Skip to content

WHT Cyber  /  Field Notes  /  Compliance

Compliance

2026 cyber insurance renewals: what carriers are actually requiring now.

Renewal applications got longer, premiums got pickier, and the “do you have antivirus?” era is over. Here's the control list carriers want to see in 2026 — and what gets a small business denied.

By WHT Cyber Engineering June 25, 2026 8 min read

Cyber insurance used to be a checkbox: pay a small premium, sign a one-page application, get a policy. That era ended somewhere around 2022, and 2026 is the year carriers stopped pretending it might come back.

If your renewal is up this quarter, the application you fill out will be longer than the one you signed last year. The questions will be more technical. And the answers carriers want now are not “yes, we have something for that” — they want documented proof, with screenshots, vendor names, and dates.

Here's what we're seeing from the underwriting questionnaires our clients are working through in 2026, and what the carriers actually do with the answers.

Why carriers got strict

Cyber claims paid out by US insurers have grown for six years running, with ransomware and Business Email Compromise as the two big drivers. Ransomware claim severity has roughly doubled since 2020 (Coalition's annual claims reports consistently show this trend), and small and midsized businesses now account for the majority of paid losses.

Carriers responded the only way they could: tighten underwriting. If you can't show you have the controls, you don't get the policy — or you pay materially more for it. According to Marsh's market reports, applicants with weak controls are routinely declined outright rather than just up-priced.

The 2026 control floor

If your business does not have these in place — documented, in production, on every account that matters — expect a non-renewal, a coverage exclusion, or a premium that will make you reconsider the policy entirely.

1. MFA on everything that matters

Multi-factor authentication is no longer a “recommendation” on the application. It's a yes-or-no gate, and several lines are individually scored:

  • Email (Microsoft 365, Google Workspace)
  • Remote access (VPN, RDP, any remote tool)
  • Privileged and administrative accounts
  • Backup systems and backup admin consoles
  • Financial and payroll systems

“We use MFA” without specifics is not a yes anymore. Carriers want to know where, with screenshots or a vendor report. And a growing number of carriers are pushing past basic MFA toward phishing-resistant MFA — FIDO2 keys, Windows Hello for Business, or number-matching push — for admins and finance roles.

2. EDR, not antivirus

Signature-based antivirus is no longer an acceptable answer. Carriers want a real EDR or MDR platform on every endpoint and server, with a 24/7 response capability behind it. Application questions now ask the product name (CrowdStrike, SentinelOne, Defender for Endpoint Plan 2, Huntress, etc.) and whether response is in-house or outsourced to an SOC.

Standalone AV will get you flagged. AV plus “our IT guy checks the alerts during business hours” will get you flagged. Most ransomware operators move fastest at 2 AM on a Saturday, and carriers know it.

3. Immutable, tested backups

This is the question category where the most renewals quietly fail. Carriers now ask:

  • Are backups stored offline or immutable (cannot be deleted or encrypted by an attacker with admin credentials)?
  • Are backups segmented from the production domain?
  • Is a full restore tested at least annually, with documentation?
  • What is the Recovery Time Objective (RTO)?

The reason: in nearly every ransomware case we see, the attacker has tried to delete or encrypt the backups before detonating. If your backups live in the same domain on the same network with the same admin credentials, the carrier assumes they will be lost. The CISA & FBI #StopRansomware guidance has been hammering this for years and carriers have aligned to it.

4. Email security and DMARC

Carriers ask whether you have a third-party email security gateway (or Microsoft Defender for Office 365 Plan 2), and whether you've enforced DMARC, SPF, and DKIM on your domain. The reason: BEC and vendor impersonation are now the #1 cause of paid claims by frequency. A correctly-enforced DMARC record is one of the cheapest controls a small business can put in place, and it visibly reduces the risk a carrier prices for.

5. Vulnerability and patch management

You'll be asked how quickly you patch critical CVEs (most carriers want 14 days or less for critical, 30 for high), and whether you're running internet-facing systems with end-of-life software. Unsupported Windows Server, Exchange Server on-prem, and certain VPN appliances are now hard exclusions on some policies — meaning if you get breached through them, the claim isn't covered.

6. Security awareness training and phishing simulations

Quarterly or at least annual training, with completion records you can produce on request. A growing number of carriers ask for phishing-simulation click rates over the last 12 months.

7. Incident response plan and IR retainer

A written IR plan that someone has actually read, with named roles, contact numbers, and decision authority. Bonus credit (and lower premiums) if you have an IR retainer with a named provider. Carriers will sometimes mandate their panel firms once a claim is opened; having your own pre-arranged keeps you in control of the first 24 hours.

What gets you denied

Based on what we're seeing in 2026 renewals across our client base, these are the most common reasons a small business gets non-renewed or moved to a much smaller carrier at a much higher rate:

  • No MFA on email or remote access. Near-automatic denial.
  • Antivirus only, no EDR. Denial or a hard sublimit on ransomware coverage.
  • Backups on the same Active Directory domain as production. Either denial or a ransomware exclusion.
  • Public-facing end-of-life systems (old Exchange, old VPN, exposed RDP). Exclusion or denial.
  • Past incident with no documented remediation. If you had a breach and can't show what you changed, carriers assume you'll have another one.
  • Inconsistent answers across the application. Underwriters cross-check. “We have MFA everywhere” on page 3 and “our remote access tool doesn't support MFA” on page 7 will get flagged.

What WHT recommends

Renewal is the moment when your security posture and your business risk meet in writing. Treat the application like an audit, not paperwork.

  1. Start 60 days early. If you wait until two weeks before expiration, your only leverage is “please bind something.” Start early and you can fix gaps before they become exclusions.
  2. Pre-audit the questionnaire yourself. Walk through it line by line. For every “yes,” have the evidence ready. For every “no,” have a plan to fix it before submission.
  3. Close the easy gaps first. MFA on every admin account. DMARC enforced. EDR rolled out everywhere. These are not expensive controls but they move the needle most.
  4. Fix the backup architecture. Immutable storage, separate credentials, segmented network. This is where the largest claims get paid — or denied.
  5. Document everything. Vendor names, version numbers, dates, screenshots. Carriers reward businesses that can show their work.
  6. Have a real IR plan, even if it's short. A two-page plan that's been read by the leadership team beats a 40-page plan no one has ever opened.
  7. Get an outside opinion. An MSSP or independent assessor will spot the answers your underwriter will challenge before the underwriter does.

The bottom line

Cyber insurance in 2026 is less a financial product and more a security audit you pay for. The carriers that are still writing policies are writing them only for businesses that look defensible on paper.

The good news: most of the controls carriers now require are the same controls you'd want anyway. The application is a forcing function. If your renewal questionnaire feels uncomfortable, that's a real signal — not about the carrier, but about the gaps. Close them before the form forces you to.

Renewal coming up? Let us pre-audit the questionnaire.

We'll walk through your carrier's application with you, flag what will get challenged, and tell you exactly what to fix before you submit. 30 minutes, no deck.

Book the call More Field Notes →