Back to Insights
Cybersecurity

What Cyber Insurers Now Require: Meeting Underwriting Standards in 2026

10 min read

Cover is now conditional on demonstrable controls. Misrepresenting them is how claims get denied.

Cyber insurance has stopped being a formality. Underwriters now assess controls in detail, decline applicants who cannot demonstrate baseline hygiene, and scrutinise application answers closely at claim time. That last point catches organisations out most severely.

The controls that gate cover

ControlExpected standard
Multi-factor authenticationAll remote access, all privileged accounts, all email — no exceptions
Endpoint detection and responseDeployed across servers and workstations with active response capability
BackupsImmutable or offline copies, credential-isolated, restoration tested
PatchingCritical and internet-facing vulnerabilities within a defined window
Incident responseDocumented plan, exercised within the last twelve months
Email securityDMARC enforcement, attachment and link protection
Privileged accessNo standing administrative rights; separate admin accounts

Note the phrase "no exceptions" against MFA. Partial deployment is the single most common reason for both declined applications and disputed claims, because the exception is invariably where the intrusion happened.

Answer the application accurately

Application responses are material representations. "Do you enforce MFA on all remote access?" has a precise answer, and it is not the one your policy document aspires to.

Before submitting, verify each claim against evidence: pull the actual MFA coverage report, the EDR deployment percentage, the most recent restore test result, and patch compliance figures. Where coverage is partial, say so and describe the compensating control. Underwriters price known gaps; they deny claims for undisclosed ones.

Understand what the policy excludes

Read the exclusions with the same attention as the limits. Common ones that surprise buyers include state-sponsored or "war" exclusions, unpatched known vulnerabilities where a fix was available, failure to maintain the controls declared at application, social engineering and funds transfer fraud requiring a separate endorsement, and betterment costs for infrastructure improvements made during recovery.

Also check whether business interruption cover starts after a waiting period, and whether it includes losses caused by a vendor's outage rather than your own — contingent business interruption is frequently excluded or sub-limited.

Build the evidence pack once

The same evidence satisfies underwriters, auditors, and enterprise customers, so assemble it as a maintained artefact: control coverage reports with dates, restore test results, incident response exercise summaries, penetration test reports with remediation status, patch compliance metrics, and vendor risk register extracts.

Organisations with this pack ready complete renewals faster and negotiate better terms, simply because they can substantiate claims that competitors merely assert.

Use renewal as a forcing function

Renewal questionnaires are an unusually effective internal lever. Map each question to your actual state, present the gaps to leadership with the premium and coverage consequence attached, and fund remediation on that basis. Security investment framed as insurable risk reduction is approved considerably more often than the same investment framed as maturity improvement.

Then keep the declared controls in place. Allowing MFA exceptions to accumulate after binding a policy converts your cover into an expense with no payout.

Frequently asked questions

What controls do insurers require?

Universal MFA on remote and privileged access, EDR coverage, immutable and tested backups, an exercised incident response plan, timely critical patching, and email security including DMARC.

Can a claim be denied for misstated controls?

Yes — application answers are material representations, and a stated control absent on the compromised system can reduce or void the claim.

How do we reduce premiums?

Provide evidence rather than assertions: phishing-resistant MFA, documented restore tests, full EDR coverage, measured patch compliance, and a recent incident exercise.

Is cyber insurance a substitute for controls?

No. It is a financial backstop, and increasingly one that requires the controls as a precondition of cover.

Tagged With:

cyber insurance
underwriting
risk management
compliance
resilience

Ready to Transform Your Digital Experience?

Let's discuss how Kinematic Digital can help you achieve your business goals.