Cyber insurance requirements for Florida businesses, in plain English

  • Ron Slyker, CEOWritten by
  • Published
  • Reading time7 min read
Radiant Technology Solutions technician reviewing a monitoring dashboard on dual monitors

Short answer

Cyber insurers commonly ask small businesses to prove seven controls before they quote: multi-factor sign-in, EDR on every computer, backups ransomware cannot reach, email security, prompt patching, staff security training and tight control of admin accounts. Florida adds a 30-day breach notice deadline under section 501.171 of the Florida Statutes.

Renewal season now brings a questionnaire that reads like an IT audit. For a law office in Clearwater or a practice in Palm Harbor, it lands on the owner's desk.

Here is what those questions mean in plain English, which controls matter most, and how to answer honestly without losing your coverage.

Why are cyber insurers asking so many questions?

Insurers now price cyber risk by the security controls you have in place, not only by your industry and revenue.

Marsh McLennan, the insurance broker, published research in April 2023 on twelve control categories it describes as commonly required by cyber insurers.

In that Marsh McLennan study, the five controls tied most closely to fewer successful attacks were system hardening, multi-factor sign-in, privileged access management, fast patching and EDR.

That is why the questionnaire is so specific. Each yes or no tells the underwriter how likely you are to file a claim.

Which security controls do insurers require in 2026?

Applications differ by carrier, but these seven controls come up again and again. Each one is simpler than its name suggests.

  1. 01

    Multi-factor authentication (MFA)

    a second proof of identity, like a phone prompt, every time someone signs in to email or remote access.

  2. 02

    Endpoint detection and response (EDR)

    software that spots an attack on a laptop or server and stops it, beyond what old antivirus catches.

  3. 03

    Offline or immutable backups

    copies of your data that ransomware cannot reach, change or delete, tested so you know they restore.

  4. 04

    Email security

    filtering that blocks phishing messages and poisoned attachments before your staff ever see them.

  5. 05

    Patching

    installing security updates for Windows, apps and network gear promptly, instead of whenever someone gets around to it.

  6. 06

    Security awareness training

    short, regular lessons and practice emails that teach your team to spot a scam.

  7. 07

    Privileged access control

    keeping admin accounts few, separate from everyday logins, and protected with MFA and strong passwords.

Many applications also ask whether someone watches your security alerts around the clock. That service is called MDR, meaning people monitoring the EDR software 24/7.

Which Radiant plan covers each control?

Our three plans map directly onto that list. Here is where each control lives, taken from our 2026 plan brochure.

Insurer controls by Radiant planWhat each plan includes for the controls insurers ask about most.
Radiant BasicRadiant AdvancedRadiant Elite
MFANot includedNot includedEnhanced MFA
EDRManaged anti-virus onlyIncludedIncluded
24/7 monitoring (MDR)Not includedIncludedIncluded
Email securityNot includedIncludedIncluded
BackupsScoped in your assessmentCloud-to-cloud backupCloud-to-cloud backup
PatchingRemote monitoring and maintenanceRemote monitoring and maintenanceRemote monitoring and maintenance
Security awareness trainingNot includedNot includedIncluded
Admin and password controlScoped in your assessmentScoped in your assessmentSecure password management
  • Radiant Elite

    MFA
    Enhanced MFA
    EDR
    Included
    24/7 monitoring (MDR)
    Included
    Email security
    Included
    Backups
    Cloud-to-cloud backup
    Patching
    Remote monitoring and maintenance
    Security awareness training
    Included
    Admin and password control
    Secure password management
  • Radiant Advanced

    MFA
    Not included
    EDR
    Included
    24/7 monitoring (MDR)
    Included
    Email security
    Included
    Backups
    Cloud-to-cloud backup
    Patching
    Remote monitoring and maintenance
    Security awareness training
    Not included
    Admin and password control
    Scoped in your assessment
  • Radiant Basic

    MFA
    Not included
    EDR
    Managed anti-virus only
    24/7 monitoring (MDR)
    Not included
    Email security
    Not included
    Backups
    Scoped in your assessment
    Patching
    Remote monitoring and maintenance
    Security awareness training
    Not included
    Admin and password control
    Scoped in your assessment

Plan contents from the Radiant Technology Solutions 2026 brochure. Backups of servers and on-site files, and admin account setup, are scoped through our backup and cybersecurity services.

If your insurer asks for all seven, Elite is the plan that lists them together. Our cybersecurity service covers setup, and backup and disaster recovery covers the offline copies.

You can compare the plans side by side on our managed IT pricing page.

How does a cyber insurance questionnaire work?

The application is a list of yes or no questions about your controls, signed by an owner or officer. The insurer relies on those answers to set your price and terms.

The hard part is that many questions sound simpler than they are. "Do you use MFA?" often really means every email account, every remote login and every admin account.

  • Answer for how things are today, not how they will be after a planned project.
  • If a control covers only part of the office, say so, or ask your broker how to note it.
  • Keep proof: screenshots, reports or a letter from your IT provider showing each control is on.
  • Fill it out with your IT provider in the room, because they know what is actually switched on.
  • Save a copy of the signed application with your policy documents.

What happens if a control was misreported?

A wrong answer usually surfaces at the worst moment: after an incident, when the insurer investigates how the attacker got in.

Say the application said MFA was on for all email, and the breach started with one mailbox that never had it. The insurer may question the claim.

Depending on the policy wording, that can mean a reduced payout, a denied claim, or in serious cases an attempt to cancel the policy for misrepresentation.

Does Florida have its own data security rules?

Yes. Section 501.171 of the Florida Statutes, known as the Florida Information Protection Act of 2014, requires businesses to take reasonable measures to protect personal information.

Under section 501.171, you must notify affected Floridians no later than 30 days after you determine a breach occurred.

If 500 or more Floridians are affected, section 501.171 also requires notice to the Florida Department of Legal Affairs within 30 days. Above 1,000 people at once, consumer reporting agencies must be told too.

Section 501.171 sets civil penalties for late notice that can reach $500,000. Personal information includes a name paired with details like a Social Security number, account number or medical information.

Medical practices also answer to HIPAA, which has its own breach rules. Our HIPAA compliance page and healthcare IT page cover that side.

Your cyber insurance readiness checklist

Walk through this with your IT provider before your next renewal. Every no is a question to fix or to disclose honestly.

  • MFA is on for every email account, not only the owner's.
  • MFA is on for remote access, VPN and every admin account.
  • Every computer and server runs EDR, not just antivirus.
  • Someone watches security alerts 24/7, in house or through MDR.
  • At least one backup copy is offline or immutable, and a restore was tested this year.
  • Microsoft 365 or Google Workspace data has its own backup.
  • Email filtering blocks phishing and malicious attachments.
  • Security updates install on a schedule, and old unsupported systems are replaced or isolated.
  • Staff completed security awareness training this year.
  • Admin accounts are few, separate from daily logins, and use a password manager.
  • You have a written plan for who to call first if a breach happens.
  • A signed copy of your last insurance application is on file.

Not sure how many of those boxes you can check? Our free network assessment walks through each one for offices in Tarpon Springs and across Tampa Bay.

Frequently asked questions

For most carriers, yes. MFA is one of the controls insurers ask about most, especially on email, remote access and admin accounts. Marsh McLennan's 2023 research counted it among the five controls most closely tied to fewer successful attacks. Without it, expect higher premiums, narrower coverage, or a declined application.

Usually not. Many applications now ask specifically about EDR, software that spots an attack on a computer and stops it, rather than traditional antivirus. Some also ask whether the alerts are watched around the clock. Check your application wording, then confirm with your IT provider which tool you actually run.

Section 501.171 of the Florida Statutes requires notice to affected Floridians within 30 days of determining a breach. If 500 or more Floridians are affected, you must also notify the Florida Department of Legal Affairs within 30 days. Above 1,000 people at once, consumer reporting agencies must be notified too.

Your IT provider should help, because they know which controls are actually switched on. The application is still signed by an owner or officer, so you are responsible for the answers. Sit down together, go question by question, and keep their written confirmation with your policy file.

Radiant blog

Keep reading

Two more plain answers from Ron for owners comparing IT options.

All posts
Ron Slyker, CEO of Radiant Technology Solutions

About the author

Ron Slyker

CEO and IT Solutions Expert

Ron runs Radiant Technology Solutions from Tarpon Springs and writes every article on this site. He has spent more than 15 years working for and managing IT consulting firms.

Read Ron's story