What Cyber Insurers Now Require: Meeting Underwriting Standards in 2026
Cover is now conditional on demonstrable controls. Misrepresenting them is how claims get denied.
Cyber insurance has stopped being a formality. Underwriters now assess controls in detail, decline applicants who cannot demonstrate baseline hygiene, and scrutinise application answers closely at claim time. That last point catches organisations out most severely.
The controls that gate cover
| Control | Expected standard |
|---|---|
| Multi-factor authentication | All remote access, all privileged accounts, all email — no exceptions |
| Endpoint detection and response | Deployed across servers and workstations with active response capability |
| Backups | Immutable or offline copies, credential-isolated, restoration tested |
| Patching | Critical and internet-facing vulnerabilities within a defined window |
| Incident response | Documented plan, exercised within the last twelve months |
| Email security | DMARC enforcement, attachment and link protection |
| Privileged access | No standing administrative rights; separate admin accounts |
Note the phrase "no exceptions" against MFA. Partial deployment is the single most common reason for both declined applications and disputed claims, because the exception is invariably where the intrusion happened.
Answer the application accurately
Application responses are material representations. "Do you enforce MFA on all remote access?" has a precise answer, and it is not the one your policy document aspires to.
Before submitting, verify each claim against evidence: pull the actual MFA coverage report, the EDR deployment percentage, the most recent restore test result, and patch compliance figures. Where coverage is partial, say so and describe the compensating control. Underwriters price known gaps; they deny claims for undisclosed ones.
Understand what the policy excludes
Read the exclusions with the same attention as the limits. Common ones that surprise buyers include state-sponsored or "war" exclusions, unpatched known vulnerabilities where a fix was available, failure to maintain the controls declared at application, social engineering and funds transfer fraud requiring a separate endorsement, and betterment costs for infrastructure improvements made during recovery.
Also check whether business interruption cover starts after a waiting period, and whether it includes losses caused by a vendor's outage rather than your own — contingent business interruption is frequently excluded or sub-limited.
Build the evidence pack once
The same evidence satisfies underwriters, auditors, and enterprise customers, so assemble it as a maintained artefact: control coverage reports with dates, restore test results, incident response exercise summaries, penetration test reports with remediation status, patch compliance metrics, and vendor risk register extracts.
Organisations with this pack ready complete renewals faster and negotiate better terms, simply because they can substantiate claims that competitors merely assert.
Use renewal as a forcing function
Renewal questionnaires are an unusually effective internal lever. Map each question to your actual state, present the gaps to leadership with the premium and coverage consequence attached, and fund remediation on that basis. Security investment framed as insurable risk reduction is approved considerably more often than the same investment framed as maturity improvement.
Then keep the declared controls in place. Allowing MFA exceptions to accumulate after binding a policy converts your cover into an expense with no payout.
Frequently asked questions
What controls do insurers require?
Universal MFA on remote and privileged access, EDR coverage, immutable and tested backups, an exercised incident response plan, timely critical patching, and email security including DMARC.
Can a claim be denied for misstated controls?
Yes — application answers are material representations, and a stated control absent on the compromised system can reduce or void the claim.
How do we reduce premiums?
Provide evidence rather than assertions: phishing-resistant MFA, documented restore tests, full EDR coverage, measured patch compliance, and a recent incident exercise.
Is cyber insurance a substitute for controls?
No. It is a financial backstop, and increasingly one that requires the controls as a precondition of cover.