If you want cyber insurance in 2026, the application is no longer a formality. Insurers now check your security before they agree to cover you, and the cyber insurance requirements they ask about have gotten a lot stricter over the past few years. The good news is that the list is short and predictable. Meet it, and you get covered at a fair price. Skip it, and you either pay far more or get turned down.
This guide walks through the five controls almost every insurer wants to see in 2026, why they care about each one, and how to document it so your application sails through. You can treat the checklist near the end as a to do list before you ask for a quote.
Why cyber insurance requirements got tougher
A few years ago you could buy a policy by ticking a couple of boxes on a one page form. Then ransomware losses exploded, insurers paid out far more than they expected, and they started losing money on cyber. Their response was simple: raise the bar on who qualifies.
Now underwriters ask detailed questions about your defenses, and they increasingly want proof, not just a yes. The single biggest reason claims get denied is a missing or undocumented security control, so the questionnaire is really the insurer protecting itself from paying out on a business that left the door open. Roughly 41% of applications are turned down on the first try, and the top two reasons are missing multifactor authentication and weak endpoint protection.

None of this means you need an enterprise security team. Most of these controls are things a small business can set up in a weekend with help from an IT provider. Let’s go through them.
The 5 controls insurers want in 2026
1. Multifactor authentication (MFA)
MFA is the one control you cannot skip. It means a password alone isn’t enough to log in. You also need a second step, usually a code from an app on your phone or a tap on a prompt. Insurers care because stolen passwords are behind a huge share of breaches, and MFA stops most of those attacks cold.
In 2026, nearly every carrier requires MFA on email, on any remote access into your network, and on administrative or admin level accounts. If you don’t have it, many insurers won’t quote you at all, and the ones that do can charge 25% or more above standard rates. When claims get denied, MFA is the thread that ties most of them together. In one widely cited review, 82% of denied claims involved a business that lacked MFA where it mattered.
How to document it: turn on MFA in your email platform (Microsoft 365 or Google Workspace both include it), your VPN or remote desktop tool, and your key business apps. Take a screenshot of the admin setting that shows MFA is enforced for all users, not just available. That screenshot is exactly what an underwriter wants to see.
2. Endpoint detection and response (EDR)
Endpoint detection and response is security software that sits on every laptop, desktop, and server and watches for suspicious behavior, then blocks or isolates it. Think of it as a smarter replacement for old fashioned antivirus. Regular antivirus looks for known threats. EDR watches for the sneaky patterns that signal an attack in progress.
Insurers have moved past basic antivirus and now expect EDR on all endpoints. Many carriers now prefer a managed version, sometimes called MDR, where a security team watches the alerts around the clock instead of only during business hours. Attackers love nights and weekends precisely because no one is looking, so 24/7 monitoring has become a real differentiator in how underwriters price your policy.
How to document it: note which EDR product you use and confirm it’s installed on every company device. If a provider manages it for you, keep their coverage summary handy.
3. Tested, isolated backups
Backups are your recovery plan when everything else fails. If ransomware locks up your files, a clean backup lets you restore instead of paying a ransom. But insurers have learned that backups often fail at the worst moment, either because the attacker reached them too, or because no one ever tested a restore.
So the 2026 standard is specific. Carriers want backups that are isolated or air gapped from your main network, ideally immutable, meaning they can’t be altered or deleted once written. And they want evidence that you’ve actually tested a restore, not just that the backup runs. If you have never confirmed that your backup can be brought back to life, you have a backup you can’t trust.

How to document it: record your backup schedule, confirm at least one copy is offline or in a separate cloud account, and run a test restore. Jot down the date it succeeded. For a fuller look at how backups tie into ransomware insurance, that piece covers what’s paid and what’s excluded when an attack hits.
4. A tested incident response plan
An incident response plan is a written playbook for what happens in the first hours of a breach. Who do you call first? Who can shut down systems? How do you reach your insurer, your lawyer, and your customers? Insurers want this because a calm, fast response usually means a smaller, cheaper claim.
The word underwriters keep using is tested. A plan sitting in a drawer doesn’t count for much. Running a tabletop exercise, where your team talks through a pretend breach for an hour, is enough to satisfy most carriers, and it usually exposes gaps you’d rather find now than during a real attack. One more thing to build in: most policies require you to report a breach within a tight window, often 48 to 72 hours, or your claim can be denied for late notice.
How to document it: write a one to two page plan with names, phone numbers, and clear steps. Note the date of your last tabletop walkthrough. Keep your insurer’s breach hotline in the plan itself.
5. A documented patch management program
Patching means keeping your software up to date so known holes get closed before attackers use them. Many of the biggest breaches trace back to a security fix that was available for months but never installed. Insurers know this, so they ask how quickly you apply updates.
You don’t need a fancy system. What you need is a routine and a record. A documented program simply means you have a defined schedule for installing critical updates, usually within a set number of days, and someone who owns the task. Lapsed patching shows up again and again as a reason claims fall through, right alongside expired MFA.
How to document it: enable automatic updates where you safely can, set a monthly patch day for the rest, and keep a simple log. Even a shared spreadsheet showing what got updated and when will do.
The readiness checklist
Here’s the short version to run through before you request a quote. These are the cyber insurance requirements that matter most, so if you can answer yes to each row with proof, you’re in strong shape.
| Control | What insurers want | Your proof |
|---|---|---|
| Multifactor authentication | MFA enforced on email, remote access, and admin accounts | Screenshot of the enforced setting |
| Endpoint detection and response | EDR on every device, ideally monitored 24/7 | Product name and device coverage |
| Backups | Isolated or immutable backups with a tested restore | Schedule plus a successful restore date |
| Incident response plan | A written plan that has been tested | The plan and your last tabletop date |
| Patch management | A defined schedule for critical updates | Your patch log or update policy |
What happens if you don’t meet the requirements
Falling short doesn’t always mean a flat no, but it costs you. Missing basic controls like MFA or EDR can add 25% to 50% to your quote, push you toward a higher deductible, or trigger a ransomware exclusion that guts the coverage you were buying it for. In the worst case, the insurer declines to quote at all.
There’s a quieter risk too. Some businesses attest to controls on the application that they don’t fully have in place, then a claim reveals the gap. That’s when a denial really stings, because the policy was paid for but the protection wasn’t real. Honesty on the questionnaire, backed by proof, is what keeps a claim payable. If you’re weighing the trade offs, our guide to what cyber insurance costs in 2026 shows how these controls move your premium in real numbers, and you can get a free quote from there once you’re ready.
How meeting the requirements lowers your premium
The same controls that qualify you also make you cheaper to insure. An underwriter reads a fully documented security posture as a lower risk, and lower risk means a better price. Businesses that show MFA everywhere, monitored EDR, tested backups, a rehearsed response plan, and steady patching tend to land at the friendlier end of the range.

It’s worth remembering that the median small business premium sits near $1,740 a year in 2026, and strong controls help keep you at or below that rather than well above it. The controls aren’t just an insurance hoop either. They’re the same protections that stop the attack from happening, which is the real win. Coverage pays for the damage, but good security means you may never file a claim at all. For the bigger picture on what a policy actually pays for, see what cyber insurance covers, and if you’re just getting started, the small business cyber insurance guide ties it all together.
Key takeaways
- Five controls carry most of the weight: MFA, EDR, tested and isolated backups, a tested incident response plan, and documented patching.
- MFA is non negotiable. Without it, many insurers won’t cover you, and it’s the most common thread in denied claims.
- Insurers increasingly want proof, not just a yes. Keep screenshots, logs, and dates ready.
- Missing controls can add 25% to 50% to your price or trigger an exclusion. Meeting them helps keep you near the median premium.
- Report any breach fast, usually within 48 to 72 hours, or you risk a denial for late notice.
Frequently asked questions
What are the cyber insurance requirements for a small business?
Most insurers in 2026 want to see multifactor authentication on email and remote access, endpoint detection and response on your devices, isolated backups you’ve tested, a written and tested incident response plan, and a routine for installing security updates. Some carriers add extras like email filtering or admin account controls, but those five are the core.
Is MFA really required for cyber insurance?
For practical purposes, yes. Nearly every carrier requires MFA on email, remote access, and administrative accounts, and without it you may not qualify or you’ll pay a steep surcharge. It’s also the control most often missing when a claim gets denied, so it’s the first thing to fix.
Can I get cyber insurance without meeting all the requirements?
Sometimes, but it costs you. You might face a higher premium, a bigger deductible, or an exclusion that removes coverage for the very thing you’re worried about, like ransomware. It’s usually cheaper and safer to close the gaps first, then apply.
How do I prove I have these controls?
Keep simple evidence: a screenshot showing MFA is enforced, the name of your EDR product and the devices it covers, a backup schedule with a successful restore date, your incident response plan with the date of your last tabletop test, and a patch log. Being able to produce proof quickly is what underwriters trust most.
Do these requirements change how much I pay?
They do. Strong, documented controls read as lower risk and tend to earn a better rate, while missing controls can add 25% to 50% or more. The same steps that qualify you also lower the odds you ever need to file, which is the bigger payoff.

