Let me ask you something: if you were leaving your business for the weekend, would you lock the front door but leave every window open?
Of course you would not. Yet many small businesses protect one part of their technology while leaving another exposed, no multi-factor authentication on email, untested backups, outdated software, or employees who have never practiced what to do after a suspicious message.
That gap is becoming more than a cybersecurity concern. It can affect whether you qualify for cyber insurance.
For St. Louis small businesses, insurers and client security questionnaires increasingly want proof that specific controls are in place before they will offer coverage, renew a policy, or approve you as a vendor. Here are the seven controls you should be ready to show.
Important distinction: Missouri does not generally require every business to carry cyber insurance. However, insurers, lenders, customers, and business partners may impose their own security requirements.
Why cyber insurance applications are getting harder
Think of a cyber insurance application like a home inspection. An insurer does not simply ask whether you own a smoke detector. They want to know where it is, whether it works, and whether you have a plan if something goes wrong.
The same idea now applies to your business systems.
The FBI’s 2024 Internet Crime Report recorded 21,442 business email compromise complaints and more than $2.77 billion in reported losses. That works out to roughly $129,000 per complaint.
That is sensitive data leaving the safety of a business, or money leaving its bank account.
And here is where it gets serious: insurers may ask whether you use MFA, how quickly you apply critical patches, whether your backups are isolated, and when you last tested a recovery. A “we think so” answer is not the same as documentation.

1. Multi-factor authentication on critical accounts
Multi-factor authentication, or MFA, requires more than a password to sign in. After entering your password, you might approve a prompt, enter a temporary code, or use a security key.
It is like having both a key and a deadbolt.
Most insurers now expect MFA on:
- Business email accounts
- Remote access and VPN connections
- Administrator accounts
- Cloud storage
- Accounting and payroll systems
- Customer relationship management platforms
MFA is especially important because stolen passwords are often the first step in ransomware, account takeover, and business email compromise.
The FTC recommends MFA for access to sensitive information, while CISA recommends phishing-resistant MFA for email, VPNs, and critical systems whenever possible.
Start by checking your email platform and administrator accounts. If MFA is missing from either one, you have a high-priority gap.
For more on the email threat facing local companies, read Business Email Compromise: The $3 Billion Scam Targeting St. Louis Small Businesses.
2. Managed endpoint protection, not just basic antivirus
Traditional antivirus scans for known threats. Modern endpoint detection and response, or EDR, watches for suspicious behavior across laptops, desktops, and servers.
That difference matters.
Imagine someone entering your office with a copied key. Basic antivirus may only recognize the person if they are already on a watchlist. EDR looks for unusual behavior, such as someone opening hundreds of files, disabling security tools, or moving through systems they do not normally access.
Insurers may ask whether EDR or comparable protection covers:
- Every company laptop and desktop
- Servers and virtual machines
- Remote workers’ devices
- Cloud-based systems
- Administrator workstations
They may also ask who reviews alerts and how quickly someone responds.
A security tool that sends alerts to an unattended inbox is not the same as active monitoring. Your application should clearly identify who investigates suspicious activity and what happens after an alert.
3. Encrypted, isolated, and tested backups
Here is the problem with saying, “We back up to the cloud”: that answer may not be enough.
If ransomware reaches your network and can also delete or encrypt your backups, you may have no practical recovery option. CISA recommends maintaining offline, encrypted backups and regularly testing whether they can actually be restored.
Your backup control should include:
- Automated backups of critical data
- Encryption in transit and at rest
- At least one offline, immutable, or otherwise isolated copy
- Documented retention periods
- Regular restore testing
- A clear recovery priority for essential systems
A backup report showing that a job completed is not proof that your business can recover. You need to know whether the files open, whether applications can be restored, and how long recovery would take.
For a practical review of this area, see Data Protection for Small Businesses in St. Louis: A Practical 2026 Guide.

4. Timely patching and vulnerability management
Every software update is not just a new feature. Many updates close a door that attackers are actively trying to open.
Insurers and client auditors may want to know whether you have a repeatable process for updating:
- Operating systems
- Web browsers
- Business applications
- Firewalls and routers
- VPN appliances
- Servers
- Cloud applications
CISA recommends prioritizing internet-facing systems and known exploited vulnerabilities. Your organization should also know which devices and applications it owns. You cannot secure technology you have forgotten about.
A documented patch schedule is a good start. Better still, maintain an asset list, record patch status, and create an escalation process for systems that cannot be updated immediately.
This is where proactive managed IT services can make a measurable difference. Updates should not depend on someone remembering to handle them after a busy day.
5. A written incident response plan
When an incident begins, you should not be deciding who to call while watching files disappear.
An incident response plan explains what happens next, who makes decisions, and how the business communicates. It should cover:
- Who receives the first alert
- Who has authority to isolate systems
- How you contact your IT or security provider
- How you notify your insurance carrier
- When legal counsel becomes involved
- How you communicate with employees and customers
- How you preserve evidence
- How you restore operations
CISA recommends maintaining and exercising an incident response plan, including communication and notification procedures.
Run through a simple scenario at least once a year: an employee clicks a phishing link, a finance account is compromised, or ransomware begins encrypting shared files. What happens during the first 15 minutes?
That conversation can reveal gaps before a real emergency exposes them.
6. Security awareness training and email protection
Your employees are not the problem. They are people working quickly, handling customer requests, and trying to keep your business moving.
But even careful people can be fooled by a realistic message.
Training should teach employees how to recognize phishing, report suspicious activity, verify payment changes, and respond to urgent requests. Keep records showing who completed the training and when.
Your email domain should also use:
- SPF, which identifies approved sending servers
- DKIM, which adds a digital signature to outgoing messages
- DMARC, which tells receiving systems how to handle suspicious messages
These controls help reduce spoofing, where criminals make an email appear to come from your business.
Add a verification rule for wire transfers, payroll changes, and vendor bank-account updates. A quick phone call using a trusted number can prevent a costly mistake.
7. Access control, secure remote work, and monitoring
The final control is really a group of connected safeguards: only the right people should access the right systems, from secure devices, with activity recorded.
Insurers and auditors may look for:
- Unique passwords and password managers
- Separate administrator accounts
- Least-privilege access
- Prompt removal of former employees
- MFA for remote access
- Secure VPN or cloud access
- A separate guest Wi-Fi network
- Firewall protection
- Network segmentation
- Centralized logging and alert review
Least privilege means employees receive only the access they need to do their jobs. If one account is compromised, that limits how far an attacker can move.
This matters whether your business is in downtown St. Louis, St. Charles County, Chesterfield, Clayton, O’Fallon, or the Metro East. A small office still has sensitive email, financial information, customer records, and systems that keep revenue moving.
What to gather before your insurance renewal
Do not wait until an application is sitting in front of you. Start building an evidence folder now.
Include:
- MFA coverage reports
- Endpoint protection status
- Backup and restore reports
- Patch-management records
- Security awareness completion records
- Incident response and continuity plans
- User-access reviews
- Network diagrams
- Vendor security documentation
This turns your cybersecurity program from a collection of promises into something you can demonstrate.
If you are reviewing ransomware defenses specifically, read Ransomware Protection for St. Louis Small Businesses. You can also review Managed IT Services in St. Louis: 7 Things Your Provider Should Be Doing for You to see what proactive support should include.
The goal is more than getting a policy
Cyber insurance can help with certain costs after an incident, but it does not replace prevention. It also does not guarantee that every claim will be covered if the controls described in your application were not actually in place.
Accuracy note: Insurance requirements vary by carrier, industry, policy, renewal date, contract, and risk profile. Review your specific application and policy with your insurance professional, and have legal counsel advise you on notification or regulatory obligations.
Platinum Web Services helps small businesses build practical cybersecurity solutions for small business, including proactive monitoring, ransomware protection, secure backups, access control, and managed IT services Missouri companies can rely on.
From St. Louis and St. Charles County IT support to Chesterfield IT services, Clayton IT consulting, O’Fallon IT support, and Metro East IT support, the goal is the same: fewer surprises, stronger security, and more peace of mind.
Platinum Web Services provides 24/7 support for IT emergencies. You can reach us at support@platinumwebservices.net or visit us at 7827 Town Square Ave, 104-1184, O’Fallon, MO 63368.
You do not need to solve every security issue in one afternoon. Start with the seven controls insurers are asking about, and make sure you can prove each one works.


0 Comments