A logistics broker in the Perimeter area called their insurance agent expecting a routine cyber policy renewal. Instead they got a seven-page supplemental questionnaire asking whether they had multi-factor authentication on every remote login, endpoint detection software rather than basic antivirus, tested backups with documented recovery times, and a written incident response plan. They answered honestly. Three of the four answers were no. The renewal quote came back nearly double, with a note that coverage for ransomware payouts specifically required closing those gaps within sixty days.
This scenario has become routine across the Atlanta business community over the past few renewal cycles, and it’s changing what “adequate IT” actually means for small and midsize companies in a way that has nothing to do with a business owner’s own risk tolerance. Insurance underwriters, burned by a wave of ransomware payouts in the early 2020s, have quietly become the strictest auditors most businesses will ever face. They don’t care whether a company feels secure. They want specific, documented controls, and they’ve built pricing models that punish businesses that can’t demonstrate them.
Why the questionnaire got so much harder
Cyber insurance used to be a fairly light-touch product, closer to a general liability rider than a serious risk assessment. That changed once insurers started paying out claims tied to attacks that basic controls would have prevented entirely: credential theft on accounts with no MFA, ransomware that spread because backups weren’t actually tested and failed to restore, breaches that went undetected for weeks because nothing was monitoring endpoint activity. Underwriters responded by tightening the application itself, turning it into a de facto security audit that determines both eligibility and price.
The businesses caught off guard aren’t usually the ones ignoring security entirely. They’re the ones who assumed a firewall and antivirus software were sufficient, because that used to be true and nobody told them the bar had moved. The questionnaire doesn’t ask if a business feels protected. It asks for specifics, and vague answers get flagged the same way as honest gaps.
What underwriters are actually checking for now
- Multi-factor authentication everywhere, not just email: Insurers increasingly require MFA on remote access, admin accounts, and cloud applications, not just the login screen employees see every morning, and partial implementation often counts against a business the same as none.
- Endpoint detection and response, not legacy antivirus: Traditional signature-based antivirus doesn’t satisfy most current applications. Insurers want tools that can detect and isolate unusual behavior on a device in real time, which is a different category of software than what many small businesses have running.
- Backup testing with documented recovery times: Having backups isn’t enough anymore. Insurers want proof that a business has actually tested restoring from those backups and knows how long recovery takes, because untested backups fail at a surprisingly high rate exactly when they’re needed.
The gap between what businesses think they have and what they can prove
The recurring problem isn’t that Atlanta businesses have no security measures at all. It’s that whatever measures exist often live in someone’s head rather than in documentation an underwriter would accept. A business owner who says “we’re pretty locked down” doesn’t have anything to show for it on paper, and insurers no longer take that answer at face value. This is a subtle but important shift: the bar isn’t just having good practices, it’s being able to prove them on demand, with specifics an underwriter’s risk team will actually check.
Where the MSP relationship changes shape
This is reshaping what businesses actually need from IT support. It’s no longer just about uptime and fixing tickets. A well-run MSP Atlanta relationship increasingly includes documentation built specifically for insurance purposes: attestations, control summaries, and audit trails that a business can hand directly to an underwriter without scrambling to reconstruct months of security history from memory. Businesses that treat their IT provider purely as a break-fix resource often discover, at the worst possible moment, that nobody’s been keeping the kind of records their insurer now requires.
What happens to the businesses that don’t adapt
The consequence isn’t abstract. Premiums for businesses that can’t demonstrate baseline controls have climbed sharply, and some insurers have started excluding ransomware coverage entirely for applicants who don’t meet minimum requirements. A few have simply declined to renew policies rather than price the risk. For an Atlanta business that’s never filed a cyber claim and considers itself low-risk, discovering that the insurance market itself has redefined “adequate security” without warning is an expensive surprise, and one that’s becoming harder to avoid ignoring.
