
Cyber insurance in PR: controls underwriting demands
MFA, EDR, offline backups: what insurers require before issuing policies in Puerto Rico.
Renewing cyber insurance in 2025 for a Puerto Rico SMB is no longer a three-question form. Continental underwriters serving Puerto Rico require evidence: MFA on email and admin, deployed EDR, offline/immutable backups, documented patch management, and incident response plan. Krebs on Security reports policies denied post-incident for control misrepresentation — honesty in application is legally critical.
Prepare evidence before application: GPO MFA enforcement screenshots, EDR dashboard coverage %, last restore test date, password policy. CISA Cybersecurity Performance Goals align with many carrier questions — use as prior internal self-assessment. Understating controls saves short-term premium; loses coverage when it matters most.
Common exclusions: cyber warfare acts, uncovered regulatory fines, reputation lost revenue. Negotiate ransomware extortion sub-limits and coinsurance. Local attorney familiar with continental insurance contracts reviewing endorsements applicable to PR operations.
Minimum controls for reasonable premium at 50–200 employees: universal MFA, EDR, advanced email filtering, quarterly tested backups, documented annual security awareness. Bruce Schneier notes risk transfer via insurance does not eliminate due care obligation — insurer may deny claim for gross negligence.
Work with cyber-specialized broker, not generalist P&C only. Compare 2–3 carriers; coverage and exclusions vary more than price. Insurance is final program layer, not MFA substitute. Document continuous improvement — favorable renewal correlates with demonstrable maturity, not just year-one checkbox.

Operations and execution — connecting strategy with what the team ships every week.


