What Cyber Insurance Underwriters Actually Want in 2026
May 28, 2026 · 5 min read
If you're applying for cyber insurance this year — or renewing an existing policy — prepare for a different conversation than the one you had a few years ago. Underwriters have tightened their requirements significantly, and they're verifying what you claim to have in place.
Premiums are up, and scrutiny is up with them
Cyber insurance premiums rose between 50% and 100% from 2020 to 2023, according to industry reports. A business that paid $3,000 for a policy in 2020 could easily be looking at $6,000 or more today — if they qualify at all. The days of filling out a one-page questionnaire and getting a quote the next day are over. Underwriters now want evidence, not promises.
What changed? Ransomware claims exploded, and insurers took heavy losses. The industry responded by tightening standards and, in many cases, sending their own assessors to verify what applicants claim on their forms.
MFA is now table stakes
Multi-factor authentication is the single most common baseline requirement across insurers today. If your business doesn't have MFA deployed on email, remote access, and any administrative accounts, expect to be denied coverage outright. Not quoted high — denied. Several major carriers now list MFA as a non-negotiable prerequisite in their underwriting guidelines.
And it's not enough to say you have it. Underwriters are increasingly asking which MFA methods you use. Push-based MFA is better than nothing, but insurers are catching up to the fact that push notifications can be bypassed through MFA fatigue and adversary-in-the-middle attacks. If you want to be ahead of the curve — and possibly qualify for better rates — start planning a move toward phishing-resistant MFA like FIDO2 security keys or passkeys.
Tested backups: proven, not promised
Having backups is no longer enough. Insurers want to know you've tested them — meaning you've actually restored data from those backups recently and confirmed the process works. A backup that hasn't been tested is just a file. Many ransomware victims learned this the hard way when their backups turned out to be corrupted, incomplete, or also encrypted by the attacker.
Some carriers now ask for restoration test logs or require a written backup testing policy. If your IT provider runs a monthly backup check, make sure that gets documented. If you're handling IT yourself, add a quarterly restore test to your calendar right now.
EDR and MDR are becoming the new normal
Endpoint Detection and Response — often called EDR or MDR (Managed Detection and Response) — is showing up on more and more insurance applications. This is software that monitors your computers and servers for suspicious behavior, not just known virus signatures. Think of it as a security camera for your endpoints: it catches things that slip past traditional antivirus.
If you don't have EDR deployed today, you're not automatically disqualified, but you're leaving yourself at a disadvantage. Insurers that don't require it yet often offer discounts for having it. Expect this one to shift from “nice to have” to “required” within the next 12-18 months.
Active vulnerability scanning by insurers
Here's one that surprises a lot of business owners: some insurers now conduct their own external vulnerability scans before issuing or renewing a policy. They're not just taking your word for it. If their scan finds open RDP ports, unpatched VPN appliances, or exposed management interfaces, you'll likely receive a remediation notice with a deadline. Miss the deadline, and the policy doesn't get issued.
Incident response plans
Most insurers now ask whether you have a written incident response plan. They're not expecting a 40-page document from a small business, but they want to see that you've thought through who to call, what to disconnect, and how to communicate if a breach happens. If you don't have one, write a one-pager that covers: who on your team makes decisions during a security incident, which IT provider or security firm you'd contact, how you'd notify affected parties, and where your backups are stored and how to access them.
What insurers typically ask for
- ✓MFA on all remote access and admin accounts — email, VPN, RDP, and any cloud admin consoles
- ✓Documented, tested backups — including offline or immutable copies that ransomware can't reach
- ✓Endpoint detection and response on all workstations and servers
- ✓Regular software patching — particularly for VPN appliances, firewalls, and any internet-facing systems
- ✓A written incident response plan — even a one-pager counts
- ✓Network segmentation — keeping guest Wi-Fi, IoT devices, and critical business systems on separate networks
If your renewal is coming up in the next few months, start gathering this documentation now. The businesses that get the best terms are the ones that can demonstrate their controls are actually in place — not just checked off on a form.
