Most cyber insurance policies have a schedule. The schedule lists the things you have told the insurer you are doing. Multi-factor authentication on all accounts. Regular patching. Endpoint protection. A documented incident response plan. Security awareness training.
If you have a breach, the first thing the insurer does is check whether you were actually doing those things on the day you got hit.
If you were not, the claim can be refused. Not reduced. Refused. And a lot of small businesses have never read their own schedule, because there are a lot of hats to wear when you are running a business and it went in a drawer the day it arrived.
This is why every completion, every enrolment and every simulation result is logged and kept. Not because reports are interesting, but because “we run security awareness training” is a claim, and the audit trail is the proof. Go and read your schedule. If training is on it, you need to be able to show it.
The insurance is there to catch you when something goes wrong. It only works if the safety net you described is the one you actually built.