CYBER · BLOG

What 2026 Cyber Insurance Underwriters Actually Require

Insurers scan your infrastructure before the questionnaire arrives. Six things underwriters check in 2026, and the line item that quietly kills claims.

By James D. Boyd · Founder and CEO

What 2026 cyber insurance underwriters actually require
CYBER August 19, 2026 ~6 min read

What 2026 Cyber Insurance Underwriters Actually Require

Insurers scan your infrastructure before the questionnaire arrives. Six things underwriters check in 2026, and the line item that quietly kills claims.

FOR: Mid-market operators · 50–500 people · heading into a cyber renewal

By James D. Boyd · Founder and CEO · Vencer Group

Quick answer

Modern cyber insurers scan your public-facing infrastructure before they ever send the renewal questionnaire. What comes back on that scan shapes your premium, your terms, and the grounds on which a claim can later be reduced. Below: six things underwriters actually check in 2026, the one line in your application that quietly undoes most claims, and a six-item prep list for your next renewal.

Every year around this time I get the same call.

“James, the cyber renewal came back. Premium’s up 30%. They’re asking for a bunch of stuff we don’t have. Can you look at it?”

Yes. But we are not going to fix it in the two weeks before the policy lapses. That is the first thing.

The second thing is this: your insurance company knows a lot more about your network than you think. Not from the form you filled out. From what they can see on the internet, before you even started filling it out.

They run their own scan on you now

Around 2021, cyber insurers largely gave up on trusting the form. Too many claims where the answers on the application didn’t match what actually happened during the incident. So the industry industrialised the checking.

Insurers now subscribe to outside-in rating services, BitSight and SecurityScorecard among them. Those services continuously scan the public internet-facing parts of your business. Your web servers, your email records, your VPN endpoints, your exposed remote desktop, your certificates, your DNS setup. All of it.

By the time the renewal quote lands in your broker’s inbox, your business already has a score. That score has already influenced your premium, your available limits, and whether ransomware is even offered as an option.

If nobody has ever walked you through any of this, that is worth a question at your next renewal meeting. Selling the policy and managing the risk behind it are two different jobs.

“We have MFA” is doing a lot of work in that sentence

The single most-checked box on every cyber insurance application: we have multi-factor authentication.

When most operators check that box, they mean: we have MFA on Microsoft 365.

When the underwriter reads that box, they mean MFA on email, MFA on VPN, MFA on every cloud admin console you own, MFA on any remote desktop system, MFA on the remote-management tool your IT provider uses to reach your endpoints, MFA on your payroll platform, and MFA on privileged access to any on-premises server. And enforced. Not “available and mostly used.”

The question on the application says one thing. The definition being applied at claim time says another. Guess which one wins.

The gap between the two is where claims quietly die. It is also, not coincidentally, most of what the twelve controls we work from are designed to close. The Twelve Controls walks through the full set, control by control.

EDR is the new antivirus, and they know the difference

Somewhere in your renewal questionnaire there is a question that looks like this: “Do you use next-generation endpoint protection with behavioral analytics and 24/7 response capability?”

There is one honest way to answer yes. It requires you to actually run an EDR platform, SentinelOne, CrowdStrike, Defender for Endpoint at the higher tiers, and to have someone watching the alerts around the clock.

The answers that are not honest look like: “Yes, we have antivirus.” Or “Yes, our IT provider handles it.” Or “Yes, I think so, let me check.”

Insurers know the difference, and not because they trust your answer. Their scan already suggested what is running on your infrastructure. If your answer contradicts what they can see, that is not a good conversation to have at claim time.

Backups, the one they will absolutely test

The dialogue that happens in every renewal review I sit in on:

Do you have backups? Yes.
Are they offsite? Yes.
Are they immutable? … Probably?
Have you actually restored from them in the last twelve months?

The pause is the answer.

Cyber policies increasingly require documented restore tests. Not “we could restore if we needed to.” A test. Written down. With a date, a technician, a system that was restored, and a note on how long it took. Once a year at minimum, quarterly ideally.

Because at claim time, if you cannot demonstrate that you tested restores before the incident, the position the insurer is likely to take is that you had a theoretical backup strategy rather than an operational one. Theoretical strategies are a poor foundation for a business interruption claim.

The incident response plan question is not rhetorical

The question: “Do you have an incident response plan?”

The follow-ups nobody prepares for: When was it last updated? Has anyone at your company read it? Have you run a tabletop against it in the last twelve months? Who is your outside privacy counsel? Who is your forensics firm? Who is your ransom negotiation vendor?

If your answer to any of those is a version of “we’d figure it out at the time,” that is the answer the insurer files away. Because “we’d figure it out” is what a lot of badly-handled incidents looked like six months earlier.

Having a plan on paper is not the point. Having a plan that has been tested and updated in the last twelve months is the point.

Ransomware sublimits, the thing your broker may not have walked you through

Read your policy this time. Not the summary. The actual policy document.

Somewhere in the schedule there is a table that lists sublimits. That is where you find out that a headline $5M cyber policy can carry a $250K sublimit on ransomware payments, a $500K sublimit on business interruption from a ransomware event, and a $100K sublimit on cyber extortion legal fees. Those numbers vary by carrier and by policy. The point is that they exist, and that they are a great deal smaller than the number on the quote.

The headline number is what went on the quote. The sublimits are what actually pays out.

If a ransomware event happens tomorrow and your operation is down for four weeks, the maths against the sublimits, not against the headline number, is what tells you whether the policy covers the actual damage.

The honest take
The premium is not the number that matters. The payout at 2 AM on a Tuesday is. Most operators can tell you their premium to the dollar and cannot tell you their ransomware sublimit at all. That asymmetry is the whole problem in one sentence.

What to actually do in the six months before renewal

Not fixable in the two weeks before the policy lapses. Fixable in the six months before.

  1. Ask your broker for the latest external risk scan on your business. They can usually get it. They may not offer it. Ask.
  2. Map every place a user or admin logs in. Not just email. All of it. Put MFA on all of it. Prove it is enforced, not just enabled.
  3. Confirm what endpoint protection is actually deployed across every server and workstation. Get the vendor name. Get the version. Get the coverage percentage.
  4. Do a documented restore test. Pick a real system, restore it to a real environment, write down what happened. Date it. File it.
  5. Update your incident response plan and run a two-hour tabletop against it with your leadership team. It does not have to be fancy. It has to be documented.
  6. Read your current policy. Find the sublimits. Do the maths against a realistic ransomware scenario. If the maths does not work, that is what next year’s renewal conversation is about.

Six months. Not two weeks.

The one takeaway

The cyber insurance market stopped taking the application form at face value years ago. The score is real, the sublimits are real, and the reasons a claim gets reduced are sitting in your current policy, right now, today.

Fix that on your schedule. Not on the schedule of the incident that would otherwise force it.

If you want a second set of eyes on your current policy, the sublimits, the exclusions, and the gap between what is on the questionnaire and what your operations actually look like, send us a note. We will read it with you.

The footnote your lawyer would write. This is one operator’s read of the mid-market cyber insurance market in 2026, not legal or insurance advice. Every policy is different, every carrier’s underwriting posture is different, and coverage decisions turn on the specific facts at claim time. Use this to sharpen the questions you put to your broker and counsel, not to replace them.

The part where our lawyers smile

Pattern recognition from 19 years of running operator IT - not prescription for your specific situation. Anyone offering prescription from a blog post is selling something. (Possibly to you.) The 30-min Strategy Review is where the pattern becomes specific to your operation. Free, no proposal, no slide deck.