Small businesses picture cyber attacks as technical sieges — someone in a distant country hammering at a firewall. The reality documented across incident reports, year after year, is more mundane: someone on your team clicked a link, reused a password, or paid an invoice to a bank account that had quietly changed. The majority of incidents begin with a human action, which means the majority of your defence is human too.
That's genuinely good news for a business without an IT department. The habits that stop most attacks cost little, and they're the same controls cyber insurers price on — so building them pays twice: fewer incidents, lower premium.
The five controls underwriters ask about
Open any cyber insurance application and the same questions appear. Multi-factor authentication on email and remote access — the single control most insurers now treat as mandatory, because stolen passwords are the front door of ransomware. Offline or immutable backups, tested by actually restoring from them. Patching, so known holes get closed. Some form of endpoint protection. And staff awareness training, however lightweight.
A business that can answer yes to those five is quotable almost everywhere and priced accordingly. A business that can't may find its premium loaded — or the market simply declining. The application, in other words, is a free map of what to fix first.
The invoice that changed banks
The costliest small-business attack isn't always technical at all. Social engineering fraud — a convincing email from a 'supplier' announcing new banking details, or a 'CEO' urgently requesting a transfer — takes money without touching a system. The defence is procedural: any change to payment details gets verified by phone, on a number you already had, before a dollar moves. Two people approve payments above a threshold you choose.
Insurance-wise, these losses sit at the seam between cyber and commercial crime coverage, and wordings differ between insurers. It's worth confirming explicitly which policy would respond to a fraudulent-transfer loss — before it happens, not while it's being adjusted.
Passwords, phones, and the accounts you forgot
A password manager fixes the reuse problem faster than any training session: unique credentials everywhere, no memorization, cheap. Pair it with a simple offboarding routine — when someone leaves, their access dies the same day. Forgotten accounts belonging to former staff are a standing gift to attackers, and they're purely a process failure.
Phones deserve a mention because so much business email now lives on them. Screen locks, OS updates, and the ability to wipe a lost device remotely are all built into the platforms your team already uses; turning them on is an afternoon of admin, not a project.
Practice the bad day
The final habit is rehearsal. If ransomware locked your systems on Monday morning, who would you call first? Where's the cyber policy's incident hotline written down — somewhere that isn't inside the locked systems? Who talks to customers? Running that conversation for thirty minutes a year turns panic into a checklist, and Canadian privacy law's breach-notification duties are far easier to meet from a plan than from a standing start. The privacy breach side of your coverage exists exactly for that response.
A 30-day rollout for a ten-person team
Here's the realistic implementation calendar, built for a business where 'the IT department' is whoever's youngest. Week one: turn on multi-factor authentication for email and any remote access — most platforms make it an afternoon of admin — and buy a password manager team plan. Announce both in the same meeting, with the honest framing: this is insurance-mandated hygiene that also keeps everyone's own accounts safer. Resistance drops when people learn the password manager works for their personal logins too.
Week two: backups. Identify what actually needs backing up (accounting data, client files, the shared drive), set up an automated solution with an offline or immutable copy, and put a monthly restore test in someone's calendar with their name on it. Week three: the payment-verification rule. Write it in three sentences, brief everyone who touches money, and tape it near the desk where payments happen: no banking-detail changes without phone verification on a known number; two approvals above your chosen threshold; no exceptions for urgency, because urgency is the attack.
Week four: the one-page incident plan and a fifteen-minute phishing chat — what current lures look like, and the no-blame rule for reporting clicks. Then book the annual repeat. Total cost for the month: a few hundred dollars in subscriptions and perhaps six working hours. It's the highest-return security spend available at this scale, and it's exactly the posture your next insurance application will ask you to describe.
What this does to your premium — the underwriting math
Cyber applications have converged on a recognizable control checklist, and your answers move real dollars. MFA is the gatekeeper question: businesses without it increasingly face declined applications or ransomware sub-limits and coinsurance — meaning the policy pays only a fraction of an extortion loss. Tested, segregated backups are the second gate, often determining whether full ransomware coverage is offered at all. Endpoint protection, patching cadence, and staff training round out the standard sheet.
The premium spread is meaningful. For a small firm, strong answers versus weak ones can be the difference between a few hundred dollars a year and a quote loaded to multiples of that — or no quote. More importantly, the same answers change claim outcomes: policies increasingly carry conditions tied to represented controls, and an application that overstated your MFA coverage is a fight waiting for the worst day. Answer accurately, then fix the gaps before binding rather than fudging them.
There's also a renewal dividend nobody mentions: incidents you prevent are claims you never make, and cyber pricing follows loss history like every other line. The thirty-day rollout above pays three times — fewer incidents, better terms, and cleaner claims if one gets through anyway. Bring the checklist to your cyber quote and watch the conversation change.
Keeping it alive: the quarterly fifteen minutes
Security habits decay on a schedule: the new hire nobody briefed, the MFA exception granted 'temporarily' in a busy week, the backup job that failed silently in June. The countermeasure is a recurring fifteen-minute quarterly check with a fixed agenda: MFA still enforced everywhere (check the admin console, not memory); last restore test date and result; any new staff briefed on the payment rule; any new software or vendors added with access to your systems; and the incident-plan page still accurate — right phone numbers, right names.
Put it in the calendar attached to something that already happens — quarter-end bookkeeping is the natural host — and give it an owner. In a ten-person business the owner is usually the owner; the point is that it's someone's name, because 'everyone's responsibility' is how controls decay in the first place.
The quarterly rhythm also feeds your insurance file painlessly. When the cyber renewal application arrives asking about controls, training, and testing, the answers exist as four short entries in a log instead of an archaeology project. Underwriters can tell the difference between a business describing its practices and one reciting aspirations — and the log is what makes you the first kind.
The vendor question: your suppliers' habits are your risk too
One boundary of this whole topic sits outside your walls: the bookkeeper with your banking access, the IT contractor with admin rights, the marketing agency inside your email platform. Their security habits are functionally yours — a growing share of small-business incidents arrive through a vendor's compromised access — and the same plain questions you've just answered internally are fair to ask them: MFA on the accounts touching your systems? Unique credentials? What happens to access when their staff leave?
Formalize the two that matter most: least-privilege access (vendors get what their work requires, not blanket admin) and prompt deprovisioning when engagements end. For vendors deep in your systems, asking whether they carry their own cyber and technology E&O coverage is reasonable diligence — professionals answer instantly. None of this is adversarial; it's the same hygiene you'd want your own clients asking of you, and it closes the last door the thirty-day rollout leaves open.
Keep the program alive with a rhythm rather than a binder: a twenty-minute tabletop twice a year (walk the team through one scenario — the fake-invoice email, the locked server — and let them decide what happens next), phishing simulations run as coaching rather than gotcha theatre, and a standing rule that reporting a suspicious click is always praised and never punished, because the employee who hides a click for three days is the one who turns an incident into a claim. Rotate the scenarios with the seasons — payment fraud around year-end, credential phishing when new tools roll out — and fold the five-minute refresher into onboarding so every new hire gets the culture on day one. Security habits decay on roughly a six-month half-life; the calendar, not the policy document, is what keeps them alive.
The bottom line
You don't need enterprise security to be a hard target — you need MFA, tested backups, verified payment changes, a password manager, and a one-page plan. That short list prevents the common attacks and earns the better premium, because insurers price exactly what it fixes.
If your renewal is coming up, or you've never carried cyber coverage at all, get a quote — the application alone will show you where your gaps are, and we'll compare the cyber markets that reward the habits you've built.