← Back to blog

Cyber Insurance Requirements for SMBs: 2026 Checklist

August 8, 2026
Cyber Insurance Requirements for SMBs: 2026 Checklist

To qualify for cyber insurance today, your business needs four controls in place before most carriers will even quote you: multi-factor authentication (MFA) on all email, admin, and remote access accounts; endpoint detection and response (EDR) or managed detection and response (MDR) on every device; immutable or offline backups with documented restore tests; and a written incident response (IR) plan with at least one tabletop exercise on record. Get those four right and you become insurable. Miss any one of them and you face either a denial or a policy with exclusions that gut the coverage you thought you were buying.

Must-have controls (carriers treat these as pass/fail):

  • MFA enforced on email, VPN, remote desktop, and all privileged accounts
  • EDR/MDR deployed on all endpoints with 24/7 monitoring
  • Immutable or air-gapped backups with a tested, dated restore log
  • Documented IR plan with a recent tabletop exercise completed

Controls that improve terms and lower premiums:

  • Privileged access management (PAM) and least-privilege enforcement
  • Network segmentation separating critical systems from general users
  • Patch management with defined SLAs for critical CVEs
  • Email security: DMARC, SPF, DKIM, and a filtering gateway
  • Vendor/third-party risk assessments
  • Security awareness training with phishing simulations

Immediate next steps: Run an internal gap check against the must-have list above. If any item is missing or unverified, contact your broker and an MSP before submitting an application. Submitting without evidence of these controls is the most common reason SMBs receive unfavorable terms or outright denials.


Table of Contents

Why do insurers require security controls now?

Cyber underwriting changed fundamentally after the ransomware surge of 2020–2023. Carriers that once issued policies based on a short questionnaire and a revenue figure started paying out claims at a rate that made the old model unsustainable. The result: underwriting is now an evidence-based security assessment, not a paperwork exercise.

The top cybersecurity threats driving insurer losses are ransomware, business email compromise (BEC), and credential theft through exposed remote access services. Insurers know exactly which controls reduce those losses, and they price policies accordingly. The FBI's Internet Crime Complaint Center (IC3) has documented consistently high volumes of cyber complaints and billions in annual financial losses, which gave carriers the claims data to identify which control gaps appear most often in loss events.

Standards bodies give insurers a technical vocabulary for those controls. The Federal Trade Commission advises businesses to read policy limits and exclusions carefully, particularly for breach response and ransomware. NIST's frameworks, the CIS Controls, and FTC guidance all inform the language underwriters use when they ask about MFA scope, backup immutability, and IR testing. Carriers do not always cite these frameworks by name on the application, but the questions map directly to them.

Pro Tip: Treat the cyber insurance questionnaire as a security gap analysis, not a compliance form. Every question you cannot answer confidently with documented evidence is a gap your IT team or MSP should close before you submit.


What security controls do carriers actually require?

Industry analysis of 2026 underwriting questionnaires confirms that MFA, EDR, immutable backups, and a tested IR plan are the baseline controls carriers expect before binding coverage. The list below reflects what most carriers weight highest, organized by priority.

Must-have controls

  • MFA on all email, admin, and remote access. Carriers want phishing-resistant MFA (FIDO2/hardware keys or Microsoft Authenticator with number matching) wherever possible. NIST SP 800-63B distinguishes between weak SMS-based OTP and stronger authenticator-app or hardware-key methods. Evidence: export your Azure AD or Entra ID Conditional Access policy showing MFA enforcement, or a screenshot of your identity provider's MFA settings with scope confirmed.
  • EDR/MDR on 100% of endpoints. Carriers ask for the percentage of devices covered and whether monitoring is 24/7 or business-hours only. Evidence: an EDR coverage report from your platform (CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or equivalent) showing device count and coverage percentage.
  • Immutable or offline backups with tested restores. Backups that ransomware can encrypt are not acceptable. Carriers want evidence of air-gapped or immutable storage and a recent restore test with a timestamp. Evidence: a backup restore log with date, file set tested, and recovery time.
  • Documented IR plan with tabletop exercise. NIST SP 800-61r2 defines the four phases of incident response (preparation, detection, containment, recovery) and recommends regular testing. Carriers want the plan document and a record of the last tabletop date. Evidence: the IR plan itself plus a one-page tabletop summary or after-action report.

Controls that reduce premiums further

Penetration testing (annual or biannual), a dedicated SIEM or SOC, and 24/7 MDR coverage with documented escalation procedures all signal a mature security posture. Carriers may offer better retentions or higher limits when these are in place. The CIS Controls framework provides a vendor-neutral mapping that aligns closely with what underwriters ask about.


What documentation do insurers ask you to provide?

Underwriters increasingly run external attack-surface scans and require screenshots or vendor reports because self-attestation without proof is often rejected at claim time. Assembling a short evidence packet before you submit speeds underwriting and reduces the chance of a denial.

Documents to attach or have ready:

  • MFA enforcement screenshots (Conditional Access policy export from Entra ID/Azure AD, or equivalent IdP settings)
  • EDR coverage report showing device count, coverage percentage, and monitoring hours
  • Backup restore test log with timestamps, file set tested, and recovery time recorded
  • Patch management cadence report or vulnerability scan with remediation dates
  • Asset inventory (hardware and software, including end-of-life systems flagged)
  • IR plan document with the last tabletop date and an after-action summary
  • Vendor/third-party security questionnaire results for critical suppliers
  • Security awareness training completion records

What to summarize vs. attach: For most applications, you summarize controls in the questionnaire fields and attach supporting documents as a separate evidence packet. Your broker will tell you which carrier requires attachments upfront and which reviews them only after a preliminary quote.

Pro Tip: Create a one-page "evidence index" listing each document, its date, and the control it supports. Give this to your broker alongside the application. It signals organizational maturity and speeds the underwriter's review significantly.


What does a cyber policy cover, and what does it exclude?

The FTC's guidance on cyber insurance advises businesses to confirm that policies include breach response, ransomware, and data-breach coverage, and to read limits and exclusions closely. Most standard cyber policies cover two broad categories.

First-party coverages (your own costs):

  • Incident response and forensics costs
  • Business interruption and lost revenue during a covered event
  • Ransomware extortion payments (often with sub-limits and co-insurance)
  • Data recovery and system restoration
  • Regulatory notification costs

Third-party coverages (claims from others):

  • Customer and partner data breach liability
  • Regulatory defense and fines
  • Media liability for content-related claims

How do underwriters assess your risk and set your premium?

Controls posture plus exposure determines your terms. Carriers look at both simultaneously, and a strong controls posture can offset a high-exposure industry profile.

  1. Industry and regulatory exposure. Healthcare organizations subject to HIPAA, retailers handling payment card data under PCI-DSS, and financial services firms face higher base rates because their data is more valuable to attackers and regulatory penalties are steeper. Securetechie's compliance audit services are designed specifically for these regulated environments.

To lower your premium quickly: enforce MFA everywhere, deploy EDR/MDR with 24/7 monitoring, show a dated backup restore test, remediate exposed internet-facing services, and consolidate your evidence into a broker-ready packet. Underwriting timelines vary, but carriers may request rapid remediation of flagged items before they will bind coverage, so addressing gaps before you apply saves time.


How to get your business insurance-ready in 30–90 days

This plan is organized by realistic time windows. Assign each step to internal IT, your MSP, or a fractional CISO.

  1. Days 7–14: Remediate exposed internet-facing services. Disable RDP exposed to the internet, patch critical CVEs on public-facing systems, and review firewall rules. Managed infrastructure services can accelerate this step for teams with limited bandwidth.
  2. Days 14–30: Run an IR tabletop exercise. Walk your team through a ransomware scenario using your incident response plan. Record the date and produce a one-page after-action summary. Owner: IT manager, MSP, or fractional CISO.

What questions will the insurer actually ask you?

The Cyber Readiness Institute's SMB guidance and 2026 underwriting analysis both highlight the same recurring questions. Here is what to expect and how to answer accurately.

  • "Is MFA enforced for all users accessing email and remote systems?" Sample answer: "Yes. MFA is enforced via Conditional Access policy in Microsoft Entra ID for all users on email, VPN, and admin portals. Policy export attached." Evidence to attach: Conditional Access policy screenshot or export.

  • "What percentage of endpoints have EDR installed and are monitored 24/7?" Sample answer: "100% of managed endpoints (47 devices) run Microsoft Defender for Endpoint with 24/7 MDR monitoring through our MSP." Evidence to attach: EDR coverage report with device count and monitoring hours.

  • "Are backups stored immutably or offline, and when was the last restore test?" Sample answer: "Backups are stored in immutable cloud storage with a separate air-gapped copy. Last restore test: [date], recovery time 2.5 hours, full file set verified." Evidence to attach: Backup restore log with timestamp.

  • "Do you have a documented IR plan, and when was it last tested?" Sample answer: "Yes. IR plan follows NIST SP 800-61r2 structure. Last tabletop exercise: [date]. After-action report attached." Evidence to attach: IR plan document and tabletop after-action summary.

  • "What is your SLA for patching critical CVEs on internet-facing systems?" Sample answer: "Critical CVEs on internet-facing systems are patched within 14 days of disclosure. Patch cadence report attached." Evidence to attach: Patch management report or vulnerability scan with remediation dates.

Red flags that lead to denials: overstating MFA coverage (e.g., claiming 100% when VPN or backup portals are excluded), missing EDR on servers or unmanaged devices, running end-of-life operating systems without a documented exception, and submitting an IR plan with no evidence of testing.


How an MSP helps you meet insurer requirements faster

An experienced MSP can reduce the time between "we need coverage" and "we are bound" by deploying controls, generating the required evidence, and acting as a technical point person with your broker. The Cyvatar 30-day readiness framework confirms that assembling a proof packet with dated screenshots and restore logs is one of the highest-leverage steps an SMB can take before applying.

MSP services that map directly to underwriting controls:

  • MFA and identity management deployment (Entra ID, Okta, Duo)
  • EDR/MDR deployment and 24/7 monitoring with documented coverage reports
  • Immutable backup configuration and scheduled restore testing with logs
  • Patch management with SLA tracking and cadence reports
  • IR plan development and facilitated tabletop exercises
  • External attack-surface scanning and remediation
  • Vendor risk questionnaire management
  • Compliance audits for HIPAA, PCI-DSS, SOC 2, and CMMC

What to request from your MSP before applying:

  • Dated screenshots of MFA enforcement settings
  • EDR coverage report with device count, coverage percentage, and monitoring hours
  • Backup restore test log with timestamps
  • Patch management cadence report
  • Asset inventory with EOL systems flagged
  • A one-page evidence index tying each document to the corresponding insurer question

Securetechie provides all of these deliverables as part of its managed cybersecurity services for SMBs in Southern California. If you are preparing for a renewal or a first-time application, a policy-readiness review with Securetechie gives you a gap assessment, a remediation plan, and a broker-ready evidence packet.

Pro Tip: Ask your MSP to date-stamp every screenshot and export. Undated evidence is frequently flagged by underwriters and can delay binding by days or weeks.


Key Takeaways

Qualifying for cyber insurance in 2026 requires four verified controls: MFA on all accounts, EDR/MDR on every endpoint, immutable backups with tested restores, and a documented IR plan with a tabletop exercise on record.

Diagram of four essential cyber insurance controls

PointDetails
MFA is the first filterEnforce MFA on email, VPN, admin portals, and remote access before submitting any application.
EDR coverage must be 100%Carriers ask for the exact percentage of endpoints covered; gaps in server or unmanaged device coverage are a common denial trigger.
Backups need proof, not promisesA dated restore test log is required evidence; immutable or air-gapped storage is the minimum standard carriers accept.
IR plan must be testedA written plan without a tabletop exercise date is treated as unverified; run one and keep the after-action report.
Securetechie accelerates readinessSecuretechie deploys these controls, generates broker-ready evidence packets, and conducts policy-readiness reviews for SMBs in Southern California.

The controls that actually move the needle for SMBs

Most SMB decision-makers approach cyber insurance the same way they approach a tax return: gather what you have, fill in the blanks, and hope for the best. That approach works until a carrier runs an external scan on your domain, finds an exposed RDP port, and either declines to quote or adds an exclusion that covers nothing you actually care about.

The honest prioritization for a business with limited IT budget is this: MFA and EDR first, always. These two controls appear in nearly every loss event analysis as the controls that were either missing or misconfigured. They are also the fastest to deploy. A competent MSP can enforce MFA across a Microsoft 365 environment in a day and confirm EDR coverage in hours. Backups and IR planning take longer to get right, but the restore test is what matters to underwriters, not the sophistication of the backup architecture.

Where SMBs consistently underinvest is in documentation. You can have every control in place and still face friction at underwriting because no one captured a dated screenshot or ran a restore test in the last six months. The evidence packet is not bureaucracy. It is the difference between a smooth bind and a two-week back-and-forth with an underwriter asking for proof you should have had ready.

If your budget forces a choice between a penetration test and fixing an exposed internet-facing service, fix the exposure. Pen tests are valuable, but carriers care more about whether known vulnerabilities are remediated than whether you paid someone to find new ones. Negotiate with your broker: if you cannot meet every control immediately, show a documented remediation timeline. Carriers will sometimes bind with conditions if you can demonstrate a credible 30-day plan.


The controls that actually move the needle for SMBs — overview diagram

Securetechie gets your business insurance-ready

For SMBs in Southern California that need coverage but are not yet meeting carrier requirements, Securetechie offers a direct path from gap to bound policy. The team deploys MFA, EDR/MDR, immutable backups, and IR planning as part of its managed cybersecurity program, then packages the evidence into a broker-ready proof packet your underwriter can act on immediately.

Securetechie

When you request a policy-readiness review, Securetechie delivers a gap assessment mapped to the current insurer checklist, a prioritized remediation plan with realistic timelines, and the dated screenshots, coverage reports, and restore logs your broker needs. For regulated businesses in healthcare, finance, or legal services, the team also handles HIPAA, SOC 2, and CMMC compliance audits that support higher policy limits and demonstrate documented controls to carriers.

Schedule a security assessment at securetechie.com and get a clear picture of where you stand before your next application or renewal.


Authoritative sources for your application preparation

These U.S.-focused resources provide the standards, technical definitions, and regulatory context that underwriters reference. Use them to verify control definitions, prepare documentation, and cite authoritative guidance when your broker or carrier asks for it.