What Cyber Insurers Actually Demand in 2026 (and How to Pass Underwriting)
Short answer: Cyber underwriting in 2026 assumes you already have MFA everywhere that matters, EDR on every endpoint, tested and isolated backups, and real controls on privileged access. Those are the entry ticket, not differentiators. The questionnaire has become a maturity audit with financial consequences: answer it accurately, prepare for it like an audit, and treat any question you cannot answer with evidence as a control gap the incident will eventually find anyway.
I remember when a cyber policy was a two-page application and a premium that felt like rounding error. The ransomware years ended that. Carriers absorbed losses they had not priced, capacity tightened, and underwriting grew teeth. Today the application runs to dozens of pages, some carriers scan your external attack surface before quoting, and a wrong answer can surface after a claim as grounds to deny it. The upside, which I say without irony: the insurance market is now enforcing a baseline that many boards would not fund when their own CISO asked. Use that.
The questionnaire is a maturity audit — treat it like one
Underwriters no longer accept yes as an answer; they want to know where, since when, and with what exceptions. Is MFA enforced for all remote access, all administrative access, and all email access — or for most of it, with a legacy VPN gateway quietly excluded? Is EDR deployed to every server, including the ones running the old finance application nobody wants to touch? The distance between the confident yes and the honest mostly is exactly where claims get contested, because after an incident the forensics report will describe your environment as it actually was on the day of the loss.
So run the application process the way you would run an external audit. Assign an owner. Collect evidence for every answer — coverage reports from the EDR console, MFA enforcement policies, backup restore logs — and file it with the application. Have the answers reviewed by the people who operate the controls, not just the people who bought them. And put a calendar reminder to notify the broker if a material answer changes mid-term, because a control you switched off in March can haunt a claim in September.
Table stakes: what carriers demand before quoting
The consistent short list across carriers: multi-factor authentication on remote access, email, and privileged accounts; endpoint detection and response with genuine coverage rather than a partial rollout; backups that are offline or otherwise separated from production credentials, with restores actually tested; privileged access controls, ideally with a vault and session recording for admin activity; a patching cadence you can describe with dates rather than adjectives; and an incident response plan that has been exercised. Ransomware drove this list, and ransomware readiness still dominates the pricing conversation — carriers will ask when you last rehearsed, which is a question my ransomware response playbook exists to help you answer with a date instead of a pause.
Miss one of these and you are not negotiating premium anymore; you are negotiating whether you get a quote at all, or a quote with a co-insurance clause and a ransomware sub-limit that guts the coverage you thought you were buying.
What kills coverage after you have bought it
Three patterns account for most contested claims. The first is misrepresentation: the application said MFA everywhere, the forensics found the exception, and the carrier now has an argument that the policy was issued on false information. The second is the unmet condition: some policies make specific controls a continuing condition of coverage, so the backup regime you let lapse in a busy quarter becomes a coverage defense later. The third is the missed notification window — policies have prompt-notice requirements, and an organization that spends three weeks deciding whether an incident is serious enough to report can find it has decided its way out of coverage.
All three have the same cure: precision. Answer what is true, not what is aspirational. Track every representation you made to the carrier as a live obligation. And notify early — brokers uniformly prefer a precautionary notice that comes to nothing over a late claim that comes to litigation.
Make the broker earn the relationship
A good broker is the most underused person in this whole process. Months before renewal, ask them three questions: which of our answers weakened the last submission, which carriers are writing our industry at sensible terms this year, and what would a better security story be worth in premium or limits? Brokers see hundreds of submissions and know exactly which control gaps carriers are punishing this quarter. Then ask for the claims-handling record of any carrier you are considering — a cheaper policy from a carrier known for contesting claims is not cheaper, it is a deductible with extra steps. And insist on being in the room for the underwriting call. Underwriters consistently respond better to a CISO who explains a gap and its remediation plan in plain terms than to a broker reading answers off a form second-hand.
Where the risk register earns its keep
The application will expose gaps. Some you will fix before binding; others you cannot fix this year. Put the ones you cannot fix into the risk register with a named business owner and a documented decision, the same discipline I describe in my cyber risk register template. This does two things. Internally, it converts an awkward questionnaire answer into a governed decision with an owner. Externally, it changes the underwriting conversation — carriers respond differently to a known gap with a remediation date and interim controls than to a gap the applicant seemed unaware of. Underwriters price uncertainty hardest of all; a documented gap is a smaller uncertainty than an undocumented one.
Know what the market can and cannot absorb
A quiet truth worth carrying into renewal: some scenarios now strain what private carriers will cover at all. Widespread events that hit thousands of insureds through one dependency, catastrophic outages at systemic cloud or software providers, and losses attributed to state-linked activity all press against exclusions and against the practical capacity of the market. Read the war and infrastructure exclusions in your policy with counsel, model your realistic worst case against your actual limits, and present the residual honestly to the board. Insurance transfers a slice of cyber risk — a useful slice — but the balance sheet keeps the rest, and pretending otherwise is how organizations discover their true retention during the worst week of the decade.
Turn underwriting into budget
Here is the practical gift buried in all this friction: the carrier’s requirements are a funding argument that arrives from outside the security team. When underwriting flags the flat network or the untested restore process, the cost of inaction stops being theoretical and becomes a number — higher premium, lower limits, a ransomware sub-limit, or declined coverage. I have watched controls that sat in the backlog for three budget cycles get funded in one meeting once they appeared in a renewal letter. Bring the underwriting feedback to the CFO verbatim, alongside the quote spread between where you are and where the carrier wants you. It is the rare security business case that a finance leader can verify independently, with their own broker, in a single phone call.
Frequently Asked Questions
What controls do cyber insurers require in 2026?
The consistent baseline is MFA on remote, email, and privileged access; EDR with near-complete endpoint coverage; backups isolated from production credentials and tested by restore; privileged access controls; a described patching cadence; and an exercised incident response plan.
Can an insurer deny a claim over questionnaire answers?
Yes. If post-incident forensics contradict a material representation on the application — MFA coverage is the classic example — the carrier may contest or rescind. Answer with evidence, note exceptions honestly, and update the broker when a material answer changes mid-term.
How should a CISO prepare for cyber insurance underwriting?
Treat the application as an external audit: assign an owner, gather evidence for every answer, have control operators validate the responses, and log unresolved gaps in the risk register with owners and remediation dates before the underwriting call.
Does cyber insurance cover ransomware payments?
Many policies still can, subject to sub-limits, co-insurance, sanctions checks, and carrier involvement in the decision. Assume the sub-limit is well below your headline limit and read it before the incident, not during one.