What cyber insurance requires in 2026

Cyber insurance underwriting has changed substantially since 2020. What was once a relatively straightforward application process has become, at many carriers, an evidence-based technical review. The 2026 application reads like a security audit: 12 to 20 pages of line-by-line control questions, and carriers verify answers independently.

The important distinction for buyers: requirements differ by insurer, policy type, coverage limit, industry, and risk profile. There is no single universal checklist. What one carrier makes a condition of coverage another may treat as a rating factor that affects premium rather than eligibility. Your broker and your actual policy documents are the authoritative source. What follows describes what insurers commonly assess, not what every policy mandates.

That said, most insurers now require phishing-resistant MFA for all remote access and privileged accounts, EDR deployment on at least 95% of endpoints, isolated or immutable backup infrastructure tested quarterly, a documented incident response plan with annual exercises, and privileged access management for administrator accounts as hard minimums. Applications that cannot demonstrate these controls are declined or face significantly higher premiums and lower coverage limits.

US cyber premiums reached $7.5 billion in 2025 and rates have softened since 2022 peaks, but the loss ratio rose 4.3 points to 53.0% in 2025, its first move above 50% since the ransomware surge. Softening pricing and rising losses mean underwriting scrutiny is not relaxing.

What cyber insurance actually covers

Cyber policy coverage varies significantly by insurer and policy wording. The following describes categories that commonly appear, not guarantees of what any specific policy includes. Read the definitions, exclusions, sublimits, and conditions in the actual policy document before relying on coverage assumptions.

First-party losses (your own costs)
Incident response and forensics costs
Business interruption and income loss
Data restoration and system recovery
Customer notification expenses
Crisis communications and PR
Legal expenses related to the incident
Cyber extortion-related costs (where covered; varies by policy and may have sublimits)
Third-party liability (claims against you)
Privacy liability from affected individuals
Network security liability claims
Defense expenses and settlements
Regulatory costs where legally insurable and covered under the policy
Media liability in some policies

Key caveats: ransomware payment coverage varies significantly and may have sublimits or specific conditions. Regulatory fines and penalties are not universally covered, and insurability depends on jurisdiction and policy wording. Business interruption typically requires a waiting period to trigger. Review exclusions carefully: many policies exclude incidents caused by unpatched known vulnerabilities, failure to maintain stated controls, or war and state-sponsored attacks.

What insurers commonly ask about and what evidence matters

Security control Why insurers commonly assess it Evidence that may be requested
MFACompromised credentials are the most common ransomware and BEC entry point. MFA coverage across email, VPN, and privileged accounts is often a pass-fail factor.Identity provider configuration showing MFA enforcement percentages; coverage across email, VPN, cloud consoles, and privileged accounts
Endpoint detection and response (EDR)Basic antivirus is no longer accepted by most carriers. EDR with behavioral analysis across all workstations and servers is increasingly baseline.EDR console showing deployment coverage across endpoints and servers; evidence of managed monitoring or response capability
BackupsTested, immutable backups are the primary recovery mechanism for ransomware. Aon has explicitly cited backup gaps alongside MFA and EDR as a coverage refusal criterion.Backup configuration, retention policy, immutability settings, and the date of the most recent successful restore test
Patch managementMany incidents exploit known, patchable vulnerabilities. Underwriters ask about patch timelines and whether critical systems carry unpatched exposures.Patch reports showing critical-patch deployment timelines; evidence that critical vulnerabilities are tracked to remediation
Privileged access management (PAM)Administrator accounts with unconstrained access amplify incident severity. PAM limits blast radius.Access records, just-in-time elevation policies, service-account vaulting evidence
Email securityPhishing remains the primary initial-access vector. Carriers increasingly expect a named email security product beyond native defaults, and DMARC at enforcement policy.Email security platform configuration; DMARC record at p=quarantine or p=reject
Security awareness trainingHuman error is a factor in a significant proportion of incidents. Training and phishing simulation reduce likelihood.Training programme records; phishing simulation completion rates and results
Incident response planA tested IR plan reduces time-to-containment and demonstrates response readiness, which insurers regard as materially affecting loss severity.Written IR plan with version date; evidence of tabletop exercise or simulation in the past 12 months
Vulnerability managementUnmanaged vulnerabilities on internet-facing systems are a primary attack path. Insurers ask about scan frequency and remediation SLAs.Scan reports; remediation tracking by severity; evidence of weekly external scanning for internet-facing assets
Logging and monitoringDetection capability affects dwell time, which affects loss severity. Insurers ask who monitors alerts, response times, and whether after-hours coverage exists.SIEM or monitoring platform configuration; evidence of 24/7 coverage or managed detection service

The attestation problem: what you say must match what's actually running

Cyber insurance applications ask organizations to attest to their security practices. Application answers function as warranties. Misstate any of them and your insurer can rescind the policy after a claim.

The risk is not only deliberate misrepresentation. It is the gap between what a company believes is true and what is actually implemented. Common examples: MFA is enabled for most employees but not for privileged accounts or backup consoles. Backups run nightly but restores have never been tested. EDR is deployed on workstations but not servers. Former-employee accounts remain active in the directory. Patches are applied to most systems, but business-critical applications are routinely deferred. An incident-response plan exists as a document but nobody has practiced it.

The practical risk of inaccurate attestation
The moment a claim is filed, insurers examine what controls were actually in place on the date of the incident, not what the application stated. A control on paper that was not enforced in practice creates grounds for claim dispute, coverage reduction, or rescission depending on policy wording and applicable law. Businesses should validate their application answers against actual implementation before signing. An MSP can help confirm what is deployed, monitored, and tested versus what is merely installed. Consult your broker, insurer, and legal advisers for policy-specific guidance.

Why your MSP matters and what to actually ask them

An MSP can be a significant asset in preparing for cyber insurance underwriting. The relevant question is not "Do we have an MSP?" but "What can our MSP actually demonstrate about the controls in our environment?"

A capable MSP managing your cybersecurity can help by: deploying and enforcing MFA across the user population and privileged accounts; managing EDR deployment and coverage across all endpoints and servers; configuring, monitoring, and testing backups; applying patches within timelines insurers expect; managing identity lifecycle so former-employee accounts are disabled promptly; producing reports on control coverage, patch status, and vulnerability posture; maintaining documentation insurers may request; and supporting incident response coordination when an event occurs.

The useful distinction
There is a meaningful difference between an MSP that says "we have these tools deployed" and an MSP that can show you screenshots from the EDR console showing coverage percentages, the identity provider showing MFA enforcement rates, the backup logs showing the date of the last successful restore test, and a patch report showing mean time to remediation by severity. The second MSP is materially more useful for insurance purposes than the first.

Having an MSP does not guarantee insurance approval or claim payment. Insurers assess the organization's actual security posture, not the presence of a vendor relationship. An MSP that manages IT without enforcing security controls does not strengthen a company's underwriting position in the way that a security-capable MSP actively monitoring and documenting those controls does.

🛡️Coverage
⚙️Controls
📋Evidence
👁Monitoring
🔁Response

A good MSP relationship should move the business through all five: adequate insurance coverage matched to actual risk; security controls actively implemented and maintained; documented evidence ready before the questionnaire arrives; ongoing monitoring that maintains control effectiveness; and tested response capability when an incident occurs. If the MSP is only active in one or two of these stages, that is a gap worth addressing before renewal.

Cyber insurance should not be treated as a form-filling exercise. The application should reflect the company's actual security posture, and the MSP should be able to help the business understand, maintain, and demonstrate that posture before the question is asked.