What cyber insurance requires in 2026
Cyber insurance underwriting has changed substantially since 2020. What was once a relatively straightforward application process has become, at many carriers, an evidence-based technical review. The 2026 application reads like a security audit: 12 to 20 pages of line-by-line control questions, and carriers verify answers independently.
The important distinction for buyers: requirements differ by insurer, policy type, coverage limit, industry, and risk profile. There is no single universal checklist. What one carrier makes a condition of coverage another may treat as a rating factor that affects premium rather than eligibility. Your broker and your actual policy documents are the authoritative source. What follows describes what insurers commonly assess, not what every policy mandates.
That said, most insurers now require phishing-resistant MFA for all remote access and privileged accounts, EDR deployment on at least 95% of endpoints, isolated or immutable backup infrastructure tested quarterly, a documented incident response plan with annual exercises, and privileged access management for administrator accounts as hard minimums. Applications that cannot demonstrate these controls are declined or face significantly higher premiums and lower coverage limits.
US cyber premiums reached $7.5 billion in 2025 and rates have softened since 2022 peaks, but the loss ratio rose 4.3 points to 53.0% in 2025, its first move above 50% since the ransomware surge. Softening pricing and rising losses mean underwriting scrutiny is not relaxing.
What cyber insurance actually covers
Cyber policy coverage varies significantly by insurer and policy wording. The following describes categories that commonly appear, not guarantees of what any specific policy includes. Read the definitions, exclusions, sublimits, and conditions in the actual policy document before relying on coverage assumptions.
Key caveats: ransomware payment coverage varies significantly and may have sublimits or specific conditions. Regulatory fines and penalties are not universally covered, and insurability depends on jurisdiction and policy wording. Business interruption typically requires a waiting period to trigger. Review exclusions carefully: many policies exclude incidents caused by unpatched known vulnerabilities, failure to maintain stated controls, or war and state-sponsored attacks.
What insurers commonly ask about and what evidence matters
| Security control | Why insurers commonly assess it | Evidence that may be requested |
|---|---|---|
| MFA | Compromised credentials are the most common ransomware and BEC entry point. MFA coverage across email, VPN, and privileged accounts is often a pass-fail factor. | Identity provider configuration showing MFA enforcement percentages; coverage across email, VPN, cloud consoles, and privileged accounts |
| Endpoint detection and response (EDR) | Basic antivirus is no longer accepted by most carriers. EDR with behavioral analysis across all workstations and servers is increasingly baseline. | EDR console showing deployment coverage across endpoints and servers; evidence of managed monitoring or response capability |
| Backups | Tested, immutable backups are the primary recovery mechanism for ransomware. Aon has explicitly cited backup gaps alongside MFA and EDR as a coverage refusal criterion. | Backup configuration, retention policy, immutability settings, and the date of the most recent successful restore test |
| Patch management | Many incidents exploit known, patchable vulnerabilities. Underwriters ask about patch timelines and whether critical systems carry unpatched exposures. | Patch reports showing critical-patch deployment timelines; evidence that critical vulnerabilities are tracked to remediation |
| Privileged access management (PAM) | Administrator accounts with unconstrained access amplify incident severity. PAM limits blast radius. | Access records, just-in-time elevation policies, service-account vaulting evidence |
| Email security | Phishing remains the primary initial-access vector. Carriers increasingly expect a named email security product beyond native defaults, and DMARC at enforcement policy. | Email security platform configuration; DMARC record at p=quarantine or p=reject |
| Security awareness training | Human error is a factor in a significant proportion of incidents. Training and phishing simulation reduce likelihood. | Training programme records; phishing simulation completion rates and results |
| Incident response plan | A tested IR plan reduces time-to-containment and demonstrates response readiness, which insurers regard as materially affecting loss severity. | Written IR plan with version date; evidence of tabletop exercise or simulation in the past 12 months |
| Vulnerability management | Unmanaged vulnerabilities on internet-facing systems are a primary attack path. Insurers ask about scan frequency and remediation SLAs. | Scan reports; remediation tracking by severity; evidence of weekly external scanning for internet-facing assets |
| Logging and monitoring | Detection capability affects dwell time, which affects loss severity. Insurers ask who monitors alerts, response times, and whether after-hours coverage exists. | SIEM or monitoring platform configuration; evidence of 24/7 coverage or managed detection service |
The attestation problem: what you say must match what's actually running
Cyber insurance applications ask organizations to attest to their security practices. Application answers function as warranties. Misstate any of them and your insurer can rescind the policy after a claim.
The risk is not only deliberate misrepresentation. It is the gap between what a company believes is true and what is actually implemented. Common examples: MFA is enabled for most employees but not for privileged accounts or backup consoles. Backups run nightly but restores have never been tested. EDR is deployed on workstations but not servers. Former-employee accounts remain active in the directory. Patches are applied to most systems, but business-critical applications are routinely deferred. An incident-response plan exists as a document but nobody has practiced it.
Why your MSP matters and what to actually ask them
An MSP can be a significant asset in preparing for cyber insurance underwriting. The relevant question is not "Do we have an MSP?" but "What can our MSP actually demonstrate about the controls in our environment?"
A capable MSP managing your cybersecurity can help by: deploying and enforcing MFA across the user population and privileged accounts; managing EDR deployment and coverage across all endpoints and servers; configuring, monitoring, and testing backups; applying patches within timelines insurers expect; managing identity lifecycle so former-employee accounts are disabled promptly; producing reports on control coverage, patch status, and vulnerability posture; maintaining documentation insurers may request; and supporting incident response coordination when an event occurs.
Having an MSP does not guarantee insurance approval or claim payment. Insurers assess the organization's actual security posture, not the presence of a vendor relationship. An MSP that manages IT without enforcing security controls does not strengthen a company's underwriting position in the way that a security-capable MSP actively monitoring and documenting those controls does.
A good MSP relationship should move the business through all five: adequate insurance coverage matched to actual risk; security controls actively implemented and maintained; documented evidence ready before the questionnaire arrives; ongoing monitoring that maintains control effectiveness; and tested response capability when an incident occurs. If the MSP is only active in one or two of these stages, that is a gap worth addressing before renewal.
Cyber insurance should not be treated as a form-filling exercise. The application should reflect the company's actual security posture, and the MSP should be able to help the business understand, maintain, and demonstrate that posture before the question is asked.