AI Search Articles

Cyber Insurance Requirements: What Your IT Must Include

Written by Marissa Olson | Aug 19, 2026, 7:30:00 AM

Cyber insurance requirements have changed significantly. Insurers no longer accept self-reported answers on a short application. In 2026, underwriters review documented evidence that specific security controls are active and functioning before they approve a policy — and before they pay a claim. Businesses that skip this step risk claim denial after a breach, even when a valid policy is in place.

What IT Security Controls Do Cyber Insurers Actually Require?

Cyber insurers commonly require six core technical controls: multifactor authentication (MFA), endpoint detection and response (EDR), immutable or offline data backups, centralized logging and monitoring, vulnerability management programs, and privileged access management (PAM). According to a 2026 Forbes Tech Council report, these controls have moved from best-practice recommendations to minimum eligibility requirements across most major insurers.

Each control addresses a specific attack vector that has generated significant insurance payouts in recent years. Ransomware, business email compromise, and credential theft are the three categories driving the largest claim volumes. The required controls are built around preventing and detecting exactly those threat types.

The six most commonly required IT controls:

  • Multifactor authentication (MFA) on all remote access, administrative accounts, and email platforms
  • Endpoint detection and response (EDR) on all devices, replacing traditional antivirus
  • Immutable or offline backups that are tested regularly and stored separately from the primary network
  • Centralized logging and monitoring with defined alerting thresholds
  • Vulnerability and patch management with documented remediation timelines
  • Privileged access management (PAM) limiting who can access sensitive systems and credentials

How Does MFA Affect Cyber Insurance Eligibility and Premiums?

MFA is one of the highest-weighted controls in cyber insurance underwriting. Most insurers will not issue a policy to businesses that lack MFA on remote access tools, email, and administrator accounts. When MFA is absent, some insurers will either decline coverage outright or add exclusions that void claims tied to credential-based attacks.

When MFA is fully deployed and documented, businesses typically see lower premium rates. Insurers treat MFA as a measurable reduction in breach probability, particularly for attacks involving phishing and stolen passwords. Deploying MFA across all user accounts and enforcing it through a centralized identity platform — rather than app-by-app — produces the strongest underwriting outcomes.

Where insurers require MFA to be enforced:

  • Remote desktop and VPN access
  • Cloud-based email platforms (Microsoft 365, Google Workspace)
  • All administrative and privileged accounts
  • Cloud infrastructure and SaaS applications with access to sensitive data

—————————————————————————

What Role Does Endpoint Detection and Response Play in Cyber Insurance Requirements?

EDR is now a standard requirement. Traditional antivirus software is explicitly considered insufficient by most cyber insurers because it relies on known threat signatures. EDR platforms use behavioral analysis to detect threats that have not yet been catalogued, which is the category that includes most active ransomware strains.

Insurers want to see EDR deployed on every endpoint — laptops, desktops, and servers — not just a subset of devices. They also look for evidence that the EDR platform is actively monitored, not simply installed. An unmonitored EDR tool provides weaker underwriting value than one connected to a security operations center (SOC) or a managed detection and response (MDR) service.

What insurers look for in EDR deployments:

  • Coverage across 100% of endpoints, with no gaps
  • Active monitoring with defined response procedures
  • Threat hunting capability, not just passive alerting
  • Integration with centralized logging for audit trail purposes

Are Data Backups Mandatory for Cyber Insurance Coverage?

Yes. Regularly tested, immutable, or offline backups are a standard requirement and one of the most closely scrutinized controls during underwriting. Insurers require backups because ransomware recovery costs — including system restoration and business interruption — represent a large share of total claim payouts.

Backups stored on the same network as production systems are not acceptable to most insurers. Ransomware routinely encrypts or destroys on-network backups as part of the attack sequence. Insurers require that at least one backup copy be air-gapped, immutable (meaning it cannot be altered or deleted), or stored with a cloud provider that uses object-lock technology.

Backup requirements most commonly specified by insurers:

  • Frequency: Daily backups at minimum; critical systems may require more frequent intervals
  • Immutability: Backups stored in a format that cannot be overwritten or encrypted by ransomware
  • Offsite or offline storage: At least one copy held in a location separate from the primary network
  • Tested restoration: Documented evidence that backup restoration has been verified on a scheduled basis
  • Retention period: Most insurers require 30 to 90 days of backup history

Is an Incident Response Plan Required to Get Cyber Insurance?

A documented and tested incident response plan (IRP) is a standard underwriting requirement. Insurers ask for evidence that the business has a defined process for identifying, containing, and recovering from a security incident — before one happens.

An IRP that exists only as a document is not sufficient. Underwriters look for evidence of testing, which may include tabletop exercises or formal simulations. The plan should identify who is responsible for each step of the response, how the business communicates with affected parties, and what the process is for preserving evidence for forensic and legal purposes.

What a qualifying incident response plan typically includes:

  • Defined roles and responsibilities for the response team
  • Procedures for containment, eradication, and recovery
  • Communication protocols for notifying customers, regulators, and law enforcement
  • Evidence preservation procedures for legal and forensic review
  • A documented schedule for testing and updating the plan

Does Security Awareness Training Factor Into Cyber Insurance Requirements?

Security awareness training is listed as a required or strongly preferred control by a growing number of insurers, particularly for policies covering business email compromise and phishing-related losses. Insurers recognize that human error remains the leading cause of initial breach access.

Training programs that include phishing simulations — where employees receive fake phishing emails and their responses are tracked — carry more underwriting weight than static annual training sessions. Insurers want to see training delivered on a recurring schedule, with records showing employee participation rates and simulation results.

What insurers look for in security awareness programs:

  • Training delivered at least quarterly, not annually
  • Phishing simulations with documented employee response rates
  • Records of completion by role or department
  • Procedures for additional training when employees fail simulations

How Do Cyber Insurance Requirements Vary Between Insurers?

Requirements vary based on policy type, coverage limit, and the specific insurer's underwriting guidelines. There is no single universal standard, which creates complexity for businesses comparing policies.

Policies with higher coverage limits carry more stringent requirements. A policy covering $1 million in losses will typically require fewer documented controls than one covering $5 million or more. Industry vertical also affects requirements — healthcare, financial services, and legal sectors face stricter controls because of the sensitivity of the data involved and the regulatory environment.

Common points of variation across insurers:

  • MFA scope: Some insurers require MFA only on privileged accounts; others require it across all user accounts
  • Backup immutability standards: Definitions of acceptable immutability differ across underwriters
  • EDR vs. managed EDR: Some policies require active managed monitoring; others accept self-managed deployment
  • Logging retention periods: Requirements range from 90 days to 12 months depending on coverage level
  • Third-party vendor assessments: Some insurers require documented security reviews of vendors with system access

Businesses should request a detailed requirements checklist from each insurer before selecting a policy. Comparing only coverage limits and premiums without reviewing technical requirements can result in policies that cannot actually be fulfilled.

What Happens If Your IT Does Not Meet Cyber Insurance Requirements?

Insurers can deny claims when the technical controls required under a policy were not in place at the time of the incident. This is a critical and frequently misunderstood element of cyber coverage. A business can pay premiums for years and still receive a denied claim if the required controls were absent during the breach.

The three most common outcomes for businesses with non-compliant IT are higher premiums, reduced coverage limits, and claim denial. Some insurers will also include exclusion clauses that remove coverage for specific attack types — for example, excluding ransomware claims if immutable backups were not maintained.

Nearly half of small businesses in the U.S. report having no cyber insurance at all, according to the SEO article research context. Among those that do carry coverage, a significant share are unaware that their current IT posture may not satisfy the technical requirements written into their policy.

How Can Managed IT Services Help Businesses Meet Cyber Insurance Requirements?

A managed IT services provider can document, deploy, and maintain the specific controls that cyber insurers require. This is relevant for small and midsize businesses that do not have internal IT staff capable of implementing and tracking controls like PAM, centralized logging, or EDR across all endpoints.

Managed IT providers typically deliver cyber insurance readiness through a combination of technology deployment, ongoing monitoring, and documentation support. Documentation is particularly important because insurers require evidence — not just the existence of controls, but proof that they are active, tested, and maintained over time.

Controls that managed IT providers commonly handle for insurance readiness:

  • MFA deployment and enforcement across all accounts and access points
  • EDR installation, monitoring, and response through a managed SOC
  • Backup configuration, immutability enforcement, and tested restoration
  • Centralized log collection with defined alerting rules
  • Vulnerability scanning and patch management with documented remediation records
  • Incident response plan development and tabletop exercise facilitation
  • Security awareness training program administration and phishing simulations
  • Privileged access management configuration and access auditing

Businesses in Las Vegas and Southern California working with a managed IT provider can typically have a full cyber insurance control set documented and operational within 60 to 90 days, depending on the current state of their IT environment.

What Should a Business Do Before Applying for Cyber Insurance?

Before submitting an application, a business should conduct an internal audit of its current IT controls against the requirements listed by the target insurer. Gaps identified before application can be remediated before underwriting review, which avoids premium loading or coverage restrictions.

The audit should produce written documentation of every required control — not verbal confirmation. Insurers ask for evidence of configuration, not just confirmation that a tool is installed.

Pre-application steps that improve underwriting outcomes:

  • Request the insurer's technical requirements checklist before filling out the application
  • Conduct a gap assessment comparing current controls to the checklist
  • Remediate gaps with documented configuration records before submitting
  • Ensure backup restoration has been tested and the results are recorded within the past 90 days
  • Confirm that MFA is enforced, not just available, across all required account types
  • Verify that the incident response plan has been tested within the past 12 months

Businesses without internal IT resources to complete this process can work with a managed IT services provider to conduct the assessment and close gaps before application submission.