Cyber Insurance in 2026: What Carriers Require
Cyber insurance underwriting is tightening. Learn which controls are commonly reviewed, which requirements vary by carrier, and what evidence to assemble before renewal.
By Tom Brennan
Cyber insurance renewal is not a security certification exercise. It is a policy and underwriting decision based on the application, the requested coverage, the organization's controls, and the carrier's interpretation of the risk. Requirements vary, but leaders can make the process more defensible by preparing evidence before the questionnaire arrives.
Controls commonly discussed in underwriting
Many applications ask about controls that reduce the likelihood or impact of a common incident:
- multifactor authentication for remote, privileged, email, cloud, and backup access;
- protected backups and documented restoration testing;
- endpoint protection, monitoring, and alert response;
- patch and vulnerability management, including exceptions;
- security awareness and phishing reporting;
- incident response, business continuity, and exercises;
- asset inventory, least privilege, and logging; and
- vendor access, third-party risk, and contractual obligations.
“Commonly discussed” does not mean universally required. An underwriter can ask for different controls, evidence, limits, exclusions, or remediation depending on industry, size, technology, claims history, requested limits, and the specific policy.
Common evidence versus carrier-specific requests
| Evidence to prepare | Why it helps | What may still vary |
|---|---|---|
| MFA enforcement and exception reports | Shows where identity protection is active and where gaps remain | Covered accounts, acceptable factors, and exception thresholds |
| Backup inventory and restore-test records | Shows coverage, isolation, recovery priorities, and observed results | Retention, immutability, recovery evidence, and required test cadence |
| EDR/MDR coverage and alert procedures | Shows monitored assets, escalation, and response ownership | Required coverage, service hours, response commitments, and reporting format |
| Patch reports, scans, and approved exceptions | Shows a repeatable process rather than an unsupported “yes” | Severity thresholds, remediation windows, and internet-facing asset rules |
| Incident plan, exercise record, and contacts | Shows that leaders have rehearsed decisions and escalation | Notification timing, panel requirements, and approved providers |
| Vendor inventory, assessments, and contracts | Shows how external access and dependencies are governed | Critical-vendor tiers, attestations, contract clauses, and review frequency |
Keep the evidence dated, identify its population and exceptions, and make sure the application language matches reality. A policy or planned project is not the same as an operating control.
Use recognized references without treating them as policy requirements
The NIST Cybersecurity Framework and CIS Critical Security Controls can help organize evidence and explain a program. They do not guarantee insurability or replace the carrier's application, broker advice, policy language, or legal review.
Prepare with the right internal owners
Assign one leader to coordinate the renewal, but involve the control owners who can verify the answers: IT and identity for MFA, infrastructure for backups and patching, security operations for detection, HR for training, legal and privacy for response obligations, procurement for vendors, and finance or executive leadership for limits and risk decisions.
Proactive Risk can help with a scoped MeasureRISK℠ evidence and gap review, CyberAdvisor℠ prioritization, RISKWatch℠ third-party risk workflows, ManageIT℠ MSOC monitoring, CATSCAN® testing, and CyberTrain℠ exercises. These services do not guarantee policy issuance, coverage, premiums, claim outcomes, or a security result. Coordinate insurance decisions with your broker, insurer, and qualified counsel.
Renewal checklist
- Get the current application and policy wording from the broker or carrier.
- Map each answer to a named owner and dated evidence.
- Document exceptions instead of converting partial implementation into a blanket “yes.”
- Resolve high-impact gaps or explain the remediation plan before submission.
- Ask which requirements are mandatory, which are underwriting preferences, and which are conditions or exclusions under the proposed policy.
- Retain the submitted application and supporting evidence so future renewals can be compared honestly.


Insurance is one layer of financial risk transfer. The defensible goal is not to promise a perfect posture; it is to understand the policy, describe the controls accurately, and improve the gaps leadership has accepted.