Cyber Insurance Requirements: A 2026 Readiness Checklist
In 2026, cyber insurers require MFA, EDR on every endpoint, immutable tested backups, a written incident response plan, and security awareness training. The bigger shift is proof. You must show each control was enforced when the loss hit.
Cyber insurance used to be a form you filled out. A few yes-or-no boxes, a signature, a premium. That form is gone. What you get now looks more like a technical audit, and the questions have teeth. Underwriters want to know whether your controls were actually running, actually enforced, actually tested, on the day something went wrong. This is where managed cybersecurity stops being a nice-to-have and becomes the thing standing between you and a denied claim.
Most companies get this backward. They treat the renewal as a paperwork problem, answer yes to every control, and assume they're covered. Then a ransomware crew slips in through the one laptop without endpoint protection, the carrier asks for proof the controls were actually running, and the policy they paid for every year quietly turns into a stack of paper that owes them nothing. According to the FBI, cybercrime losses hit $16.6 billion in 2024, up 33% in a year. The businesses that actually collect on their policies share one trait. They could prove the controls were on. Not on paper. In production.
What do cyber insurers actually require in 2026?
Carriers now expect a core stack of controls. MFA everywhere, EDR on every endpoint, immutable and tested backups, a documented incident response plan, patch management, and security awareness training. Miss one of the big three and you get declined. Miss one of the rest and you get rated up.
The list itself is not new. What changed is how carriers sort it, splitting your controls into the ones that decide whether they'll cover you at all, the ones that quietly raise your premium when they're weak, and the handful that earn a discount when you can document them. Some controls are pass-fail. Some cost you money. A few pay you back. That's the frame most checklists skip, so here it is the way an underwriter actually scores it.
- Non-negotiable. MFA on email, remote access, and admin accounts, EDR or MDR on all endpoints and servers, and immutable, tested backups. Missing any one is a common decline, and roughly 80% of insurers require MFA and 65% require EDR.
- Rated up if weak. Patch SLAs, email filtering, awareness training, a written IR plan, and privileged access controls. You can still get covered, but you'll pay more or carry a bigger deductible.
- Premium credits. Phishing-resistant MFA, OT/IT network segmentation, 24/7 SOC monitoring, and tested tabletop exercises. Document these and carriers often shave 5% to 10% off, and segmentation credits matter most for manufacturers.

Notice the pattern. Everything in that top row is binary. You either enforced it everywhere or you didn't. Underwriters stopped grading on effort a while ago.
Why "we have MFA" is the answer that gets claims denied
Because carriers no longer take your word for it. The single most important change in cyber underwriting is that the question flipped from whether you own a control to whether you can prove it was fully enforced across every account on the day the attacker actually got in. A checked box is now the start of the conversation, not the end.
Two cases made this real. In Travelers v. International Control Services (2022), the insurer moved to rescind a cyber policy entirely after finding the company had claimed MFA was deployed across all systems when it was only protecting the firewall. The court sided with the insurer. The policy was voided. The ransomware claim went unpaid, and it didn't matter that the misrepresentation was unintentional.
Then there's the City of Hamilton. MFA had been flagged internally as a requirement years before the breach. It was only partially rolled out. When the attack came, the insurer denied the claim and taxpayers absorbed a $18.3 million recovery bill. Partial MFA didn't count as partial credit. It counted as no MFA.
Read that twice if you run IT for a living. From an underwriting seat, MFA is binary. 90% covered is a gap. And a gap is exactly what the forensics report will find first.
The controls you already think you have (but probably don't)
Here's the uncomfortable part. Most of the gaps that sink a claim aren't controls a company forgot to buy. They're controls the company believes it already has. The tool is installed. The job runs. Nobody checked whether it actually does the specific thing the insurance questionnaire assumes it does, which is a very different bar than being switched on, and it's exactly the difference underwriters are trained to find.
This is the trap. You answer the questionnaire from memory, not from evidence, and the two don't match.
- You might think you have MFA because it's in Microsoft 365. Carriers count it only when it's enforced on every account, including admins and service accounts, not just offered to users who opt in.
- You might think you have backups because a job runs every night. Carriers count immutable or air-gapped backups with a documented restore test you can date.
- You might think you have endpoint protection because antivirus is installed. Carriers count modern EDR or MDR on every endpoint and server, with alerting to someone who watches it.
- You might think your people know about phishing because it came up in a meeting. Carriers count recurring training and phishing simulations with completion records.
See the difference? One version is a feeling. The other is a document. Underwriters buy the document.
We see this constantly. A company assumes M365 means MFA, but licensing only turned it on for the leadership team. Or the nightly backup dutifully writes to a network share sitting on the same domain the ransomware would encrypt in its first ten minutes, which means the backup and the production data die together. The control exists. The proof doesn't. That's the gap that turns a $500,000 claim into a $500,000 loss.
The 2026 readiness checklist, control by control
Work through these seven before your renewal lands, not after. For each one, the question isn't whether you have it. The question is what you would actually hand the underwriter to prove it. If you can't answer the second part, treat the control as missing.

1. Multi-factor authentication, enforced everywhere
MFA on email, VPN, remote desktop, cloud consoles, and every admin account. No opt-outs. Carriers increasingly prefer phishing-resistant methods like FIDO2 hardware keys over SMS codes, which attackers can intercept. Proof looks like a policy export showing enforcement, not a screenshot of the setting being available.
2. EDR or MDR on every endpoint and server
Basic antivirus catches known signatures. It misses the behavior modern ransomware uses. Underwriters want EDR deployed on everything, with 24/7 alerting, either in-house or through a managed provider. The word that sinks applications is everywhere. One unmanaged laptop, or an old server running an unsupported OS that everyone forgot was still plugged in, is enough to fail the whole application on its own, no matter how clean the rest of your fleet looks.
3. Immutable, air-gapped, tested backups
Ransomware crews hunt your backups first, then encrypt production. So carriers want copies attackers can't alter or delete, plus a restore test with a date on it. In 2024, ransomware showed up in 44% of breaches, and backups are the single control that decides whether a bad morning ends with you wiring a ransom to a crew in another country or quietly restoring from a clean copy and getting back to work. If you haven't actually tested a full restore, you don't have backups. You have hope.
4. Patch and vulnerability management
Documented patch SLAs. Critical vulnerabilities closed inside 7 to 15 days, recurring scans, and a record showing remediation happened. We patch regularly won't pass. A report with dates will.
5. Email security and awareness training
Modern email filtering at the gateway or API layer, plus recurring security awareness training with phishing simulations. Email is still how most attacks start. Training your team to spot phishing and social engineering is one of the cheapest controls on the list, and one carriers ask about by name.
6. A written, tested incident response plan
Not a wiki page nobody's opened. A documented plan with roles, contacts, and steps, plus evidence you ran a tabletop exercise against it. Some carriers now require the tabletop before they'll renew, and others quietly discount the premium when you can show that your team walked through a real breach scenario and knew who does what before the clock started running. A tested plan changes your entire risk profile on paper.
7. Identity and privileged access controls
Least-privilege access, separate admin accounts, and a way to prove who can touch what. Attackers rarely stop at the first account they crack. They escalate through over-permissioned users until they reach something worth encrypting, which is why carriers ask who can touch what and expect a real answer. Tie this to your broader compliance readiness if you already run a framework like NIST or CMMC, because most of the evidence overlaps.
What this costs, and what skipping a control costs you
Most small businesses pay between $45 and $200 a month for a cyber policy with a $1 million limit. That's the sticker price. The real number depends on your controls, and this is where the math gets sharp.
Miss a basic control and the same policy can cost 25% to 50% more, if a carrier writes it at all. So the cheapest line item on your renewal isn't the premium. It's the control you skipped to save a few thousand dollars this year, the one that then adds five figures to next year's quote, blows up your deductible, or quietly removes the option to buy a policy at all.
Direction of travel matters too. S&P Global Ratings projects premium increases of 15% to 20% in 2026, driven by rising claim severity and AI-assisted attacks. The market still rewards well-controlled businesses with flat or lower pricing. It punishes everyone else. For manufacturers, one lever stands out. Documented segmentation between your OT and IT networks, the production floor kept apart from email and file servers, earns credits at many carriers and shrinks the blast radius of an attack at the same time.
How to get ready before the questionnaire lands
Start with the top row. Fix MFA, EDR, and backups first, because those are the decline triggers. Everything else just moves you between covered and covered cheaply. Then build the evidence folder as you go, so the questionnaire becomes a copy-paste job instead of a scramble.
Here's a rough order that works.
- Enforce MFA on every account and export the policy that proves it.
- Get EDR or MDR onto every endpoint and server. Hunt down the machine nobody remembered.
- Move backups to immutable storage and run a restore test. Write down the date.
- Document patch SLAs, the IR plan, and training records in one place a human can find in a hurry.
Could you do all of this in-house? Sure, if you've got the staff and the hours. Plenty of companies don't, which is where a managed cybersecurity partner earns its keep, deploying the controls and, more importantly, producing the proof carriers now demand. Bias disclosed, we do this work. But here's the honest version. If you already have all seven controls enforced and documented, you don't need us for your renewal. You need us when the gap between what you think you have and what you can prove is wider than you're comfortable with. Most companies find out that gap exists the hard way. On a claim.
The bottom line
Cyber insurance in 2026 rewards businesses that can prove their security, and quietly penalizes the ones that only claim it. The controls aren't exotic. MFA, EDR, tested backups, patching, training, an IR plan, and access control. What's new is the burden of evidence, and the price of getting caught short isn't a slightly higher premium, it's a denied claim that lands in the exact week you're trying to rebuild your business from backups you only hoped would work.
Three things to take with you. Treat MFA, EDR, and backups as pass-fail, because carriers do. Build the proof before the questionnaire, not during. And close the gap between the controls you believe you have and the ones you can document. If you're staring down a renewal and you're not sure which controls would survive an underwriter's questions, start with a readiness assessment and speak to a cybersecurity expert who can map your gaps before the carrier does.