Knowledge base

August 17, 2026

Cyber Insurance: The Five Requirements That Determine Whether Your Claim Will Be Approved

More and more small and medium-sized businesses are taking out cyber insurance. That’s a wise move. But a policy is a contract, and that contract contains requirements that your organization must demonstrably meet. The premium is collected punctually every year; whether the coverage actually works only becomes clear at the worst possible moment: when a claim is filed.

That’s the part of cyber insurance that almost no one talks about. It’s not whether you should have a policy, but whether the policy you have will actually do what you expect it to.

In this blog, you’ll learn about the requirements that virtually every cyber insurance provider has in common, two real-life stories about what went right and what went wrong, what’s often excluded from coverage, and the best order in which to set up your security measures and insurance policy.

The five requirements that virtually every insurer has

The questionnaires and policy terms vary by insurer, but five requirements are common to virtually all of them: multi-factor authentication for every account, a tested backup with a copy stored off your network, active patch management, security awareness training for employees, and a ready-to-use incident response plan.

The word that usually appears in the terms and conditions is “demonstrable.” A measure that is implemented in practice but not formally documented will not be taken into account during a claim assessment. That distinction—between “implemented” and “demonstrable”—is what the rest of this blog is about.

The claim that was rejected

A business owner showed us his rejection letter. Ransomware, days of downtime, significant damage. He had cyber insurance, which he had paid for diligently every year. The insurer denied the claim: the policy terms required MFA for all accounts, and it wasn’t enabled on two old administrative accounts. The attackers gained access through one of those accounts.

The painful lesson lies not in the rejection itself, but in the moment it became apparent. The policy had been in effect for years without anyone comparing its terms to the actual environment. Forgotten management accounts are a classic example of this: they fall outside the scope of the day-to-day workplace and, for that very reason, outside the MFA rollout.

That’s exactly what you can check without an appointment. Our free Tenant Check at tenant.alta-ict.nl scans your Microsoft 365 environment and shows, among other things, your MFA coverage and your administrator accounts. Let’s be clear from the start: the check doesn’t identify or resolve any issues, it doesn’t store any of your data, and it doesn’t replace the assessment required under your specific policy terms. But it would have revealed the forgotten admin accounts mentioned in this story.

Same company, different premium

When renewing their policy, a customer was offered a significantly higher premium. The insurer’s reason: the risk profile was not sufficiently substantiated. In other words: they couldn’t tell whether the security measures were adequate, so they assumed the worst-case scenario.

We filled out the questionnaire again, this time with evidence from the existing environment: MFA coverage from Entra, backup test results with dates and outcomes, patch status per workstation, and participation in the awareness training. Nothing new was built; the only difference was that it was now verifiable. The surcharge was dropped.

That’s how the market works: insurers price what they can’t see as a risk. Those who provide proof are assessed differently than those who make promises.

What Is Often Not Covered

When the payment request was sent from the airport, several readers asked the same question: If that money had actually been transferred, would the insurance have covered it? Often not. Social engineering and fraud in which an employee makes the payment themselves are excluded or only partially covered under many cyber insurance policies. The insurer’s reasoning: nothing was hacked; someone was tricked. That’s a different risk—and often a separate coverage module.

The lesson: When purchasing a cyber insurance policy, don’t just read what’s covered—focus especially on what’s excluded. And protect against those exclusions with measures that actually work: a payment process that includes two-factor authentication, and training so that employees can recognize these threats.

Why Your Policy Shouldn’t Be an Open Document

Something few business owners know: After a breach, ransomware groups actively search for insurance documents. If they find a cyber insurance policy that lists the insured amount, they’ll base their ransom demand on that figure. Your coverage becomes your price tag.

Insurance without proper security doesn’t make you any safer; it makes you a target with a known budget. The solution lies in the basics: anyone who has a tested backup separate from the network can recover without paying. Then the policy is what it’s supposed to be: a safety net for residual damage, not a bargaining chip for the attacker. And store the policy yourself where not everyone can access it.

The order: first the basics, then the policy

“What should I take care of first, security or insurance?” is a question we’re often asked, and the honest answer is: in that order. An insurance policy covers damages; it doesn’t prevent anything, doesn’t fix anything, and doesn’t wake anyone up in the middle of the night. The measures that insurers require both reduce the likelihood that you’ll ever need the policy and determine the premium you’ll pay for it.

So the sequence isn’t a choice between two options, but a step-by-step process: get the basics in order, document the evidence, and then choose a policy that matches the remaining risk.

One set of evidence, three parties

Furthermore, the evidence your insurer requests is not exclusive to the insurer. Major clients ask for the same measures in supplier assessments, and the Cybersecurity Act requires organizations subject to it to demonstrate the same foundation. Those who set up their workplace so that every measure automatically provides evidence can answer three questions with a single file: MFA reports, backup test results, patch status, training participation, and the incident response procedure.

ALTA-ICT’s Position on This Matter

To be clear: we do not sell insurance and do not provide advice on policies or insurers; that is your insurance advisor’s job. What we do is the other side of the table: we set up your workplace so that every measure is documented and verifiable, allowing you to answer your insurer’s questionnaire with proof rather than promises. We base our work on our own certification for ISO 27001:2023, ISO 9001:2015, and NEN 7510:2024, so we know from our own audits exactly how evidence should be presented.

Frequently Asked Questions

Can an insurer really deny my claim even though I’ve always paid my premiums?

Yes. An insurance policy is a contract with terms and conditions, and those terms are assessed when a claim is filed. If your living environment did not demonstrably meet the requirements at that time, the insurer may deny the claim or reduce the payout.

Which requirement is most often overlooked in practice?

MFA on all accounts, with forgotten administrative and service accounts being the classic exception. The rollout covers everyday workstations, yet the accounts with the most privileges are left out.

Is CEO fraud covered under a cyber insurance policy?

Often not covered or only partially covered: Fraud in which an employee makes the payment themselves is typically excluded from many policies or covered under a separate module. Check your own policy terms and conditions, and mitigate the risk organizationally by implementing a verification process.

Does good security result in lower premiums?

Insurers assess the risk profile based on what can be demonstrated. In practice, demonstrable measures lead to a more favorable assessment than a profile that the insurer cannot verify; how this affects the premium varies by insurer.

Does ALTA-ICT help with choosing an insurance policy?

No, we do not sell insurance or provide advice on policies. We provide the verifiable technical and organizational foundation required by the policy, as well as the documentation you need to complete your insurer’s questionnaire.

Conclusion

Cyber insurance is a sensible final step, but it is no substitute for security. The requirements in the policy terms are not just a bureaucratic hurdle: they are the measures you would want to implement anyway, and being able to demonstrate compliance is what gives them value to the insurer, the customer, and the law alike. Those who lay the groundwork first and document the evidence will know where they stand in advance, rather than finding out only after a claim is filed.

Would you like to know if your environment meets the Poli requirements? Schedule a short session with ALTA-ICT, and we’ll walk you through the five requirements together.

Want to know more?

Get in touch
Hero bij cyberverzekeringen: een polistoets met de vijf eisen die verzekeraars aantoonbaar op orde willen zien