Cyber Insurance Requirements 2026: The Real Checklist
TL;DR: For 2026 renewals, four controls trigger most denials when missing: MFA on email and remote access, EDR on every endpoint, a tested incident response plan, and privileged access management. Underwriters now have three-plus years of claims data proving these correlate with payouts. Requirements also vary by revenue tier and sector.
A $30M manufacturer answers a different application than a $300M healthcare firm. According to Gallagher's 2026 Cyber Market Outlook, mid-market firms without full MFA coverage saw renewal premium increases averaging 28% in the 2024 to 2025 cycle, and Munich Re's Cyber Insurance Risks and Trends 2026 report attributes roughly 60% of paid cyber claims to ransomware events.
Why Requirements Tightened: The Underwriter's Perspective
The cyber market hardened in 2021 when industry loss ratios pushed past 70%, and carriers haven't relaxed since. Coalition, Beazley, Chubb, and Munich Re now run automated external attack surface scans before a human underwriter even opens your file. Open RDP, unpatched Exchange, exposed Citrix portals, all of it gets flagged at quote time.
Here's the part most brokers won't say out loud. Carriers don't treat MFA and a written password policy as equivalent controls, even though both appear as line items on the application. There are checkbox controls and there are weighted controls. The weighted ones move premiums.
Coalition's 2024 Cyber Claims Report shows the average ransomware demand against mid-market firms reached $1.54 million, with actual paid losses (including business interruption) averaging $353,000 per incident. IBM's Cost of a Data Breach 2024 puts the average mid-market breach at $4.88 million all-in. That's why carriers care.
Coalition and Beazley also keep watching after they bind your policy. If your posture degrades mid-term, they can reprice or non-renew. A newly exposed appliance carrying a critical CVE, picked up by a mid-term scan, is enough to put a bound policy at risk. Patch cadence matters after you sign, not just before you apply.
The Underwriter's Scoring Rubric
Most articles list controls as a flat checklist. They aren't flat. Here's how carriers actually weight them.
Tier 1, deal-breakers. Missing any one can trigger denial.
- MFA on email and all remote access (Duo at roughly $3 to $9 per user per month, or Okta at $6 to $15)
- EDR on 100% of endpoints (CrowdStrike Falcon at $15 to $25 per endpoint per month, or SentinelOne Singularity at $6 to $12)
- Offline or immutable backups, tested within 90 days (Veeam at roughly $1,200 to $3,000 per year for SMB tier)
Tier 2, premium movers. Present them and you'll see a 10% to 25% discount signal.
- Privileged Access Management on admin accounts
- Network segmentation isolating crown-jewel systems
- Documented and tested incident response plan
Tier 3, scored but rarely decisive alone.
- Security awareness training with phishing simulation
- Vulnerability scanning cadence (quarterly minimum for mid-market)
- NIST Cybersecurity Framework alignment documentation
Why does MFA outrank everything? The Verizon 2024 DBIR found that 68% of breaches involved a non-malicious human element, with credential abuse and Business Email Compromise dominating frequency counts. Coalition's claims data echoes this. BEC and credential-stuffing claims outnumber ransomware claims by frequency, even though ransomware drives bigger payouts. Block the credential, block most of the claim volume.
Requirements by Business Size
This is the segmentation no top-ten article gives you.
Tier A, 50 to 150 employees, under $50M revenue. MFA mandatory. EDR on all endpoints mandatory. Immutable backups mandatory. Written IR plan mandatory. Basic PAM for domain admin accounts expected. Annual security awareness training expected. Sub-$5M policies often go through simplified carrier portals (Coalition, Cowbell) but still hard-gate on MFA. No MFA, no quote.
Tier B, 150 to 500 employees, $50M to $300M revenue. Everything in Tier A, plus network segmentation (required by most carriers), 24/7 SOC or MDR coverage (now required, not preferred), PAM tooling not just policy, a documented tabletop exercise within 12 months, vulnerability scanning quarterly minimum.
Tier C, 500-plus employees or regulated sectors. Full Zero Trust Architecture roadmap requested by some carriers. CMMC or HIPAA alignment documentation. SOC 2 Type II often requested as evidence for limits above $5M. Applications run 20 to 40 pages.
HIPAA-covered entities, take note. A carrier denial often implies a HIPAA Security Rule gap under 45 CFR §164.312 (technical safeguards). Flag it to legal before it becomes an OCR matter.
Carrier-by-Carrier Comparison
Munich Re. Sits as reinsurer behind many primary carriers. Their 2026 risk guidelines explicitly weight ransomware resilience, immutable backups, and tested recovery. If you can't show a backup restore test log, you're fighting uphill.
Chubb. Detailed application questionnaires for mid-market. Requires documented IR plan with evidence of a tabletop exercise. Often requests third-party penetration test results for limits above $5M. Conservative underwriting.
Coalition. Tech-forward. Runs automated external attack surface scans at quote time. Open RDP, unpatched Exchange, exposed admin panels, all flagged before human review. Their public Cyber Claims Report 2024 named missing MFA as the single most common control gap preceding a paid claim.
Beazley. Strong in professional services and healthcare mid-market. Continuous monitoring post-bind via their security platform. IR plan and access controls weighted heavily. Will non-renew on detected critical unpatched CVEs.
The practical takeaway: if you've got RDP exposed or no MFA, Coalition's scan finds it before you can paper over the application. Fix the posture first, then apply.
How Denials Actually Happen
Three patterns account for most declined and non-renewed cyber applications. None of them are exotic.
Scenario 1, the MFA gap. The application says MFA is enforced, and it is, on email. Remote desktop is not covered, and the carrier's external scan finds open RDP on an edge server. What triggers the decline is the mismatch between the attestation and the scan, not the gap on its own. Closing RDP entirely and putting every remote access path behind MFA is faster than arguing the appeal.
Scenario 2, the backup that wasn't tested. Veeam or an equivalent is in place, the licence is current, and the last documented restore test is years old. After a ransomware event the carrier's investigator asks for evidence that backup integrity was ever verified, and there is none. That is how a claim becomes a coverage dispute. Timestamped restore tests on a quarterly cycle, and a defined RTO written into the IR plan, are what close it off.
Scenario 3, the IR plan on paper only. A written plan exists, dated several years back, with no tabletop exercise on record and a named IR vendor the business no longer retains. A mid-term review after a Business Email Compromise incident surfaces both problems at once. A short tabletop with an external IR firm costs very little against a non-renewal, and it produces exactly the documentation the carrier is asking for.
Gallagher's 2026 Outlook found that roughly 41% of cited denial reasons in their broker survey involved MFA gaps specifically. The single biggest cause, by a wide margin.
90-Day Pre-Renewal Readiness Timeline
This is the roadmap nobody publishes. Tie it to NIST CSF 2.0, specifically the Protect and Recover functions, since those map most directly to carrier requirements.
90 days out. Run an external attack surface scan. Coalition's free Security Assessment is a reasonable starting point, or pay $2,000 to $5,000 for a Qualys scan with deeper coverage. Run an internal gap assessment against the Tier A or Tier B checklist above. MFA and EDR gaps come first.
75 days out. Deploy or verify MFA across remote access, email (M365 or Google Workspace), and admin consoles. Duo and Okta both deploy in under two weeks for SMB tiers. Confirm EDR coverage is 100% of endpoints, not just servers. I've seen too many CrowdStrike deployments stop at the data centre door.
60 days out. Implement or verify PAM on privileged accounts. BeyondTrust runs around $50 to $100 per user per year on mid-market plans. CyberArk for enterprise. Run a documented backup restore test and log the timestamps.
45 days out. Update or draft your IR plan. Named contacts, defined RTO and RPO, escalation chain, current vendor list. Schedule a tabletop, two hours with an external IR firm runs $1,500 to $3,000.
30 days out. Compile the evidence package. MFA enrolment screenshots, EDR coverage report, backup test log, IR plan with revision date, training completion records. This is what the supplemental questionnaire will ask for.
14 days out. Submit. If you're using a broker like Gallagher or Marsh, hand them the evidence package proactively. Underwriting turnaround for mid-market cyber typically runs 10 to 21 days. A complete evidence package shaves days off and signals maturity.
Documentation is what moves a premium. A submission that arrives with evidence of tested IR procedures, verified restores, and MFA coverage across every remote access path gives an underwriter something to credit rather than something to assume. Producing that evidence package is the whole point of the 5-Star Cyber Shield programme, and it is the difference documentation makes.
When to Get Help
If you're within 90 days of a cyber insurance renewal and aren't sure your MFA, EDR, or IR plan will hold up to carrier scrutiny, book a free 30-minute audit with Mike. He'll tell you exactly which gaps will cost you coverage, and which fixes the carrier will actually credit.
FAQ
Q: What's the single most common reason cyber insurance applications are denied in 2026? Missing MFA on remote access or email. Confirmed by Coalition's 2024 Cyber Claims Report and Gallagher's 2026 broker renewal survey, which found roughly 41% of denials cite MFA gaps.
Q: Do I need SOC 2 certification to get cyber insurance? No. But SOC 2 Type II evidence can reduce premiums and satisfy supplemental questionnaires for limits above $5M, particularly for SaaS companies.
Q: How much does cyber insurance cost for a 200-person company in 2026? Roughly $15,000 to $45,000 per year for $1M to $5M limits, depending on sector, revenue, and control posture. Healthcare and finance pay more.
Q: Can my carrier cancel mid-term if my security posture changes? Yes. Coalition and Beazley both run continuous post-bind monitoring. They can reprice or non-renew if they detect unpatched critical CVEs or newly exposed services.
Q: Does HIPAA compliance satisfy cyber insurance requirements? Partially. The HIPAA Security Rule (45 CFR §164.312) overlaps with carrier access control and audit log requirements, but carriers also require controls HIPAA doesn't mandate, like EDR and tested IR plans.
Know exactly where your security stands.
Get your free security assessment →Ready to take the next step?
Our team is here to help. No sales pitch, just a conversation.
Get a Free Security Assessment