Cyber Insurance Requirements: A 2026 Readiness Checklist

07/10/2026
Cybersecurity

In 2026, cyber insurers require MFA, EDR on every endpoint, immutable tested backups, a written incident response plan, and security awareness training. The bigger shift is proof. You must show each control was enforced when the loss hit.

Cyber insurance used to be a form you filled out. A few yes-or-no boxes, a signature, a premium. That form is gone. What you get now looks more like a technical audit, and the questions have teeth. Underwriters want to know whether your controls were actually running, actually enforced, actually tested, on the day something went wrong. This is where managed cybersecurity stops being a nice-to-have and becomes the thing standing between you and a denied claim.

Most companies get this backward. They treat the renewal as a paperwork problem, answer yes to every control, and assume they're covered. Then a ransomware crew slips in through the one laptop without endpoint protection, the carrier asks for proof the controls were actually running, and the policy they paid for every year quietly turns into a stack of paper that owes them nothing. According to the FBI, cybercrime losses hit $16.6 billion in 2024, up 33% in a year. The businesses that actually collect on their policies share one trait. They could prove the controls were on. Not on paper. In production.

What do cyber insurers actually require in 2026?

Carriers now expect a core stack of controls. MFA everywhere, EDR on every endpoint, immutable and tested backups, a documented incident response plan, patch management, and security awareness training. Miss one of the big three and you get declined. Miss one of the rest and you get rated up.

The list itself is not new. What changed is how carriers sort it, splitting your controls into the ones that decide whether they'll cover you at all, the ones that quietly raise your premium when they're weak, and the handful that earn a discount when you can document them. Some controls are pass-fail. Some cost you money. A few pay you back. That's the frame most checklists skip, so here it is the way an underwriter actually scores it.

  • Non-negotiable. MFA on email, remote access, and admin accounts, EDR or MDR on all endpoints and servers, and immutable, tested backups. Missing any one is a common decline, and roughly 80% of insurers require MFA and 65% require EDR.
  • Rated up if weak. Patch SLAs, email filtering, awareness training, a written IR plan, and privileged access controls. You can still get covered, but you'll pay more or carry a bigger deductible.
  • Premium credits. Phishing-resistant MFA, OT/IT network segmentation, 24/7 SOC monitoring, and tested tabletop exercises. Document these and carriers often shave 5% to 10% off, and segmentation credits matter most for manufacturers.

Three-tier cyber insurance controls graphic from non-negotiable to premium credits

Notice the pattern. Everything in that top row is binary. You either enforced it everywhere or you didn't. Underwriters stopped grading on effort a while ago.

Why "we have MFA" is the answer that gets claims denied

Because carriers no longer take your word for it. The single most important change in cyber underwriting is that the question flipped from whether you own a control to whether you can prove it was fully enforced across every account on the day the attacker actually got in. A checked box is now the start of the conversation, not the end.

Two cases made this real. In Travelers v. International Control Services (2022), the insurer moved to rescind a cyber policy entirely after finding the company had claimed MFA was deployed across all systems when it was only protecting the firewall. The court sided with the insurer. The policy was voided. The ransomware claim went unpaid, and it didn't matter that the misrepresentation was unintentional.

Then there's the City of Hamilton. MFA had been flagged internally as a requirement years before the breach. It was only partially rolled out. When the attack came, the insurer denied the claim and taxpayers absorbed a $18.3 million recovery bill. Partial MFA didn't count as partial credit. It counted as no MFA.

Read that twice if you run IT for a living. From an underwriting seat, MFA is binary. 90% covered is a gap. And a gap is exactly what the forensics report will find first.

The controls you already think you have (but probably don't)

Here's the uncomfortable part. Most of the gaps that sink a claim aren't controls a company forgot to buy. They're controls the company believes it already has. The tool is installed. The job runs. Nobody checked whether it actually does the specific thing the insurance questionnaire assumes it does, which is a very different bar than being switched on, and it's exactly the difference underwriters are trained to find.

This is the trap. You answer the questionnaire from memory, not from evidence, and the two don't match.

  • You might think you have MFA because it's in Microsoft 365. Carriers count it only when it's enforced on every account, including admins and service accounts, not just offered to users who opt in.
  • You might think you have backups because a job runs every night. Carriers count immutable or air-gapped backups with a documented restore test you can date.
  • You might think you have endpoint protection because antivirus is installed. Carriers count modern EDR or MDR on every endpoint and server, with alerting to someone who watches it.
  • You might think your people know about phishing because it came up in a meeting. Carriers count recurring training and phishing simulations with completion records.

See the difference? One version is a feeling. The other is a document. Underwriters buy the document.

We see this constantly. A company assumes M365 means MFA, but licensing only turned it on for the leadership team. Or the nightly backup dutifully writes to a network share sitting on the same domain the ransomware would encrypt in its first ten minutes, which means the backup and the production data die together. The control exists. The proof doesn't. That's the gap that turns a $500,000 claim into a $500,000 loss.

The 2026 readiness checklist, control by control

Work through these seven before your renewal lands, not after. For each one, the question isn't whether you have it. The question is what you would actually hand the underwriter to prove it. If you can't answer the second part, treat the control as missing.

Grid of seven cyber insurance control icons

1. Multi-factor authentication, enforced everywhere

MFA on email, VPN, remote desktop, cloud consoles, and every admin account. No opt-outs. Carriers increasingly prefer phishing-resistant methods like FIDO2 hardware keys over SMS codes, which attackers can intercept. Proof looks like a policy export showing enforcement, not a screenshot of the setting being available.

2. EDR or MDR on every endpoint and server

Basic antivirus catches known signatures. It misses the behavior modern ransomware uses. Underwriters want EDR deployed on everything, with 24/7 alerting, either in-house or through a managed provider. The word that sinks applications is everywhere. One unmanaged laptop, or an old server running an unsupported OS that everyone forgot was still plugged in, is enough to fail the whole application on its own, no matter how clean the rest of your fleet looks.

3. Immutable, air-gapped, tested backups

Ransomware crews hunt your backups first, then encrypt production. So carriers want copies attackers can't alter or delete, plus a restore test with a date on it. In 2024, ransomware showed up in 44% of breaches, and backups are the single control that decides whether a bad morning ends with you wiring a ransom to a crew in another country or quietly restoring from a clean copy and getting back to work. If you haven't actually tested a full restore, you don't have backups. You have hope.

4. Patch and vulnerability management

Documented patch SLAs. Critical vulnerabilities closed inside 7 to 15 days, recurring scans, and a record showing remediation happened. We patch regularly won't pass. A report with dates will.

5. Email security and awareness training

Modern email filtering at the gateway or API layer, plus recurring security awareness training with phishing simulations. Email is still how most attacks start. Training your team to spot phishing and social engineering is one of the cheapest controls on the list, and one carriers ask about by name.

6. A written, tested incident response plan

Not a wiki page nobody's opened. A documented plan with roles, contacts, and steps, plus evidence you ran a tabletop exercise against it. Some carriers now require the tabletop before they'll renew, and others quietly discount the premium when you can show that your team walked through a real breach scenario and knew who does what before the clock started running. A tested plan changes your entire risk profile on paper.

7. Identity and privileged access controls

Least-privilege access, separate admin accounts, and a way to prove who can touch what. Attackers rarely stop at the first account they crack. They escalate through over-permissioned users until they reach something worth encrypting, which is why carriers ask who can touch what and expect a real answer. Tie this to your broader compliance readiness if you already run a framework like NIST or CMMC, because most of the evidence overlaps.

What this costs, and what skipping a control costs you

Most small businesses pay between $45 and $200 a month for a cyber policy with a $1 million limit. That's the sticker price. The real number depends on your controls, and this is where the math gets sharp.

Miss a basic control and the same policy can cost 25% to 50% more, if a carrier writes it at all. So the cheapest line item on your renewal isn't the premium. It's the control you skipped to save a few thousand dollars this year, the one that then adds five figures to next year's quote, blows up your deductible, or quietly removes the option to buy a policy at all.

Direction of travel matters too. S&P Global Ratings projects premium increases of 15% to 20% in 2026, driven by rising claim severity and AI-assisted attacks. The market still rewards well-controlled businesses with flat or lower pricing. It punishes everyone else. For manufacturers, one lever stands out. Documented segmentation between your OT and IT networks, the production floor kept apart from email and file servers, earns credits at many carriers and shrinks the blast radius of an attack at the same time.

How to get ready before the questionnaire lands

Start with the top row. Fix MFA, EDR, and backups first, because those are the decline triggers. Everything else just moves you between covered and covered cheaply. Then build the evidence folder as you go, so the questionnaire becomes a copy-paste job instead of a scramble.

Here's a rough order that works.

  • Enforce MFA on every account and export the policy that proves it.
  • Get EDR or MDR onto every endpoint and server. Hunt down the machine nobody remembered.
  • Move backups to immutable storage and run a restore test. Write down the date.
  • Document patch SLAs, the IR plan, and training records in one place a human can find in a hurry.

Could you do all of this in-house? Sure, if you've got the staff and the hours. Plenty of companies don't, which is where a managed cybersecurity partner earns its keep, deploying the controls and, more importantly, producing the proof carriers now demand. Bias disclosed, we do this work. But here's the honest version. If you already have all seven controls enforced and documented, you don't need us for your renewal. You need us when the gap between what you think you have and what you can prove is wider than you're comfortable with. Most companies find out that gap exists the hard way. On a claim.

The bottom line

Cyber insurance in 2026 rewards businesses that can prove their security, and quietly penalizes the ones that only claim it. The controls aren't exotic. MFA, EDR, tested backups, patching, training, an IR plan, and access control. What's new is the burden of evidence, and the price of getting caught short isn't a slightly higher premium, it's a denied claim that lands in the exact week you're trying to rebuild your business from backups you only hoped would work.

Three things to take with you. Treat MFA, EDR, and backups as pass-fail, because carriers do. Build the proof before the questionnaire, not during. And close the gap between the controls you believe you have and the ones you can document. If you're staring down a renewal and you're not sure which controls would survive an underwriter's questions, start with a readiness assessment and speak to a cybersecurity expert who can map your gaps before the carrier does.

Find your control gaps before your carrier does

Renewals now turn on proof, not promises. Consilien deploys MFA, EDR, immutable backups, and the documentation your underwriter asks for, then hands you the evidence to pass the questionnaire.

If you are not sure which controls would hold up, we will map the gaps first, before the carrier does it for you.

Questions Businesses Ask Before Renewal

How much does cyber insurance actually cost a small business in 2026?
$45 to $200 a month is the typical range for a $1 million policy. But the controls you can prove swing that number hard. Weak MFA or no EDR can add 25% to 50%, or take you out of the market entirely. Well-documented controls pull it back down.
Do small businesses really need cyber insurance, or is it a big-company thing?
Small and mid-sized companies are the target, not the exception. The FBI logged over 4,800 ransomware-related complaints from organizations across manufacturing, finance, and other sectors in 2024. Attackers pick the businesses with gaps, not the ones with the biggest logos.
Is phishing-resistant MFA required, or will app-based codes do?
Usually, yes. App-based MFA still passes with most carriers today. That said, phishing-resistant methods like FIDO2 keys are moving from preferred to expected, especially on admin accounts. If you are deploying MFA now, deploy the stronger version. You will save yourself a re-do at the next renewal.
What if we cannot meet every requirement before our renewal date?
Prioritize the decline triggers first. MFA, EDR, and backups are the controls most likely to cost you coverage outright. Get those enforced and documented, then work the rest. Some carriers will write the policy with a remediation timeline attached if you show a credible plan. Talk to your broker early, not the week before.
Will a claim really get denied over one missing control?
Yes, and it already has. Travelers rescinded a policy in 2022 over an MFA misstatement. The City of Hamilton ate an $18.3 million bill after partial MFA. Carriers treat these controls as conditions of coverage, not suggestions. One documented gap is enough.
How long does it take to get ready?
Anywhere from a few weeks to a couple of months, depending where you start. A company with decent hygiene might close the gaps fast. One starting from antivirus and nightly file copies should plan on a couple of months of steady work to deploy EDR everywhere, stand up immutable backups, and build the evidence trail underwriters now expect to see. The point is to start before the questionnaire, not after.

Related Articles

Stay ahead with expert tips, industry trends, and actionable strategies.