Small businesses have always been difficult to bring into the cyber insurance market. Cost gets much of the blame, along with complexity and the lingering belief among some smaller companies that cyber insurance simply isn’t something they need. But there may be another reason hiding in the application process itself. Insurance Business recently reported comments from a cyber underwriter who argued that insurers may actually be contributing to slow SME adoption because businesses interested in coverage can find themselves staring at eight or ten pages of questions about cybersecurity controls, systems, vendors, backups and recovery capabilities.

The obvious conclusion is that the application is too complicated, and there’s probably some truth to that. But I think there’s something more interesting going on. Maybe the problem isn’t that small businesses don’t understand cyber insurance. Maybe cyber insurance is exposing how little some businesses understand about their own operations and the technology they depend on to run them.

Think about what an insurer needs to know before agreeing to take on cyber risk. They need information about MFA, backups, privileged access, vendors, incident response, recovery and other things that could affect the likelihood or severity of a loss. Those aren’t unreasonable questions. The problem is that answering them often requires knowledge spread across several people and companies. The owner knows part of it, the IT provider knows another part, operations understands how certain systems are actually used, and a software vendor may know something nobody inside the company does. By the time everyone starts trying to complete the application, they may discover that nobody has ever pulled all of that information together.

That discovery matters well beyond insurance. If nobody knows whether the backups can actually be restored, the problem isn’t that someone is having trouble answering an underwriting question. The company has just learned something important about its ability to recover. The same is true if nobody can identify which vendors have privileged access or explain how long the company could operate without a critical system. The insurance application didn’t create those problems. It simply forced someone to ask questions that apparently hadn’t been asked before.

That’s why I’ve started thinking about cyber insurance underwriting as an accidental business stress test. Insurers didn’t design the application to determine whether the company can survive a serious disruption. They’re trying to understand the risk they’re being asked to insure and price it accordingly. But many of the questions they need answered happen to touch the same dependencies and assumptions that determine what happens when something actually goes wrong.

There is an important difference between answering an underwriting question and understanding what the answer means to the business. An insurer may need to know whether backups exist, while the business should probably be more concerned with how long restoration actually takes and what stops working while that happens. An application might ask whether there is an incident response plan, but having a document somewhere doesn’t tell you much about what happens when customer orders stop processing on a Sunday morning and the people named in the plan are suddenly expected to make decisions under pressure.

Vendors create the same problem. A company may have a perfectly reasonable third-party risk process and be able to answer the related insurance questions correctly without anyone understanding which provider could create the greatest operational problem if it disappeared tomorrow. That distinction between having the right answer and understanding what happens in the real world is where a lot of hidden fragility lives.

This is also where businesses can get the cyber insurance process wrong. It’s easy to treat underwriting as another exercise that needs to be completed. The company answers the questions, implements whatever additional controls are required, gets the policy and moves on. That may produce a more insurable company, and some of the required controls may genuinely reduce risk, but neither automatically tells us how well the company will function when a serious incident occurs.

Cyber insurance remains incredibly important because a major incident can create significant financial consequences, and transferring some of those consequences to an insurer can make an enormous difference. But the policy itself doesn’t keep the company operating. It doesn’t process customer orders while systems are unavailable or restore the production environment. It can help pay for recovery and replace certain financial losses, but the company still has to deal with everything happening between the beginning of the incident and whatever recovery eventually looks like.

That’s why I think businesses should approach underwriting a little differently. Getting coverage obviously matters, but there’s value in paying attention to what the process reveals along the way. When someone struggles to answer a question, the first instinct shouldn’t always be to figure out what needs to go in the box. Sometimes the better question is why the company doesn’t know the answer in the first place and whether that uncertainty matters to the operation of the business.

Even companies that can answer every underwriting question confidently can still have significant hidden fragility. Backups may exist but take much longer to restore than anyone expects. MFA may be widely deployed while a handful of important systems or service accounts remain outside it. An incident response plan may be current on paper even though the leadership team has never exercised it together. The company may also have a mature vendor management program without understanding that one relatively obscure provider sits underneath several critical business processes.

Those details matter because serious business disruption rarely stays inside the category where it started. A cyberattack can become an outage, and the outage can begin interfering with operations while recovery takes longer than expected. Customers eventually feel the impact and revenue can follow. At the same time, leadership is trying to understand what happened, restore systems, communicate with stakeholders and determine what insurance will ultimately cover. What started as a security incident has become a much broader business problem.

This is particularly important for smaller companies because they rarely have the organizational infrastructure available to large enterprises. There may not be separate security, risk, business continuity, architecture, internal audit and insurance functions looking at different parts of the organization. In many smaller businesses, the cyber insurance application may actually be one of the few times someone forces the company to look across several of these areas at once, which makes the difficulty of completing it potentially useful information.

That’s also why I’m not convinced the answer is simply making cyber insurance applications easier. There are clearly opportunities to simplify the process, particularly when owners are being asked highly technical questions they have little chance of answering without help. But eliminating every difficult question risks eliminating some of the value hidden in the process. Every time someone has to stop and say they don’t know, there’s an opportunity to find out whether they just discovered an administrative inconvenience or something the business genuinely needs to understand.

Cyber insurance underwriting is becoming more sophisticated because the risk itself has become more complicated, so some friction is probably inevitable. What businesses do with that friction is more interesting. If answering basic questions about security, technology dependencies, vendors and recovery is difficult while everything is operating normally, trying to figure those things out during an actual incident is going to be considerably harder.

The objective should still be obtaining the right coverage, but there’s no reason the value of underwriting has to end there. A company that finishes the process with a better understanding of what it depends on, where its assumptions are weak and what could interfere with recovery has gained something beyond an insurance policy. It has learned something about its ability to survive the event the policy was purchased to cover in the first place.

That’s ultimately what I think matters. Cyber insurance asks whether the risk can be insured and under what conditions. Business survivability asks what happens to the company when that risk becomes real. The more useful underwriting becomes at exposing the gap between those two things, the more valuable the process may actually be.