Businesswoman in blue suit discussing documents with two colleagues in a modern office setting.

3 Signs Your Cyber Insurance Policy Has Coverage Gaps And What to Do Before Renewal

September 11, 2026

In This Article

A cyber liability insurance policy, insurance covering losses from data breaches, ransomware, and related cyber incidents, can contain exclusions, sub-limits, and attestation requirements that void or drastically reduce a payout. Underwriting standards have tightened considerably since 2022, meaning a policy purchased two or three years ago may no longer align with what your insurer actually requires today.

How Cyber Insurance Exclusions Quietly Shrink Your Coverage

Cyber insurance exclusions are policy clauses that remove specific loss types from coverage entirely. Common exclusions include losses from unencrypted devices, cloud-hosted data not explicitly listed, and social engineering fraud. Most SMB owners never read past the declarations page, the policy summary sheet listing coverages and limits, so these exclusions go unnoticed until a claim is filed.

What Has Changed Since You Last Renewed

Insurers now routinely require multi-factor authentication (MFA), endpoint detection and response (EDR) software, and tested backups as conditions of coverage, not just good practices. If your environment has shifted since your last application and your attestations haven't kept pace, you have a gap. The three signs below are the most consequential ones to check before your next renewal.

Sign 1: Your Ransomware Sub-Limit Is a Fraction of Your Actual Exposure

A ransomware sub-limit is a separate, lower cap within your policy that specifically limits what the insurer will pay on a ransomware claim even when your overall cyber liability limit is much higher. Many SMB policies carry ransomware sub-limits of $100,000-$250,000, while ransomware demands to small businesses regularly exceed those figures when ransom, downtime, and recovery costs are combined.

Declarations page: The summary document at the front of your insurance policy that lists your coverage types, individual limits, sub-limits, and policy period in one place.

How to Find Your Ransomware Sub-Limit

  • Pull your declarations page and look for a line item labeled "Ransomware," "Cyber Extortion," or "Extortion Coverage."
  • Compare that figure to your overall policy limit if the sub-limit is less than 25% of your total limit, that gap is worth closing.
  • Ask your broker three specific questions: What does the sub-limit cover, ransom payment only, or also recovery costs and downtime? Does MFA on all remote access affect the sub-limit? Can the sub-limit be bought up to match the full policy limit, and at what added premium?

Why This Gap Hits SMBs Harder Than Enterprises

Enterprise policies are typically negotiated line by line. SMB policies are often off-the-shelf products where sub-limits are set by default, not by your actual exposure. A Raleigh manufacturer or professional-services firm with 30 employees and $3M in annual revenue can face a recovery bill that blows past a $250,000 sub-limit in the first week of downtime alone. Reviewing this number is one of the highest-return items on any pre-renewal checklist.

Sign 2: You Attested to Controls You No Longer Have or Never Fully Implemented

Attestation drift occurs when a business answered "yes" to a security control on its cyber insurance application, but that control was either partially implemented or has since lapsed. Underwriters can deny a cyber insurance claim by citing material misrepresentation, meaning the application contained a false statement that affected the insurer's decision to issue the policy.

The MFA Cyber Insurance Requirement Is More Specific Than You Think

MFA (multi-factor authentication, which requires a second verification step beyond a password) is the single most scrutinized control on renewal applications. Most insurers now define MFA compliance as requiring MFA on email, VPN (virtual private network), RDP (Remote Desktop Protocol), and cloud admin consoles simultaneously. Checking "yes" because email has MFA while VPN does not is the exact scenario that triggers claim denial.

The Controls American Frontier Audits Before Your Renewal

Unlike generic broker advice that stops at "buy more coverage," American Frontier closes the gap from the IT side. Before your policy renews, American Frontier audits the cybersecurity controls your insurer now requires: MFA across all remote access points, EDR (endpoint detection and response software) deployment, privileged access management, and patch currency. They then produce a written gap report you can use with your broker to correct attestations before they become a claim problem.

What Attestation Drift Looks Like in Practice

  • MFA on email only: Application says "yes to MFA"; VPN and RDP have no MFA.
  • EDR on most endpoints: A few older machines or a remote employee's laptop was never enrolled.
  • Backups configured but untested: Backup software is running, but no restore test has been completed in over 12 months.
  • Privileged accounts unmanaged: Domain admin credentials are shared or have no MFA, despite the application claiming otherwise.

Sign 3: Social Engineering Losses Are Quietly Excluded or Capped

Social engineering losses, financial losses caused by an employee being deceived into transferring funds or revealing credentials, including business email compromise (BEC) and wire fraud, are frequently excluded from the base cyber policy or covered only through a separate social engineering endorsement with its own low cap, often $25,000-$50,000.

Business Email Compromise vs. First-Party Crime Coverage

Loss Type Typically Covered By Common SMB Cap
Ransomware / data breach Base cyber policy (subject to sub-limit) Varies, see declarations page
Business email compromise (BEC) / wire fraud Social engineering endorsement (separate add-on) $25,000-$50,000
Employee theft / internal fraud First-party crime coverage (separate policy) Varies by policy

Business email compromise is a fraud scheme in which an attacker impersonates a vendor, executive, or client to trick an employee into wiring funds to an attacker-controlled account. BEC losses are among the most financially damaging incidents for Triangle-area professional-services firms and manufacturers, industries where wire transfers are routine and the dollar amounts are large.

Why the Social Engineering Endorsement Cap Matters for Raleigh SMBs

A social engineering endorsement is an optional add-on that extends a cyber policy to cover BEC and wire-fraud losses up to a stated sub-limit. A $25,000-$50,000 cap is a meaningful shortfall for any business that routinely processes invoices or payroll above that threshold. Ask your broker whether your policy includes a social engineering endorsement, what the current cap is, and whether that cap can be increased: this is a straightforward negotiation that many SMBs simply never have.

What to Do Before Renewal on All Three Signs

  • Pull your declarations page and locate the ransomware sub-limit and any social engineering endorsement cap.
  • Cross-reference your MFA deployment against every remote access point, not just email.
  • Confirm your tested backup and recovery plan is documented and that a restore test has been completed within the past 12 months.
  • Review your documented disaster recovery plan; insurers increasingly require evidence of incident response procedures, not just backups.
  • Confirm that Microsoft 365 data protection is explicitly listed in your policy as M365 data is frequently absent from base policy schedules.
  • Engage your cyber insurance services in Raleigh provider to produce a written control-gap report before your broker submits the renewal application.

Not Sure Your Policy Will Actually Pay Out? Let's Check Before Renewal.

Book a 15-minute discovery call with American Frontier. We'll review the security controls your insurer requires, identify any attestation gaps, and confirm your Raleigh business is positioned to get covered and stay covered at renewal.

Book Your 15-Minute Discovery Call