954-539-5678Free audit
Menu

Cybersecurity · Cyber insurance

What cyber insurers expect from small businesses in 2026

The controls that decide coverage, why your application answers must be accurate, and a checklist to get ready before renewal.

MFA, EDR and tested backups first

Answers on applications must be true

Keep evidence for every control

Get your free Technology Health Assessment

30 minutes of data collection, your report the next day, yours to keep with no obligation. Or pick a time now. Or call 954-539-5678.

The short answer

As of 2026, most cyber insurers expect a small business to have multi-factor authentication (MFA) on email, remote access and admin accounts; endpoint detection and response (EDR) on computers and servers; backups that are protected from tampering and have been test-restored; timely patching; and regular security awareness training. Many also ask about email filtering, an incident response plan and how you handle wire transfers. Gaps in the first three can mean a decline, higher premiums or lower limits.

Every carrier’s application is different. Treat this as general information and confirm the exact requirements with your broker or insurer.

Why the questions got harder

A few years ago, a cyber policy came with a short questionnaire. Today the application reads like a security audit. Marsh, one of the largest insurance brokers, says insurers now ask more questions than ever about an applicant’s controls, and that “the adoption of certain controls has now become a minimum requirement of insurers.”

The reason is claims data. Coalition’s 2026 Cyber Claims Report, covering 2025, found that business email compromise and funds transfer fraud made up 58% of the incidents it observed, and that ransomware was the most expensive claim type, averaging $269,000. Insurers have learned which controls reduce those losses, and they now price and underwrite around them.

Insurers also check. Many run external scans of your internet-facing systems and ask for evidence, not just a checked box.

The controls insurers commonly ask about

Marsh’s list of twelve key controls is a useful map, because it lines up with most carrier applications. Here they are in plain English, grouped by how often they decide whether you get coverage.

Usually make or break

  • MFA on email, remote access (VPN, remote desktop), cloud apps and every admin or privileged account. “Email only” is a common gap.
  • EDR on every workstation and server. EDR watches behavior and can isolate a device; traditional antivirus alone often isn’t enough for underwriters.
  • Secure, tested backups. Encrypted copies kept separate from your network or behind their own MFA, with recent restore tests on record.

Commonly asked, often affect price and limits

  • Email filtering and protection against spoofed and look-alike domains.
  • Patching on a schedule, with a target time for critical fixes.
  • Control of admin accounts: few people, separate admin logins, MFA on all of them.
  • Security awareness training and simulated phishing.
  • A written incident response plan.
  • No remote desktop exposed directly to the internet.
  • Logging and monitoring of key systems.
  • A plan for unsupported (end-of-life) systems.
  • Vendor and supply-chain risk management.

Payment and wire controls

Because funds transfer fraud is so common, many applications ask whether you confirm new or changed payment instructions by phone to a known number, and whether two people approve large transfers. These are cheap to put in place and worth doing even without insurance.

Common application questions, translated

Wording varies by carrier, but these questions show up on most small business applications. Here is what they usually mean and what to have ready.

  • “Do you require MFA for all remote access to your network?” Every way in from outside: VPN, remote desktop tools, remote support software, and cloud email. Evidence: an MFA enrollment report showing every user, including owners.
  • “Is MFA required for all privileged or administrative accounts?” Separate admin logins for IT tasks, each protected by MFA. Shared admin passwords are a red flag.
  • “Do you use an EDR solution? What percentage of endpoints are covered?” Count every laptop, desktop and server, then compare to the EDR console. Aim for 100%, and know why any device is missing.
  • “Are backups encrypted, separated from the network and tested?” Describe where copies live, who can delete them and the date of your last restore test.
  • “How quickly are critical patches applied?” Have a target, such as within days for critical fixes, and a report showing you meet it.
  • “Do employees receive security awareness training?” Dates, attendance and phishing-test results.
  • “Do you verify changes to vendor payment instructions?” A written procedure, and proof staff know it.
  • “Do you have an incident response plan?” A document with names, phone numbers and the insurer’s breach hotline.

If you can’t produce the evidence in a day, treat that as a gap to fix before renewal.

The answer you give has to be true

The application is part of the policy. If an answer is wrong, the insurer may refuse a claim or rescind the policy. In a 2022 case, Travelers asked a federal court to void a cyber policy after a ransomware attack, saying the insured had stated MFA protected its systems when it covered only the firewall. According to Lockton, the case ended with a judgment rescinding the policy.

Practical rules for filling out the form:

  • Answer for the whole company, not the parts you hope are true. If one partner or one server is an exception, say so.
  • Ask your IT provider to confirm each technical answer in writing.
  • Keep evidence: MFA enrollment reports, EDR coverage lists, backup logs and restore-test notes.
  • If a control is in progress, ask your broker how to describe it and when you need it finished.

Want to know how your answers would look today? Our free Technology Health Assessment takes about 30 minutes of data collection. The next day you get a plain-language report on your cybersecurity, backups and continuity, rated controlled, needs attention, significant exposure or unknown, with next steps in order. No obligation. Request your assessment.

A 2026 readiness checklist

  1. List every login that matters: email, remote access, cloud apps, banking, payroll, admin accounts. Confirm MFA on each one.
  2. Check EDR coverage: compare the EDR console’s device list to your actual computers and servers. Every gap is a question you may answer wrong.
  3. Separate your backups: make sure at least one copy can’t be deleted or encrypted by a compromised admin account.
  4. Run a restore test and write down what you restored, how long it took and who did it.
  5. Set a patch schedule and track it. Know your oldest unpatched system.
  6. Turn off exposed remote desktop and use a secure remote access method with MFA.
  7. Train staff at least yearly and run a phishing simulation.
  8. Write a one-page incident plan: who calls the insurer’s hotline, who calls IT, who decides on customer notice with counsel.
  9. Put the wire rule in writing: payment changes are confirmed by phone to a known number.
  10. Keep a folder of evidence for renewal time.

What it costs to meet the requirements

We won’t quote numbers here, because they vary widely. The cost drivers are predictable: number of users and devices, whether you already have Microsoft 365 or Google Workspace licenses that include security features, how many servers and locations you run, how much data you back up, and whether someone is watching alerts. Many small businesses find the biggest cost is not software but the time to set things up properly and keep them running.

Timing matters too. Start three to four months before renewal. That leaves room to roll out MFA or EDR, run a restore test and collect evidence without rushing, and it gives your broker time to shop the application if your controls have improved since last year.

Compare that with the alternative. A declined application, a sublimit on ransomware, or a disputed claim usually costs far more than closing the gaps.

How JLB USA helps

JLB USA provides cybersecurity and managed IT for businesses with roughly 25 to 100 employees. That includes MFA, access reviews, same-day removal of people who leave, endpoint protection, updates, encryption, email security, monitored backups with tested restores and a written recovery plan. We also help you work through cyber-insurance questionnaires, so the technical answers match what is actually in place.

We are not an insurance broker and don’t give legal or coverage advice. Your broker and insurer decide what a policy requires. Our job is to help you meet it and prove it. If you’re in Atlanta, see our Atlanta cybersecurity services; everywhere else we work remotely.

Book it now

Pick a time for your 30 minutes

Choose a slot that suits you. We’ll confirm by email, collect the data with you on the call, and send your report the next day. It’s free, and the report is yours to keep with no obligation.

Prefer to talk first? Call 954-539-5678, or send the form and we’ll contact you.

Questions we hear

What are the most common cyber insurance requirements in 2026?

MFA on email, remote access and admin accounts, endpoint detection and response on all computers and servers, and protected backups with recent restore tests. Patching, email filtering, staff training and an incident response plan are also commonly asked about. Confirm specifics with your broker or insurer.

Can an insurer deny a claim if our application was wrong?

It can happen. Applications are typically part of the policy, and inaccurate answers can lead to disputes or rescission. In one 2022 case a court rescinded a cyber policy after MFA turned out to cover far less than the application stated. Ask counsel or your broker about your policy.

Is antivirus enough for cyber insurance?

Often not. Many insurers ask specifically about endpoint detection and response, which monitors behavior and can isolate an infected device, rather than signature-based antivirus alone.

Do insurers verify our security controls?

Many run external scans of internet-facing systems and may ask for evidence such as MFA reports, EDR coverage lists and backup test records, especially at renewal or after a claim.

Can JLB USA fill out our cyber insurance application?

We help you answer the technical questions accurately and gather evidence. You, your broker and your insurer remain responsible for the application and coverage decisions.

Related services

Want to know where your business stands?

Pick a time for my free assessmentCall 954-539-5678