Blog · Cyber Insurance · July 12, 2026 · By Mike Parker

What Cyber Insurers Now Require Before They'll Cover You

The renewal questionnaire reads like a security audit because it is one. Here's what carriers expect in place, how premiums respond — and why a wrong checkbox can cost more than a rate hike.

A few years ago, a cyber insurance application asked whether you had antivirus and a firewall, and the answer was worth a discount. This year's renewal packet asks whether MFA covers every remote access path including vendor connections, which endpoints lack EDR, when you last restored from an offline backup, and the date of your most recent incident-response tabletop. It wants attestations. Sometimes it wants evidence.

Business owners tend to read this as insurance companies being difficult. It's simpler than that: they got tired of losing money.

Why underwriting turned into an audit

The ransomware wave made cyber a money-losing line for a stretch, and carriers responded the way carriers do — by repricing risk and demanding the behaviors that reduce it. They now underwrite the way a fire insurer looks at sprinklers: no controls, no coverage. And the risk picture for smaller businesses is specifically what they're reading. Per the Verizon DBIR 2026, 88% of breach incidents at small and mid-sized businesses involved ransomware or extortion — more than double the share at large organizations. Per IBM's Cost of a Data Breach 2026 report, the average U.S. breach now runs $11.5 million, a record. Your claim won't look like that average, but your carrier's book of claims does.

The control checklist carriers now expect

Questionnaires differ, but the same core keeps appearing. Consider this the de facto minimum for decent terms in 2026:

  • MFA everywhere that matters. Email, VPN and any remote access, administrator accounts, and — increasingly called out by name — the backup console. "Mostly deployed" is a real answer; say so precisely.
  • EDR on every endpoint, with someone watching it. An EDR platform installed is table stakes; carriers now ask who monitors and responds, and whether that coverage is 24/7. This is where managed detection and response enters the conversation.
  • Backups that would survive your attacker. Encrypted, with an offline or immutable copy, separated credentials, and documented restore tests. Backups the ransomware can also encrypt don't count — and underwriters know to ask.
  • A written, exercised incident response plan. Not a binder — a plan with names, phone numbers, and a tabletop exercise on the calendar.
  • Patch discipline and no end-of-life systems. Critical vulnerabilities remediated on a defined timeline; unsupported operating systems gone or isolated.
  • Email security and user training. A filtering gateway, DMARC enforcement, and phishing-awareness training with some evidence it happens.
  • Privileged access under control. Admin rights limited and logged, no shared admin accounts, vendors' remote access constrained.
What the carrier sees

The numbers your premium is priced on

Underwriters read the same research your IT provider does. These are the figures sitting behind the questionnaire.

88%

of SMB breach incidents involve ransomware or extortion — the claim type that broke the market

Verizon DBIR 2026

$11.5M

average cost of a U.S. data breach — a record high

IBM Cost of a Data Breach 2026

$20.9B

in reported U.S. cybercrime losses in 2025, up 26% in a year

FBI IC3 2025

How premiums and terms actually respond

Controls don't just get you covered — they set the shape of the coverage:

  • Strong posture earns better premiums, lower retentions, higher limits, and a smoother renewal with fewer follow-up questions.
  • Gaps get priced in: surcharges, ransomware sublimits and coinsurance (you pay a percentage of every ransomware loss), exclusions tied to the missing control, or a flat declination.
  • Misstatements are the expensive ones. The application is a signed representation. Carriers have contested and denied claims — and moved to rescind policies — when the controls a business attested to weren't actually in place at claim time. A false "yes" on the MFA question can convert your premium into a donation.

The rule: answer precisely, never aspirationally. "Deployed for all staff except the warehouse kiosks, remediation scheduled Q3" is a strong answer. An unqualified checkbox you can't back with evidence is a time bomb.

Preparing for the questionnaire: the 90-day version

  1. Get the current form early from your broker — carriers revise them, and last year's answers won't map cleanly.
  2. Answer it as a gap assessment with your IT team or provider, months before it's due. Every "no" is now a project with a deadline instead of a premium penalty.
  3. Close the big four first: MFA coverage, monitored EDR, backup isolation and restore tests, and the incident response plan with a tabletop on record. They carry the most underwriting weight.
  4. Build an evidence file: MFA policy exports, monitoring agreements, restore-test logs, training completion reports, the IR plan's revision date. Renewal becomes paperwork instead of archaeology.
  5. Have your IT partner co-complete the technical sections. Guessing is how misstatements happen. Ours sit on renewal calls with clients' brokers for exactly this reason.

Where a security partner fits

Most of what carriers demand is simply a competent security program — the questionnaire is just the first audience for it. A capable provider maps your controls to the application, closes the gaps (that's the heart of our managed cybersecurity service, and our cloud backup and disaster recovery work covers the restore-test evidence), and hands you documentation an underwriter respects. The controls also have to actually work, of course — the insurer is only the second-worst party to discover they don't.

Insurers stopped selling promises and started auditing controls. Walk into renewal with evidence, and the market starts working for you again.

The readiness checklist, as a one-pager

Nine controls underwriters ask about — check them off before the renewal arrives. Read it as a full page →

Download the PDF
Quick answers

Cyber insurance requirements, answered plainly

Can we get cyber insurance without MFA?

It is getting close to impossible on reasonable terms. MFA on email, remote access, and administrator accounts has become the de facto entry ticket — many carriers decline outright without it, and others quote punishing premiums or carve ransomware down to a token sublimit. If MFA is your gap, close it before you shop; it is also simply the highest-value security control you can deploy.

What counts as a "tested" backup to an underwriter?

Not the green checkmark in a dashboard. Underwriters want backups that are encrypted, that include a copy isolated from your production network — offline or immutable — with separate credentials, and that you have actually restored from on a schedule, with the results documented. A dated restore-test log is exactly the kind of evidence that turns a hesitant renewal into a routine one.

Can a carrier really deny a claim because of the application?

Yes. Applications are signed representations, and carriers have contested claims — up to rescinding policies — where the security controls attested to were not actually in place when the incident hit. The lesson is not to fear the form; it is to answer it precisely. "Deployed on 90% of endpoints, remainder scheduled this quarter" is an answer that protects you. A false "yes" is an answer that can void the policy when you need it most.

Do insurers specifically require MDR, or is EDR enough?

The wording varies by carrier, but the direction is consistent: they increasingly want to know not just that an EDR platform is installed, but who is watching it and how fast someone can contain a threat — nights and weekends included. A managed detection and response arrangement answers that question cleanly, which is why questionnaires keep asking about 24/7 monitoring and response capability rather than software alone.

When should we start preparing for renewal?

About 90 days out. Real control changes — rolling out MFA, standing up monitored detection, fixing backup isolation, running a tabletop exercise — take weeks to implement and prove. Starting the questionnaire the week it is due is how businesses end up either overstating their posture or accepting whatever terms they are handed.

Renewal coming? Find out what the questionnaire will say

A free 30-minute assessment with the owner — we'll read your posture the way an underwriter will, and tell you which gaps to close first. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment