In 2026, most cyber insurers won’t write a policy without five things in place: multi-factor authentication everywhere, EDR on endpoints, tested offline backups, security awareness training, and documented patching. Miss one and you’ll face higher premiums, exclusions, or a flat decline. Miss it after signing and a claim can be denied.
That last sentence is the part owners underestimate. The application you sign is a warranty. If the form says MFA is on every account and an adjuster later finds the shared warehouse login without it, you may have paid premiums for coverage that evaporates exactly when you need it. Carriers have litigated this and won. So treat this article as two checklists in one: what gets you a policy, and what keeps the policy honest.
Why did cyber insurance requirements get so strict?
Because carriers lost money for years. Through the late 2010s, cyber policies were cheap and applications were three questions long. Then ransomware payouts, business-interruption claims, and wire-fraud losses stacked up, and the market corrected hard. Underwriters now behave less like paperwork processors and more like auditors: detailed applications, outside scans of your public internet footprint, and in some cases a requirement to attest annually that controls are still running.
The practical effect is that your security posture now sets your insurance cost the way your driving record sets your auto premium. Businesses with mature controls are seeing workable renewals. Businesses without them are seeing 40–100% premium jumps, sublimits that cap ransomware payouts at a fraction of the policy face value, or no offer at all.
The 2026 requirements checklist
Here’s what applications from the major carriers consistently demand, and what each item means in practice:
| Requirement | What insurers actually check | Common failure we find |
|---|---|---|
| MFA on email, remote access, admin accounts | Attestation + sometimes external scan | Service accounts and shared logins skipped |
| EDR / endpoint detection | Named product on the application | Legacy AV listed and rejected |
| Offline or immutable backups | Backup product + tested restore cadence | Backups exist, restores never tested |
| Security awareness training | Vendor name + phishing test frequency | One video at onboarding, nothing since |
| Patch management | Documented process, critical patches in days | “We update when it prompts us” |
| Email filtering / anti-phishing | Product in place | ISP-default filtering only |
| Incident response plan | Written plan, sometimes tabletop evidence | Plan exists in one retired employee’s head |
Two of these deserve a closer look because they sink the most applications.
The MFA requirement for cyber insurance
MFA is non-negotiable with essentially every carrier now, and “on email” isn’t the full requirement. Underwriters want it on all remote access (VPN, remote desktop), all administrative accounts, and increasingly on access to backups themselves, since attackers who reach backups delete them before encrypting anything else. CISA identifies MFA as the single most effective baseline control against credential-based attacks (CISA), and carriers price accordingly.
The trap is coverage gaps you forgot exist: the scan-to-email account on the copier, the vendor’s maintenance login, the “temporary” shared account from 2021. An application that says “MFA: yes, all users” while those exist is the exact fact pattern claim denials are built on. Do the inventory before you sign the form.
The EDR requirement
Applications now ask you to name your endpoint product, and underwriting desks keep lists of what qualifies. Traditional antivirus increasingly doesn’t. We covered why insurers stopped accepting legacy antivirus in depth, but the underwriting logic is simple: signature-based tools can’t see the credential-driven attacks generating most claims. Several carriers go a step further and price meaningfully better when a 24/7 monitored service sits behind the software, because 24/7 detection and response coverage shortens incidents, and short incidents are cheap claims.
What happens during a cyber insurance audit?
Three checkpoints, in practice. At application, expect a 6–12 page questionnaire and, from many carriers, an external scan of your domains looking for exposed remote desktop, expired certificates, and leaked credentials, run without asking you. At renewal, expect the questionnaire again plus questions about any incidents, with attestations compared year over year. At claim time, the real audit: forensics teams verify that the controls you attested to were actually running on the date of loss. Logs, screenshots, license records. This is the one that matters, and it’s why “technically true at signing” isn’t a standard worth meeting.
Our take: fill out the application with your IT provider in the room, literally. Half the questions are ambiguous (“Do you segment your network?” means what, exactly, for a 20-person office?), and an owner answering alone tends to check optimistic boxes. We’d rather flag a “no” honestly and fix it in 30 days than discover it during claim forensics. One is a to-do item. The other is a denied six-figure claim.
A worked example from McKinney
A 22-person CPA firm in McKinney, mid-renewal, brought us a quote that had jumped sharply with a ransomware sublimit added. The application review found three honest “no” answers: MFA missing on two admin accounts and the remote-access tool partners used during tax season, backups running but never test-restored, and no phishing training since 2023. Total remediation was about three weeks of part-time work: MFA rollout, a quarterly restore test on the calendar with evidence saved, and a training platform at a few dollars per user per month. Resubmitted, the sublimit came off and the premium landed materially lower than the first quote. The fixes cost less than one year of the premium difference. Firms in that position are a big part of why our IT support in McKinney work is half security engineering, half paperwork translation.
Worth knowing on top of the policy itself: Texas law gives you 60 days to notify affected individuals after a breach of sensitive personal information, with Attorney General notification required when 250 or more Texans are affected (Tex. Bus. & Com. Code § 521.053, Texas statutes). Good policies fund the lawyers and notification vendors that deadline suddenly makes necessary. Another reason the coverage needs to actually pay.
How to prepare before you apply
Order of operations we recommend, based on what moves quotes most per dollar:
- Inventory every account and access path, then close the MFA gaps, including service accounts, shared logins, and vendor access.
- Replace legacy AV with a named EDR product insurers recognize, monitored if budget allows.
- Test a restore this month and save the evidence. A backup you’ve never restored is a hope, not a control.
- Start recurring phishing training with a vendor that produces reports, because reports are what attestations lean on.
- Write the one-page incident response plan: who calls whom, in what order, with the insurer’s hotline on it.
If it were our building: we’d do all five before requesting quotes rather than after receiving a bad one. Applying with weak controls doesn’t just price this year’s policy badly; the answers stay in your underwriting file and follow you to renewal.
Three questions to ask your broker before binding
Requirements flow both directions, so interrogate the policy the way the carrier interrogates you. First: what are the sublimits, in dollars? A $1M policy with a $100,000 ransomware sublimit and a $250,000 cap on social-engineering fraud is not a $1M policy for the two loss types most likely to hit you. Second: does the policy require using the carrier’s panel vendors for forensics and recovery, and who’s on it? Knowing this before an incident prevents the expensive mistake of hiring your own responders and eating the bill. Third: what exactly voids coverage? Get the material-change and minimum-controls language explained in writing, because letting your EDR lapse mid-term can matter as much as the application itself.
One more layer applies to a specific slice of readers: if you hold Department of Defense contracts, insurer requirements are the easier half of your compliance picture, and the controls overlap heavily with what the DoD now verifies. Our CMMC guide for DFW defense contractors covers how the two stack, and why remediation dollars can satisfy both at once.
Frequently Asked Questions
What are the minimum requirements for cyber insurance?
Is MFA required for cyber insurance?
Can a cyber insurance claim be denied?
What is a cyber insurance audit?
Does cyber insurance require EDR?
Renewal on the desk and not sure which boxes you can honestly check? Our cybersecurity compliance support team will review the application with you line by line and quote exactly what closing each gap takes.
