Cyber Insurance Requirements 2026: MFA, EDR, Backups
If your cyber insurance renewal packet looks more like a security audit every year, that's because it is one. In 2026, carriers won't write or renew small-business policies without specific, verifiable controls: multi-factor authentication on email and remote access, EDR on endpoints, tested and offline backups, a patching process, security training, and email filtering. Answer yes to something you don't actually have, and the policy you paid for can evaporate exactly when you need it. Here's what insurers require, why, and what happens when the attestation doesn't match reality.
Why did cyber insurance requirements get so strict?
Because carriers lost money. Through the early 2020s, ransomware claims blew up loss ratios across the industry, and insurers responded the only way they could: raise premiums and stop covering businesses that skip the basics. Industry data showed that a huge share of paid claims traced back to the same few gaps — no MFA, no EDR, backups that ransomware encrypted along with everything else. So those items stopped being suggestions and became conditions of coverage.
For a Sacramento business with 5–100 employees, this actually cuts both ways. The requirements are a hassle, but they're also a floor: every control on the list is something you should have anyway, and the businesses that implement them see fewer incidents and better premiums. The application is essentially a free map of what attackers exploit.
What controls do insurers actually require in 2026?
The core list is remarkably consistent across carriers. Here's what shows up on nearly every small-business application, what the insurer is really asking, and the trap in each question:
| Required control | What the carrier means | Where businesses get it wrong |
|---|---|---|
| MFA everywhere | MFA on email, VPN/remote access, and all admin accounts — not just some users | "We have MFA" but three service accounts and the owner's account are exempted |
| EDR on endpoints | Behavior-based detection and response on every workstation and server | Consumer antivirus checked as EDR; unmanaged personal laptops accessing company data |
| Tested backups | Offline or immutable copies, with documented restore tests | Nightly backup to a NAS on the same network; never restore-tested |
| Patch management | A defined process and timeline for OS and application updates | Windows Update on autopilot; forgotten server or firewall firmware years behind |
| Security awareness training | Recurring training plus phishing simulations, with records | A single onboarding video from 2022 counted as "annual training" |
| Email filtering | Advanced filtering for phishing, spoofing, and malicious attachments | Default spam filter only; no protection against lookalike-domain invoice fraud |
| Incident response plan | A written plan naming who does what in a breach | Nothing written; "we'd call our IT guy" |
Mid-size policies and regulated industries often see additional questions: privileged access management, network segmentation, encryption of data at rest, end-of-life software inventory, and 24/7 monitoring or a SOC. If you're in healthcare, finance, or law, expect the longer version — and expect it to overlap heavily with your regulatory obligations, which is why IT compliance and insurance readiness are usually solved as one project.
What happens if you check a box you shouldn't have?
The polite term is "material misrepresentation," and the consequence is claim denial or policy rescission. When you sign a cyber application, you're attesting facts. If ransomware hits and the carrier's forensics team finds that the MFA you attested to wasn't actually enforced on the account that got phished, the carrier can refuse the claim — and in publicized cases, carriers have gone to court to rescind policies entirely over inaccurate attestations. You end up with the breach, the recovery bill, and no coverage.
The failure is rarely dishonest; it's usually optimistic. The owner remembers approving an MFA project, assumes it got finished, and checks yes. Nobody verifies that the CFO's legacy email protocol bypass or the after-hours remote access tool got included. The gap between "we bought it" and "it's enforced everywhere" is exactly where claims die.
The fix is simple: treat every application answer as a claim you'd have to prove in court, and have whoever runs your IT verify each one in writing. Not sure your answers would survive a forensics review? Book a free IT assessment and we'll tell you exactly which boxes you can honestly check.
How do you close the gaps before renewal?
Start 60–90 days before your renewal date, not the week the application arrives. The typical sequence: run a gap assessment against the carrier's control list, fix the cheap and fast items first (MFA enforcement, email filtering settings, removing end-of-life software), then tackle the projects (EDR deployment, backup redesign with offline or immutable copies, documented patching). Keep evidence as you go — screenshots, reports, training logs — because some carriers now verify with external scans rather than taking your word.
Cost-wise, third-party market data puts the full small-business security stack — MFA, EDR, managed backup, filtering, training — in the range of roughly $100–$250 per employee per month when bundled through a managed provider, often less than the premium increase (or coverage loss) that comes from skipping it. Standalone pieces are cheaper but leave you assembling and attesting on your own.
This is the core of what a managed cybersecurity program does: implement the controls, keep them enforced continuously rather than just at renewal time, and hand you the documentation when the application or the auditor asks. For businesses with in-house IT, a co-managed setup covers the same ground without replacing your team.
What should you do before signing this year's application?
Verify, don't recall. Pull the actual application, go control by control, and demand current evidence for every yes: an MFA enforcement report from Microsoft 365, an EDR console showing all devices covered, the date and result of your last restore test, training completion records. Anything you can't evidence, either fix before signing or answer honestly and let the underwriter price it.
An honest "no" costs you some premium. A wrong "yes" can cost you the entire claim — which, for a serious ransomware event, is the difference between a bad quarter and a business that doesn't reopen. Insurers built the list from real losses; the smartest move a small business can make is to treat it as the free security roadmap it accidentally is.