Cyber insurance requirements have changed significantly. Insurers no longer accept self-reported answers on a short application. In 2026, underwriters review documented evidence that specific security controls are active and functioning before they approve a policy — and before they pay a claim. Businesses that skip this step risk claim denial after a breach, even when a valid policy is in place.
Cyber insurers commonly require six core technical controls: multifactor authentication (MFA), endpoint detection and response (EDR), immutable or offline data backups, centralized logging and monitoring, vulnerability management programs, and privileged access management (PAM). According to a 2026 Forbes Tech Council report, these controls have moved from best-practice recommendations to minimum eligibility requirements across most major insurers.
Each control addresses a specific attack vector that has generated significant insurance payouts in recent years. Ransomware, business email compromise, and credential theft are the three categories driving the largest claim volumes. The required controls are built around preventing and detecting exactly those threat types.
The six most commonly required IT controls:
MFA is one of the highest-weighted controls in cyber insurance underwriting. Most insurers will not issue a policy to businesses that lack MFA on remote access tools, email, and administrator accounts. When MFA is absent, some insurers will either decline coverage outright or add exclusions that void claims tied to credential-based attacks.
When MFA is fully deployed and documented, businesses typically see lower premium rates. Insurers treat MFA as a measurable reduction in breach probability, particularly for attacks involving phishing and stolen passwords. Deploying MFA across all user accounts and enforcing it through a centralized identity platform — rather than app-by-app — produces the strongest underwriting outcomes.
Where insurers require MFA to be enforced:
—————————————————————————
EDR is now a standard requirement. Traditional antivirus software is explicitly considered insufficient by most cyber insurers because it relies on known threat signatures. EDR platforms use behavioral analysis to detect threats that have not yet been catalogued, which is the category that includes most active ransomware strains.
Insurers want to see EDR deployed on every endpoint — laptops, desktops, and servers — not just a subset of devices. They also look for evidence that the EDR platform is actively monitored, not simply installed. An unmonitored EDR tool provides weaker underwriting value than one connected to a security operations center (SOC) or a managed detection and response (MDR) service.
What insurers look for in EDR deployments:
Yes. Regularly tested, immutable, or offline backups are a standard requirement and one of the most closely scrutinized controls during underwriting. Insurers require backups because ransomware recovery costs — including system restoration and business interruption — represent a large share of total claim payouts.
Backups stored on the same network as production systems are not acceptable to most insurers. Ransomware routinely encrypts or destroys on-network backups as part of the attack sequence. Insurers require that at least one backup copy be air-gapped, immutable (meaning it cannot be altered or deleted), or stored with a cloud provider that uses object-lock technology.
Backup requirements most commonly specified by insurers:
A documented and tested incident response plan (IRP) is a standard underwriting requirement. Insurers ask for evidence that the business has a defined process for identifying, containing, and recovering from a security incident — before one happens.
An IRP that exists only as a document is not sufficient. Underwriters look for evidence of testing, which may include tabletop exercises or formal simulations. The plan should identify who is responsible for each step of the response, how the business communicates with affected parties, and what the process is for preserving evidence for forensic and legal purposes.
What a qualifying incident response plan typically includes:
Security awareness training is listed as a required or strongly preferred control by a growing number of insurers, particularly for policies covering business email compromise and phishing-related losses. Insurers recognize that human error remains the leading cause of initial breach access.
Training programs that include phishing simulations — where employees receive fake phishing emails and their responses are tracked — carry more underwriting weight than static annual training sessions. Insurers want to see training delivered on a recurring schedule, with records showing employee participation rates and simulation results.
What insurers look for in security awareness programs:
How Do Cyber Insurance Requirements Vary Between Insurers?
Requirements vary based on policy type, coverage limit, and the specific insurer's underwriting guidelines. There is no single universal standard, which creates complexity for businesses comparing policies.
Policies with higher coverage limits carry more stringent requirements. A policy covering $1 million in losses will typically require fewer documented controls than one covering $5 million or more. Industry vertical also affects requirements — healthcare, financial services, and legal sectors face stricter controls because of the sensitivity of the data involved and the regulatory environment.
Common points of variation across insurers:
Businesses should request a detailed requirements checklist from each insurer before selecting a policy. Comparing only coverage limits and premiums without reviewing technical requirements can result in policies that cannot actually be fulfilled.
Insurers can deny claims when the technical controls required under a policy were not in place at the time of the incident. This is a critical and frequently misunderstood element of cyber coverage. A business can pay premiums for years and still receive a denied claim if the required controls were absent during the breach.
The three most common outcomes for businesses with non-compliant IT are higher premiums, reduced coverage limits, and claim denial. Some insurers will also include exclusion clauses that remove coverage for specific attack types — for example, excluding ransomware claims if immutable backups were not maintained.
Nearly half of small businesses in the U.S. report having no cyber insurance at all, according to the SEO article research context. Among those that do carry coverage, a significant share are unaware that their current IT posture may not satisfy the technical requirements written into their policy.
A managed IT services provider can document, deploy, and maintain the specific controls that cyber insurers require. This is relevant for small and midsize businesses that do not have internal IT staff capable of implementing and tracking controls like PAM, centralized logging, or EDR across all endpoints.
Managed IT providers typically deliver cyber insurance readiness through a combination of technology deployment, ongoing monitoring, and documentation support. Documentation is particularly important because insurers require evidence — not just the existence of controls, but proof that they are active, tested, and maintained over time.
Controls that managed IT providers commonly handle for insurance readiness:
Businesses in Las Vegas and Southern California working with a managed IT provider can typically have a full cyber insurance control set documented and operational within 60 to 90 days, depending on the current state of their IT environment.
Before submitting an application, a business should conduct an internal audit of its current IT controls against the requirements listed by the target insurer. Gaps identified before application can be remediated before underwriting review, which avoids premium loading or coverage restrictions.
The audit should produce written documentation of every required control — not verbal confirmation. Insurers ask for evidence of configuration, not just confirmation that a tool is installed.
Pre-application steps that improve underwriting outcomes:
Businesses without internal IT resources to complete this process can work with a managed IT services provider to conduct the assessment and close gaps before application submission.