switchit.today

Security

Cyber Insurance and Switching IT Providers

switchit.today team · September 2026 · 6 min read

Somewhere in your files is a cyber insurance questionnaire, and somebody signed it. It asked whether you use multi-factor authentication everywhere, whether your endpoints run managed protection, whether backups are tested, whether patches go out on a schedule. If your IT provider filled in those answers, your policy now rests on their honesty and their competence at the same time.

That is worth sitting with for a second, because it changes how you should think about switching providers. Owners often worry that a switch will spook their insurer. In practice it usually works the other way: the businesses that struggle with cyber insurance are the ones whose current provider cannot back up the answers on the form. A well-run switch is how many of them fix that. But "well-run" is doing real work in that sentence, because a sloppy transition can genuinely open the gaps insurers care about most.

How insurers actually see a provider change

Insurers do not price your policy on which MSP's logo is on your invoice. They price it on controls: is MFA enforced, is there endpoint detection and response (EDR) on every machine, are backups separated from the network they protect, is someone patching, is email filtered. Switching providers is neither good nor bad to an underwriter by itself. What matters is whether the controls stay true during and after the change.

Two situations do get attention. First, if a renewal or application lands mid-transition, "we are between providers" is an uncomfortable answer to questions about who monitors your environment. Second, if a claim happens and the insurer finds that a control you attested to (MFA, EDR, backups) had quietly lapsed during a provider handover, that becomes a coverage argument at the worst possible moment. Policies have been contested over exactly this kind of gap between the form and the reality. We are not lawyers and this is not legal advice; for how your specific policy treats attestations and lapses, ask your broker or attorney. But the practical rule is simple: never let a control go dark, even briefly, and never sign a questionnaire you cannot verify.

The three continuities that matter most

A provider switch touches dozens of systems, but from an insurance standpoint, three deserve explicit, dated handover plans.

MFA and identity

The riskiest moments for identity are the moments admin credentials change hands, which is exactly what a transition is. The rule: MFA enforcement stays on throughout, the new provider's admin accounts are created with MFA from the first login, and the old provider's accounts are disabled the day access is no longer needed, not "eventually." Stale admin accounts belonging to a former provider are precisely the kind of finding that makes both underwriters and auditors wince. Recovering and resetting every credential is a formal step in our transition plan for this reason, and it pairs with checking who actually owns your domain and email admin, since those accounts are where identity ultimately lives.

EDR and monitoring

Many MSPs license EDR and monitoring tools under their own agreements. When the relationship ends, so can the license, sometimes automatically. If the old agent comes off your machines before the new one is on, you have unprotected endpoints and an attestation on file saying otherwise. The fix is sequencing: the new provider deploys its tooling in parallel, confirms every endpoint reports in, and only then is the old tooling removed. Overlap costs a few dollars for a few weeks. A gap can cost a claim.

Backups

Same trap, higher stakes. If backups run through the old provider's platform, ending the contract can end the backups, and it can also strand your history: those restore points may become unreachable once the account closes. Before any cutover, the new provider should stand up its own backup jobs, run a test restore (not just a green checkmark, an actual restored file or system), and confirm how long the old provider's restore points remain available and how to get data out of them if needed. If your policy or your industry requires a retention period, make sure the transition preserves it.

The questionnaire, before and after

Use the switch as a forcing function. Before you transition, pull your most recent cyber insurance application and read every attestation on it. For each one, ask: can my current provider show me evidence this is true today? If the answer is no, you have learned something important about the provider, and it belongs on the list alongside the other signs it is time to move on.

Then hand the same questionnaire to the incoming provider and make it part of onboarding: every "yes" on this form gets verified and documented within the first 30 days. A good provider will welcome this, because it is a ready-made checklist of what your insurer considers essential. When the next renewal arrives, you answer from evidence instead of memory, and if anything on the form needs to change, you tell your broker proactively rather than letting the application drift from reality.

One more practical note: if your renewal date is close, tell your broker you are changing providers and ask whether timing matters for the application. Brokers handle this constantly, and a five-minute conversation beats a surprise. If the relationship with your current provider is strained but the controls are genuinely solid, it may even be worth fixing the process first and switching after renewal, on your own schedule.

Questions to ask a new provider before you sign

A provider who answers these crisply has done this before. A provider who improvises is asking you to carry transition risk they should be managing.

The bottom line

Switching IT providers does not endanger your cyber insurance. Unmanaged gaps do, and those gaps are a symptom of an improvised transition, not of switching itself. Run the change so that MFA, EDR, and backups never blink, verify the questionnaire against evidence on both sides of the cutover, and keep your broker in the loop. Done that way, most businesses come out of a switch more insurable than they went in.

Switch without the security gap

Our free 48-hour switch plan maps your controls, MFA, EDR, and backups included, and sequences the transition so none of them ever lapse.

Start the Switch