
Cyber Insurance 2026: What Underwriters Want
Cybersecurity, Cyber Insurance, Risk Management
Cyber Insurance in 2026: What Underwriters Really Want (That Your Broker Won’t Spell Out)
Cyber insurance used to be a quick application and a signature. In 2026, it’s a technical audit in disguise. Underwriters now expect you to prove you’re hard to hack before they’ll put their capital on the line—or keep your premiums remotely affordable. This is the line‑by‑line reality your broker usually won’t walk you through.
Why Cyber Insurance Got So Tough: The 2026 Landscape
Between 2019 and 2022, cyber insurers were hammered by waves of ransomware and business email compromise claims. Losses spiked faster than premiums, and many carriers either pulled back or rewrote the rules. From mid‑2022 through 2025, prices surged, then began to soften as insurers tightened underwriting, raised standards, and exited the riskiest accounts.
By early 2026, several trends are colliding:
Rates have softened, but not for everyone. Global cyber rates have declined for multiple quarters, yet analysts warn the market is nearing a pricing floor. Some forecasts still call for premium increases of 5–20% in 2026, especially for businesses with weak controls or recent claims (sources including Marsh, WTW, S&P Global, and industry outlooks).
Attack severity keeps rising. Ransomware, data theft, and business email compromise are more frequent and more expensive, according to reinsurers like Munich Re and multiple cyber market reports. Losses are not “going back to normal.”
Underwriters now use security as the main pricing lever. With competitive pressure on rates, the easiest way to protect profitability is to insure only organizations that can prove strong cyber hygiene—and to limit or deny the rest.
That’s why the 2026 cyber policy application looks less like an insurance form and more like a condensed IT audit. Your broker may summarize it as “just a questionnaire,” but underwriters are quietly using your answers to decide three things: Do we quote?At what price?With what limits and exclusions?
📌 Key Takeaway: In 2026, cyber insurance is no longer a substitute for cybersecurity. It’s a test of whether your cybersecurity is good enough to be insurable.
The 2026 Underwriter Control Checklist: What They Actually Expect
Different carriers phrase questions differently, but by 2026 most underwriters converge on a core set of controls. Think of this as the “table stakes” list: if you’re missing several of these, you’re either uninsurable or headed for painful pricing and exclusions.
1. Multi-Factor Authentication (MFA)
Plain English: MFA means users need more than just a password to log in—typically a one‑time code, mobile app approval, or security key. It’s like adding a deadbolt to your front door instead of relying on a single lock anyone can copy.
Where underwriters expect MFA in 2026: Email (Microsoft 365, Google Workspace), remote access (VPN, remote desktop, virtual desktops), admin accounts, cloud services, and privileged systems like finance, HR, and production environments.
SMS-only MFA is increasingly viewed as weak; app-based or hardware keys are preferred, especially for admins.
💡 Pro Tip: If your answer to “Is MFA enforced for all remote access and email?” is anything but “Yes, for all users,” expect a tough conversation or a flat denial.
2. Endpoint Detection and Response (EDR)
Plain English: EDR is “next‑generation antivirus.” It doesn’t just block known bad files; it watches behavior on laptops, servers, and workstations to spot suspicious activity and stop it quickly. Think of it as a security guard on every device, not just a locked door.
Underwriters prefer centrally managed EDR across all corporate‑owned endpoints, including servers and remote laptops, with alerts monitored by internal IT or a managed security provider 24/7.
“Basic antivirus only” is now a red flag and often triggers higher deductibles or reduced limits.
3. Backups: Tested, Segmented, and Offline/Immutable
Plain English: Backups are your “time machine.” If attackers encrypt or delete your data, backups let you roll back to a clean copy. Underwriters now assume ransomware will try to destroy your backups too, so they care as much about how you protect backups as whether you have them at all.
Tested: You don’t just create backups—you regularly restore from them to prove they work and document those tests. “We think they work” doesn’t cut it anymore.
Offline or immutable: At least one backup copy is stored in a way that ransomware can’t easily touch—offline, in a separate environment, or in “immutable” storage that can’t be altered for a set period.
Segregated access: Backup systems use separate credentials, and only a few trusted admins can delete or change backups.
4. Email Security and Anti-Phishing Controls
Plain English: Most attacks still start with an email. Underwriters want to know you’re filtering out malicious messages and making it hard for attackers to impersonate your domain or trick employees into wiring money or sharing passwords.
Use advanced email filtering (not just basic spam), including attachment scanning, URL rewriting, and sandboxing suspicious content for cloud email platforms like Microsoft 365 or Google Workspace.
Implement DMARC, SPF, and DKIM (email authentication records) to reduce spoofing and impersonation of your domain.
Apply payment verification procedures (for example, call‑back rules) for invoices, vendor changes, and wire transfers to reduce business email compromise losses.
5. Employee Security Awareness Training
Plain English: People are often the weakest link. Training helps employees recognize phishing emails, suspicious links, and social engineering tricks. Underwriters know a single click can cost millions, so they want proof that you’re not leaving staff to figure it out alone.
Underwriters look for annual, mandatory training for all employees, plus extra training for high‑risk roles like finance, HR, and executives who approve payments or access sensitive data.
Many also ask whether you run simulated phishing campaigns and track improvement over time.

-toned training room where employees watch a cybersecurity awareness presentation on a large...
Regular, documented employee training can significantly reduce phishing-related claims and premium pressure.
6. Incident Response Plan (IRP)
Plain English: An incident response plan is your playbook for “something bad just happened.” Who do you call? What systems get shut down? How do you communicate with customers, regulators, and your insurer? Underwriters want to know you won’t waste the first 48 hours figuring that out on the fly.
A good IRP lists roles and responsibilities, decision‑makers, external partners (forensics, legal, PR), and your insurer’s breach response hotline or panel providers.
Underwriters now ask if you test the plan with tabletop exercises (scenario walk‑throughs) at least annually and update it based on lessons learned.
💡 Pro Tip: Keep a printed copy of your incident response plan and key contacts. If your systems are down, you may not be able to access digital files.
7. Patch and Vulnerability Management
Plain English: Patch management means keeping software up to date—fixing known holes before attackers crawl through them. Underwriters have seen too many breaches caused by months‑old, widely publicized vulnerabilities that were never patched.
Underwriters expect a formal patching process: critical patches applied within a defined window (often 7–14 days), regular updates for operating systems, applications, and network devices, and documented exceptions with compensating controls.
Many now ask whether you run vulnerability scans on internal and external systems and how quickly you remediate high‑risk findings.
8. Privileged Access Management (PAM)
Plain English: Privileged access management is about locking down “keys to the kingdom” accounts—admin logins that can change settings, access lots of data, or shut systems down. If attackers steal one of those, they can do maximum damage quickly.
Underwriters want to see limited and tracked admin accounts, with MFA enforced, no shared passwords, and “just‑enough, just‑in‑time” access where possible (temporary elevated access instead of permanent admin rights).
They also look favorably on centralized PAM tools that store admin passwords in a secure vault, rotate them automatically, and log all privileged actions.
Beyond the Basics: Other Controls Now on the Radar
While the checklist above is core, many 2026 questionnaires also probe:
Zero trust and network segmentation (limiting how far attackers can move once inside).
Vendor and supply chain security (controls around third‑party access and data sharing).
Cloud configuration management (are your cloud environments hardened and monitored, or left on default settings?).
The more mature you are in these areas, the more comfortable an underwriter feels offering broader coverage and better pricing.
Why Premiums Hardened—and Why They’re Still Not “Cheap”
After years of severe losses, carriers responded with a classic insurance playbook: raise rates, restrict coverage, and underwrite more aggressively. From mid‑2022 through mid‑2025, many organizations saw double‑digit percentage increases, tighter limits, and more exclusions for things like “poor security hygiene” or certain types of ransomware payments.
By 2026, market reports show a more buyer‑friendly environment, with several quarters of falling or flat rates. But that doesn’t mean insurers are relaxed. Analysts warn that the combination of softening prices and rising attack severity could push profitability to the edge by 2027 if discipline slips. To avoid another crisis, underwriters are doubling down on control requirements rather than simply charging more across the board.
📌 Translation: The market may be softer, but you only benefit if you can prove you’re a “good risk.” Weak security often means you pay 2022‑style prices in a 2026 market—or get no quote at all.
What Gets a Cyber Policy Denied in 2026?
Insurers rarely say “no” without a reason. But there are now clear deal‑breakers that commonly lead to declinations or non‑renewals, especially for mid‑size and larger organizations:
No MFA on email or remote access. This is the single biggest red flag. Many carriers have made MFA a hard requirement; without it, they simply won’t quote or will severely limit coverage.
No modern endpoint protection. Relying on outdated antivirus with no EDR, especially on servers and high‑value systems, is often a non‑starter.
Backups that are online only and untested. If ransomware can encrypt your backups or you’ve never tested restoring them, expect underwriters to walk away or exclude ransomware coverage entirely.
Recent severe claim with no changes made. If you suffered a major incident and can’t demonstrate meaningful improvements since then, carriers see you as a repeat claim waiting to happen.
Incomplete or inconsistent answers. Saying “Yes” to everything without detail, or contradicting yourself between sections, can trigger concerns about honesty and control maturity. Some underwriters would rather decline than insure what they suspect is misrepresented.
What Actually Reduces Premiums or Improves Terms?
The flip side is encouraging: underwriters will reward organizations that can demonstrate strong, well‑documented security. While each carrier’s pricing model is different, the following typically help reduce premiums or secure higher limits and fewer exclusions:
Mature MFA and EDR deployment. Universal MFA and comprehensive EDR coverage often place you in a preferred risk tier, especially if monitored 24/7 by a security operations center (SOC) or managed detection and response (MDR) provider.
Documented backup and recovery testing. Being able to show logs or reports of regular restore tests, including recovery time objectives, reassures underwriters that a ransomware event won’t become a total loss.
Independent security assessments. Recent penetration tests, third‑party audits, or recognized security certifications (for example, ISO 27001, SOC 2) can support more favorable pricing and broader coverage.
Effective vendor management. Demonstrating due diligence for critical third parties—security questionnaires, contractual requirements, and monitoring—reduces the risk of supply‑chain‑driven claims.
💡 Pro Tip: Don’t just say you have controls—show them. Attach policies, diagrams, test reports, and screenshots (where appropriate) through your broker. Underwriters price what they can see.
First-Party vs. Third-Party Coverage: What Are You Actually Buying?
Many buyers sign cyber policies without fully understanding what’s covered. At a high level, coverage breaks into two big buckets:
First-Party Coverage: Your Own Losses
First‑party coverage pays for costs your organization directly incurs from a cyber incident. Common components include:
Incident response and forensics: Specialists who investigate what happened, contain the attack, and help restore systems.
Data restoration and system recovery: Costs to rebuild servers, re‑image laptops, and restore data from backups or other sources.
Business interruption: Lost income and extra expenses while systems are down or degraded due to a covered cyber event.
Ransomware and cyber extortion: Negotiation and, subject to policy terms and legal restrictions, ransom payments and related costs.
Crisis communications: PR and communication support to manage reputational fallout.
Third-Party Coverage: Your Liability to Others
Third‑party coverage applies when others claim your cyber incident harmed them. Typical elements include:
Privacy and network security liability: Lawsuits or claims from customers, partners, or individuals whose data was exposed or whose operations were disrupted by your systems being compromised.
Regulatory investigations and fines (where insurable): Costs to respond to regulators after a breach, and in some jurisdictions, certain penalties or settlements.
Media and content liability: Claims related to defamation, copyright infringement, or other wrongful online content, where included in your policy.
📌 Key Question for Your Broker: “If we had a major ransomware attack that took us offline for two weeks and leaked customer data, which parts of that scenario are covered under first‑party, which under third‑party, and what’s excluded?”
How to Prepare for the 2026 Underwriter Questionnaire (Before It Lands)
Treat the questionnaire as an open‑book exam you can study for—not a pop quiz. Here’s how to get ready so you don’t scramble, guess, or accidentally misrepresent your environment.
Step 1: Build a Cross-Functional Response Team
Don’t let the questionnaire live only with your broker or your legal team. Involve:
IT and security leaders who understand the actual controls in place.
Risk management or finance to align on acceptable deductibles, limits, and budget.
Legal and compliance for accuracy around regulatory obligations and incident reporting.
Step 2: Inventory Your Controls Honestly
Before you ever see the form, document where you stand on the core controls:
Which systems have MFA? Which don’t? Are there exceptions for legacy apps or service accounts?
Is EDR deployed on all servers and endpoints, or only some? Who monitors alerts?
When was your last successful backup restore test? Is there an offline or immutable copy?
How often do you train employees? Do you run phishing simulations? Do you track click rates?
Where there are gaps, note them clearly—and start remediation work before renewal. Underwriters respond far better to “We identified a gap and here is our plan and timeline to close it” than to vague or overly optimistic answers.
Step 3: Gather Evidence and Documentation
Underwriters are increasingly using automated tools and external scans to verify your answers. Having documentation ready helps you respond quickly and credibly if they ask for more detail:
Security policies (access control, incident response, acceptable use, vendor management).
Screenshots or reports from MFA, EDR, backup systems, and vulnerability scanners showing coverage and recency.
Training completion records and phishing simulation metrics.
Step 4: Answer in Plain, Accurate Language
While the forms can be technical, don’t hide behind jargon or boilerplate. Underwriters appreciate clear, specific answers:
Instead of “Yes, we use backups,” say, “We perform nightly backups of all production systems, retain daily copies for 30 days, and maintain a weekly immutable copy in a separate cloud account. We last tested a full restore in March 2026.”
Instead of “We have MFA,” specify where: “MFA is enforced for all email accounts, VPN, remote desktop, and privileged admin access. We are rolling out MFA to two legacy internal apps by Q3 2026.”
⚠️ Warning: Misrepresenting your controls can lead to denied claims later. Underwriters increasingly compare application answers with forensic findings after an incident.
Step 5: Use the Questionnaire as a Security Roadmap
Finally, flip the script: treat the underwriter’s checklist as a prioritized security improvement plan. Controls they ask about most aggressively—MFA, EDR, backups, training, incident response, patching, PAM—are also the ones most likely to reduce your real‑world risk and your premiums over time.
The Conversation Your Broker Probably Won’t Have With You
Brokers are invaluable for navigating markets, negotiating terms, and translating policy language. But they’re not your CISO, and most won’t walk you line by line through what underwriters now expect from your security program. That leaves many organizations surprised when:
A renewal quote comes back with a higher premium and lower limits than last year, despite “no major changes” in the business.
A carrier declines to quote because MFA isn’t universal or backups aren’t adequately protected.
A claim is challenged because answers on the application overstated how mature your controls really were.
The reality in 2026 is that cyber insurance and cybersecurity are now deeply intertwined. You can’t treat the policy as a standalone financial product; it’s inseparable from how you manage identity, endpoints, data, email, and vendors every day.
If you take away one message, let it be this: the best way to “win” with cyber insurance in 2026 is to build the security program underwriters wish every insured had. Do that, and you’ll not only improve your chances of getting covered at a reasonable price—you’ll also dramatically reduce the odds you ever need to file a claim in the first place.
