July 17, 2026 · updated 2026-07-27 · requirements · pillar
The 7 controls every cyber insurance application asks about in 2026
The short answer
In 2026, cyber insurance applications consistently require seven controls: enforced MFA on email, remote access, and admin accounts; endpoint detection and response (EDR); tested, offline-capable backups; timely patching with no unsupported systems; email security protections; documented security awareness training; and a written, tested incident response plan, each backed by evidence, because applications end with a signed attestation.
Surable Security Team
20 years in IT and information security
A cyber insurance application in 2026 is a security audit with a signature line. Carriers stopped taking "we're careful" for an answer several renewal cycles ago. Now they ask for specific controls, ask whether they're documented, and have you attest in writing that your answers are accurate. Answer wrong and the best case is a premium surcharge. The worst case is a denied claim months later, when it matters most.
Here are the seven controls that show up, in some form, on virtually every small-business cyber application. For each one: what carriers mean by it, and what evidence you should have in hand before you sign.
1. MFA on email, remote access, and admin accounts
The first page of nearly every application. Carriers ask about three places specifically: business email, remote access (VPN, remote desktop, remote-support tools), and administrator accounts. "Enabled for most people" fails the question. Underwriters ask whether it's enforced, because attackers find the one exception.
Evidence to have: your MFA enforcement policy, plus a screenshot or export from Microsoft 365 / Google Workspace showing enforcement status. (CIS v8.1 IG1, safeguards 6.3–6.5.)
2. Endpoint detection and response (EDR)
Traditional antivirus checks files against known signatures. EDR watches for attacker behavior, the hands-on-keyboard activity that comes before ransomware. Many carriers now ask for it by name, and some list acceptable products. Protection that nobody manages or watches generally doesn't support a "yes."
Evidence to have: the product name, what it covers (every workstation and server), and who sees alerts.
3. Backups that are tested and survivable
Every application asks about backups. The better questionnaires ask three follow-ups: are they automatic, is there an offline or immutable copy ransomware can't reach, and have you actually tested a restore? That last one matters more than most owners expect. Refusing to pay a ransom has become the norm (a record 86% of victims refused in Coalition's 2026 claims analysis), and working, tested backups are what make refusing a real option.
Evidence to have: your backup and recovery policy, and a dated note from your last restore test.
4. Patching, with no end-of-life systems
The 2026 Verizon DBIR puts vulnerability exploitation at the top of initial-access vectors. So applications ask how quickly you patch and whether anything in your environment no longer receives security updates: Windows Server 2012, old firewalls, abandoned line-of-business software. An unsupported system that can be reached from the internet is one of the fastest routes to a declination, or to an exclusion written specifically around it.
Evidence to have: a patch-management policy with real cadences, and an asset list showing support status.
5. Email security beyond the defaults
Business email compromise and funds-transfer fraud drive 58% of incidents in Coalition's 2026 claims data. That's more than ransomware. Carriers respond by asking what sits in front of your inbox: advanced filtering, anti-phishing and impersonation protection, and increasingly whether SPF, DKIM, and DMARC are configured on your domain.
Evidence to have: your email security configuration summary, plus the control that pairs with it: a written funds-transfer verification procedure requiring phone confirmation of any bank-detail change. It's free, and it prevents the single most common loss type outright.
6. Documented security awareness training
Applications don't ask whether your people are careful. They ask whether training is documented and recurring, and sometimes whether you run phishing simulations. The attendance log is the answer; "we remind people to be careful" is a "no" in underwriting terms.
Evidence to have: your training policy, this year's attendance records, and the materials you use.
7. A written, tested incident response plan
The requirement that fails the most applications, because it's pure documentation and nobody owns it. Carriers ask two things. Is the plan written, with named roles, current phone numbers, isolation steps, and carrier and counsel contacts? And has it been tested? A one-hour tabletop walk-through counts, if you keep dated notes.
Evidence to have: the plan itself and the notes from your last exercise. If you have neither, this is a one-afternoon fix with the right template, and it flips one of the most common "no" answers to an honest "yes."
What ties all seven together: the attestation
Every application ends the same way: a signature affirming your answers are true. That's what turns a sloppy "yes" into a denied claim later. The working rule, ours and the one that protects you, is simple — make every answer honestly "yes," or disclose accurately with compensating controls. Never shade an answer.
If you want to know which of the seven you'd pass today, the free Readiness Check scores you across all of them in about five minutes. Instant, no email required. Working from a real form? Every question an application asks is written out, with the fix for each.
Common questions
Do small businesses really get declined for missing these controls?+
Yes. Qualification is the real fight now. Survey data shows 76% of companies had to invest in their defenses specifically to qualify for coverage (Sophos, 2024), and carriers respond to gaps with declinations, ransomware exclusions, and surcharges. A shaded answer is worse: it can surface at claim time as a denial.
Which control should I fix first?+
Enforced MFA on email is the highest-leverage fix: it's free, takes an afternoon in Microsoft 365 or Google Workspace, and its absence is the most common hard stop in underwriting. Tested backups and a written incident response plan are next.
Do I need written policies, or just the technical controls?+
Both. Applications ask whether policies and plans are written and current, and the attestation you sign asserts your answers are accurate. A control that isn't documented is a control you can't prove, and in a claim dispute, proof is what matters.
Are requirements the same across all carriers?+
The core seven appear across virtually all major small-business cyber carriers. Wording and depth differ; some carriers add supplemental questionnaires about backups or funds-transfer procedures. That's why mapping your documents to each carrier's actual questions matters.
Sources
Terms in this guide
Keep reading
Cybersecurity 101: the basic precautions insurers actually notice
A plain-English starter guide to the cybersecurity basics that move the needle on a cyber insurance application: MFA, EDR, tested backups, patching, email protection, training, and a written incident response plan — most fixable in an afternoon.
What MFA do cyber insurance carriers actually require?
Carriers require enforced multi-factor authentication in three places: all business email accounts, all remote access (VPN and remote desktop), and all administrator accounts. Here's exactly what 'enforced' means, how to set it up free in an afternoon, and how to answer the application questions accurately.
How Surable is built for cyber insurance — the method behind the readiness
Surable maps every document and recommendation to the questions carriers actually ask, verifies its knowledge base weekly against primary sources, never coaches misrepresentation, and grounds its AI assistant in that same curated base. Here's exactly how the system works, and why it's built the way it is.
Find out where you stand: free, in 5 minutes
Instant readiness score across the ten domains carriers probe, plus your top three gaps and how to fix them.