Logbook

Cyber Insurance Requirements Checklist: What Carriers Actually Want in 2026

September 4, 2026 · 4 min read

Cyber insurance used to be a paperwork exercise. Answer a questionnaire, check some boxes, get a quote. That’s not how it works anymore.

As of 2026, most carriers have moved from self-attestation to evidence-based underwriting. It’s no longer enough to say “yes, we have MFA enabled.” Underwriters want screenshots, configuration exports, and dated reports with your company’s name on them — and if what you attested doesn’t match what’s actually deployed, that’s the single biggest reason claims get denied.

A mid-market manufacturer found this out the hard way in late 2025: a ransomware attack got in through one VPN account that didn’t have MFA enabled. The company had attested that MFA was enforced on all remote access. One account was missed. The carrier denied the $2.3 million claim, citing material misrepresentation.

This checklist is what carriers are actually looking for right now — not a generic “best practices” list, but the specific controls that determine whether you get quoted at all, what you’ll pay, and whether a claim actually gets paid out if the worst happens.

The Three Non-Negotiables

Most carriers now treat these as hard gates. Missing any one of them can mean an application gets declined outright, regardless of everything else on your questionnaire.

  • ☐ Multi-factor authentication — on every remote access tool, email account, admin/privileged account, and cloud platform. Not “most” accounts. All of them. One account without it, like the case above, is enough to void a claim even if you believed the box was checked.
  • ☐ Endpoint detection and response (EDR) — on every device and server. Traditional antivirus alone is increasingly treated as insufficient by underwriters; EDR watches for suspicious behaviour, not just known malware signatures.
  • ☐ Tested, immutable backups — not just “we have backups,” but backups that can’t be altered or deleted by ransomware, with restoration actually tested rather than assumed to work. The common standard here is 3 copies of your data, on 2 different types of storage, with 1 copy offsite and immutable.

The Supporting Controls

These won’t necessarily sink an application on their own, but they shape your premium significantly, and carriers are asking about them in more detail than they used to.

  • ☐ A written, documented incident response plan — not a plan that exists only in someone’s head. Who gets called, in what order, and what happens in the first 24 hours matters to an underwriter.
  • ☐ Patch management — a documented, consistent process for keeping software updated, not “employees update their own devices whenever.”
  • ☐ Privileged access management — limiting who has admin rights, and removing access promptly when someone leaves the company.
  • ☐ Employee security awareness training — with phishing simulation testing, not a once-a-year video. Carriers increasingly want to see completion rates and click-rate trends, not just confirmation that training exists.
  • ☐ Email authentication — SPF, DKIM, and DMARC configured on your domain, which make it harder for someone to send email that impersonates your business.
  • ☐ Vendor and third-party risk review — some awareness of the security posture of the vendors and suppliers who touch your systems or data.

Why “We Have Antivirus” Doesn’t Cut It Anymore

This is the gap that catches the most businesses off guard. Antivirus checks files against a list of known threats. EDR watches for behaviour — a program suddenly encrypting hundreds of files, a login from a device that’s never been seen before — and can isolate a device automatically before damage spreads. Underwriters have seen enough claims data to know the difference in outcomes, which is exactly why several carriers now price EDR and traditional antivirus differently on the same application.

The same shift applies across this whole list. A cyber insurance questionnaire in 2026 isn’t really asking “do you have security tools.” It’s asking “can you prove they’re configured correctly, actively monitored, and actually work when tested” — which is a different, harder question than most small businesses are prepared to answer.

Where This Leaves Most Small Businesses

Almost nobody fails this checklist because they’re careless. They fail it because these controls take active, ongoing management to maintain — not a one-time setup. MFA gets enabled for new hires but missed on a legacy account. Backups run automatically but nobody’s tested a restore in a year. Training gets assigned but completion never gets tracked.

That gap between “we set this up once” and “we can currently prove this is working” is exactly what a renewal questionnaire is designed to expose.

This is precisely what the LogosCyber Guarded plan is built around: 24/7 endpoint protection, MFA enforcement, documented patch compliance, verified backup and recovery, tracked security training completion, and always-current asset documentation — the specific evidence an underwriter asks for, ready when you need it, not scrambled together the week before a renewal.

See Your Cyber Risk

Ready to remove cybersecurity as a business risk?

Every business carries cyber risk. The question is how much you are willing to carry.

Pricing → See Your Risk Score →