
2026 Cyber Insurance Requirements for Small Business
MFA is now mandatory, EDR has replaced basic antivirus, and a large share of applications get denied on the first try. Here are the controls insurers expect before they will quote — or renew — your policy.
Cyber insurance used to be a short questionnaire and a check. Not anymore. After years of ransomware losses, insurers now underwrite like security auditors — and if you cannot demonstrate a baseline set of controls, you will be quoted a punishing premium, given a low limit, or simply denied. Renewals are where small businesses get caught flat-footed.
The controls insurers now expect
- Multi-factor authentication — on email, remote access, VPN, and privileged accounts. Now effectively non-negotiable.
- EDR / managed detection — endpoint detection and response has replaced “antivirus” as the floor.
- Tested, offline backups — with documented recovery, not just “we back up to the cloud.”
- Email security and security-awareness training — phishing is still the front door.
- Patch and end-of-life management — unsupported software is a common denial reason.
- A written incident-response plan — and someone accountable for it.
Why applications get rejected
A significant share of cyber-insurance applications are declined or sent back on first submission, and the reasons are remarkably consistent: missing or partial MFA, inadequate endpoint protection, and weak backup hygiene. The frustrating part is that these are not exotic, expensive controls — they are table-stakes hygiene that simply was not in place when the application went in.
What to do before your renewal date
Pull your renewal date forward on the calendar and work backward. Give yourself thirty to sixty days to close gaps, because some controls — enforced MFA across every system, EDR deployment, tested backups — take time to roll out cleanly. Walking into the renewal with the controls already in place is how you turn a denial into a competitive quote.



