Cyber Insurance Readiness: What Insurers Require

Cyber Insurance Readiness: What Insurers Actually Require Now

Having a Policy Is Not the Same as Being Covered

By David Luft | CEO, LDD Consulting | MCSE, MCT, MBA | Published September 17, 2026 | 6 min read

Cyber Insurance Readiness What Insurers Require

THE SHORT ANSWER

Cyber insurance used to be a simple application and a check. Today, insurers require documented proof of specific security controls — multi-factor authentication, endpoint detection and response, tested backups, and a written incident response plan — before they’ll write or renew a policy. Missing any one of them can mean a denied application, a much higher premium, or a denied claim after the fact, even if you had a policy in place when the incident happened.

Why Cyber Insurance Isn’t What It Used to Be

For years, cyber liability insurance was easy to buy: fill out a short questionnaire, answer mostly “yes,” and get a policy. That changed as claims caught up with carriers. Business email compromise alone accounted for roughly $2.77 billion in reported losses in 2024, and ransomware claims have followed a similar trajectory. Insurers responded the way any industry does when it starts losing money on thin underwriting: they got specific. Today’s applications and renewals ask pointed, technical questions, and answering “yes” without evidence to back it up is a common reason coverage gets denied or a later claim doesn’t pay out.

Pro tip: If it’s been more than a year since your business last reviewed its cyber policy application, assume the questions have gotten more specific since then — they usually have.

The Core Controls Insurers Require in 2026

Multi-Factor Authentication (MFA) Everywhere:

Not just on email — insurers increasingly expect MFA on remote access, admin accounts, and cloud applications. Enabled but not enforced is treated the same as not having it.

Endpoint Detection and Response (EDR), Not Just Antivirus:

Traditional antivirus catches known threats. EDR watches for suspicious behavior in real time, and most carriers now require it specifically by name, especially for coverage above $1 million.

Immutable, Tested Backups:

Backups that exist are not the same as backups that work. Insurers increasingly want evidence of regular restore testing on your data backup and recovery process, not just a backup schedule.

A Documented, Tested Incident Response Plan:

A written plan that’s never been exercised is treated with real skepticism during underwriting — and during a claim investigation.

Security Awareness Training:

Since the large majority of successful attacks start with human error, insurers increasingly expect evidence of regular staff training, not just a one-time onboarding session.

What “Documented Proof” Actually Means

This is the part most businesses underestimate. It’s not enough to have MFA, EDR, and backups in place — insurers want evidence: screenshots of MFA enforcement settings, EDR deployment reports, backup restore test logs, and a dated, named incident response plan. If a claim is filed and an investigation finds a control was missing or unenforced at the time of the incident, insurers can reduce the payout or deny the claim outright, even though the policy was active and premiums were paid.

Pro tip: Keep a simple, dated folder of this evidence as you go — screenshots, test logs, training completion records — rather than trying to reconstruct it during a renewal or, worse, during a claim.

How to Get, and Stay, Insurance-Ready

Start With a Gap Assessment:

Compare what you actually have in place against what your specific policy or renewal questionnaire asks for. This is also good groundwork for a broader compliance review, since the two overlap significantly.

Build the Proof Packet as You Go:

Documentation gathered in the moment, when a control is set up or tested, is far more reliable than documentation reconstructed months later under deadline pressure.

Revisit at Every Renewal, Not Just at Signup:

Requirements have tightened every year for several years running. What qualified you for coverage two years ago may not qualify you today.

This is one of the areas where managed IT services and cybersecurity work together directly: the controls insurers require are largely the same controls that reduce your actual risk of an incident in the first place, and a managed provider can maintain both the controls and the documentation as ongoing practice rather than a scramble before renewal.

Common Mistakes Businesses Make

Mistake 1 — Assuming Existing Antivirus Counts as EDR:

They’re different categories of protection, and most carriers now distinguish between them explicitly on applications.

Mistake 2 — Enabling MFA but Not Enforcing It:

Optional MFA that employees can dismiss or skip is functionally the same as not having it, from an insurer’s perspective.

Mistake 3 — Answering the Questionnaire From Memory:

Underwriting and claims investigations both rely on documentation, not recollection. If you can’t produce it, it’s treated as if it doesn’t exist.

Mistake 4 — Treating the Policy as Done Once It’s Bound:

Controls drift over time — new employees, new tools, lapsed training. A policy signed a year ago based on that year’s setup doesn’t guarantee coverage matches your setup today, which is part of why a tested incident response plan matters on an ongoing basis, not just once.

Frequently Asked Questions

We already have a cyber policy — doesn't that mean we're covered?

Having a policy and being able to actually collect on it after an incident are two different things. If a claims investigation finds a required control was missing, insurers can reduce or deny payment even on an active policy.

What's the difference between EDR and the antivirus we already have?

Antivirus checks files against known threat signatures. EDR monitors behavior in real time and can catch attacks that don’t match anything in a signature database — which is most modern ransomware and BEC activity.

How often do backup restores actually need to be tested?

Quarterly is a common baseline among carriers, though some require it more often for higher coverage limits. The key point is that testing needs to be documented, not just performed.

Will meeting these requirements actually lower our premium?

Often, yes. Carriers have publicly noted meaningful premium reductions for businesses that can demonstrate MFA, EDR, and tested backup recovery, since those controls measurably reduce claims risk.

Do we need a formal third-party assessment to qualify?

Not always, but it’s increasingly requested for higher coverage limits or regulated industries, and it strengthens an application even when it isn’t required outright.

Where should we start if we're not sure what we currently have documented?

Start with a straightforward gap review: what controls exist, what’s actually enforced, and what you could prove if asked today. Contact us and we can walk through it with you.

David Luft

CEO, LDD Consulting

David founded LDD Consulting in 2003 with a straightforward mission: help small and mid-sized businesses in Albuquerque and across New Mexico get reliable, enterprise-quality IT support without the enterprise price tag. He holds an MBA with a concentration in Information Systems from the University of New Mexico, along with Microsoft Certified Systems Engineer (MCSE) and Microsoft Certified Trainer (MCT) credentials. He’s been solving business technology problems for more than 25 years. 

Linkedin |  Learn More About David