Risk Intelligence

Cyber Insurance in 2026: What Carriers Require

Cyber insurance underwriting is tightening. Learn which controls are commonly reviewed, which requirements vary by carrier, and what evidence to assemble before renewal.

By Tom Brennan

Featured image for Cyber Insurance in 2026: What Carriers Require

Cyber insurance renewal is not a security certification exercise. It is a policy and underwriting decision based on the application, the requested coverage, the organization's controls, and the carrier's interpretation of the risk. Requirements vary, but leaders can make the process more defensible by preparing evidence before the questionnaire arrives.

Controls commonly discussed in underwriting

Many applications ask about controls that reduce the likelihood or impact of a common incident:

  • multifactor authentication for remote, privileged, email, cloud, and backup access;
  • protected backups and documented restoration testing;
  • endpoint protection, monitoring, and alert response;
  • patch and vulnerability management, including exceptions;
  • security awareness and phishing reporting;
  • incident response, business continuity, and exercises;
  • asset inventory, least privilege, and logging; and
  • vendor access, third-party risk, and contractual obligations.

“Commonly discussed” does not mean universally required. An underwriter can ask for different controls, evidence, limits, exclusions, or remediation depending on industry, size, technology, claims history, requested limits, and the specific policy.

Common evidence versus carrier-specific requests

Evidence to prepareWhy it helpsWhat may still vary
MFA enforcement and exception reportsShows where identity protection is active and where gaps remainCovered accounts, acceptable factors, and exception thresholds
Backup inventory and restore-test recordsShows coverage, isolation, recovery priorities, and observed resultsRetention, immutability, recovery evidence, and required test cadence
EDR/MDR coverage and alert proceduresShows monitored assets, escalation, and response ownershipRequired coverage, service hours, response commitments, and reporting format
Patch reports, scans, and approved exceptionsShows a repeatable process rather than an unsupported “yes”Severity thresholds, remediation windows, and internet-facing asset rules
Incident plan, exercise record, and contactsShows that leaders have rehearsed decisions and escalationNotification timing, panel requirements, and approved providers
Vendor inventory, assessments, and contractsShows how external access and dependencies are governedCritical-vendor tiers, attestations, contract clauses, and review frequency

Keep the evidence dated, identify its population and exceptions, and make sure the application language matches reality. A policy or planned project is not the same as an operating control.

Use recognized references without treating them as policy requirements

The NIST Cybersecurity Framework and CIS Critical Security Controls can help organize evidence and explain a program. They do not guarantee insurability or replace the carrier's application, broker advice, policy language, or legal review.

Prepare with the right internal owners

Assign one leader to coordinate the renewal, but involve the control owners who can verify the answers: IT and identity for MFA, infrastructure for backups and patching, security operations for detection, HR for training, legal and privacy for response obligations, procurement for vendors, and finance or executive leadership for limits and risk decisions.

Proactive Risk can help with a scoped MeasureRISK℠ evidence and gap review, CyberAdvisor℠ prioritization, RISKWatch℠ third-party risk workflows, ManageIT℠ MSOC monitoring, CATSCAN® testing, and CyberTrain℠ exercises. These services do not guarantee policy issuance, coverage, premiums, claim outcomes, or a security result. Coordinate insurance decisions with your broker, insurer, and qualified counsel.

Renewal checklist

  1. Get the current application and policy wording from the broker or carrier.
  2. Map each answer to a named owner and dated evidence.
  3. Document exceptions instead of converting partial implementation into a blanket “yes.”
  4. Resolve high-impact gaps or explain the remediation plan before submission.
  5. Ask which requirements are mandatory, which are underwriting preferences, and which are conditions or exclusions under the proposed policy.
  6. Retain the submitted application and supporting evidence so future renewals can be compared honestly.

Cyber insurance application answers compared with demonstrated control evidence

The eight layers behind an insurable cybersecurity posture

Insurance is one layer of financial risk transfer. The defensible goal is not to promise a perfect posture; it is to understand the policy, describe the controls accurately, and improve the gaps leadership has accepted.

Back to the Proactive Risk blog · Talk with Proactive Risk