5 steps to lower your cyber insurance

Table of Contents

How to Secure Better Rates for Cyber Insurance

Today, the double-edged sword called cyber insurance is both a must-have and a safeguard that’s increasingly difficult to acquire and afford.

In 2022, cyber insurance coverage is more elusive for companies than it was in 2021—and chances are strong that that trend will continue. Why is it so scarce and costly? The explosion of ransomware and cyber attacks means that for carriers, cyber insurance has simply become a less enticing area of business.

As specialized carriers such as SeedPod Cyber know all too well, ransomware attackers spare virtually no one. The company’s recent white paper points out that although firms with more than $1B in revenues are twelve times more likely to experience a data breach compared to firms with less than $10M in revenue, the most frequently targetted size of firm in Q4 of 2021 had just 133 employees.

In such a high-risk climate, cyber carrier requirements are becoming so strict and detailed for policy qualifications that a great many organizations simply can’t meet them. This makes it all the more critical for both MSPs and their customers to adopt recognized security standards and then adapt them to changes in the cyber threat landscape.

Although a great many MSPs are less adept at securing cloud IT compared to traditional on-premises applications and systems, the scope of protection that clients and cyber insurers see simply can’t end at the office door; it has to extend across all applications, internal or external, on-prem or cloud. Only that degree of comprehensiveness will give carriers the necessary confidence to underwrite cyber risk at affordable premiums.

So how can proactive MSPs take charge of their clients’ cyber security in ways that optimize protection and greatly improve their standing in the eyes of stringent cyber insurers? Here’s a five-step plan.

Step 1. Conduct a comprehensive SaaS discovery app audit 

You can’t secure what you can’t see. SaaS proliferation has given rise to risky Shadow IT, the unauthorized apps that employees and departments often add on their own, opening additional doors for cybercriminals. Fortunately, an auditing tool such as Augmentt Discover gives you full visibility into the SaaS apps in a client’s ecosystem, providing the insight required to address Shadow IT and improve the overall security posture that cyber insurance carriers evaluate.

 

Step 2. Leverage global security threat reports to identify and highlight active risk.

These days, a mainstay platform like Microsoft 365 has millions of fraudulent sign-in attempts happening each day—but how do MSPs gain visibility into these and other threats on a continuous basis? Threat reports like those enabled in Augmentt Secure can give them and their clients a clear and immediate picture of active risks, offering critical insights upon which to improve security policies and posture.

Step 3. Customize MFA alerts to focus on what matters most.

Alert fatigue is a significant problem in IT security largely because most alerts are after-the-fact reactions to issues that arise using the widest possible alerting scope. Thankfully Augmentt Secure is equipped with specialized alerts related to the all-important multi-factor authentication (MFA) security measure. Given how there a millions of alerts received daily by MSPs, Augmentt Secure helps them tune out the noise and focus on the MFA threats that matter most.

Step 4. Configure MFA policies to efficiently secure Microsoft 365

Multi-factor authentication is the single most important security setting for SaaS software. That’s why Augmentt Secure now combines alerting with time-saving MFA configuration capability, enabling MSPs to audit, monitor, and secure MFA directly from the Augmentt platform. Traditionally, M365 would require a security admin to click into each security policy and perform a lot of added configuration steps manually. Augmentt Secure eliminates these additional steps with a single, comprehensive view of which MFA policies are enabled.

Step 5. Document ongoing security improvements to share with clients and insurance carriers.

While MSPs often struggle to show the concrete value of their security services to clients, the customer-facing reports feature in Augmentt Secure lets MSPs track and illustrate exactly how they are protecting the client’s users and data. The reports also show security score improvements over time, something that both clients and their insurance carriers are highly interested to know about in detail.

Want to learn more?

Contact us to start a conversation on how Augmentt Secure can enable higher levels of protection leading to a lower level of cyber insurance costs.

Author
Gavin Garbutt
Co-Founder & Chairman of Augmentt

FAQ

Using our GDAP tool & Magic Link, setting up is easy! You can integrate with your CSP partner portal in minutes
Augmentt uses a combination of Microsoft Secure Score best practices as well as industry standards such as NIST & CIS. You can use the out of box templates to get started right away and even build your own custom templates to match your client requirements.
Out of box, Augmentt comes pre-configured to not be noisy. Very few Microsoft alerts are critical in nature so you will be receiving tickets for account breaches and not minor user log related events. That said, everything is customizable and you can turn alerts on & off to match your clients’ needs.
No. You can choose to schedule alerts to any stakeholder you want and at the frequency you want or manually download reports when you need them.
Regardless of how MFA is managed across your tenants, we have you covered. Augmentt supports Conditional Access Policies, Security Defaults, Entra ID per user (Legacy) MFA as well as 3rd party MFA services like DUO.
No. You can use Augmentt to monitor and manage all clients regardless of their licensing. For environments with no premium licensing you can still provide alerts and monitoring for account breaches and configure security best practices. For environments with premium licensing, you can leverage Microsoft’s premium alerts and premium security configurations such as Conditional Access Policies.
Augmentt is one of the few vendors SOC 2 Type II, and GDPR compliant.
Site licenses to make sure you can deliver standardized service across all clients very affordably.

SUBSCRIBE for more resources

Related Content

Policy Sprawl Is Killing MSP Efficiency
Policy sprawl is quietly draining your margins, creating security gaps, and eroding client trust. The good news? Standardization is the cure.
Does Microsoft Secure Score Tell the Whole Story?
Do you have a complete understanding of your security? See why MSPs need to understand the role licensing plays in Secure Score results.
Top 10 M365 Security Best Practices for MSPs
Here are the top M365 security best practices to help you enhance protection, ensure compliance, and stay ahead of emerging threats.