Compyl

Cyber Insurance Readiness: What Underwriters Require in 2026

August 11, 2026
Playbook · Cyber Insurance

Cyber Insurance Readiness: What Underwriters Require in 2026

By Compyl ResearchLast updated: August 11, 202612 min read

Cyber insurance readiness means proving, with dated evidence, that the controls you attest to on your application are actually in place. In 2026 underwriters require MFA everywhere, EDR, tested immutable backups, privileged access management, patching discipline, and a rehearsed incident response plan. Misstate any of them and your insurer can rescind the policy after a claim.

Key takeaways
  • Cyber rates fell 4% globally in Q2 2026, the twelfth consecutive quarterly decline, and primary cyber pricing is roughly 42% below 2022 levels — but capacity is priced on demonstrable control quality, not on promises.
  • US cyber premiums reached $7.5 billion in 2025 while the loss ratio rose 4.3 points to 53.0%, its first move above 50% since the ransomware surge. Softening pricing and rising losses mean underwriting scrutiny is not relaxing.
  • Application answers function as warranties. Travelers rescinded a $1 million CyberRisk policy seven weeks after inception when it found the insured’s MFA covered only its firewall.
  • Answer control questions with coverage percentages and a documented exception register, not yes/no. A defensible 98% beats an unverified 100%.
  • The duty to disclose does not end at binding — applications require you to notify the insurer of material changes, so attested controls need continuous monitoring, not annual review.

What Does the Cyber Insurance Market Look Like in 2026?

Cyber insurance buyers are in their strongest negotiating position since the ransomware crisis of 2020-2021. According to Marsh’s Global Insurance Market Index for the second quarter of 2026, cyber rates declined 4% globally, the twelfth consecutive quarter of declines, supported by stable capacity and high insurer competition. Global composite commercial rates fell 6% in the same quarter.

The cumulative effect is dramatic. Marsh reports that primary cyber pricing is down approximately 42% from 2022 levels. Buyers who cut limits during the hard market can often buy back higher limits today for similar or lower premium.

Underneath the soft pricing, loss trends are moving the other way. AM Best’s 2026 review of the US market, reported on June 26, 2026, found US cyber premiums edged up to $7.5 billion in 2025 from $7.1 billion, while the overall loss ratio rose 4.3 percentage points to 53.0% — a second consecutive annual increase and the first time above 50% since the pandemic-era ransomware surge. Surplus lines carriers now write close to two-thirds of US cyber premium, with an incurred loss ratio of 55.9 versus 50.2 for admitted carriers.

AM Best senior industry analyst Christopher Graham framed the difference plainly: the 2020-2021 loss spike triggered an immediate price increase, but “this time the loss ratio increase is occurring as pricing is still declining and even accelerating the decline.” Fitch Ratings titled its April 15, 2026 sector review U.S. Cyber Insurance Growth Raises Underwriting Risk.

The translation for a GRC leader: price competition is real but unevenly distributed. Underwriters differentiate aggressively on control quality, and the discount goes to organizations that can prove their posture rather than describe it — which makes evidence a line item in your cybersecurity budget.

The 2026 market at a glance
  • Pricing: global cyber rates down 4% in Q2 2026, twelfth consecutive quarterly decline (Marsh GIMI).
  • Cumulative softening: primary cyber pricing roughly 42% below 2022 levels (Marsh).
  • US premium: $7.5 billion in 2025, up from $7.1 billion in 2024 (AM Best).
  • Loss ratio: 53.0% in 2025, up 4.3 points and above 50% for the first time since the ransomware surge (AM Best).
  • Implication: soft pricing plus rising losses means underwriting scrutiny of controls stays tight even as premiums fall.

What Controls Do Cyber Underwriters Require in 2026?

Carrier questionnaires converge on roughly a dozen controls. Marsh publishes the list as 12 key cyber hygiene controls considered best practice by cybersecurity experts and insurance carriers alike, and notes they are now tied directly to insurability.

How binding are they? The Multi-Factor Authentication Attestation Travelers required from one applicant in 2022 said it outright: “The controls described above and listed below are the minimum controls that must be in place in order to be eligible for a Cyber policy.” That language is in the public record of Travelers Property Casualty Company of America v. International Control Services, Inc., discussed below. Controls are an eligibility gate, not a scoring exercise.

Control What the underwriter asks Why it matters to them
Multi-factor authentication Is MFA required for email, all remote access, and all internal and remote admin access to directory services, backups, network infrastructure, and endpoints/servers? Blocks the credential path to ransomware. Partial MFA is the most common reason an attestation turns out to be false.
Endpoint detection and response What EDR/MDR product is deployed, on what percentage of endpoints and servers, and who monitors alerts 24/7? Decides whether an intrusion is contained in hours or found after encryption. Coverage percentage matters more than product name.
Backups: immutable, offline, tested Are backups immutable or offline, segregated from production credentials, and when did you last complete a full restore test? Drives business interruption severity and whether a ransom payment is necessary at all.
Privileged access management Are domain admin and service accounts vaulted, rotated, and separated from daily-use accounts? Privilege escalation is the step between a foothold and an enterprise-wide event.
Vulnerability and patch management What are your patching SLAs for critical and internet-facing vulnerabilities, and what is your compliance rate? Edge-device and known-CVE exploitation is a leading initial access vector.
Email security Do you run advanced filtering, external-sender banners, and SPF/DKIM/DMARC enforcement? Email remains the main channel for both ransomware delivery and funds transfer fraud.
Network segmentation Are critical systems, OT, and backup networks segmented from the general user network? Segmentation limits blast radius and therefore claim severity.
End-of-life technology Do you run unsupported operating systems or applications, and what compensating controls apply? Unsupported systems are uninsurable in some appetites and sub-limited in others.
Security awareness and phishing testing How often do you train staff and simulate phishing, and what are your click and report rates? Correlates with social engineering and wire fraud losses, which carriers sub-limit heavily.
Incident response plan Do you have a documented IR plan, when was it last exercised, and who can authorize payment? Response speed is the main lever on cost once an incident starts.
Logging and monitoring What is centrally logged, how long is it retained, and is there 24/7 alert triage? Without logs, forensics costs rise and breach scope cannot be narrowed, inflating notification costs.
Third-party and vendor risk How do you assess critical vendors, and which dependencies would halt operations? Dependent business interruption and supply chain aggregation are the fastest-growing exposures.

Two of these cross into business planning. Backup and restore answers are validated against your recovery objectives, so they belong in your business continuity plan. And MFA and EDR coverage percentages should come from the same source of truth as your security posture assessment, so underwriters and your board see the same numbers.

How Does the Application and Attestation Process Actually Work?

Most placements follow the same sequence, and each step creates a document that can be read back to you during a claim.

  1. Broker intake and pre-underwriting. Brokers run diagnostics before going to market — Aon’s Cyber Quotient Evaluation (CyQu) and Marsh’s Cybersecurity Self-Assessment are the most widely used — producing a control profile that shapes which carriers see your submission.
  2. Carrier application. A named officer answers structured questions on revenue, record counts, industry, prior incidents, and controls, and identifies the individual responsible for network and information security by name.
  3. Supplemental attestations. Separately signed documents covering MFA, ransomware preparedness, and sometimes backups or funds transfer controls, often dated before the main application and treated as standalone representations.
  4. Clarification calls. Any control answered with a qualifier gets pinned down to dates and percentages.
  5. Quote, terms, and binding. Sub-limits, retentions, waiting periods, extortion coinsurance, and control-related endorsements are set here.

The legal weight sits in the signature block. In the Travelers application at issue in the case below, the text above the CEO’s signature read that the authorized representative represents “that to the best of his or her knowledge and belief, and after reasonable inquiry, the statements provided in response to this Application are true and complete” and “may be relied upon by Travelers as the basis for providing insurance,” adding that “the Applicant will notify Travelers of any material changes to the information provided.”

Three phrases do most of the damage in disputes. After reasonable inquiry means the signer cannot rely on assumption; someone has to check. May be relied upon as the basis for providing insurance establishes materiality, the test for rescission in most states. Notify of any material changes creates a duty that survives binding — if MFA is disabled for a legacy application in month four, the obligation is live.

Some policies go further and convert controls into conditions of coverage. The policy in Columbia Casualty Company v. Cottage Health System contained a “Minimum Required Practices” condition under which the insured warranted, “as a condition precedent to coverage under this Policy,” that it would “maintain all risk controls identified in the Insured’s Application,” backed by an exclusion for “any failure of an Insured to continuously implement” those controls.

What Happens If Your Application Is Wrong? Two Real Cases

Coverage disputes over application accuracy are not hypothetical, and the filings are public. Two cases define the risk.

Travelers v. International Control Services (C.D. Ill., 2022)

International Control Services (ICS), an Illinois manufacturer, applied for a Travelers CyberRisk Tech policy with an application dated March 31, 2022, signed by its CEO, plus a Multi-Factor Authentication Attestation dated March 10, 2022. On the attestation ICS answered “Yes” to every affirmation: MFA for all employees accessing email through a website or cloud service; MFA for all remote access provided to employees, contractors, and third-party providers; and MFA for all internal and remote admin access to directory services, network backup environments, network infrastructure, and endpoints and servers.

Travelers issued the policy effective April 4, 2022, with a $1 million aggregate limit. ICS had disclosed a December 2020 ransomware event and represented that it had since made improvements, including changing the compromised administrator credentials.

On or about May 25, 2022 — seven weeks after inception — ICS was hit again, by ZEON ransomware on a server. Investigating the claim, Travelers alleged it “first learned that at the time ICS completed and submitted the Application Documents, (1) MFA was not being utilized to protect the Server and (2) ICS only utilized MFA to protect its firewall, and did not use MFA to protect any other digital assets.”

Travelers filed a complaint for rescission and declaratory judgment on July 6, 2022, alleging the misstatements “materially affected the acceptance of the risk” and that it “would not have issued the Policy” had it known, and tendered back the premium. The parties filed a stipulation for rescission, and on August 30, 2022 Judge Colin Stirling Bruce granted the motion and dismissed the case with prejudice on the public docket, No. 2:22-cv-02145. Net effect: a company already hit once by ransomware ended up with a returned premium instead of a $1 million limit.

Columbia Casualty v. Cottage Health System (C.D. Cal., 2015-2016)

Columbia Casualty (a CNA company) funded a $4.125 million class action settlement for Cottage Health after a data exposure, then sued for reimbursement under the policy’s “Failure to Follow Minimum Required Practices” exclusion and matching condition precedent. The first federal complaint (No. 2:15-cv-03432, filed May 7, 2015) was dismissed that July because the policy required alternative dispute resolution first; Columbia refiled in 2016.

Cottage Health matters for its mechanism more than its outcome. The insurer did not argue the loss fell outside the insuring agreement; it argued the insured had stopped doing what its application said it did. That theory needs no proof of intent to deceive — only a gap between the attested control set and operating reality.

Three ways a control answer can cost you coverage
  • Rescission: the policy is treated as void from inception for material misrepresentation; premium is returned, coverage is not.
  • Exclusion: a “failure to follow minimum required practices” clause bars loss connected to a lapsed control.
  • Condition precedent / warranty: maintaining the attested controls is a condition of coverage attaching at all.

How Do You Build the Evidence File Underwriters Want?

The goal is not to pass the questionnaire. It is to reconstruct, years later, what was true on the day you signed and how you knew. Treat renewal like an audit with a 90-day runway.

  1. Day 90 — fix scope first. Every control answer is a fraction, and the denominator is your asset inventory. Reconcile identity providers, endpoint agents, servers, cloud accounts, and OT before counting anything. An MFA figure computed against a stale directory is the classic source of an inadvertently false attestation.
  2. Day 75 — convert every control to a coverage percentage. Replace “Yes” with “MFA enforced on 100% of remote access, 100% of cloud email, 98% of privileged accounts; two service accounts excepted with compensating controls.” Underwriters trust a documented 98% more than an undocumented 100%.
  3. Day 60 — produce dated artifacts, not assertions. Conditional access exports, EDR deployment reports by OS, backup and restore-test logs, patch SLA compliance reports, PAM vault inventories, and the IR plan with its last tabletop date. Every artifact carries a generation date and a system of record.
  4. Day 45 — write the exception register. Every deviation, its business reason, compensating control, owner, and remediation date. Disclosing an exception rarely kills a quote; discovering one after a claim can kill the policy.
  5. Day 30 — run the reasonable-inquiry review. Walk the questionnaire line by line with the signer and the security owner, recording who verified each answer against what evidence. This memo turns “we thought so” into “we checked.”
  6. Day 15 — snapshot and freeze. Archive the application, every supplemental attestation, and the evidence pack as a point-in-time record a claims team could retrieve in a week.
  7. Day 0 onward — instrument the continuing duty. Alert on changes that would falsify an answer: MFA exemptions created, EDR agents removed, backup jobs failing, an acquired subsidiary joining the domain.

Organizations already running continuous control monitoring have a structural advantage: evidence exists as a byproduct of operations rather than a fire drill, and coverage percentages are defensible because they are measured, not estimated.

What Should You Ask Your Broker Before You Bind?

Most buyers spend their energy on premium and almost none on the terms that decide whether a claim pays. Push your broker on these.

  • Is my limit modeled or inherited? Ask for a loss scenario, not a peer benchmark. Marsh warns that 67% of its UK clients buy cyber limits insufficient for a 1-in-10-year event. Pair the answer with your own cyber risk quantification so the limit is defensible to the board.
  • How severe is the tail? Marsh’s Global Cyber Claims Report found the 75th percentile business interruption loss is 63.53 times the median. Ask what a bad-tail scenario does to your tower, not an average one.
  • What is my BI waiting period, and does dependent BI apply? An eight- or twelve-hour waiting period and the presence of contingent/dependent BI often matter more than the headline limit.
  • Where are the sub-limits and coinsurance? Extortion, funds transfer fraud, social engineering, betterment, and regulatory fines are commonly sub-limited well below the aggregate.
  • Is any control a condition precedent or warranty? Ask for the exact endorsement language, and what happens if that control lapses mid-term through no fault of yours.
  • What happens if I self-report a control gap mid-term? Get the process in writing before you need it.
  • Who is on the incident response panel? Confirm counsel, forensics, and negotiators in advance; panel restrictions surface at the worst moment.
  • What is the retroactive date? Switching carriers can quietly reset prior-acts coverage.
  • Who advocates for me on claim? Ask how many cyber claims the broker’s team handled last year.

Bring severity data into that conversation. Coalition’s 2026 Cyber Claims Report, published March 5, 2026 from more than 100,000 policyholders, found initial ransom demands jumped 47% year over year to more than $1 million, that attacks combining data exfiltration with encryption made up 70% of 2025 ransomware claims and cost twice as much as encryption-only events, and that a record 86% of affected policyholders refused to pay. IBM’s Cost of a Data Breach Report 2026 put the global average breach cost at $4.99 million, a 12% increase and a record high.

How Does Your GRC Posture Affect What You Pay?

Be skeptical of anyone promising a specific percentage discount for a certification or a tool. The evidence supports something narrower: underwriting outcomes are increasingly driven by exposure quality and risk management. Marsh’s Q2 2026 index makes the point directly — risk differentiation continued to increase, and clients with well-performing risks achieved the strongest renewal outcomes.

Depth of implementation matters more than presence. Marsh’s analysis pairing its claims dataset with Cybersecurity Self-Assessment responses, Using data to prioritize cybersecurity investments, found automated hardening techniques had the greatest ability of any control studied to reduce the likelihood of a successful attack, and that MFA “only has a strong positive impact when implemented fully.” A partially deployed control is both a weaker defense and a weaker underwriting story.

That is where GRC tooling earns its place in an insurance conversation. Three effects are real and defensible:

  • Credibility. Answers backed by dated system exports survive scrutiny; answers backed by memory invite conservative pricing or a control-related endorsement.
  • Speed. Complete submissions with supplementals and evidence attached reach more markets before capacity is committed; incomplete ones get quoted late and priced defensively.
  • Continuity. Monitoring catches the drift that turns an accurate attestation into a stale one, protecting coverage you already bought.

Frameworks help for the same reason. A SOC 2 Type 2 report or ISO/IEC 27001 certificate triggers no automatic rate credit, but it gives underwriters independent evidence that controls operated over a period rather than on a single day — and the same maturity work behind improving your security posture produces most of the artifacts an underwriting file needs. Expect better terms rather than a guaranteed discount: broader coverage, lower retentions, fewer control-related conditions, and access to carriers who decline weaker risks outright.

How Do You Stay Insurance-Ready Between Renewals?

Readiness decays. The attestation you signed in March describes a world that starts changing in April, and the duty to report material changes runs for the whole policy period.

Four practices keep the file current. Treat every attested control as a monitored control with a named owner and an alert when coverage drops below the attested threshold. Put corporate events on the insurance checklist — an acquisition, a new subsidiary domain, or an ERP cutover can falsify an application answer within weeks. Exercise the incident response plan annually with the people who would make the decisions, and keep the attendance record. Review limits annually against revenue, record counts, and dependency changes.

The threat environment justifies the discipline. The FBI’s Internet Crime Report for 2025 recorded 1,008,597 complaints and $20.877 billion in reported losses, a 26% increase over 2024, including more than 3,600 ransomware complaints and 63 newly identified ransomware variants. Marsh’s claims data shows extortion severity rising even as extortion claim volumes fall, as attackers shift from encryption toward exfiltration and leak threats.

Year-round readiness checklist
  • Monitor every attested control continuously, with an owner and a coverage threshold.
  • Report material changes to your broker as they happen, not at renewal.
  • Exercise the IR plan annually and keep the dated record.
  • Re-model limits each year against revenue, data volume, and third-party dependencies.
  • Archive each year’s application, attestations, and evidence pack as an immutable point-in-time record.

Cyber insurance in 2026 rewards organizations that can prove things. Pricing is favorable and capacity is available, but every dollar of that advantage is conditional on the accuracy of what you attest. The best outcomes go to companies for whom the application is a report on a system they already run, not a questionnaire filled out once a year.

Frequently asked questions

Can a cyber insurer really void my policy after a breach?
Yes. If an application answer was materially wrong, insurers can seek rescission, which treats the policy as void from inception and returns the premium instead of paying the claim. Travelers pursued exactly that in 2022 against an Illinois manufacturer whose MFA attestation did not match its actual deployment.
Is multi-factor authentication mandatory for cyber insurance?
In practice, yes. Carriers require MFA on cloud email, all remote access, and internal and remote administrative access to directory services, backups, network infrastructure, and endpoints. Attestation forms describe these as the minimum controls needed to be eligible for a cyber policy, not as preferences.
Are cyber insurance rates going up or down in 2026?
Down, but more slowly. Marsh’s Global Insurance Market Index recorded a 4% global decline in cyber rates in the second quarter of 2026, the twelfth consecutive quarterly decrease. Marsh also reports primary cyber pricing is roughly 42% below 2022 levels, though loss ratios are now rising.
What evidence should I gather before a cyber insurance renewal?
Collect dated exports rather than assertions: conditional access and MFA policy reports, EDR deployment coverage by device type, backup and restore-test logs, patch SLA compliance rates, privileged account inventories, your incident response plan with its last exercise date, and a written exception register.
Does SOC 2 or ISO 27001 lower my cyber insurance premium?
Not automatically. Neither certification triggers a fixed rate credit, but both give underwriters independent evidence that controls operated over time. That usually shows up as better terms, lower retentions, and fewer control-related conditions rather than as a headline discount.
What happens if a control lapses in the middle of the policy period?
Applications typically require you to notify the insurer of material changes to the information provided. Some policies also make named controls a condition precedent to coverage. Report the lapse to your broker promptly and get the carrier’s position in writing before a claim arises.

Make Cyber Insurance Readiness a Byproduct of Your GRC Program

Compyl continuously monitors the exact controls underwriters ask about — MFA coverage, EDR deployment, backup testing, privileged access, and patching — and keeps dated evidence ready for every application, attestation, and renewal. When your insurer asks what was true on the day you signed, you can prove it.

Request a demo →

About this guide. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


Monitoring thousands of environments daily
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies