Cyber Insurance Requirements 2026: MFA, EDR, Backups

If your cyber insurance renewal packet looks more like a security audit every year, that's because it is one. In 2026, carriers won't write or renew small-business policies without specific, verifiable controls: multi-factor authentication on email and remote access, EDR on endpoints, tested and offline backups, a patching process, security training, and email filtering. Answer yes to something you don't actually have, and the policy you paid for can evaporate exactly when you need it. Here's what insurers require, why, and what happens when the attestation doesn't match reality.

Why did cyber insurance requirements get so strict?

Because carriers lost money. Through the early 2020s, ransomware claims blew up loss ratios across the industry, and insurers responded the only way they could: raise premiums and stop covering businesses that skip the basics. Industry data showed that a huge share of paid claims traced back to the same few gaps — no MFA, no EDR, backups that ransomware encrypted along with everything else. So those items stopped being suggestions and became conditions of coverage.

For a Sacramento business with 5–100 employees, this actually cuts both ways. The requirements are a hassle, but they're also a floor: every control on the list is something you should have anyway, and the businesses that implement them see fewer incidents and better premiums. The application is essentially a free map of what attackers exploit.

What controls do insurers actually require in 2026?

The core list is remarkably consistent across carriers. Here's what shows up on nearly every small-business application, what the insurer is really asking, and the trap in each question:

Required control What the carrier means Where businesses get it wrong
MFA everywhere MFA on email, VPN/remote access, and all admin accounts — not just some users "We have MFA" but three service accounts and the owner's account are exempted
EDR on endpoints Behavior-based detection and response on every workstation and server Consumer antivirus checked as EDR; unmanaged personal laptops accessing company data
Tested backups Offline or immutable copies, with documented restore tests Nightly backup to a NAS on the same network; never restore-tested
Patch management A defined process and timeline for OS and application updates Windows Update on autopilot; forgotten server or firewall firmware years behind
Security awareness training Recurring training plus phishing simulations, with records A single onboarding video from 2022 counted as "annual training"
Email filtering Advanced filtering for phishing, spoofing, and malicious attachments Default spam filter only; no protection against lookalike-domain invoice fraud
Incident response plan A written plan naming who does what in a breach Nothing written; "we'd call our IT guy"

Mid-size policies and regulated industries often see additional questions: privileged access management, network segmentation, encryption of data at rest, end-of-life software inventory, and 24/7 monitoring or a SOC. If you're in healthcare, finance, or law, expect the longer version — and expect it to overlap heavily with your regulatory obligations, which is why IT compliance and insurance readiness are usually solved as one project.

What happens if you check a box you shouldn't have?

The polite term is "material misrepresentation," and the consequence is claim denial or policy rescission. When you sign a cyber application, you're attesting facts. If ransomware hits and the carrier's forensics team finds that the MFA you attested to wasn't actually enforced on the account that got phished, the carrier can refuse the claim — and in publicized cases, carriers have gone to court to rescind policies entirely over inaccurate attestations. You end up with the breach, the recovery bill, and no coverage.

The failure is rarely dishonest; it's usually optimistic. The owner remembers approving an MFA project, assumes it got finished, and checks yes. Nobody verifies that the CFO's legacy email protocol bypass or the after-hours remote access tool got included. The gap between "we bought it" and "it's enforced everywhere" is exactly where claims die.

The fix is simple: treat every application answer as a claim you'd have to prove in court, and have whoever runs your IT verify each one in writing. Not sure your answers would survive a forensics review? Book a free IT assessment and we'll tell you exactly which boxes you can honestly check.

How do you close the gaps before renewal?

Start 60–90 days before your renewal date, not the week the application arrives. The typical sequence: run a gap assessment against the carrier's control list, fix the cheap and fast items first (MFA enforcement, email filtering settings, removing end-of-life software), then tackle the projects (EDR deployment, backup redesign with offline or immutable copies, documented patching). Keep evidence as you go — screenshots, reports, training logs — because some carriers now verify with external scans rather than taking your word.

Cost-wise, third-party market data puts the full small-business security stack — MFA, EDR, managed backup, filtering, training — in the range of roughly $100–$250 per employee per month when bundled through a managed provider, often less than the premium increase (or coverage loss) that comes from skipping it. Standalone pieces are cheaper but leave you assembling and attesting on your own.

This is the core of what a managed cybersecurity program does: implement the controls, keep them enforced continuously rather than just at renewal time, and hand you the documentation when the application or the auditor asks. For businesses with in-house IT, a co-managed setup covers the same ground without replacing your team.

What should you do before signing this year's application?

Verify, don't recall. Pull the actual application, go control by control, and demand current evidence for every yes: an MFA enforcement report from Microsoft 365, an EDR console showing all devices covered, the date and result of your last restore test, training completion records. Anything you can't evidence, either fix before signing or answer honestly and let the underwriter price it.

An honest "no" costs you some premium. A wrong "yes" can cost you the entire claim — which, for a serious ransomware event, is the difference between a bad quarter and a business that doesn't reopen. Insurers built the list from real losses; the smartest move a small business can make is to treat it as the free security roadmap it accidentally is.

Frequently asked questions

What IT controls do cyber insurance carriers require?
The near-universal list in 2026 is multi-factor authentication on email, remote access, and admin accounts; endpoint detection and response (EDR) on all devices; tested backups that are offline or immutable; a documented patching process; security awareness training with phishing simulations; and email filtering. Larger policies often add requirements like privileged access management, incident response plans, and 24/7 monitoring.
Can an insurer really deny my claim over the application answers?
Yes. The application is a legal attestation, and carriers have denied or rescinded coverage when businesses claimed controls they didn't actually have — checking the MFA box when only some accounts were covered is a common example. If a breach happens and forensics show the attested control was missing or misconfigured, the carrier can decline to pay.
Is antivirus the same thing as EDR?
No, and insurers know the difference. Traditional antivirus matches known malware signatures. EDR (endpoint detection and response) watches behavior — a process encrypting hundreds of files, a login dumping credentials — and can isolate a machine automatically. Most 2026 applications ask for EDR by name, and free consumer antivirus won't satisfy the question.
What counts as a "tested" backup for insurance purposes?
A backup you have actually restored from, recently, with a record of it. Carriers increasingly ask how often you test restores and whether backups are offline, air-gapped, or immutable — meaning ransomware that owns your network still can't encrypt them. A backup job that reports success every night but has never been restore-tested doesn't meet the spirit of the question.
How much does cyber insurance cost for a small business?
Third-party market surveys generally put small-business cyber premiums in the range of roughly $1,000 to $3,000 per year for around $1 million in coverage, though industry, revenue, claims history, and your security posture move that significantly. Businesses with strong controls — MFA, EDR, tested backups — typically see better pricing and fewer exclusions than those without.
Who should fill out the cyber insurance application?
Whoever actually manages your IT should answer the technical questions — not the office manager guessing, and not the owner checking boxes optimistically. If you outsource IT, have your provider review every answer in writing before you sign. The application becomes evidence in a claim dispute, so every yes needs to be verifiably true on the day you sign.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment