It’s Monday morning at a small manufacturer in Sterling Heights. The bookkeeper gets an email from a longtime supplier: “We changed banks. Please send this week’s payment to our new account.” It looks real. It isn’t. The money is gone before lunch.

Stories like this happen in Michigan every day. In 2025, Michiganders filed more than 22,000 internet crime complaints with the FBI, reporting about $381 million in losses.[1] Small businesses get hit the most. In one major 2026 study, about 96% of ransomware victims were small and mid-sized businesses.[2]

Cyber insurance can help you recover from a day like that. But getting a policy isn’t as simple as it used to be. This guide explains it in plain English: what it covers, what insurers will ask you, and how to get ready.

// Short answer

To get cyber insurance, you need to put a few security basics in place first (a second login step on email, modern security software, safe backups, regular updates, staff training, and a call-back rule for payments). Then work with a licensed agent, answer the application honestly, and read what the policy does not cover. Not sure where you stand? Take our free Cyber Insurance Readiness Check.

What is cyber insurance?

Think of it like insurance for a break-in, except the burglar comes in through your computers. Coverage usually falls into two groups:[3]

// Your own costs
  • Experts to find and fix the problem
  • Getting your data and systems back
  • Letting customers know their information was exposed
  • Income you lose while you’re shut down
  • Ransom demands and some kinds of fraud
// Costs when others blame you
  • Lawyers if customers or partners sue
  • Settlements and court judgments
  • Dealing with government investigations

Every policy is different. Some cover a lot, some cover very little. That’s why reading the details matters (more on that below).

What insurers will ask you

A few years ago, the application was a page or two. Currently, it reads more like a security checkup. Insurers want proof that you’ve done the basics, and generally ask about the same things.[4] Here they are in plain English:

  • A second login step (MFA). Similar to when your bank texts you a code. Insurers want this on email, remote logins, and admin accounts. It’s usually the first thing they ask about.[5]
  • Modern security software. Basic antivirus isn’t enough anymore. Insurers look for tools (called EDR) that spot unusual behavior and alert someone right away.
  • Backups hackers can’t reach. If your only backup is plugged into the same network, ransomware can lock it too. One copy of the backup should be kept offline or locked so it can’t be changed.
  • Regular updates. Install security updates on a schedule, and replace computers and software the manufacturer no longer supports.
  • Staff training. Most attacks start with a fake email. Short yearly training and practice “phishing” emails help people spot them.
  • A call-back rule for payments. Before changing anyone’s bank details or sending a wire, call them at a phone number you already have on file. Insurers ask about this directly.[6]
  • A written plan. A simple page that says who to call and what to do if you get hacked.

A Michigan example

Let’s go back to that Sterling Heights company. They are a 25-person shop and use Microsoft 365 for email, have a server sitting in the back room, and rely on a software vendor that remotely accesses the system when support is needed.

When the owner asks their insurance agent for a cyber insurance quote, the agent sends over an application. The owner works through it with their IT provider, and discovers several gaps they hadn’t realized were there.

  • Most employees are required to use a second login step on email, but the shared “accounting” mailbox does not.
  • The vendor’s remote login only requires a password.
  • The computers have basic antivirus only but no endpoint security.
  • Backups are stored in a box in the same room, on the same network. Nobody has tested them in a year.

There is another weakness that has nothing to do with technology. Changes to bank or payment information are approved through email. There is no requirement to verify the request by phone.

The owner could simply check “yes” on the insurance application and move on. After all, nobody wants to admit their business has security gaps. But that creates a much bigger problem. If a claim occurs later, inaccurate answers on the application can become an issue when the insurance company investigates what actually happened.

Instead, the owner decides to fix the problems.

Over the next three months, the IT provider strengthens Microsoft 365 security, secures the vendor’s remote access, upgrades endpoint protection, moves backups away from the production network, establishes a regular backup testing process, and implements a simple but important rule: any request to change banking or payment information must be verified by phone using a trusted number already on file.

Once the changes are in place, the owner completes the insurance application based on the environment that actually exists.

A few weeks later, an email arrives that appears to be from a supplier. Their banking information has supposedly changed, and the bookkeeper is asked to send the next payment to a new account.

Under the old process, the request might have been approved with nothing more than an email reply.

Under the new process, the bookkeeper calls the supplier using the number already on file.

The supplier didn’t send the email.

The attempted fraud ends with a phone call instead of a wire transfer.

That is the point of a good cyber insurance process. The goal isn’t to find the right boxes to check on an application. It’s to uncover the weaknesses that could cost the business money, disrupt operations, or create a much larger problem after an incident occurs.

Getting ready for insurance made the business safer before the policy ever had to pay.

How to get cyber insurance in 6 steps

  1. Know what you have

    Make a simple list: your computers, the software and cloud services you use, and where you keep sensitive information like customer records, employee files, or card numbers.

  2. Check your current policies

    Ask your agent if any policy you already have includes cyber coverage, and how much. It’s often small.

  3. Fix the basics first

    Work through the list above. Fixing gaps before you apply usually gets you better options than explaining them after.

  4. Find a licensed agent

    Look for an agent or broker who knows cyber policies. In Michigan, you can check their license for free with the state’s Department of Insurance and Financial Services (DIFS).[7]

  5. Answer honestly, with your IT person

    Fill out the application together with whoever runs your IT, and save proof like screenshots and backup reports. A wrong answer can cost you the whole policy.[8]

  6. Read the fine print, then keep it up

    Compare what each policy covers, not just the price. After you buy, put the insurer’s hotline in your emergency plan and keep your security basics in place until renewal.

How ready are you right now?

Answer 12 quick yes-or-no questions and get a readiness score, a simple to-do list, and a checklist you can print for your agent. Free, no email needed.

Take the Readiness Check

Fine print to watch for

Ask your agent about these before you sign:

  • Smaller limits inside the policy. A $1 million policy might pay much less for certain things, like wire fraud.
  • Waiting periods. Lost-income coverage often doesn’t start until you’ve been down for a set number of hours.
  • Call first. Most policies require you to call the insurer before hiring help or paying anything, including a ransom.[9]
  • Things that aren’t covered. Problems you already knew about, some attacks linked to wars or foreign governments, and upgrades you make after an attack are common exclusions.

Michigan rules to know

  • Telling customers about a breach. Michigan law generally requires businesses to notify affected Michigan residents, without unreasonable delay, when certain personal information (like Social Security or bank account numbers) is exposed. Knowingly skipping a required notice can lead to fines.[10] A lawyer can tell you what applies to you.
  • Checking your agent. Use the free DIFS license lookup before you share details about your business.[7]
  • Reporting a cyber crime. Contact the Michigan State Police Cyber Command Center at 877-MI-CYBER or mc3@michigan.gov. They also recommend reporting to the FBI at ic3.gov.[11]

Your cyber insurance checklist

Print this out and check off what you already have. Anything unchecked is a good place to start.

Logins

  • Second login step (MFA) on every email account, including shared ones
  • Second login step on remote access and vendor logins
  • Second login step on admin accounts

Computers

  • Modern security software (EDR) on every computer and server
  • Security updates installed on a regular schedule
  • No old, unsupported computers or software

Backups

  • One backup copy kept offline or locked so it can’t be changed
  • A test restore in the last 12 months that actually worked

People and money

  • Email filtering that catches scam messages
  • Yearly security training with practice phishing emails
  • Call-back rule before any bank change or wire

Paperwork

  • A one-page plan for what to do if you’re hacked
  • A list of past incidents to share honestly on the application
  • Your agent’s license checked with DIFS

If you get hacked

  1. Call your insurer’s hotline and your agent first, before paying anyone.
  2. Unplug affected computers from the network, but don’t wipe them.
  3. Call your bank right away if money was sent.
  4. Report it to the Michigan Cyber Command Center (877-MI-CYBER) and the FBI at ic3.gov.
  5. Talk to a lawyer about whether you need to notify customers.

Frequently asked questions

What is cyber insurance?

Cyber insurance is a business insurance policy that helps pay for the costs of a cyberattack or data breach. That can include hiring experts to fix the problem, notifying customers, lost income while you are down, and legal costs if someone sues. What is covered depends on the policy you buy.

Do Michigan businesses have to carry cyber insurance?

We are not aware of a Michigan law that requires a typical private business to buy cyber insurance. The push usually comes from somewhere else: a big customer, a lender, or a contract that asks you to carry it. Check your contracts, and ask an attorney if you are not sure.

How much does cyber insurance cost for a small business?

Only an insurance company can give you a real price. It depends on your industry, your revenue, how much customer data you keep, how much coverage you want, and how well your systems are protected. Businesses with strong security basics usually have more choices.

What do insurance companies ask before they will cover me?

Most applications ask whether you use a second login step (MFA) on email and remote access, whether computers have modern security software, whether you have backups hackers cannot reach, how you install updates, whether staff get security training, and how you check payment requests before sending money.

What is MFA and why do insurers care so much about it?

MFA, or multi-factor authentication, means logging in takes two steps, like a password plus a code or a tap on your phone. It stops many attacks that start with a stolen password, which is why insurers ask about it on almost every application.

What happens if I answer an application question wrong?

Insurers rely on your answers when they decide to cover you. If an answer turns out to be untrue, the insurer may fight a claim or even cancel the policy. In one 2022 case, a court declared a policy void after the insurer said a company had overstated its use of MFA. Answer honestly, with help from whoever runs your IT.

Will cyber insurance pay a ransom?

Some policies include coverage for ransom demands, usually with conditions. Most insurers require you to call them before paying anything, and paying certain criminal groups can break federal rules. Call your insurer and a lawyer first.

Does my regular business insurance already cover cyberattacks?

Maybe, but often not much. Some business policies include a small cyber add-on with low limits. Ask your agent to show you exactly what your current policy says before you assume you are covered.

Who should I buy cyber insurance from?

Work with a licensed insurance agent or broker who knows cyber policies. In Michigan you can confirm an agent's license for free on the Department of Insurance and Financial Services (DIFS) website.

Can Wizcom sell me cyber insurance?

No. Wizcom is a technology company, not an insurance agency. We help businesses put the security basics in place and document them, so you can answer an application with confidence. Your licensed agent handles the insurance itself.

Get Ready Before You Apply

For more than 40 years, Wizcom has helped Michigan businesses keep their technology safe and running. We can check your setup, fix the gaps insurers ask about, and help you document everything, so your application is easy and honest.

Schedule Your Free IT Strategy Session

Sources

  1. 1. Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report, 2026.
  2. 2. Verizon Business, 2026 Data Breach Investigations Report, 2026.
  3. 3. Federal Trade Commission, Cyber Insurance (Cybersecurity for Small Business), accessed Sept. 30, 2026.
  4. 4. Marsh, Cyber resilience: Twelve key controls to strengthen your security, Apr. 2022.
  5. 5. Travelers, Multi-Factor Authentication Supplement (CYB-14306), Rev. 03-23.
  6. 6. Travelers, Social Engineering Fraud Short Form Supplement (CYB-14301), accessed Sept. 30, 2026.
  7. 7. Michigan Department of Insurance and Financial Services, DIFS Reminds Consumers to Verify That Their Insurance Agent Is Licensed, Apr. 17, 2023.
  8. 8. U.S. District Court, C.D. Illinois (via CourtListener), Travelers Property Casualty Co. of America v. International Control Services, Inc., No. 2:22-cv-02145, filed July 6, 2022.
  9. 9. National Association of Insurance Commissioners, Ransomware (Insurance Topics), updated Dec. 19, 2025.
  10. 10. Michigan Legislature, MCL 445.72, Identity Theft Protection Act (Act 452 of 2004), as amended through 2010 PA 315.
  11. 11. Michigan State Police, Michigan Cyber Command Center (MC3), accessed Sept. 30, 2026.

Sources checked September 30, 2026. Figures are as reported by each source.

Scott VanCoppenolle
Chief Technology Officer at Wizcom

Scott VanCoppenolle

Scott VanCoppenolle is the Chief Technology Officer at Wizcom Ltd, where he helps organizations transform technology from a constant headache into a strategic advantage. With more than two decades of experience leading enterprise IT initiatives, Scott has architected nationwide infrastructure modernizations, unified communications platforms, cloud migrations, cybersecurity programs, disaster recovery strategies, and business-critical software implementations for organizations of every size. His passion lies in simplifying complex technology and helping businesses leverage it to work smarter, communicate better, and grow with confidence, allowing them to get more from their technology while spending less time worrying about it.

Born and bred in the heart of Detroit, when he isn't architecting IT solutions, or writing about the trends, tools, and ideas shaping the future of business technology, you'll likely find him in the garage bringing vintage cars and classic motorcycles back to life. Whether it's rebuilding an engine or an IT infrastructure, Scott believes the best results come from understanding how every part works together. LinkedIn.