Boston underwriters evaluating cyber insurance small business applications in 2026 are checking for five specific technical controls: MFA on email and remote access, endpoint detection and response (EDR), immutable offsite backups, patch cadence documentation, and employee security-awareness training logs. Each control maps directly to a documented category of loss that drove prior claims.
In This Article
- The Four Policy Exclusions Most Small Businesses Discover Too Late
- First-Party vs. Third-Party Coverage: Which One a Boston SMB Actually Needs
- What Your IT Partner Should Document Before You Apply (or Renew)
- Frequently Asked Questions
- Not Sure Your IT Posture Will Pass an Underwriter's Checklist? Let's Find Out.
- MFA on email and remote access: Compromised credentials are the leading entry point for ransomware. Underwriters require MFA on email platforms and VPN/remote-desktop access because its absence correlates directly with higher claim frequency.
- Endpoint Detection and Response (EDR): EDR is security software that monitors device behavior in real time and can isolate a compromised endpoint before a threat spreads. Basic antivirus no longer satisfies most applications. Underwriters specify EDR by name.
- Immutable offsite backup: An immutable offsite backup is a backup set that cannot be altered or deleted by ransomware because it is stored in a write-once, air-gapped environment. Underwriters require confirmed restore tests, not just backup schedules.
- Patch cadence documentation: Mean time to patch critical CVEs (Common Vulnerabilities and Exposures, publicly disclosed software flaws) is a measurable risk factor. Applications increasingly ask for a specific patching window, often 14-30 days for critical severity.
- Security-awareness training logs: Phishing remains the most common initial access vector. Underwriters want completion records, not a policy statement that training happens.
Why Massachusetts 201 CMR 17.00 Gives Boston SMBs a Head Start
Massachusetts 201 CMR 17.00, the state's data security regulation, requires any business handling Massachusetts residents' personal information to maintain a Written Information Security Program (WISP). A WISP is a documented policy governing how your organization protects sensitive data. Underwriters independently require a WISP-equivalent document, meaning Boston businesses that have met the state mandate through proper IT compliance services already satisfy this underwriter requirement, an advantage most national guides miss entirely.
The Four Policy Exclusions Most Small Businesses Discover Too Late
Four exclusion categories account for the majority of denied or reduced cyber insurance claims for SMBs: the misrepresentation exclusion, nation-state or war exclusions, social-engineering sub-limits, and unencrypted data exclusions. Each can eliminate coverage on the exact incident type your business is most likely to face.
The Misrepresentation Exclusion
If your application attested to MFA being enforced company-wide and an audit after a breach shows three user accounts weren't covered, your insurer can void the claim entirely under the misrepresentation exclusion, the mechanism that hit the Cambridge firm in the opening example. Attesting to a control you don't fully have isn't just a technicality; it's a grounds for policy rescission.
Nation-State and War Exclusions
Following years of insurer litigation over whether state-sponsored cyberattacks constitute ""war,"" many policies now include explicit nation-state exclusions. For Boston manufacturers and healthcare practices, sectors that have faced targeted intrusion campaigns, this exclusion can eliminate coverage for the exact incident type your business faces. Review your policy's war exclusion language before renewal, not after an incident.
Social-Engineering and Funds-Transfer-Fraud Sub-Limits
A $1M cyber liability policy frequently carries a $100,000-$250,000 sub-limit on social-engineering fraud, the category covering business email compromise (BEC) and fraudulent wire transfers. BEC is among the most common attack vectors against small businesses. If a Back Bay financial services firm is tricked into wiring $400,000 to a fraudulent account, a $250,000 sub-limit doesn't cover the loss, the headline policy limit is irrelevant.
Unencrypted Data Exclusions
Many policies exclude claims arising from personally identifiable information (PII) stored in unencrypted formats. A Seaport biotech startup storing patient records or trial data in a standard cloud drive with no encryption-at-rest may find its data breach insurance for small business coverage void at the moment it's needed most.
First-Party vs. Third-Party Coverage: Which One a Boston SMB Actually Needs
First-party cyber coverage pays your own costs after an incident like ransom payments, forensic investigation, business interruption, and breach notification. Third-party coverage pays costs arising from claims made against you by clients or regulators. Most Boston SMBs need both, but the right balance depends on the data you hold and the regulations that govern it.
| Coverage Type | What It Pays | Most Critical For |
|---|---|---|
| First-Party | Ransom, forensics, business interruption, notification costs | Any SMB that would lose revenue during a system outage |
| Third-Party | Client lawsuits, regulatory fines, defense costs | Practices holding patient data, client financial records, or regulated PII |
Why Boston Healthcare and Dental Practices Need Strong Third-Party Limits
A dental practice or medical group in Greater Boston faces HIPAA breach-notification liability, including OCR (Office for Civil Rights) penalties and patient-notification costs, that can far exceed first-party recovery costs. Robust third-party limits are not optional for these practices; HIPAA compliance exposure alone can dwarf the ransom or forensic bill.
Why CPA Firms Face a Different Third-Party Risk
A CPA or financial advisory firm falls under the FTC Safeguards Rule, the Federal Trade Commission's regulation requiring non-bank financial institutions to implement a written information security program. Client-data liability under the FTC Safeguards Rule creates third-party exposure that demands its own sub-limit review. Pressure-test your current policy's sub-limits against your actual client data volume, not the headline coverage number.
What Your IT Partner Should Document Before You Apply (or Renew)
Underwriters are now requesting documented evidence of controls at application time, and sometimes again at claim time. An MSP that can produce configuration reports, backup logs, and training records on demand is providing a materially different service than one that simply manages your systems without audit trails.
OnPoint Technology Group, Inc. provides cybersecurity services in Greater Boston specifically structured to generate the documentation artifacts underwriters demand. The gap between an insurance broker's advice and what actually satisfies an underwriter is evidence, and evidence is an IT deliverable, not an insurance one.
The Five Documentation Artifacts That Satisfy Underwriter Requirements
- MFA enforcement reports from Microsoft 365 or Entra ID: These reports confirm 100% user coverage with named accounts, dates enforced, and authentication method, not a verbal attestation that MFA is "turned on."
- Backup completion and integrity-test logs: Logs must show completed backup jobs, offsite or air-gapped confirmation, and documented restore tests with pass/fail results. A backup schedule is not evidence of a functioning backup.
- Endpoint protection deployment reports: EDR coverage reports showing every managed device, the agent version running, and any coverage gaps across the fleet.
- Patch compliance dashboards: Mean time to patch for critical CVEs, broken down by device class, showing your organization meets its stated patching window.
- Phishing simulation results and training completion records: Dated records showing which employees completed training, click rates from simulated phishing campaigns, and remediation steps for repeat clickers.
Generating and maintaining these records is a core deliverable of OnPoint's managed IT services, not an add-on. When a claim is filed, your insurer may request this documentation within days. Having it ready eliminates the coverage gap the Cambridge firm discovered too late.
Frequently Asked Questions
How much does cyber insurance cost for a small business in Massachusetts?
Premiums vary based on revenue, data volume, industry, and which controls you have in place. Businesses with MFA, EDR, and documented backups consistently qualify for lower rates. The best way to understand your cost is to close any control gaps before applying; missing controls raise premiums or trigger declination.
Does cyber insurance cover ransomware attacks?
Most cyber liability policies cover ransomware under first-party coverage, including ransom payments, forensic costs, and business interruption. Coverage can be voided if you misrepresented your controls at application, if the attack is attributed to a nation-state under a war exclusion, or if your backups were unencrypted and an unencrypted-data exclusion applies.
What is a WISP and do I need one for cyber insurance in Massachusetts?
A WISP (Written Information Security Program) is a documented policy governing how your business protects personal information. Massachusetts 201 CMR 17.00 legally requires a WISP for any business handling Massachusetts residents' data. Most cyber underwriters also require a WISP-equivalent document, so meeting the state mandate satisfies both obligations simultaneously.
What documentation does an underwriter require from my IT provider?
Underwriters increasingly request MFA enforcement reports showing full user coverage, backup completion and restore-test logs, EDR deployment reports across all devices, patch compliance dashboards with mean-time-to-patch data, and phishing simulation and training completion records. These must be produced as reports, as verbal attestation is no longer sufficient at application or claim time.
Not Sure Your IT Posture Will Pass an Underwriter's Checklist? Let's Find Out.
Book a free 15-minute discovery call with OnPoint's Boston team and we'll review your current controls against the most common 2026 underwriter requirements and tell you exactly what gaps, if any, could raise your premium or void a future claim.
Schedule Your 15-Minute Discovery Call
