Cyber security
Will your cyber insurance actually pay out?
Only if the things you told the insurer you were doing were actually happening on the day you got hit. Your policy schedule lists them: multi-factor authentication, patching, endpoint protection, training, an incident response plan. If one of them was not true, a claim can be refused outright rather than reduced.
Only if you were doing the things you said you were doing. That is the whole of it.
Your policy has a schedule, and the schedule lists what you told the insurer was in place when you took the cover out. If you have a breach, one of the first things an insurer does is check whether those things were true on the day. If one of them was not, the claim can be refused. Not reduced, refused.
We are not insurance brokers and this is not advice on your policy. Your broker and the wording itself are the authority. What we can tell you is which line items on a typical schedule are the ones businesses get wrong.
What is usually on the schedule?
The list varies by insurer, and most of them include some version of:
- Multi-factor authentication on all remote access and all email accounts, and increasingly on all privileged accounts as well.
- Security updates applied within a defined window, often fourteen or thirty days for critical ones.
- Endpoint protection deployed on every device.
- Backups taken at a stated frequency, with at least one copy separated from the main environment.
- Security awareness training for staff, on a stated schedule.
- A documented incident response plan.
- Sometimes a defined process for verifying changes to payment details.
Read as a list, none of that is unreasonable. Read as a set of warranties you have given, it is a set of things somebody will check line by line at the worst possible moment.
Which one catches people?
Multi-factor authentication, and specifically the word "all".
The declaration usually says all accounts, or all email accounts, or all remote access. What businesses actually have is multi-factor authentication on most accounts, with a handful of exceptions that were made years ago for practical reasons and never revisited. The shared mailbox. The account a piece of software signs in with. The director who found it annoying. The global administrator account somebody set up during a migration.
Every one of those is a gap between what the schedule says and what is true, and the second one is the one an attacker uses.
The other common one is training. "Annual security awareness training" is easy to agree to and easy to let slide in a busy year, and it is trivially checkable after the fact, because either there are records or there are not.
Why do so many businesses never read it?
Because there are a lot of hats to wear when you run a small business, and insurance is the one you put on for an afternoon each year.
Most small firms I talk to bought the policy, put it in a drawer, and assumed they were covered. That is a completely understandable thing to have done. It is also the reason the first time anybody reads the schedule properly is often after something has happened, which is the worst possible time to discover a mismatch.
How do you check it in half an hour?
- Find the policy and open the schedule. Not the summary at the front. The actual list of what you have warranted.
- Go through it line by line with whoever handles your IT. Ask for evidence rather than reassurance. "Yes, MFA is on" and "here is the report showing every account with its status" are different answers.
- Write down anything that is not currently true. That is your gap list, and it needs closing before renewal, not after a claim.
- Check the reporting obligations while you are in there. Most policies require notification within a set period, and a delay can be its own problem.
For most businesses that exercise produces two or three items, and most of them are configuration rather than money. Switching multi-factor authentication on is free.
The bit worth saying plainly
The insurance is there to catch you when something goes wrong. It only works if the safety net you described to the insurer is the safety net you actually have.
That is also why this is worth doing even if you never claim. Every item on that schedule is something you would want to be true anyway. The policy just turns it into a list somebody else will check, which for a lot of businesses is what finally gets it done.
If you want the evidence side of it handled properly, that is most of what our Secure level is for: multi-factor authentication enforced rather than requested, Bitdefender endpoint protection with 24 hour monitoring behind it, patching you can show a report for, and security awareness training included rather than bought separately. The full list and what it costs is on the pricing page, and the detail sits on the cyber security page.
Most of the same controls are also what Cyber Essentials asks for, so if you are doing one you are most of the way through the other.
If you would like somebody to sit down with your schedule and tell you which lines are currently true, get in touch. It is half an hour and you will know where you stand.
Questions
The questions people ask us about this
Where do we find the schedule?
It comes with the policy documents, usually as a separate section rather than in the summary at the front. If you cannot find it, your broker can send it in a couple of minutes.
What if we find something on the list that is not true?
Fix it before renewal rather than after a claim, and talk to your broker about whether the current wording needs correcting in the meantime. Most of the items on a typical schedule are configuration rather than spending.
Is Cyber Essentials the same list?
It overlaps heavily. Multi-factor authentication, patching, malware protection, access control and secure configuration appear in both, so work done for one usually counts towards the other.