9 Cyber Insurance Requirements Your Business Needs to Meet
Tabla de contenido
- What is cyber liability insurance?
- Is cyber insurance mandatory?
- What is happening to cyber insurance pricing?
- Why are some insurers and brokers advocating for government intervention in the cyber insurance market?
- Why has underwriting become an audit?
- 9 key cybersecurity insurance requirements
- 1. Deploy phishing-resistant multi-factor authentication
- 2. Implement endpoint detection and response
- 3. Maintain immutable, tested backups
- 4. Enforce privileged access management
- 5. Patch on a documented cadence
- 6. Test your incident response plan
- 7. Secure email and train your people
- 8. Segment your network
- 9. Demonstrate third-party and supply chain controls
- What happens when your insurer scans you?
- The attestation trap: how cyber insurance claims actually get denied
- How much cyber insurance do you need?
- Which businesses need cyber insurance the most?
- Cybersecurity insurance requirements FAQs
- Wrapping up: treat the renewal like the audit it is
Cyber incidents remain a growing concern for businesses of all sizes, and the financial impact keeps climbing. IBM found that the global average cost of a data breach reached a record USD 4.99 million, a 12% increase year on year. In the United States, the average hit USD 11.5 million, more than double the global figure.
But something else has changed, and it matters more than the headline number.
Cyber insurance underwriting is no longer a questionnaire you fill in. It is a technical audit, and insurers verify your answers independently.
Ahead, we will break down what cyber liability insurance covers, where pricing is heading, the nine controls insurers verify before they bind or renew, and the attestation mistake that causes more claim denials than any other.
What is cyber liability insurance?
Cyber liability insurance is a policy that helps businesses manage the fallout from cyberattacks, including covering costs related to data breaches, compromised systems, or theft of sensitive customer data.
It typically covers:
- Legal fees and expenses if your business is sued following a cyberattack.
- Credit monitoring services for impacted customers.
- Costs of notifying customers or stakeholders about breaches.
- Recovery costs, such as restoring systems or data.
- Ransom payments in some cases of ransomware or cyber extortion, depending on the policy.
Cyber liability policies are typically divided into first-party and third-party coverage:
- First-party coverage addresses losses to your company directly, such as system repair, recovery and response costs.
- Third-party coverage helps cover claims made against your business by customers, vendors or partners affected by the incident.
Is cyber insurance mandatory?
Cyber insurance is not universally mandatory, but in some industries and jurisdictions, regulations are increasingly pushing for its adoption.
Highly regulated sectors like healthcare and finance face more stringent requirements due to the sensitivity of the data they handle. Frameworks like RGPD in Europe and HIPAA in the US place heavy emphasis on managing breach risk, which in turn drives cyber insurance adoption. In the EU, DORA has added a further layer of ICT and third-party risk obligations for financial entities since January 2025.
In countries including Germany and the United States, certain businesses working with government contracts or critical infrastructure may be required to hold cyber coverage.
The bigger practical constraint is commercial rather than legal. Enterprise customers, lenders and partners increasingly require proof of coverage as a condition of doing business, which makes insurability a revenue question as much as a risk question.
What is happening to cyber insurance pricing?
This is where most guidance published this year gets it wrong.
Cyber insurance rates have now fallen for four consecutive years. According to Swiss Re, global rates declined by around 5% in 2026, easing from a drop of roughly 13% in 2025, with the moderation driven largely by US carriers responding to profitability pressure. In Europe, price competition remains stronger and rates are still falling more sharply.
Premium volume continues to grow, projected to reach USD 16.4 billion in 2026 and USD 17.1 billion in 2027, but that growth is coming from new buyers rather than higher prices.
So this is a buyers’ market. That is only half the picture, and the other half is what catches people out.
Prices are falling. Entry requirements are not. Carriers are competing on price while raising the evidentiary bar for coverage at the same time. The softening reflects competition and improved loss ratios, not a relaxation of standards. In practice, two companies of identical size in the same sector now see materially different outcomes based purely on what they can prove.
If you can evidence your controls, you are looking at the best pricing available in four years. If you cannot, you are looking at declined applications, exclusions that gut the coverage in the areas you actually need, or surplus lines pricing.
Sector matters as well. IBM’s 2026 data puts healthcare at USD 6.64 million per breach, the thirteenth consecutive year it has topped the table, with financial services close behind at USD 6.29 million. Both sectors carry corresponding premium loads.
Why are some insurers and brokers advocating for government intervention in the cyber insurance market?
As cyberattacks grow in frequency and severity, some insurers and brokers, including Zurich and Marsh McLennan, have been vocal about the need for government intervention to stabilize the cyber insurance market. Their joint whitepaper argues that closing the cyber protection gap requires the insurance industry and the public sector to collaborate and innovate together, and frames wider societal cyber resilience as inseparable from the health of the cyber insurance market itself.
That protection gap has not closed. Munich Re’s Global Cyber Risk and Insurance Survey 2026, drawing on more than 9,500 respondents across 20 countries, found that nearly nine in ten C-level executives do not believe their organisation is adequately protected. Swiss Re estimates insurance penetration at 5% to 10% among micro businesses and 10% to 20% across SMEs, rising to 40% to 50% in the mid-market and only 60% to 70% among large corporates.
The rising cost of claims drives concern that the market alone cannot absorb the financial burden, particularly in a catastrophic loss such as a large-scale attack on infrastructure or a major cloud provider. Vendor outages with potential losses running into billions have sharpened that concern considerably.
Government involvement could create a public-private partnership providing reinsurance or a financial backstop, ensuring businesses remain protected while the market stays viable. The debate remains unresolved, which is one reason carriers are managing their exposure through tighter underwriting instead.
Why has underwriting become an audit?
Carriers spent several years absorbing ransomware losses that exceeded their models. The response was structural.
Underwriting is now evidence-based. Most carriers run external attack surface scans against applicants before binding, and cross-check what they find against what you declared. Self-attestation alone is no longer accepted by most major carriers, who increasingly want screenshots, deployment reports and restore-test logs.
Why it is important: The questionnaire is not paperwork sitting in front of the underwriting decision. The questionnaire is the underwriting decision.
What insurers expect: Documented evidence with dates, owners and scope for every control you claim. Expect a 60 to 90 day preparation window for a clean renewal, and four to six months if you have gaps to close in identity, endpoint or backup first.
9 key cybersecurity insurance requirements
Most carriers now work from a recognisable control set. Here are the nine that appear on almost every questionnaire.
1. Deploy phishing-resistant multi-factor authentication
MFA is the single most influential control on your premium, and the bar has risen. “We have MFA on email” no longer satisfies most carriers.
Why it is important: MFA substantially reduces the likelihood that attackers can access systems using compromised passwords alone. It remains the most effective single control against unauthorised access.
What insurers expect: Phishing-resistant MFA deployed across email, remote access and all privileged accounts, with documented coverage percentages. Shared administrator accounts are a common failure point. Carriers offer meaningful premium credits for full deployment.
2. Implement endpoint detection and response
EDR or managed detection and response with continuous monitoring has moved from preferred to required for most coverage tiers.
Why it is important: Endpoint visibility determines how quickly an intrusion is detected and contained, which directly drives the size of a loss. IBM found the mean time to identify and contain a breach rose to 247 days, reversing five consecutive years of improvement.
What insurers expect: EDR deployed across the estate with evidence of coverage, not a partial rollout. Carriers will ask what percentage of endpoints are protected and who monitors the alerts.
3. Maintain immutable, tested backups
Backups remain central, but the requirement has sharpened from “do you back up” to “can you prove you restored.”
Why it is important: Backups allow businesses to restore operations without paying a ransom or absorbing extended downtime. Attackers know this, which is why they target backup infrastructure first.
What insurers expect: Immutable or offline backups following a 3-2-1 approach, encrypted, with dated restore-test logs. An untested backup is treated as no backup.
4. Enforce privileged access management
Identity access management generally, and privileged access specifically, now appears on virtually every questionnaire.
Why it is important: Privileged accounts are the target. Controlling who holds elevated access, and for how long, limits how far an intrusion can travel.
What insurers expect: Role-based access controls, least-privilege policies, session monitoring for privileged accounts, and documented offboarding. Least privilege and Zero Trust language is increasingly appearing in carrier guidance and renewal audits.
5. Patch on a documented cadence
Why it is important: Vulnerability exploitation overtook stolen credentials as the leading initial access vector in the Verizon 2026 DBIR. Unpatched internet-facing systems are the most visible risk an external scan will find.
What insurers expect: A documented patch cadence with defined timelines for critical vulnerabilities, and no unsupported end-of-life systems in the environment. End-of-life software is one of the fastest routes to a declined application.
6. Test your incident response plan
Why it is important: IBM attributes 63% of total breach cost to detection, escalation and lost business. Those are the cost categories a tested response plan compresses.
What insurers expect: A dated, written incident response plan that has been exercised, with the exercise documented. Carriers distinguish sharply between a plan that exists and a plan that has been run.
7. Secure email and train your people
Why it is important: Business email compromise and funds transfer fraud account for a substantial share of claims by volume, even though ransomware dominates by value.
What insurers expect: Email filtering and authentication controls, plus documented security awareness training with phishing simulation metrics. Underwriters read training records as a proxy for security culture rather than as a compliance box.
8. Segment your network
Why it is important: Segmentation determines whether an intrusion becomes an incident or a catastrophe. It is the difference between one compromised system and an encrypted estate.
What insurers expect: Evidence of segmentation between critical systems, general user environments and any operational technology. For higher coverage limits, expect annual penetration testing to validate it.
9. Demonstrate third-party and supply chain controls
This is the fastest-growing section of the questionnaire, and the one most applicants struggle to answer.
Why it is important: The 2026 Verizon Data Breach Investigations Report found third-party involvement in 48% of breaches, a 60% year-on-year increase following a year in which the figure had already doubled. Vendor-related incidents now account for a significant share of insured losses, and carriers have responded by scrutinising system failure and dependency clauses far more closely.
What insurers expect: An inventory of critical vendors, evidence of due diligence, contractual security requirements, and increasingly some form of ongoing monitoring rather than an annual questionnaire. For higher limits and for regulated sectors like healthcare and financial services, a formal third-party risk assessment is often mandatory, and some carriers offer explicit credits for one.
What happens when your insurer scans you?
Here is the part most applicants do not plan for.
Before binding, your carrier runs an external scan of your attack surface. They are looking at what an attacker would see: exposed services, unpatched internet-facing systems, expired certificates, forgotten subdomains, misconfigured storage, credentials circulating from previous breaches.
Then they compare that picture to your application.
Why it is important: You are being assessed on assets you may not know you own. Shadow IT, decommissioned infrastructure that never got decommissioned, a supplier’s misconfigured server holding your data, credentials exposed in an unrelated breach. None of those appear on an internal asset inventory, and all of them appear on an external scan.
What insurers expect: Consistency. The gap between your declared posture and your observable posture is what underwriters price, and what they revisit if you ever file a claim.
This is where an external threat intelligence platform earns its place in a renewal. Knowing what your insurer will find, before they find it, turns a surprise into a remediation task with a deadline. CybelAngel’s Gestión de la Superficie de Ataque surfaces exposed and forgotten assets, Inteligencia de Credenciales identifies exposed credentials tied to your domains and your suppliers’ domains, and Prevención de fugas de datos detects sensitive documents sitting on misconfigured servers inside and beyond your perimeter.
The attestation trap: how cyber insurance claims actually get denied
Misrepresenting controls, even unintentionally, is among the most common causes of claim denial.
The mechanism is straightforward and uncomfortable. You attest in good faith that MFA is enforced across all privileged accounts. Eleven months later you suffer an incident, and the forensic investigation your carrier commissions establishes that three service accounts were excluded from the policy. The claim is contested, and in some circumstances coverage can be rescinded retroactively.
Why it is important: The exposure is not just the denied claim. It is that you carried a year of risk believing you were covered, and made decisions on that basis.
What insurers expect: Accuracy over optimism. If a control is partially deployed, say so and state the scope. Underwriters price partial deployment. They do not forgive inaccurate attestation.
Two practical safeguards:
- Attest to what you can evidence. If you cannot produce a dated artefact for a control, do not declare it as fully implemented.
- Re-verify before each renewal. Attested controls must be continuously maintained, not implemented once. Configuration drift is a real source of denied claims.
How much cyber insurance do you need?
There is no universal figure, but carriers and brokers generally work from three inputs.
- Records held. The volume of sensitive personal, financial or health records you process, multiplied by a realistic per-record cost of notification, credit monitoring and legal response.
- Downtime tolerance. What one day of full operational outage costs your business, multiplied by a realistic recovery period. IBM’s 247-day average lifecycle to identify and contain is a useful reality check against optimistic assumptions.
- Regulatory exposure. Which regimes apply to you, and what the realistic penalty range looks like. This is why US organisations face materially higher breach costs than the global average.
Sector benchmarks help calibrate. IBM’s 2026 figures put healthcare at USD 6.64 million per breach and financial services at USD 6.29 million, against a global average of USD 4.99 million.
A common mistake is buying to a limit that covers the ransom but not the business interruption, forensics, notification and litigation that follow. Ransom payment is frequently the smallest line item.
Which businesses need cyber insurance the most?
Organisations handling sensitive customer data, and those whose operations halt when systems go down, carry the greatest exposure.
- Healthcare and life sciences. Highest breach costs of any sector for thirteen consecutive years, with patient data that carries enduring value on criminal markets.
- Financial services. Second-highest breach costs, the heaviest regulatory load, and in the EU a DORA obligation to manage ICT third-party risk on an ongoing basis.
- Manufacturing and critical infrastructure. Operational downtime translates directly into lost revenue, and OT environments frequently contain legacy systems that complicate underwriting.
- Any organisation deep in a supply chain. If your customers depend on you, your incident becomes their incident, and third-party liability claims follow.
Cybersecurity insurance requirements FAQs
At minimum, most carriers now require phishing-resistant MFA on email, remote access and privileged accounts, EDR deployed across the estate, immutable and tested backups, a documented and exercised incident response plan, and current patching with no end-of-life systems. Below that baseline, expect declined applications or surplus lines pricing.
Some policies do, but many carriers now apply ransomware-specific sublimits, higher retentions, and conditions requiring carrier approval before any payment is made. Several jurisdictions are also moving toward restrictions on ransom payments, which policies increasingly reflect. Check your specific terms rather than assuming.
The most common causes are misrepresented or lapsed controls, failure to disclose known risks, and violating policy conditions. Because carriers can rescind coverage retroactively where attested controls were not maintained, the practical defence is evidence: dated artefacts showing each declared control was in place and continuously operating.
Sixty to ninety days for a clean renewal where controls are already in place. Four to six months if you need to implement EDR, close identity gaps or rebuild backup infrastructure first. Missing documentation, rather than missing controls, is the most common cause of renewal delay.
Yes. Most major carriers run external attack surface scans as part of underwriting and compare the results to your application. They see what an attacker sees, including assets you may have forgotten and exposure sitting at your suppliers.
Carriers reward demonstrable risk reduction. Full MFA deployment attracts the largest single credit from most major carriers, and organisations that combine MFA, EDR and evidenced backup restore testing typically see meaningful reductions. Some insurers also offer explicit credits for a completed third-party risk assessment.
Wrapping up: treat the renewal like the audit it is
Cyber insurance in 2026 rewards organisations that can prove what they claim. To put yourself in the best position:
- Start 60 to 90 days out, and involve your broker early to get the questionnaire in advance.
- Build an evidence binder with dated artefacts, named owners and explicit scope for every control.
- Run an external view of your own attack surface before your carrier runs theirs.
- Attest accurately, including partial deployments, and re-verify at every renewal.
- Extend your inventory beyond your own perimeter to the suppliers holding your data.
With the right controls and the evidence to back them, you improve your terms and your actual security posture at the same time.
If you want to see your attack surface the way your underwriter will, request a demo.
