Cyber insurance used to be a safety net. In 2026, it’s also a security exam. And the test is no longer optional.
There was a time when buying cyber insurance was simple.
Fill out a questionnaire. Pay the premium. File the PDF somewhere between your business license and that printer manual nobody has opened since 2019.
Then ransomware happened.
And insurers realized something uncomfortable: companies were buying protection against cyberattacks without necessarily doing much to prevent them. So the questions changed.
Welcome to the new underwriting reality
The 2026 underwriting bar is increasingly specific:
- Over 90% of applications ask detailed MFA questions, including RDP, VPN, cloud, and privileged accounts. SMS-based MFA is increasingly flagged as insufficient.
- Over 80% of carriers require EDR or MDR across all endpoints.
- Immutable backups are becoming a hard requirement, not a nice-to-have.
- Documented proof is replacing checkbox answers. Some renewals now involve independent audits or evidence reviews.
These figures reflect the underwriting picture in our brief; requirements vary by carrier and policy. The message, however, is clear: saying you have security is no longer enough. You need to prove it.
Continue reading