A few years ago, a cyber insurance application asked whether you had antivirus and a firewall, and the answer was worth a discount. This year's renewal packet asks whether MFA covers every remote access path including vendor connections, which endpoints lack EDR, when you last restored from an offline backup, and the date of your most recent incident-response tabletop. It wants attestations. Sometimes it wants evidence.
Business owners tend to read this as insurance companies being difficult. It's simpler than that: they got tired of losing money.
Why underwriting turned into an audit
The ransomware wave made cyber a money-losing line for a stretch, and carriers responded the way carriers do — by repricing risk and demanding the behaviors that reduce it. They now underwrite the way a fire insurer looks at sprinklers: no controls, no coverage. And the risk picture for smaller businesses is specifically what they're reading. Per the Verizon DBIR 2026, 88% of breach incidents at small and mid-sized businesses involved ransomware or extortion — more than double the share at large organizations. Per IBM's Cost of a Data Breach 2026 report, the average U.S. breach now runs $11.5 million, a record. Your claim won't look like that average, but your carrier's book of claims does.
The control checklist carriers now expect
Questionnaires differ, but the same core keeps appearing. Consider this the de facto minimum for decent terms in 2026:
- MFA everywhere that matters. Email, VPN and any remote access, administrator accounts, and — increasingly called out by name — the backup console. "Mostly deployed" is a real answer; say so precisely.
- EDR on every endpoint, with someone watching it. An EDR platform installed is table stakes; carriers now ask who monitors and responds, and whether that coverage is 24/7. This is where managed detection and response enters the conversation.
- Backups that would survive your attacker. Encrypted, with an offline or immutable copy, separated credentials, and documented restore tests. Backups the ransomware can also encrypt don't count — and underwriters know to ask.
- A written, exercised incident response plan. Not a binder — a plan with names, phone numbers, and a tabletop exercise on the calendar.
- Patch discipline and no end-of-life systems. Critical vulnerabilities remediated on a defined timeline; unsupported operating systems gone or isolated.
- Email security and user training. A filtering gateway, DMARC enforcement, and phishing-awareness training with some evidence it happens.
- Privileged access under control. Admin rights limited and logged, no shared admin accounts, vendors' remote access constrained.