Key takeaways
Cyber insurance has two main categories: first-party and third-party. First-party coverage pays for what your business absorbs—incident response, data recovery, business interruption, and ransom payments. Third-party coverage pays for legal fees, fines, and claims from affected customers or vendors.
Qualification depends on provable controls. Insurers expect MFA, an incident response plan, identity and access management, tested backups, EDR, patching, and employee training. MFA is now a baseline condition on most applications.
Documentation often decides the outcome. Underwriters review incident history, policies, and training records. A strong security program can still be declined if the evidence behind it is thin.
Match coverage to your risk. Policies differ on liability, extortion, business interruption, and regulatory exposure. Check sublimits and whether supplier or cloud incidents are included.
Qualification is ongoing. Insurers reassess at renewal and are moving toward continuous posture evaluation, with growing interest in passwordless authentication and device health monitoring.
What is cyber insurance?
Cyber insurance is a policy that helps businesses cover the costs of responding to and recovering from a cyberattack or data breach. Coverage typically includes first-party costs the business itself incurs, plus third-party costs from vendors, customers, or other parties affected by the breach.
To qualify for coverage, insurers usually require security controls like multi-factor authentication, an incident response plan, and regular employee training. Coverage often pays for forensics, legal fees, business interruption losses, and ransom payments.
Why do businesses need cyber insurance?
Cyber insurance helps businesses recover from attacks that could otherwise disrupt operations. Partners, contracts, and regulators increasingly require it as a condition of doing business. The right policy helps offset costs that could derail a company after a breach.
The financial impact of an attack can be significant. According to the IBM Cost of a Data Breach Report 2025, the average cost of a breach was $4.44 million worldwide and $10.22 million in the United States. These costs reflect regulatory fines, legal actions, and recovery work. Beyond direct costs, businesses face productivity losses, customer churn, and reputation impact that can affect revenue for years.
Cyberattacks affect businesses of all sizes. Small and mid-sized businesses (SMBs) are frequent targets because they often have fewer dedicated security resources. Consequently, cyber insurance for small businesses is just as important as it is for enterprises; SMBs often face the highest relative risk because their defenses are typically not as mature as those at larger organizations.
What does cyber insurance cover?
Cyber insurance has two main categories: first-party coverage and third-party liability coverage.
First-party coverage pays for losses the business itself encounters, such as incident response, business interruption, and ransomware payments. Third-party liability coverage pays for losses incurred by others due to an attack on your business, including legal expenses, penalties, and liability claims.
Common costs that cyber insurance can cover include:
Incident response, forensic investigation, and remediation
Recovery and restoration of lost or encrypted data
Loss of revenue from business interruption
Legal costs, including lawsuits, regulatory fines, and attorney fees
Ransom payments
Notification and credit monitoring for victims of personally identifiable information (PII) theft
Reputation management, including public relations and media campaigns
The coverage you secure depends on your business, the assets you need to protect, your security posture, and your budget.
What do cyber insurers look for?
Multi-factor authentication (MFA) requires users to verify their identity using two or more methods. A typical MFA process asks for a password plus a second factor, such as a fingerprint or one-time passcode (OTP). MFA helps guard against breaches that use stolen credentials, the most common cyberattack method. Cyber insurance MFA requirements appear on most insurers' checklists, and many insurers now expect MFA compliance as a baseline condition of coverage.
How Duo helps you meet insurer MFA requirements
Cisco Duo is built to meet the exact MFA controls insurers ask about on their applications. Duo provides easy-to-deploy multi-factor authentication across cloud apps, on-premises systems, VPNs, and Active Directory, so you can demonstrate consistent MFA coverage across your environment.
For organizations whose insurers expect stronger protection against phishing and credential theft, Duo also supports phishing-resistant MFA using FIDO2 (Fast Identity Online 2) security keys and platform authenticators. With detailed audit logs, device trust evaluation, and risk-based policies, Duo helps you document the controls underwriters want to see. This supports the broader identity security maturity that insurers increasingly reward with better coverage and pricing.
Incident response and recovery plans
Incident response plans help you remediate a breach, investigate what happened, meet notification obligations, and manage communications afterward. Insurers want to see a clear framework in place. It demonstrates that you can detect, contain, and recover from an attack, which keeps claim costs down and signals lower risk to the insurer.
Identity and access management
Identity and access management (IAM) governs which users can access which data and systems based on their role. IAM is a core component of a zero-trust approach, which continually verifies users during a session rather than only at login. Strong IAM helps guard against unauthorized access and limits damage if an attacker breaches the system.
Other security controls insurers expect
Beyond MFA, incident response, and IAM, insurers expect a baseline of additional cybersecurity hygiene. Regular data backups, ideally with isolated or air-gapped copies and periodic recovery testing, help you restore operations after a ransomware attack. Endpoint detection and response (EDR) continuously monitors devices like laptops, servers, and mobile phones, and can isolate compromised endpoints before threats escalate.
Ongoing employee security training helps address the human element, which was present in 62% of breaches analyzed in the Verizon 2026 Data Breach Investigations Report, up from 60% in the previous report. The report also found that vulnerability exploitation became the most common initial access vector, accounting for 31% of breaches. A documented patch management and vulnerability scanning program can show insurers that your organization actively identifies and addresses security weaknesses.
How to apply for cyber insurance
Before applying, consider what insurers look for, assess your cybersecurity posture, prepare your application, and ensure coverage aligns with your risk profile.
What cyber insurers assess
Underwriters evaluate your cybersecurity posture, including incident history, response capabilities, governance policies, and preparedness. They assess the controls you have deployed as well as human factors, such as security training and documented security plans.
Preparing your application
Clear documentation of your controls helps insurers make policy decisions. Poor documentation can lead to declines or exclusions, even for an otherwise strong security program.
A few practical steps:
Assign ownership for security policies and controls.
Map controls to the questions in the application.
Document everything so you can respond to insurer questions.
Be prepared to undergo a third-party audit.
Detailed documentation also helps demonstrate compliance with regulations.
Align coverage with risk
Make sure the coverage you receive aligns with your risk profile. Different policies cover different combinations of liability, extortion, business interruption, and regulatory exposure. Understand the scope of coverage and how first-party and third-party losses are treated. Watch for sublimits, which place lower limits on certain specific losses. Determine whether incidents at suppliers or cloud providers need to be included in your coverage.
Cyber insurance is not a one-time purchase. Insurers reexamine your controls at renewal, and companies that treat qualification as an ongoing program often receive better pricing and more stable coverage.
Where is cyber insurance heading?
Cyber insurance underwriting is evolving quickly. Insurers are moving beyond checklist-based requirements toward continuous security posture evaluation. They expect processes like MFA, EDR, incident response plans, and access controls as a baseline.
Basic MFA will remain a minimum requirement, but insurers are increasingly asking about passwordless authentication, continuous device health monitoring, and automated identity governance. The organizations that qualify for the best coverage in the future are those that can demonstrate ongoing identity security maturity, not just point-in-time compliance.
Duo Directory capabilities, including passwordless enforcement, device trust evaluation, and breached password checking, position organizations ahead of these evolving requirements. Companies that invest in identity security maturity today will qualify for better coverage and lower premiums tomorrow.
Are you ready to build the security program insurers want to see? Learn about Cisco Duo's phishing-resistant MFA or signup for a free trial.