Three years ago, a cyber insurance application was a checkbox exercise. Do you have antivirus? Yes. Do you have a firewall? Yes. Do you back up your data? Yes. Approved.
That era is over.
Today's underwriters are asking detailed, specific questions about your technology environment — and the answers your team gives will determine not just your premium, but whether you get coverage at all. For mid-market manufacturers and distributors, this shift is creating a new category of technology risk that most companies are not prepared for.
What the application is actually asking
The modern cyber insurance application is, in effect, a technology audit. Underwriters want to know about your ERP and core systems: what version are you running, when was it last patched, who has administrative access and how is that access controlled, do you have multi-factor authentication on remote access to production systems.
They want to know about your access controls: how do you manage privileged accounts, what happens to system access when an employee leaves, do you have a formal process for reviewing and revoking access or does it happen informally when someone remembers to do it.
They want to know about your incident response: do you have a documented incident response plan, has it been tested, who is responsible for executing it and do they know that.
They want to know about your backups: where are they stored, are they isolated from your production environment, when did you last test a restore.
These are not abstract questions. Underwriters have learned, from years of claims data, exactly which control failures lead to the most expensive incidents. They are asking about those failures specifically.
Why mid-market companies are particularly exposed
Large enterprises have dedicated security teams whose job is to maintain the documentation and controls that underwriters are asking about. Small businesses often qualify for simplified applications that don't probe this deeply.
Mid-market companies — roughly $20M to $250M in revenue — frequently fall into a gap. They have complex enough technology environments that the detailed questions apply, but they often lack the dedicated security staff to maintain the answers.
The result is a technology team that knows the systems work, but cannot easily produce the documentation that proves the controls are in place. That gap — between operational reality and documented evidence — is what creates insurance risk.
The ERP problem specifically
For manufacturers and distributors, the ERP system is the center of the technology environment. It holds financial data, customer data, supplier data, and operational data. It is also, in many mid-market companies, the system that is least well-governed from a security perspective.
ERP systems are complex. They have been customized over years. They have user accounts that were created for people who left the company. They have integrations with other systems that were built by consultants who are no longer engaged. The administrative access is often broader than it needs to be, because restricting it would require understanding the system well enough to know what each permission actually does.
When an underwriter asks about your ERP access controls, the honest answer at many mid-market companies is: we're not entirely sure. That answer — or the evasion of it — is what drives premiums up and coverage down.
What to do before your next renewal
The goal is not to pass the application. The goal is to actually have the controls in place, and to be able to document them clearly.
Start with an access review. Who has administrative access to your ERP, your financial systems, and your network infrastructure? Is that access still appropriate? When was it last reviewed?
Document your patch status. What versions are your core systems running? What is your process for applying patches, and how current are you?
Test your backups. Not just that they run, but that you can restore from them. A backup that has never been tested is not a backup — it is a hope.
Write down your incident response process. It does not need to be a 50-page document. It needs to be clear enough that the people responsible for executing it know what to do when something goes wrong at 2 AM.
None of this is glamorous work. But it is the work that determines whether your cyber insurance renewal is a routine administrative task or a crisis.
If you're not sure where your technology environment stands relative to what underwriters are asking, a discovery call with CTO360 is a good place to start. We've been through this process with mid-market manufacturers and distributors, and we know what the gaps typically look like.
Written by
David Rosenberg
Fractional CTO with 35 years of enterprise technology leadership across manufacturing, distribution, and professional services.
Schedule a Discovery Call