Cyber Insurance Underwriting in 2026: What Carriers Require to Bind
Insurers stopped taking your word for it years ago. In 2026, binding or renewing a cyber policy means proving specific, named controls, not describing a general security posture, and the applications from major carriers now read like security audits.
Initial ransom demands rose 47% year over year in 2025, and dual-extortion attacks, where an attacker both encrypts systems and steals data, now account for 70% of all ransomware claims (Coalition, 2026 Cyber Claims Report). Carriers responded the way underwriters always respond to rising severity: they tightened eligibility. A cyber insurance application in 2026 is not a form describing your general security philosophy. It is a control-by-control checklist, and failing enough of the checklist means a higher premium, a reduced sublimit, an exclusion, or an outright decline.
Why underwriting got this specific
The shift did not happen overnight, and it is not really about 2026. Carriers spent the ransomware surge of 2020 through 2022 paying out claims on policies written against thin, self-attested applications, then discovered during claims investigations that the attested controls were not actually in place. The market response was to move from asking "do you have a security program" to asking "do you have this specific control, on this specific system, verified this specific way." Coalition's 2026 data shows why the discipline is holding: 86% of Coalition policyholders hit by ransomware in 2025 refused to pay the ransom demand, a record share, and 64% of closed claims resolved with zero out-of-pocket loss for the policyholder (Coalition, 2026 Cyber Claims Report). Underwriters read those numbers as validation that the control-first model works, which means the bar is not coming back down.
What carriers actually ask for
Rather than paraphrase generic "cybersecurity best practices," it is more useful to look at what a real carrier application requires. Beazley's current cyber insurance application asks applicants to affirm each of the following, specifically and individually, not as a bundled attestation (Beazley Cyber Insurance Application):
- Multi-factor authentication on all web-based email access, and on all remote network access for applicants above roughly £1 million in revenue.
- Offline or otherwise isolated backups that would survive a full environment compromise, backed up regularly and tested regularly for recoverability.
- Security awareness training for every user with network or confidential-data access, including anti-phishing training, reinforced by regular simulated phishing tests with additional training assigned to users who fail them.
- Endpoint protection, detection, and response, specifically distinguishing an Endpoint Protection Platform (EPP), Endpoint Detection and Response (EDR), and Managed Detection and Response (MDR) as separate capabilities the applicant is asked to confirm.
- Email security controls that scan incoming messages for malicious attachments and links, plus an advanced threat-hunting product such as Microsoft 365 Defender or an equivalent for phishing and business email compromise.
- A 28-day patch SLA for critical vulnerabilities on anything exposed to the internet, with a flat prohibition on end-of-life software or operating systems facing the internet at all.
- No exposed Remote Desktop Protocol. RDP or equivalent remote desktop software cannot be reachable directly from the internet under any circumstance the application accepts.
- IP allowlisting on exposed services, including email systems and remote access such as VPN, with everything else blocked by default.
- A hardened baseline configuration applied across substantially all devices, plus macros disabled by default in office productivity software.
- A documented incident response plan specifically covering network intrusions and malware incidents, not a general business-continuity document.
Travelers' renewal process runs on a parallel but differently structured model: a Ransomware Supplemental Assessment inside its Security Questionnaire, a Cyber Risk Scan that produces a Cyber Risk Score, and an Action Center that generates a prioritized remediation list tied to a "Guide to Common Security Controls" (Travelers, How to Get Renewal Ready). The mechanism differs from Beazley's checklist-style application, but the intent is identical: verify specific, named controls before binding, and flag gaps that will affect terms.
Both approaches track closely with the control categories in CISA's #StopRansomware Guide, which recommends a written, CEO-approved incident response plan with an offline hard copy, and a communications plan covering breach-notification obligations. That overlap is not a coincidence. Carriers, brokers, and CISA converged on largely the same control set because it is the set that actually reduces claim frequency and severity, not because any one of them invented it independently.
What this means if you are the one filling out the application
Three consequences follow directly from how specific these applications have become, and all three show up during renewal season more than at initial binding:
- Partial compliance still costs you. Having MFA on remote access but not on webmail, or having backups but never testing restoration, will not fail an application outright, but it moves you into a higher-severity risk tier that shows up as a higher premium, a reduced ransomware sublimit, or a coinsurance requirement on ransomware claims specifically.
- Attestations get checked. Several carriers now run external attack-surface scans against the domains you list on the application, independent of what you self-report. A "yes" on the RDP-exposure question that does not match the scan results is the fastest way to end up with a rescission dispute after a claim, not before one.
- The applicant of record matters for flow-down risk too. Organizations in regulated supply chains, defense subcontractors reporting under DFARS 252.204-7012, healthcare entities under HIPAA, credit unions under NCUA rules, increasingly face a version of this same control-verification exercise twice: once from their regulator or prime contractor, and again from their cyber insurer. Building one control environment that satisfies both, rather than treating them as separate compliance exercises, is materially cheaper than maintaining two.
Closing the gap before your next renewal
Most organizations that fail an underwriting review are not missing exotic controls. They are missing verification of controls they believe they already have. A practical sequence, in priority order:
- Pull your current cyber policy application or renewal questionnaire and go line by line against what is actually configured today, not what was configured when the control was first deployed.
- Close MFA gaps first. Webmail and remote network access are the two surfaces every carrier application asks about explicitly, and they are also the two most common initial access vectors in the claims data carriers are using to price your renewal.
- Test your backups, not just your backup schedule. A backup job that runs nightly and has never been restored is not evidence of resilience to an underwriter or to your own incident responders.
- Confirm nothing critical touching the internet is unpatched past 28 days or past end of life. This is the single most common gap flagged in post-incident forensic reviews and the easiest one for an underwriter's scan to catch independently.
- Write down the incident response plan and get it signed. An unwritten plan or one nobody in leadership has reviewed does not satisfy the application question, regardless of how capable the team executing it actually is.
None of this requires waiting for a renewal cycle to start the work. If you already run a 24/7 SOC or a managed detection and response program built around EDR and MDR, most of the Beazley-style checklist above is a documentation exercise on top of controls you already operate. If it is not yet built, closing these gaps before your next application is materially cheaper than absorbing a ransomware sublimit or a coverage dispute after an incident. Our guide to managed SOC pricing breaks down what that build-out actually costs, and our MDR versus MSSP versus SIEM comparison covers how to choose the operating model. If you want a second set of eyes on your renewal questionnaire before you submit it, reach out.
Frequently asked questions about cyber insurance underwriting
Is multi-factor authentication actually required to get a cyber policy in 2026?
For most carriers, yes, on two specific surfaces: web-based email access and remote access to the network. Beazley's current application requires MFA on webmail for all applicants and on remote network access for applicants above roughly £1 million in revenue, and most major carriers ask the same two questions in some form.
What is the difference between EDR and MDR on a cyber insurance application, and do I need both?
Endpoint Detection and Response (EDR) is the technology that monitors endpoints and flags suspicious activity. Managed Detection and Response (MDR) is the staffed service that actively watches, triages, and responds to what EDR flags, day and night. Carrier applications increasingly ask about both separately because unmonitored EDR alerts sitting in a queue provide little practical protection against a fast-moving ransomware intrusion.
What happens if I only have some of the required controls in place?
You will generally still be offered a policy, but with worse terms: a higher premium, a reduced ransomware sublimit, a coinsurance percentage applied specifically to ransomware losses, or an exclusion tied to the missing control. Full declines are typically reserved for organizations with major, unremediated gaps like internet-exposed RDP or end-of-life software running the core network.
Do insurers actually verify what I put on the application, or is it self-reported?
Both. The application itself is self-attested, but several carriers, including Travelers through its Cyber Risk Scan, run independent external attack-surface scans against the domains an applicant lists. A mismatch between an attestation and scan results is a common trigger for follow-up questions before binding and for coverage disputes after a claim.
Why do carrier applications specify a 28-day patch window instead of just asking about patch management generally?
Because vague patch-management attestations proved unreliable predictors of claims outcomes during the ransomware surge of 2020 through 2022. A specific, measurable SLA tied to internet-facing critical vulnerabilities is something an underwriter can verify against scan data and something a claims investigator can check against the actual timeline of an incident.
Does my incident response plan need to be a formal written document?
Yes. Carrier applications and CISA's own #StopRansomware Guide both call for a documented plan, reviewed and understood across the chain of command, with CISA specifically recommending it be reviewed and approved in writing by the CEO or equivalent, and that a hard copy and an offline version both exist in case systems are unavailable during an incident.
If I already meet DFARS, HIPAA, or NCUA requirements, does that satisfy my cyber insurance application too?
Largely yes for the underlying controls, since MFA, patch management, backups, and incident response planning overlap heavily across frameworks, but the verification format differs. Insurers ask their own specific questions in their own specific wording, so the practical step is mapping your existing regulatory controls to the carrier's exact application language rather than assuming one attestation covers both.