Security

Insurers Play Catch-Up on Cybersecurity Policies

When you renew cybersecurity insurance, expect a new application, stricter requirements like enforced MFA, and, in some cases, policies no longer offered.

October 23, 2023

When you next try to renew your cybersecurity insurance, you might find the approval process and the available policies quite different from before. Insurers are getting more specific and more cautious.

You should expect a new application for the policy you already hold, and in some cases you'll find that the policy you've had for a few years is no longer being offered.

In the past, insurance applications were often geared only toward protecting personally identifiable information (PII) or credit card processing. But as claims increase for ransomware attacks, business information compromised by phishing, and the resulting disruption to operations, insurers are catching up with real-world vulnerabilities. As a result, they are dramatically increasing (appropriately so) the level of security their policies require for all organizations.

What's really going on?

Cyber attacks are disruptive and can cost businesses and insurance carriers a lot of money. With broad-based risk analysis and clear insight into the costs associated with cybersecurity vulnerabilities, insurance companies are updating their policies to better reflect best practices. That's good news, because better security lowers the risk and cost for all of us. It's good to see the security best practices we've recommended for years find their way into insurance policy requirements.

For example, insurers now expect your organization to have multi-factor authentication (MFA) enforced across the board. That includes MFA for all services an organization uses (Google, Microsoft, Dropbox, Zoom, Slack, and the like), plus any VPN that lets users reach internal networks and servers from home. For many businesses, depending on the age of the equipment and tools in use, MFA may not even be available to authenticate VPN access. So renewing a policy may prompt an overdue strategic reckoning and re-prioritization of resources.

If you've been dragging your feet on our recommendation to enforce MFA on all your email accounts, your insurance company may finally force the issue: it's time.

Best practices

It is irresponsible to pretend that ransomware, phishing, and information theft don't exist. You should be concerned about your business's data security, and there are clear, straightforward steps you can take to protect it.

  • Identity and access management solutions bring a broad range of security benefits, including MFA enforcement across all your online services (and, yes, your VPN).
  • Device management ensures a baseline of security protections on your workstations and laptops.
  • Malware and endpoint protection watch for downloads that may cause problems and for unusual activity.
  • Properly configured and monitored backups give your organization a lifeline if ransomware does somehow find a perch.

How we can help

Macktez has been protecting our clients' data and systems for decades. We have subscriptions designed specifically to address vulnerabilities in workstations, networks, servers, and identities. For a complete set of protections, our Core Suite package gives your organization the tools to function productively in a changing cybersecurity environment.

Work With Us

Have a project like this on the horizon?

If something here maps to what your organization is facing, let's talk it through — no pitch deck, just a senior technical perspective on your situation.