talk to an IT expertremote support
Speak With An IT Professional Immediately. Call (480) 366-4567

Cyber Insurance Won't Save You If Your IT Isn't Up to Standard

Call (480) 366-4567
We’ll Respond Within 3 Rings.
Real Technician Answers - No Voicemail, No Queue.

In July 2025, the City of Hamilton, Ontario learned its cyber insurance policy was worth exactly nothing. After a ransomware attack knocked out 80% of the city's network in February 2024, forcing officials to spend nearly $18.3 million on recovery, the city turned to its insurer to cover the damage. The claim was denied. Not because the attack wasn't covered. Not because the ransom demand exceeded policy limits. The insurer's reasoning was that multi-factor authentication had not been fully rolled out across every department, and the policy explicitly excluded losses where a lack of MFA was the root cause of the breach. Hamilton had known about the MFA requirement since 2022. The rollout was still incomplete when the attackers got in.

That story isn't an outlier anymore. It's the new normal for how cyber insurance actually works, and most Phoenix SMBs have no idea their policy is built the same way.

Your Policy Isn't a Safety Net, It's a Contract With Conditions

Business owners tend to think of cyber insurance the way they think of fire insurance: pay the premium, file a claim if something happens, get a check. That's not how it functions anymore. According to the National Association of Insurance Commissioners' 2025 Cybersecurity Insurance Report, U.S. insurers closed nearly 38,500 cyber claims in 2024, and only about 9,900 of them, roughly 26%, actually resulted in a payment. The rest were closed without one.

Some of those denials come down to below-deductible losses or withdrawn filings. But a significant and growing share trace back to a simple pattern: the business attested to security controls on its application that weren't actually in place, or weren't fully in place, when the breach happened. Insurers are no longer taking those answers at face value either. Applications increasingly get checked against external scans and post-incident forensics, and if what's found on the network doesn't match what was attested to on the application, that gap becomes the insurer's exit.

MFA Isn't a Checkbox, It's a Root Cause Investigation

Every cyber insurance application today asks some version of "Is multi-factor authentication enabled?" Most business owners answer yes because MFA is turned on somewhere in their environment. That's not what the question is actually asking.

Insurers increasingly define MFA scope down to the account level: every privileged and admin account, every remote access path, every email login, every cloud console, every backup admin interface. If MFA is enforced on 90% of user accounts but a handful of service accounts or an old admin login slipped through, that's the gap a post-breach investigation will find, and it's the gap an insurer will point to when denying the claim. When the City of Hamilton, Ontario had its cyber insurance claim denied after a 2024 ransomware attack, the city's own staff report confirmed the policy excluded coverage for any loss where the absence of MFA was the root cause, and that exclusion applied even though MFA was partially in place across some departments.

This is the exact misconfiguration CDSI finds most often when we take over a new client's environment. MFA gets enabled during a rushed setup, or by a previous provider working through a checklist, and then it quietly falls out of enforcement as new users, new admin accounts, and new cloud services get added without anyone circling back. It looks secure from the outside. It isn't. If you want a clear picture of where those gaps actually sit in your environment, that's the starting point of any real cybersecurity assessment, not a follow-up step.

EDR and Documented Backups Are the Next Line Insurers Are Drawing

MFA is where insurers started, but it isn't where they stopped. Underwriters now commonly expect endpoint detection and response on every device, not just traditional antivirus, along with a documented incident response plan and evidence that backups are tested, not just running. "We have backups" is not an answer an insurer or a forensic investigator will accept anymore. What matters is whether those backups are isolated from the production network, whether they've been restore-tested on a regular cadence, and whether there's a paper trail proving it.

This is exactly why CDSI builds a hybrid backup architecture for every client: an onsite appliance paired with real-time cloud replication, with restore testing built into the schedule rather than left to chance. It's also why documentation matters as much as the tools themselves. An insurer isn't going to take a business's word that its network is segmented and its endpoints are monitored. They want logs, configuration records, and proof the controls were active at the time of the incident. A properly maintained network security posture isn't just a defense against attackers anymore, it's the evidence file your business needs if you ever have to prove your policy should pay out.

The Gap Between "Set Up" and "Actually Secure" Is Where Claims Get Denied

Most SMBs in the Phoenix area aren't negligent about IT. They hired someone at some point to configure Microsoft 365, set up a firewall, and turn on antivirus, and they've reasonably assumed that work holds up. The problem is that a Microsoft 365 tenant that was configured correctly two years ago isn't the same as one that's properly managed today. Conditional access policies get bypassed by exceptions nobody remembers granting. Former employees keep active accounts. New SaaS tools get connected without anyone reviewing the permissions they request.

None of that shows up as an obvious problem day to day. It shows up as a claim denial after the breach, when it's too late to fix. This is the difference between a tenant that was set up once and one that's actively, continuously managed, which is the entire premise behind ongoing managed IT services instead of a one-time project.

What to Check Before Your Next Renewal, Not After Your Next Incident

If your cyber insurance is coming up for renewal, or if you've never actually verified what your current policy requires versus what your environment delivers, there are a few questions worth answering now:

Is MFA enforced on every privileged account, every remote access path, and every admin console, not just standard user logins? Is there a documented, tested incident response plan that someone other than your IT provider could execute? Are backups isolated from your production network and restore-tested on a regular schedule, with records to prove it? Do you actually know who has admin access to your Microsoft 365 tenant right now, and whether all of it is still needed?

If you can't answer those with confidence, your policy is likely worth less than what you're paying for it.

Don't Wait for the Denial Letter to Find Out

The businesses that get burned by this aren't the ones ignoring cybersecurity entirely. They're the ones who reasonably believed their setup was good enough, because it was good enough when it was first configured. Insurers have moved the bar, and they're checking against it more aggressively every renewal cycle.

If it's been more than a year since anyone actually audited your Microsoft 365 environment, your endpoint protection, and your backup testing against what your insurance policy requires, now is the time to find out where the gaps are, not after an incident forces the question. CDSI's security assessments are built specifically to surface these gaps before an insurer, or an attacker, finds them for you. Contact us to get your environment reviewed before your next renewal.

Is Your IT Supporting Growth or Slowing It Down?

Let’s have a conversation about where your technology stands and what needs attention.

No sales pitch. Just clarity.
linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram