Cyber Insurance in 2026: What Insurers Now Demand Before They'll Pay Out
Cyber insurance used to be straightforward. You answered a short form, paid a modest premium, and filed it away. That market is gone. After several years of heavy ransomware losses, insurers rebuilt their requirements from the ground up, and the questions on today's proposal form are not a formality. They are a checklist of controls you are expected to already have, and answering them optimistically is the fastest way to find your policy does not respond when you need it.
The short version
- Controls are now a condition of cover, not a discount. Miss them and you may be declined outright.
- MFA, EDR and tested offline backups are the three that come up almost every time.
- The proposal form is a legal document. An inaccurate answer can void the policy at the point of claim.
- Ransomware is often sub-limited, so the headline figure is rarely what you would receive.
- Getting the controls in place usually costs less than the premium difference, and you keep the benefit either way.
What insurers now expect as standard
Requirements vary by insurer and by the size of the risk, but the same items appear on nearly every form.
Multi-factor authentication, everywhere external
Not just email. Remote access, VPN, administrative accounts and any system reachable from the internet. This is the single most common reason a proposal is declined, and it is usually because coverage has gaps rather than being absent. Our guide on what businesses get wrong about MFA covers where those gaps typically hide.
Endpoint detection and response
Traditional antivirus is no longer sufficient for most insurers. They expect EDR: tooling that detects suspicious behaviour rather than matching known file signatures, and that lets someone isolate a compromised machine quickly. Increasingly they also want to know whether anyone is actually watching the alerts, because software nobody monitors is not a control.
Backups that are offline, or immutable, and tested
Three questions, and the third is where most businesses come unstuck. Are backups separated from the main network so ransomware cannot encrypt them too. Are they immutable, meaning they cannot be altered or deleted within a retention window. And when did you last restore from them. "We have backups" is not an answer. "We restored a server from backup in March and it took four hours" is.
Patching within a defined window
Usually 14 days for critical vulnerabilities, sometimes less. Related, and increasingly explicit, they ask whether any unsupported software is still in use. If you are still running Windows 10 after its end of support, expect that to be asked directly.
An incident response plan someone has read
A written plan naming who decides what, who to call and in what order. Some insurers ask whether it has been rehearsed. A document created for the proposal form and never opened again is easy to spot in a claim.
Email filtering and awareness training
Most incidents still begin with an email. Insurers want to see a filtering layer beyond the platform default, and evidence that staff receive some form of phishing training rather than a one-off induction slide.
Need Reliable IT Support for Your Business?
Our managed IT support services keep your systems secure, monitored, and running efficiently.
The part that catches people out
A proposal form is a legal declaration. If you state you have MFA on all remote access and it later emerges that the finance system was exempt, the insurer may argue the risk was misrepresented. Depending on the circumstances that can reduce a payout or void the policy entirely, and it tends to come to light during a claim, which is the worst possible moment.
This is not insurers looking for excuses. It is that the answers materially change the price of the risk. The practical implication is simple: have someone verify each answer against reality before it is signed, rather than filling the form in from memory. If the honest answer is no, say no and price accordingly. An honest no is insurable. An inaccurate yes is not.
Read the limits, not just the number
The headline figure on a cyber policy is rarely the amount available for the event most likely to happen to you. Look specifically for:
- Ransomware and extortion sub-limits, frequently a fraction of the overall limit.
- Business interruption, including the waiting period before it starts and whether it covers a slow degraded recovery rather than a total outage.
- Dependent business interruption, which covers you when a supplier is breached rather than you. Increasingly relevant and often excluded.
- Whether incident response is provided or reimbursed, and whether you must use the insurer's panel. Calling your own IT provider first can occasionally affect cover.
- Exclusions for unsupported software, unpatched systems and, in some wordings, incidents attributed to state actors.
How to approach a renewal
- Get the proposal form early, several weeks before renewal rather than days.
- Go through it with whoever runs your IT and mark every answer as verified, unknown or no.
- Fix the cheap noes first. MFA gaps and enabling immutable backup retention are often configuration changes rather than purchases.
- Gather evidence. A screenshot of enforced MFA, a restore test dated this year, a patch report. Brokers can use these to argue your case.
- Then submit, with answers you could defend in a dispute.
Businesses that do this typically find the controls cost less than the premium reduction, and unlike the premium, the controls also reduce the chance of the incident happening at all.
Where certification helps
Cyber Essentials overlaps heavily with what insurers ask, covering MFA, patching, supported software, access control and malware protection. Holding it will not automatically reduce your premium with every insurer, but it answers a large part of the form with an independently assessed yes, and some insurers offer better terms for it.
If you would rather not guess
We work through cyber insurance proposal forms with London businesses, checking each answer against what is actually configured, fixing the gaps that are quick, and producing the evidence brokers ask for. It is usually half a day, and it is considerably cheaper than discovering the position during a claim.
Call 0207 112 4812 or book ad-hoc support here. Our rate is £50 per hour plus VAT.
Looking for proactive IT support instead of reactive fixes?
Speak to our team today and discover how IT-MSP can transform your business technology.










