Author: Ami DePierro | Co-Founder, 2 Dog Digital
Ami DePierro is Co-Founder of 2 Dog Digital and a former US Marine Intelligence Analyst who brings analytical precision to cybersecurity strategy for small and mid-sized businesses across the Raleigh/Triangle area. Digit is the voice. Ami is the author.
The problem is that what the insurer accepted last year is not what they will accept in 2026. Policies are tightening. Underwriters are asking harder questions. And when a claim lands on their desk, the first thing they do is check whether you actually had the controls you said you had.
Some businesses find out they do not. After the breach. That is a bad time to find out.
Cyber insurance requirements in 2026 are not what they were two years ago. Ransomware payouts pushed carriers to the edge. They responded the way every insurance company responds when losses get out of hand: they raised the bar for who gets covered and started denying claims where the application said one thing and the actual security posture said another.
The average ransomware recovery costs more than most SMBs clear in a quarter. That is not a scare tactic. That is what the FBI Cyber Division and Verizon’s 2024 Data Breach Investigations Report keep showing, year after year. Insurers read those same reports.
This post covers what underwriters are actually looking for in 2026, which gaps are getting claims denied, and what you need in place before your next renewal. The cybersecurity insurance checklist here is not aspirational. It is the minimum.
🐾 Digit’s Rule 3: The backup you never tested is not a backup. It’s a hope.
1. What Changed and Why It Matters Now
Three years ago, cyber insurance for small business looked a lot like homeowner’s insurance. Short questionnaire. Check a box that you had antivirus. Get a policy. Carriers competed on price. Coverage was broad. Nobody was kicking the tires very hard.
Then the ransomware payouts started stacking up. Colonial Pipeline. Kaseya. Hundreds of smaller businesses that never made the news but absolutely wrecked their quarter. Insurers started paying claims in the tens of millions and doing the math on how many more were coming. The market hardened.
By 2024, major carriers had added 40-plus-question security questionnaires. By 2025, several required third-party attestation. In 2026, the ones that do not require proof of controls either charge significantly more or write policies with exclusion language that effectively cancels your coverage the moment you need it.
The insurers did not change the rules to be difficult. They changed them because the old rules were not working. Small businesses are now in the middle of that correction. If your broker is not walking you through a cybersecurity insurance checklist at every renewal, find a broker who does.
2. What Cyber Insurance Actually Requires in 2026
The controls list varies by carrier and coverage tier, but the core set has converged. Here is what underwriters expect to see when they write a cyber liability insurance policy in 2026.
Multi-Factor Authentication (MFA)
MFA is no longer a differentiator. It is the floor. You are not getting credit for having it. You are losing coverage for not having it.
Endpoint Detection and Response (EDR)
Basic antivirus does not qualify. Carriers want endpoint detection and response software, meaning tools that monitor endpoint behavior in real time, flag anomalies, and can isolate a compromised device before it spreads. The distinction between antivirus and EDR is not technical pedantry. It is the difference between catching a breach at 2 a.m. and finding out about it from a customer on Monday morning.
Incident Response Plan
Insurers want to see a documented incident response plan before they write the policy. Not because they expect you to follow it perfectly. Because a business that has thought through what to do when something goes wrong recovers faster and costs them less. The plan does not have to be 80 pages. It has to be real, named, and tested. ‘We’ll figure it out when it happens’ is not a plan. It is a timeline for a bad week.
Privileged Access Management and Access Controls
Security Awareness Training
Carriers are asking specifically whether employees receive regular security awareness training, not annual checkbox training. Human error is still the leading cause of data breach. Insurers know this. Your premium reflects it. A phishing simulation that runs four times a year costs less than a breach. By a significant margin.
Backup and Recovery
Tested. Offsite or cloud-isolated. Separate from the primary network. If your backup lives on the same system the ransomware just encrypted, you do not have a backup. You have a very expensive lesson.
3. The Controls That Get Claims Denied
Cyber insurance claim denial is more common than most brokers lead clients to believe. The specific language varies by policy. The pattern does not. A business says it has controls it does not actually have, something happens, and the carrier denies the claim under material misrepresentation.
The four most common triggers for cyber insurance claim denial in 2026:
- MFA was not enabled on the accounts or systems specified in the application. You checked the box. You had MFA on email. You did not have it on your remote desktop protocol. The attacker used RDP. The carrier checks.
- EDR was installed but not actively monitored. Software running without anyone reviewing alerts is not security. It is the appearance of security. There is a difference, and underwriters know what to look for.
- The incident response plan existed on paper and had never been tested. Carriers are starting to require tabletop exercise documentation. ‘We have a plan’ and ‘we tested the plan’ are two different statements.
- Backup and recovery had not been tested within the timeframe stated on the application. If your policy says monthly restore tests and your logs show the last successful test was fourteen months ago, that is not a potential problem. That is an actual, claim-denying problem.
This is not insurers looking for an excuse not to pay. It is insurers applying the terms of the contract. The way to avoid it is to actually have the controls you say you have. A cyber risk assessment before renewal catches these gaps. That is the point of doing one.
4. What to Do Before Your Renewal Date
- Run a gap assessment 90 days before renewal. Not after. Before. You need time to fix what you find. A competent MSP can run this in a few days. What you learn either improves your coverage or prevents a denial.
- Document everything. MFA deployment records. EDR monitoring logs. Training completion reports. Backup test results with dates. Insurers are asking for evidence, not promises. Build the file now.
- Review your questionnaire answers against your actual environment. Every answer on a cyber insurance application is a representation. If your environment changed since last renewal and your answers did not, that gap is yours to own. Walk through it line by line.
- Confirm your coverage limits match your actual risk. The coverage that made sense two years ago may not reflect your current data exposure, revenue, or vendor dependencies. Your broker should be running this conversation with you. If they are not, ask.
- Get your incident response plan in writing and test it. A tabletop exercise takes half a day. It does not require an actual crisis to run. Running one before a breach is how you find out your plan references three steps that assume a system you no longer have. Fix it before it matters.
5. Conclusion: Get Covered Before You Need to Be
The short version:
- MFA on every system that matters, not just email
- EDR actively monitored, not just installed
- Incident response plan tested in the last 12 months
- Backup and recovery tested and logged, not assumed
- Security awareness training that actually runs, not a once-a-year video
If any of this sounds like your current setup, 2 Dog Digital does a no-charge cyber risk assessment. You will learn something either way. The time to do it is before the renewal paperwork lands on your desk, not the morning after something goes wrong.
Ready to find out where you actually stand? Contact 2 Dog Digital for a free cybersecurity assessment. We will tell you what you have, what you are missing, and what it takes to get there.
2 Dog Digital — Raleigh, NC | 2dogdigital.com
Frequently Asked Questions
Q: What do cyber insurance companies require in 2026?
Most carriers require MFA on all privileged and remote access accounts, endpoint detection and response on endpoints, a documented and tested incident response plan, proof of security awareness training, and verified backup and recovery. Some now require third-party attestation. The specifics vary by carrier and coverage tier, but these controls appear consistently across the market.
Q: Why do cyber insurance claims get denied?
The most common reason is material misrepresentation. The business stated it had security controls that were not actually in place or not functioning as described. MFA listed as active but not deployed on critical systems is the most frequent trigger. Documentation matters as much as the controls themselves.
Q: What cybersecurity controls are required for cyber insurance for small businesses?
Small businesses typically need MFA, endpoint detection and response software, an incident response plan, access controls that limit who can reach sensitive data, regular security awareness training, and tested backups stored separately from the primary network. Carriers scale requirements to coverage limits, but this list appears consistently.
Q: How do I prepare for cyber insurance renewal in 2026?
Start 90 days early. Run a gap assessment against your policy application answers. Document MFA deployment, EDR monitoring logs, training completions, and backup test records. If your environment changed since last renewal, update your answers before submission. Mismatches between your application and your actual environment are what get claims denied.
Q: Are Raleigh-area small businesses facing stricter cyber insurance requirements than before?
Yes, though it is not unique to the Triangle. The market hardening is national. Businesses working with a local MSP have an advantage: a pre-renewal assessment from someone who knows your environment is faster and more accurate than answering a cold questionnaire. 2 Dog Digital does that assessment at no charge.