Business insurance insights

Cyber Insurance and Outsourced IT: What Your Provider Still Needs to Know

When you outsource IT support, your cyber insurer still evaluates your access controls, backup documentation, and incident-response process. Use this vendor responsibility matrix to map what stays with your business before your next renewal.

By PolicyBenchmark Editorial TeamPublished
Cyber Insurance and Outsourced IT: What Your Provider Still Needs to Know

This content is for informational purposes only and does not constitute insurance advice. Always consult with a licensed insurance professional before making coverage decisions.

What Your Cyber Insurance Provider Needs to Know When You Outsource IT

Outsourcing IT support does not transfer your cyber insurance obligations to your vendor. When you apply for or renew a cyber policy, the insurer is evaluating your security posture — including how you govern the people and systems that have remote access to your network. If your outsourced IT provider can reach your environment, that access is part of your risk story, and your insurer will want to understand how it is controlled.

The Federal Trade Commission advises businesses to limit vendor access to a need-to-know basis and only for the time the vendor needs to do the job, and to consider creating a separate database holding only the data points the vendor actually needs — rather than granting broad access to sensitive information. (FTC, Cybersecurity for Small Business) Those access-control decisions belong to you as the business owner, not to your IT vendor.

This article maps the responsibilities that typically stay with you, the responsibilities that vendors typically carry, and the information your insurer may need to understand both sides.

Why Vendor Remote Access Is a Coverage Question, Not Just an IT Question

Cyber insurance proposals and renewals routinely ask about how third parties connect to your systems. The FTC's guidance on cyber insurance specifically identifies coverage for cyber attacks on your data held by vendors and other third parties as a feature to look for in a policy — which implies that such attacks are a recognized and distinct exposure, not an automatic default. (FTC, Cyber Insurance Considerations for Small Businesses)

This matters practically because:

  • An incident that starts through a vendor's remote-access credential may be reported by the vendor, by you, or by both — and the timing and method of that report affects your response.
  • A policy may distinguish between a breach of your network and a breach of data held by a vendor; these can fall under different coverage parts.
  • Your insurer may ask whether you have documented access controls, authentication requirements, and a tested incident-response process — none of which your vendor controls on your behalf.

Before assuming your vendor's insurance covers a loss that originates through their access to your systems, ask your licensed insurance professional which entity's policy responds to which scenario, and how the two policies interact.

IT Responsibility Matrix: Who Owns What

This worksheet is organized around five risk areas. Fill in each row using your actual vendor contract, your policy application, and your current security documentation. Leave cells blank where you do not yet have a documented answer — those blanks are the questions to bring to your insurer or IT vendor.

How to use this matrix: Print or copy it. For each row, record (1) what your IT vendor's contract says they are responsible for, (2) what your business actually controls day-to-day, and (3) what your cyber insurance application or policy says about this area.


Risk Area 1: Remote Access Identity and Authentication

QuestionYour vendor's contract saysYour business controlsYour policy application describes
Who grants and revokes remote-access credentials for your network?
Does your vendor use multi-factor authentication (MFA) to connect?
Can you revoke vendor access immediately if there is a dispute or incident?
Are vendor remote sessions logged and reviewed?

The FTC warns that scammers sometimes ask victims to grant remote access, which then exposes all information on that computer and any connected network. (FTC, Cybersecurity for Small Business) Controlling who can initiate and terminate remote sessions is a business-owner responsibility, not one that can be fully delegated.


Risk Area 2: Data Access Scope

QuestionYour vendor's contract saysYour business controlsYour policy application describes
Which specific systems or databases can your IT vendor access?
Is vendor access limited to the minimum needed for each task?
Are customer or employee records in a separate database from operational tools?
Does access expire automatically after a job is complete?

The FTC recommends putting controls on databases with sensitive information and limiting vendor access to only the data the vendor needs to complete the job. (FTC, Cybersecurity for Small Business) Whether that separation exists — and how it is documented — is information an insurer may request.


Risk Area 3: Backup Ownership and Recovery

QuestionYour vendor's contract saysYour business controlsYour policy application describes
Who is responsible for scheduling and verifying data backups?
Where are backups stored, and can your vendor access that location?
What is the recovery time objective your vendor has agreed to?
Have backups been tested for restoration in the past 12 months?

Cyber insurance first-party coverage can include recovery and replacement of lost or stolen data, but the availability and integrity of your backups is something your insurer may evaluate as a prerequisite. (FTC, Cyber Insurance Considerations for Small Businesses) If your IT vendor controls backup verification, confirm in writing that those tests actually occur and that you receive reports.


Risk Area 4: Incident Detection and Response

QuestionYour vendor's contract saysYour business controlsYour policy application describes
Who is responsible for detecting a breach in your environment?
How does your vendor notify you of a suspected incident, and within what timeframe?
Who initiates forensic investigation — your vendor, your insurer's breach hotline, or a third party?
Do you have the vendor's 24/7 emergency contact information?

The FTC advises that breach investigation should determine how a hacker gained access, what data was reached, and help quarantine affected systems — and that this work should be carried out by experienced IT or cybersecurity staff or a contracted third party. (FTC, Cybersecurity for Small Business) Your cyber policy may specify who is authorized to engage forensic investigators; confirm that your IT vendor's response process is compatible with your policy's requirements.

The FTC also notes that some cyber policies include a breach hotline available every day of the year at all times as a feature worth asking about. (FTC, Cyber Insurance Considerations for Small Businesses) Knowing whether that number supersedes your IT vendor's on-call line — or complements it — is a process question to resolve before an incident.


Risk Area 5: Policy Coverage for Third-Party Incidents

QuestionYour vendor's contract saysYour business controlsYour policy application describes
Does your cyber policy explicitly cover attacks on your data held by a third party?
Does your vendor carry their own cyber liability insurance, and have you seen their certificate?
If both policies could respond to the same loss, which pays first?
Does your policy cover incidents originating outside the United States?

The FTC's guidance on what to look for in a policy includes coverage for cyber attacks that occur anywhere in the world, not only in the United States — a relevant question if your IT vendor operates support staff in other countries. (FTC, Cyber Insurance Considerations for Small Businesses) A certificate of insurance from your vendor shows that a policy exists, but it does not confirm the coverage parts, limits, or how the policy interacts with yours. Ask a licensed insurance professional how the two policies coordinate.


What to Bring to Your Next Insurance Conversation

Before a cyber insurance application or renewal, pull together:

  1. A written list of every vendor with remote access to your systems, what they can reach, and how that access is authenticated.
  2. Your IT vendor's contract, specifically the sections covering data handling, breach notification, and liability.
  3. Your most recent backup test results, including who ran the test and what was restored.
  4. Your vendor's certificate of insurance, and any questions about coverage overlap.
  5. Your current incident-response contact list, including whether your insurer's breach hotline number is in it.

The PolicyBenchmark Cyber Risk Assessment tool can help you organize your data-handling, security-control, and insurance-wording questions before that conversation. It does not calculate breach probability, audit security, prove compliance, or determine a sufficient limit — but working through it will surface the gaps in your documentation before your insurer does.

For a broader explanation of how cyber insurance is structured — first-party coverage, third-party coverage, and what each typically includes — see the Cyber Insurance coverage overview.

If you are approaching a renewal and want to capture what has changed in your IT vendor relationships over the policy period, the Cyber Insurance Renewal Checklist addresses how to document those changes before submitting updated answers to your insurer.

The Bottom Line

Outsourcing IT shifts the day-to-day work of managing your systems — it does not shift your insurance obligations or your insurer's expectation that you govern who has access to your data and how incidents get reported. The matrix above is designed to show you exactly where those responsibilities sit today, so you can have a more precise conversation with your insurer and your vendor before the next renewal — or before the next incident.

If you have specific questions about how your IT vendor's remote access affects your cyber insurance application, you can submit a coverage inquiry to PolicyBenchmark. No quote or provider connection is promised; your information is saved privately with PolicyBenchmark.