
Home / Guides & Insights / Cyber insurance requirements
Cyber insurance security requirements in 2026: what insurers now demand
The questionnaire got teeth. Here's what underwriters actually require, what your "yes" legally commits you to, and a 30-day path to answering honestly — before the renewal, not after the claim.
In 2026, cyber insurers commonly require MFA on email, remote access, and admin accounts; EDR on endpoints; offline or immutable backups; a patching process; security awareness training; and an incident response plan — as conditions of coverage, not suggestions. Overstating a control on the application is the classic path to a denied claim when it matters most.
Cyber insurance quietly became one of the strongest security forces in the SMB market — not because insurers love security, but because they got tired of paying ransomware claims for companies whose front doors were open. The application used to be a formality. Now it's an audit you grade yourself on, under penalty of your claim. Here's what's on it, and how to get to "yes" honestly.
Why the questionnaire grew teeth
The economics are simple: ransomware losses forced underwriters to distinguish between insurable and uninsurable hygiene. The mechanism is the application — a technical questionnaire whose answers become part of the policy. Answer inaccurately and you've handed the insurer a material-misrepresentation argument exactly when you need them; insurers have litigated claims over misstated controls, and the industry noticed. The practical takeaway isn't fear — it's that the questionnaire is now a free, insurer-designed security assessment. Treat it as your checklist, get the controls real, and the premium conversation improves too.
The 2026 requirements table
| Control | What underwriters ask | What your "yes" must mean | Proof to keep |
|---|---|---|---|
| MFA | "MFA on email, remote access, privileged accounts?" | All three, no carve-outs — the forgotten VPN account is the breach and the denial | Tenant/IdP policy export, screenshots |
| EDR | "Endpoint detection and response deployed?" | Real EDR on effectively all endpoints, monitored — legacy antivirus doesn't qualify | Console coverage report |
| Backups | "Offline/immutable backups, tested?" | Copies an attacker with admin credentials can't destroy, restore-tested on a calendar | Architecture note + dated restore-test logs |
| Patching | "Process and timelines for critical vulnerabilities?" | A stated cadence you actually meet, fast lane for internet-facing criticals | Written cadence + scan or patch reports |
| Training | "Security awareness / phishing training?" | Regular and recorded — not a 2023 onboarding video | Completion records, simulation stats |
| IR plan | "Documented incident response plan?" | A real plan with roles and contacts, ideally exercised | The plan + exercise date |
| Privileged access | "How are admin accounts managed?" | Separate admin identities, strong MFA, limited membership | Admin group review, dated |
| Email security | "Filtering and anti-spoofing (SPF/DKIM/DMARC)?" | Published and enforced records, filtering in front of mailboxes | DNS records, DMARC reports |
| EOL systems | "Unsupported OS/software in use?" | Honest inventory; anything end-of-life isolated with a replacement plan | Asset list with support status |
Exact questions vary by carrier and market segment, but this set appears in substantially every 2026 SMB application we've helped clients complete.
The attestation trap: how honest companies lose coverage
The pattern that hurts people isn't lying — it's optimistic rounding. "MFA everywhere" (except the file server's local accounts). "EDR deployed" (on the machines that were online during rollout). "Backups tested" (once, at setup, in 2024). Each rounding feels harmless on a form; each is a thread an adjuster can pull after a six-figure claim. Two rules keep you safe. First, answer the question that's asked, precisely — if the true answer is "95% of endpoints," write that, and close the 5% before binding. Second, keep dated evidence for every yes — the table's right-hand column is your claim-survival kit. In our assessments we now produce exactly this evidence pack, because the renewal is where clients need it twice a year.
A 30-day path from "mostly no" to "honestly yes"
If the table above reads as bad news, the fix is more tractable than it looks — these are the same controls from our 20-point baseline, prioritized by what insurers weight heaviest. A realistic month: week one, MFA on email, VPN, and every admin account (the single highest-leverage move on the form — and in reality); week two, EDR deployment across endpoints and servers; week three, backup architecture — add an immutable or offline copy, then run and document a restore test; week four, write the one-page IR plan, publish SPF/DKIM/DMARC, launch the training program, and inventory anything end-of-life. None of this is exotic. All of it is the difference between a policy that pays and one that argues — and it's genuinely the same work that makes the incident less likely in the first place. The insurance form is just the first audience; the second is the attacker, and the third is the worst night of the year these controls exist to shorten.
Beyond the checkboxes: what the market rewards next
Carriers increasingly differentiate beyond the minimum: managed detection (someone actually watching the EDR), vulnerability scanning cadence, and independent penetration testing show up as premium-relevant questions on larger policies and in harder verticals — healthcare, finance, anyone holding sensitive data at scale. If you're in a regulated space, expect the questionnaire to converge with your compliance framework: the same evidence increasingly serves your insurer, your auditor, and your biggest customer's due diligence. Build the controls once, let three audiences read the same proof — that's the quiet efficiency most SMBs miss.
Reading the policy itself: where coverage quietly narrows
The questionnaire is half the story; the policy wording is the other half, and it deserves twenty minutes with a highlighter. Look for sublimits — a $1M policy with a $100k ransomware sublimit is a $100k policy for the scenario you bought it for; the same trick appears on social engineering and funds-transfer fraud, which are precisely the SMB loss events. Look for panel requirements: many policies require using the insurer's approved forensics and legal vendors, and reimbursement for your own picks can be partial or zero — know this before the bad night, because your first three phone calls are dictated by it. Look for notification windows (some policies require notice within days of discovery), war and infrastructure exclusions, and the retroactive date — incidents that began before it aren't covered, which matters more than people think given how long intrusions dwell before detection. None of this is a reason to skip coverage; all of it is a reason to read before binding, and to ask your broker pointed questions in writing.
The renewal calendar: 90 days out
Renewals go badly when they're treated as paperwork week. A calm cycle looks like this. 90 days before renewal: pull last year's application, walk every "yes" against reality, and list the gaps — this is exactly the hour-long ritual from our baseline checklist, wearing an insurance hat. 60 days out: close what's closable (MFA gaps, a missing restore test, DMARC) and collect the evidence pack — policy exports, EDR coverage report, dated restore logs, training records. 30 days out: complete the application from evidence rather than memory, have whoever signs it actually read it (it's a legal representation, and the signer should know that), and send your broker the evidence pack proactively — differentiated submissions get shopped to carriers more favorably. The pattern we see: the first cycle done this way is work; every one after is an afternoon, because the evidence pipeline already exists for the auditor and the enterprise customer asking the same questions.
Who should own this internally
The application fails when it's orphaned between departments: finance owns the premium, IT owns the controls, and nobody owns the accuracy. Give the renewal a single owner — in an SMB, usually whoever owns risk or operations — with authority to pull evidence from IT and sign-off from leadership. Their job description in one line: every answer on the form is true, evidenced, and dated. One named owner, a 90-day calendar, and an evidence folder outperform any amount of renewal-week heroics — and the same owner naturally becomes the person your auditors and enterprise customers deal with, because the material is identical.
Frequently asked questions
Can an insurer really deny a claim over a questionnaire answer?
Yes — a materially inaccurate application answer is grounds to rescind coverage or deny a claim, and disputes over misstated controls (MFA especially) have reached litigation. Precision on the form, with dated evidence behind each answer, is the protection.
What if we genuinely can't check every box yet?
Answer truthfully and attach a remediation timeline. Many carriers will bind with conditions or a surcharge, and some accept "in progress with date." A truthful partial-yes with a plan beats an optimistic yes every time — one is underwriting, the other is future claim denial.
Do these requirements apply to very small companies?
The core set — MFA, EDR, backups, training — now appears in applications for even 5–10-person firms. Limits and scrutiny scale with size and sector, but the era of coverage without controls is over at every size we see.
Does a penetration test help with cyber insurance?
Increasingly yes — larger policies and harder verticals ask about independent testing directly, and a recent report with remediation evidence strengthens any submission. It also pre-answers the forensic question a claim raises: what was your security posture before the incident? A dated report is a better answer than recollections — and unlike recollections, it survives staff turnover.
Will better security actually lower the premium?
Often, though the bigger financial effect is being insurable at all, at sane limits, without ransomware exclusions bolted onto the renewal — a quieter but far more expensive form of repricing. Brokers tell us clean applications with evidence get materially better terms; what we can verify from our side is that clients who fixed the table above stopped having renewal drama.
Get renewal-ready How our assessment maps to the form
General information from field experience with 2026 SMB applications, not insurance or legal advice. Your policy's exact wording governs — read it, and route coverage questions through your broker or counsel.