Cyber Insurance Requirements for Idaho Small Businesses
Most cyber insurance applications now turn on a short list of technical controls. If your business cannot answer yes to multi-factor authentication, tested backups, endpoint detection and response, and a written incident response plan, you are likely looking at a declined application, a reduced limit, or a significant premium increase. The good news is that this list is short, specific, and fixable well before renewal.
Idaho small businesses are feeling this shift. Carriers that once accepted a two-page questionnaire now send detailed technical attestations, and they verify what you claim. Signing an attestation you cannot support is worse than failing to qualify, because it can void coverage at claim time. This guide walks through what carriers commonly ask, what each requirement actually means in practice, and how long it typically takes to close the gaps.
What do cyber insurance carriers actually ask about?
Requirements vary by carrier, by policy limit, and by industry, so treat the list below as the common core rather than a universal standard. Your broker can tell you exactly which controls your specific carrier weights most heavily. That said, the following controls appear on nearly every application we see.
| Control area | What the application typically asks |
|---|---|
| Multi-factor authentication | Whether MFA is enforced on email, remote access, VPN, and administrator accounts |
| Endpoint detection and response | Whether managed EDR is deployed across all endpoints and servers, not just antivirus |
| Backup and recovery | Whether backups exist offline or immutable, and whether restores have been tested |
| Email security | Whether advanced filtering is in place for phishing, spoofing, and malicious attachments |
| Patch management | How quickly critical patches are applied, and whether end-of-life systems remain in service |
| Security awareness training | Whether staff receive regular training and phishing simulations, with records kept |
| Incident response plan | Whether a written plan exists, who is on it, and when it was last reviewed |
| Privileged access | Whether administrator accounts are separated from daily-use accounts |
| Remote access exposure | Whether Remote Desktop Protocol is exposed directly to the internet |
Why do small businesses get declined or surcharged?
The most common reason is not a missing control. It is a partial one. A business deploys MFA on email, checks the MFA box, and then discovers at underwriting that the carrier meant MFA on remote access and administrator accounts as well. The application was answered honestly and still fails, because the question was broader than it appeared.
The second most common reason is backups that have never been restored. Having a backup product installed is not the same as having a recoverable business. Carriers increasingly ask when the last successful test restore was performed and what the measured recovery time was. If nobody can answer, the control does not count.
The third is documentation. Training that happened but was not recorded, a patch policy that exists in practice but not in writing, an incident response plan that lives in someone's head. Underwriters cannot credit what you cannot evidence.
What does MFA everywhere actually mean?
When a carrier asks about multi-factor authentication, they are usually asking about four separate surfaces, and partial coverage on any one of them can sink the answer.
- Email. Every mailbox, including shared and service accounts where technically possible.
- Remote access. VPN, remote desktop gateways, and any tool used to reach the network from outside the office.
- Administrator accounts. Domain admins, Microsoft 365 global admins, and any account that can change security settings.
- Critical business applications. Increasingly, accounting, banking, and line-of-business systems that hold sensitive data.
Text message codes are still accepted by many carriers but are viewed as the weakest option. App-based approval or hardware keys score better and are not meaningfully harder to roll out.
What counts as a tested backup?
A backup satisfies most carriers when three things are true. There is a copy the ransomware cannot reach, meaning offline, immutable, or in a separate security boundary. A restore has actually been performed from that copy within a defined period. And someone has written down how long the restore took and what it covered.
That last part matters more than it sounds. Recovery time is what determines your business interruption exposure, and business interruption is where cyber claims get expensive. A carrier that knows your measured recovery window can price the policy. A carrier that does not will assume the worst.
How long does it take to close the gaps?
For a typical small business in the Treasure Valley, the technical work is measured in weeks, not months. Enforcing MFA across Microsoft 365 and remote access is usually a matter of days. Deploying managed EDR across a fleet of endpoints is typically a week or two depending on size. Building an immutable backup copy and running a documented test restore takes a couple of weeks including the scheduling.
Documentation is often the long pole, because writing an incident response plan means making decisions about who calls whom at two in the morning. Start there, not last.
The practical advice is to begin ninety days before renewal. That gives you time to close gaps, run a test restore, and generate the evidence an underwriter will want, without making decisions under deadline pressure.
How IDACOMP helps Boise businesses prepare
IDACOMP has supported businesses across Boise and the wider Treasure Valley for more than twenty years, and insurance-driven security requirements have become one of the most common reasons clients call us. We work through the questionnaire with you control by control, identify what is genuinely in place versus partially in place, and close the gaps in a sequence that matches your renewal date.
Our managed IT and cybersecurity services cover the controls carriers ask about, including MFA enforcement across Microsoft 365, managed endpoint protection, backup and tested recovery, email filtering, patch management, and security awareness training. We keep the evidence organized so that when the attestation arrives, the answers are already documented.
Clients reach a live local team with a guaranteed response time under one hour, which matters as much during a renewal scramble as it does during an outage.
Next step
If your renewal is inside the next ninety days, send us the questionnaire. We will walk it with you and tell you plainly which answers you can support today and which ones need work first. Call (208) 314-1181 or reach out through our managed IT services page.
One note worth repeating: requirements differ between carriers and change from year to year. Confirm the specifics with your broker before you attest to anything. Nothing here is insurance advice.










