Your outsourced IT department, serving NJ & NYC small businesses
North Jersey IT Insights

Cyber Insurance Requirements NJ Businesses Keep Failing, and How to Pass

Carriers stopped taking your word for it. Here are the six controls underwriters actually verify in 2026, and the documentation that gets applications approved.

A Bergen County accounting firm came to us last fall after their cyber insurance renewal jumped 40%, and the carrier attached a supplemental questionnaire with 47 yes/no questions. Their old policy had been issued on a one-page application. That's the shift in a nutshell: five years ago carriers asked if you had antivirus; today they ask for screenshots of your MFA configuration, the date of your last backup restore test, and the name of your EDR product.

We fill out these questionnaires alongside clients constantly. Below are the six requirements that appear on virtually every application we see, what "yes" actually has to mean, and where businesses get tripped up.

Requirement 1: MFA, and "almost everywhere" counts as no

Multi-factor authentication is the first question on every application, and it's where most denials start. Carriers want MFA on three specific surfaces: email accounts, remote access (VPN/remote desktop), and administrator accounts. The trap is the word "all." If 28 of your 30 mailboxes have MFA but two shared mailboxes don't, and you check "yes," you haven't just risked denial, you've given the carrier grounds to rescind coverage after a claim. Travelers famously sued a policyholder in federal court to void a policy over exactly this kind of misstatement, and underwriters have only gotten stricter since.

What passing looks like: a conditional access policy in Microsoft 365 that enforces MFA tenant-wide with zero exceptions, plus MFA on your firewall's VPN portal. Export the policy report; that's your evidence.

Requirement 2: EDR, antivirus no longer qualifies

Applications now ask for endpoint detection and response by name, and many list acceptable products. Traditional antivirus checks files against known signatures; EDR watches behavior, a Word document spawning PowerShell, a workstation suddenly encrypting hundreds of files, and can isolate the machine automatically. If your answer to "Do you have EDR deployed on all endpoints?" is the name of a consumer antivirus product, expect a denial or a premium surcharge. EDR runs roughly $5-$12 per endpoint per month and is included in any serious managed cybersecurity stack, there is no good reason to fail this one in 2026.

Requirement 3: Backups that are tested, offline-capable, and provable

The backup section has three sub-questions that matter: Are backups separated from your network (immutable or air-gapped, so ransomware can't encrypt them too)? Are they tested, meaning you've actually restored files, not just watched a green checkmark? And do they cover Microsoft 365 data, which Microsoft itself does not back up for you? A USB drive plugged into the server fails all three. We've watched an application get kicked back solely because the business couldn't name the date of its last restore test. Our backup and disaster recovery service logs every test specifically so that answer is never blank.

Requirement 4: Email filtering and anti-phishing controls

Since business email compromise drives more claim dollars than ransomware now, carriers ask about advanced email filtering, link protection, and attachment sandboxing, plus SPF, DKIM, and DMARC records on your domain. The DNS records are a 30-minute job that most NJ small businesses have simply never done. It's also one of the few requirements that helps you even if you never file a claim: proper DMARC stops criminals from spoofing your domain to your own customers.

Requirement 5: Security awareness training, on a schedule

"Do you provide security awareness training?" doesn't mean the lecture you gave at a staff meeting in 2023. Underwriters want a recurring program (typically monthly or quarterly modules plus simulated phishing tests) with completion records per employee. The platforms cost a few dollars per user per month. The records matter more than the platform: when a claim hits, the adjuster will ask whether the employee who clicked the link had been trained, and "yes, here's the log" changes the conversation.

Requirement 6: A written incident response plan

The newest addition to most applications. It doesn't need to be a 60-page binder, it needs to name who gets called first, how you isolate infected systems, where backups live, and who talks to the insurer, your attorney, and your customers. If you don't have one, start with our hour-by-hour ransomware response guide, it's effectively the skeleton of an IR plan, and you can adapt it to your business in an afternoon.

Why applications actually get denied

In our experience it's rarely one missing control. The common failure modes: answering "yes" optimistically and getting caught in underwriting; leaving questions blank (treated as "no"); having controls but zero documentation; and the renewal trap, coverage written loosely in 2022 that gets re-underwritten to 2026 standards, leaving the business scrambling with a two-week deadline. If a question is ambiguous, make your IT provider answer it with you. Guessing on a legal document that an adjuster will later scrutinize is how policies get rescinded after the breach, which is the worst possible time to discover you were never really covered.

How to document compliance so renewals take an hour, not a month

Keep a living "insurance evidence" folder: MFA policy exports, EDR deployment reports, backup test logs with dates, training completion records, DNS records, and the IR plan with its last review date. We maintain exactly this for managed IT clients, refreshed quarterly, so when the questionnaire arrives, it's a transcription job instead of a fire drill. It also pairs naturally with knowing what coverage costs you're offsetting; see our breakdown of what IT support actually costs in North Jersey for how the security tier prices out.

We help businesses across Bergen County and the rest of North Jersey close these gaps before the renewal date, not after. More guides live on the Setnom blog, or skip ahead and book a free gap assessment.

The underwriter's checklist

Can you answer "yes" (with evidence) to all six?

This is the core of every cyber application we've completed for an NJ business in the past year. One undocumented "yes" is all it takes to jeopardize a claim.

  • MFA enforced everywhere Email, VPN/remote access, and admin accounts, zero exceptions, policy export saved.
  • EDR on every endpoint A named EDR product with a current deployment report, not consumer antivirus.
  • Tested, isolated backups Immutable copies including Microsoft 365, with dated restore-test logs.
  • Email filtering + SPF/DKIM/DMARC Advanced filtering active and authentication records published on your domain.
  • Recurring awareness training Scheduled modules and phishing simulations with per-employee completion records.
  • Written incident response plan Named roles, isolation steps, and notification contacts, reviewed within the last year.
Get started

Pass your cyber insurance application the first time.

Book a free assessment and we'll map your current controls against what carriers actually require, then close the gaps and hand you the documentation before your renewal date.

Book Your Free IT Assessment

Tell us a little about your business and we'll be in touch within one business day.

No spam. No sales pressure. Just straight answers about your IT.

Call Now Get My Risk Score