July 28, 2026

Cyber Insurance Requirements for Idaho Small Businesses

Most cyber insurance applications now turn on a short list of technical controls. If your business cannot answer yes to multi-factor authentication, tested backups, endpoint detection and response, and a written incident response plan, you are likely looking at a declined application, a reduced limit, or a significant premium increase. The good news is that this list is short, specific, and fixable well before renewal.

Idaho small businesses are feeling this shift. Carriers that once accepted a two-page questionnaire now send detailed technical attestations, and they verify what you claim. Signing an attestation you cannot support is worse than failing to qualify, because it can void coverage at claim time. This guide walks through what carriers commonly ask, what each requirement actually means in practice, and how long it typically takes to close the gaps.

What do cyber insurance carriers actually ask about?

Requirements vary by carrier, by policy limit, and by industry, so treat the list below as the common core rather than a universal standard. Your broker can tell you exactly which controls your specific carrier weights most heavily. That said, the following controls appear on nearly every application we see.

Control area What the application typically asks
Multi-factor authentication Whether MFA is enforced on email, remote access, VPN, and administrator accounts
Endpoint detection and response Whether managed EDR is deployed across all endpoints and servers, not just antivirus
Backup and recovery Whether backups exist offline or immutable, and whether restores have been tested
Email security Whether advanced filtering is in place for phishing, spoofing, and malicious attachments
Patch management How quickly critical patches are applied, and whether end-of-life systems remain in service
Security awareness training Whether staff receive regular training and phishing simulations, with records kept
Incident response plan Whether a written plan exists, who is on it, and when it was last reviewed
Privileged access Whether administrator accounts are separated from daily-use accounts
Remote access exposure Whether Remote Desktop Protocol is exposed directly to the internet

Why do small businesses get declined or surcharged?

The most common reason is not a missing control. It is a partial one. A business deploys MFA on email, checks the MFA box, and then discovers at underwriting that the carrier meant MFA on remote access and administrator accounts as well. The application was answered honestly and still fails, because the question was broader than it appeared.

The second most common reason is backups that have never been restored. Having a backup product installed is not the same as having a recoverable business. Carriers increasingly ask when the last successful test restore was performed and what the measured recovery time was. If nobody can answer, the control does not count.

The third is documentation. Training that happened but was not recorded, a patch policy that exists in practice but not in writing, an incident response plan that lives in someone's head. Underwriters cannot credit what you cannot evidence.

What does MFA everywhere actually mean?

When a carrier asks about multi-factor authentication, they are usually asking about four separate surfaces, and partial coverage on any one of them can sink the answer.

  • Email. Every mailbox, including shared and service accounts where technically possible.
  • Remote access. VPN, remote desktop gateways, and any tool used to reach the network from outside the office.
  • Administrator accounts. Domain admins, Microsoft 365 global admins, and any account that can change security settings.
  • Critical business applications. Increasingly, accounting, banking, and line-of-business systems that hold sensitive data.

Text message codes are still accepted by many carriers but are viewed as the weakest option. App-based approval or hardware keys score better and are not meaningfully harder to roll out.

What counts as a tested backup?

A backup satisfies most carriers when three things are true. There is a copy the ransomware cannot reach, meaning offline, immutable, or in a separate security boundary. A restore has actually been performed from that copy within a defined period. And someone has written down how long the restore took and what it covered.

That last part matters more than it sounds. Recovery time is what determines your business interruption exposure, and business interruption is where cyber claims get expensive. A carrier that knows your measured recovery window can price the policy. A carrier that does not will assume the worst.

How long does it take to close the gaps?

For a typical small business in the Treasure Valley, the technical work is measured in weeks, not months. Enforcing MFA across Microsoft 365 and remote access is usually a matter of days. Deploying managed EDR across a fleet of endpoints is typically a week or two depending on size. Building an immutable backup copy and running a documented test restore takes a couple of weeks including the scheduling.

Documentation is often the long pole, because writing an incident response plan means making decisions about who calls whom at two in the morning. Start there, not last.

The practical advice is to begin ninety days before renewal. That gives you time to close gaps, run a test restore, and generate the evidence an underwriter will want, without making decisions under deadline pressure.

How IDACOMP helps Boise businesses prepare

IDACOMP has supported businesses across Boise and the wider Treasure Valley for more than twenty years, and insurance-driven security requirements have become one of the most common reasons clients call us. We work through the questionnaire with you control by control, identify what is genuinely in place versus partially in place, and close the gaps in a sequence that matches your renewal date.

Our managed IT and cybersecurity services cover the controls carriers ask about, including MFA enforcement across Microsoft 365, managed endpoint protection, backup and tested recovery, email filtering, patch management, and security awareness training. We keep the evidence organized so that when the attestation arrives, the answers are already documented.

Clients reach a live local team with a guaranteed 15-minute average first response time for managed clients, which matters as much during a renewal scramble as it does during an outage.

Next step

If your renewal is inside the next ninety days, send us the questionnaire. We will walk it with you and tell you plainly which answers you can support today and which ones need work first. Call (208) 314-1181 or reach out through our managed IT services page.

One note worth repeating: requirements differ between carriers and change from year to year. Confirm the specifics with your broker before you attest to anything. Nothing here is insurance advice.

An accounting professional reviewing paperwork at a desk in a bright modern office.
By John Jackson August 28, 2026
The FTC Safeguards Rule requires tax and accounting firms to keep a written information security plan. What belongs in it and where Boise firms fall short.
An attorney reviewing documents at a desk in a bright office with bookshelves behind them.
By John Jackson August 28, 2026
Practical questions Boise law firms should ask any IT provider about protecting client data: encryption, access control, retention, breach response, and vendor risk.
A business owner reviewing insurance paperwork at a desk in a bright modern office.
By John Jackson August 28, 2026
Cyber insurance carriers verify controls, not just attestations. What Boise businesses need in place before an audit or renewal, and where gaps appear.
Two IT colleagues working together at a desk with laptops in a bright modern office.
By John Jackson August 28, 2026
Co-managed IT keeps your internal IT person in charge while an outside team adds depth, after-hours coverage, and security. How the split works in Boise.
A desk phone and open laptop on a tidy office desk in warm natural light.
By John Jackson July 28, 2026
Why Boise businesses get Microsoft 365 and hosted VoIP from one provider, what breaks when vendors are split, and how to choose between Teams Phone and hosted VoIP.
A manufacturing worker in a hard hat inspecting equipment on a factory production floor.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise manufacturers. Keep production running, secure office IT and the shop floor, and protect designs from ransomware and theft.
A diverse group of nonprofit team members and volunteers collaborating around a table.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise nonprofits. Stretch limited budgets, protect donor data, and keep your team running so you can focus on your mission.
An architect reviewing building blueprints and a scale model at a desk in a modern studio.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise architecture and engineering firms. Support demanding CAD and BIM workloads, protect design data, and keep teams in sync.
A financial advisor meeting with a client across a desk in a bright modern office.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise financial advisors. Protect client data, align with GLBA and SEC expectations, and keep systems running for clients.
An attorney reviewing documents at a desk with shelves of legal volumes behind them.
By John Jackson June 28, 2026
Managed IT and cybersecurity for Boise law firms. Protect privileged client data, meet cyber insurance requirements, and keep systems running for every deadline.