriers Are Looking for in 2026
The cyber insurance market has matured quickly, and underwriting requirements have followed. Five years ago, a business could answer a short questionnaire and get a policy without much scrutiny. That era is over. Carriers reviewing claims are now checking whether your actual security posture matches what your application said it was. If you said multi-factor authentication was in place on all accounts and it was only enabled on some, that discrepancy alone can be enough to void a claim.
Beyond multi-factor authentication, the controls most carriers now treat as baseline requirements include a written incident response plan, regular data backups stored offline or in a protected environment, endpoint detection and response tools on workstations, and employee training on phishing awareness. These are no longer extra credit. They are the price of admission, and the difference between checking a box on an application and actually having these in place is the difference that shows up when a claim is filed.
The Claims That Hit Small Businesses Hardest
Ransomware and business email compromise account for more than half of the cyber claims small businesses file. A ransomware event can freeze your operations entirely, locking you out of customer records, financial data, and the systems your team uses every day. The average cost of a ransomware claim involving business interruption has averaged $1.4 million over the past five years, roughly 650 percent higher than claims without it. That number is not a misprint. When an attack shuts your doors, the cost multiplies.
Business email compromise works differently but can be just as damaging. An attacker gains access to an email account, studies your communication patterns, and sends a convincing request to redirect a payment or share sensitive information. It does not require a sophisticated operation. It requires a convincing email and one employee who acts on it without a second verification step. The average loss per incident for small businesses is climbing, and these attacks are getting harder to spot because the technology behind them is improving faster than most teams can keep up.
How to Make Sure Your Policy Actually Pays
The most important step is to treat your cyber policy not just as a purchase but as an ongoing commitment. Confirm that your multi-factor authentication covers every account, not just the ones you use most. Make sure your incident response plan is written down and accessible, not just assumed. Run a backup test to make sure your data can actually be restored if you need it. And review your application annually to verify that the answers still reflect reality. Businesses grow, tools change, and a control that was in place last year may have slipped during a system update or a staffing change.
The second step is to read your policy with someone who can walk you through the exclusions. Some policies exclude social engineering losses unless a specific endorsement is added. Others have sublimits on ransomware that are far lower than the primary limit. Knowing what your policy actually covers before a claim happens is how you avoid a denial after one does. donegan can review your current cyber coverage and your controls side by side and tell you exactly where you stand.
Frequently Asked Questions
What is the most common reason cyber claims are denied?
Missing or incomplete security controls, particularly multi-factor authentication. Carriers verify that the controls described on your application are actually in place, and discrepancies between what was stated and what exists at the time of a claim are the leading cause of denials.
Does my general liability or business owners policy cover a cyberattack?
In nearly all cases, no. Standard general liability and BOP policies were not designed to cover data breaches, ransomware, or the costs associated with a cyber event. A dedicated cyber policy is necessary to cover breach response, legal fees, business interruption, and regulatory fines.
How often should I review my cyber insurance controls?
At least annually, and whenever your business makes a significant change to its technology environment. Adding new systems, changing vendors, or bringing on remote employees can all affect whether your controls still match what your policy requires.

