
Cyber insurance in PR: what it covers, what it does not, and prerequisites
Buying a policy without MFA and tested backups is an expensive ticket to denied claims. A guide for owners hearing "you need insurance now."
Brokers in Puerto Rico push cyber insurance after Caribbean incidents — and they are right that risk exists. But policies are not amulets: carriers require increasingly technical questionnaires on MFA, EDR, off-site backups, and segmentation. Lying on the form is a direct path to claim denial when ransomware hits.
Understand coverage: incident response and forensics, extort
Understand coverage: incident response and forensics, extortion (with legal nuances), business interruption, third-party liability. What rarely covers: gross negligence fines, declared cyber war, or pure reputational damage. Read exclusions with your attorney; not just the broker summary.
Use underwriting as free audit: if you cannot meet requireme
Use underwriting as free audit: if you cannot meet requirements today, prioritize controls before paying high premium for fictional coverage. NIST CSF and CIS Controls are references some carriers explicitly recognize.
Document controls: MFA enforced screenshots, backup test report, patch policy. On claim, the adjuster asks for evidence hours after the incident — not weeks. Keep IR firm contact on the policy updated.
Insurance + baseline controls is sensible for SMBs handling card data, health, or government contracts. Insurance without controls is expensive theater. Controls without insurance may work for some; evaluate risk retention with real peak-season downtime numbers.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


