Cyber Insurance Requirements in 2026: What Insurers Ask Before They Cover You
Cyber Insurance Requirements in 2026: What Insurers Ask Before They Cover You
Ten years ago you could buy a cyber policy with a phone call and a signature. In 2026 the application looks more like a security audit. Insurers lost a lot of money to ransomware between 2019 and 2022, and they responded the way insurers always do: stricter underwriting, longer questionnaires, and hard technical requirements that decide whether you get covered at all.
This guide walks through what insurers actually require today, what their questionnaires look like, and the mistakes that can void your coverage after a breach.
Why the requirements got strict
The short version: ransomware. Loss ratios on cyber policies spiked hard in 2020 and 2021, and several large carriers either left the market or rebuilt their underwriting from scratch. The carriers that stayed learned to price risk based on your actual security posture, not your industry and revenue alone.
The result is a market where your security controls directly determine three things: whether you can get a policy, how much you pay for it, and how much of a claim gets paid out when something happens.
The baseline: controls most insurers require in 2026
Requirements vary by insurer, country and company size, but a clear baseline has formed. If you are missing items from this list, expect higher premiums, coverage carve-outs, or a straight decline.
Multi-factor authentication (MFA). The single most common hard requirement. Insurers typically want MFA on email, on remote access (VPN and RDP), and on admin accounts. "We have MFA on email but not on VPN" is one of the most common reasons applications get bounced back.
Tested, offline or immutable backups. Not just "we have backups". Underwriters ask whether backups are separated from the main network, how often restoration is actually tested, and how quickly you could recover. Untested backups are treated as no backups.
Endpoint detection and response (EDR). Traditional antivirus stopped being enough around 2022. Many carriers now require an EDR or MDR solution on servers and workstations, especially for companies above roughly 50 employees. Notably, insurers increasingly bundle this: in the Ryskly catalog of 682 cyber products worldwide, 28% include MDR or EDR services as part of the policy itself.
Patch management. A defined process for applying critical security updates, usually with an expected timeline (for example, critical patches within 14 days). Unpatched, internet-facing systems are the classic entry point that underwriters screen for.
Employee security training. Phishing is still the number one initial attack vector, so insurers ask whether staff get regular awareness training. Some go further and include the training themselves: 39% of products in our catalog bundle security awareness training, and 20% include phishing simulation campaigns.
Privileged access management. Who has admin rights, are admin accounts separate from daily accounts, are service accounts inventoried. For larger companies this section can be extensive.
An incident response plan. Even a short, written one. Insurers know that response speed drives claim size, which is why 77% of cyber insurance products now include incident response services directly in the policy.
What the questionnaire actually looks like
A typical 2026 cyber application has four sections.
1. Company profile. Industry, revenue, headcount, geography, what kind of data you hold (personal data, payment data, health records), and dependence on critical IT vendors.
2. Technical controls. The checklist above, in yes/no or multiple-choice form. Expect specific questions: "Is MFA enforced for all remote access?", "Are backups stored offline or in an immutable format?", "Do you use an EDR solution, and which one?"
3. History and exposure. Past incidents and claims, known vulnerabilities, previous ransomware events, and sometimes results of external scans the insurer runs on your domains before quoting.
4. Supplemental forms. If you answer "yes" to holding sensitive data at scale, or "no" to a key control, you often get a supplemental application: a deeper form on that specific topic (ransomware supplementals are the most common).
For small companies the whole thing can be 2 pages. For mid-market companies 10 to 20 pages is normal.
Cyber insurance requirements in contracts
A growing share of cyber policies are bought not because the owner woke up worried, but because a contract demanded it. Large customers increasingly require their vendors and contractors to carry cyber insurance with defined minimum limits, and government tenders in many countries now include it as a standard clause.
If you are on the receiving end of such a clause, check three things before buying:
- The required limit (contracts typically ask for 1 to 5 million in coverage).
- Whether the contract requires specific coverages, such as third-party liability or data restoration.
- Whether you must name the customer as an additional insured.
Buying the cheapest policy that technically satisfies the clause is tempting, but limits and exclusions vary enormously between products. Comparing a few options side by side is worth an hour of your time. Our comparison table covers 682 products across 57 countries if you want to see what the market looks like.
What happens if you get the answers wrong
This is the part too many buyers underestimate. The application is a legal document. If you state that MFA is enforced everywhere and the post-breach forensics show it was not, the insurer can reduce the payout or deny the claim entirely. In several publicized disputes, carriers rescinded policies based on misrepresentation in the application.
Practical rules:
- Answer what is true today, not what you plan to implement next quarter.
- If a control is partially deployed, say so explicitly.
- Keep evidence: screenshots of MFA policies, backup test logs, training completion reports.
- Re-check your answers at renewal. Your environment changed; your answers must too.
Regional note: NIS2 and regulatory pressure in Europe
In the EU, the NIS2 directive pushed thousands of companies into mandatory security requirements, and insurers adapted quickly: 60% of products in our catalog now advertise NIS2 or DORA compliance support as part of the offering. If your company falls under NIS2, expect your insurer's questionnaire to overlap heavily with what the regulator already requires, which is actually good news: one set of controls satisfies both.
Checklist: before you apply
- MFA on email, VPN, remote access and admin accounts
- Offline or immutable backups, with a documented restore test
- EDR or MDR on endpoints and servers
- Patch process with defined timelines for critical fixes
- Security awareness training for staff, at least annual
- Separate admin accounts, inventory of privileged access
- Written incident response plan with contacts and first steps
- Honest, evidenced answers in the application
FAQ
Can I get cyber insurance without MFA in 2026?
Sometimes, but expect a higher premium, a ransomware sub-limit or exclusion, and pressure to implement it by renewal. For mid-sized and larger companies, no MFA is increasingly a hard decline.
How long does the application process take?
For a small business with good security hygiene, a few days from application to quote. For mid-market companies with supplemental forms and external scans, two to four weeks is typical.
Do insurers verify the answers?
Increasingly yes. Many run external scans of your internet-facing systems before quoting, and after a claim the forensic investigation will surface any gap between your answers and reality.
Who in the company should fill in the questionnaire?
IT fills in the technical sections, but leadership should sign off. The answers bind the company legally, and finance or legal should understand what was promised to the insurer.