Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature Compliance Strategy

Cyber Insurance Requirements in 2026: The Evidence Underwriters Now Demand Before They Bind Coverage

Cyber insurance underwriting shifted from questionnaire to evidence-based in 2024-2026. MFA is no longer enough to check a box — underwriters want screenshots, deployment reports, and restore test logs. For financial services firms, here's the full list of what carriers are requiring before they bind, and how to organize your evidence file.

Table of Contents

TL;DR

  • Cyber insurance underwriting shifted to evidence-based in 2024–2026: MFA enforcement screenshots, EDR deployment reports, and backup restore logs are now standard documentation requirements — checking a questionnaire box is no longer sufficient
  • Marsh McLennan data found 41% of applications get denied on first submission, with missing MFA enforcement and inadequate endpoint protection as the top two reasons
  • Financial services firms need $3M–$10M+ in coverage; SOC 2 Type 2 and penetration testing are often required for policies above $5M
  • Nation-state and war exclusions are the biggest coverage risk for financial institutions — different carriers define them differently, and financial institutions are disproportionately targeted by state-sponsored threat actors
  • The incident response plan is no longer just a checkbox — underwriters want a dated plan with evidence of tabletop testing

In 2023, a compliance officer could fill out a cyber insurance application by checking “yes, we have MFA” and move on. By 2024, the largest carriers had shifted to an evidence-based underwriting model. By 2026, if you can’t produce the screenshots, deployment reports, and restore test logs during the application, you’re getting declined or quoted at a rate that reflects your actual exposure profile — not the one you described in a questionnaire.

The shift happened because the market got hit hard. Ransomware losses, business email compromise claims, and nation-state-adjacent incidents forced carriers to actually verify controls rather than take applicants’ word for it. The result is an underwriting process that has become, functionally, an unannounced security audit — and financial services firms are among the most scrutinized applicants.

Here’s what the documentation actually looks like in 2026, and how to organize it before your renewal.

Why the Questionnaire Model Broke

Cyber insurance underwriting ran on applicant questionnaires for most of the 2010s. Organizations self-reported their controls, and carriers set prices accordingly. The problem: loss ratios from 2020–2023 revealed that questionnaire responses didn’t predict claims experience — organizations that checked every box were still having major incidents because the controls weren’t actually implemented the way the questionnaire answers implied.

The pivot to evidence-based underwriting had two drivers:

Claims data showed specific control failures. Ransomware incident forensics repeatedly showed the same pattern: MFA was “available” but not enforced on the compromised account, or EDR was deployed on most endpoints but not the one the attacker pivoted through. Carriers changed their underwriting to require proof of actual enforcement, not just existence.

Coverage denials created market pressure. Post-incident claim denials — particularly in cases where the carrier’s forensic investigation revealed that the policy application had misrepresented control implementation — created significant litigation and regulatory attention. Carriers responded by moving the verification to the front end of the process, during underwriting, rather than the back end during claims.

The Four Non-Negotiable Controls

Every major cyber insurance carrier in 2026 treats these four controls as threshold requirements. Applications missing any of them face denial or coverage limits that effectively make the policy unusable for a significant incident.

1. Multi-Factor Authentication — Enforced, Not Available

MFA has been an underwriting question for years. What changed in 2024–2025 is the move from “do you have MFA?” to “is MFA enforced, and can you show us?”

What underwriters require in 2026:

  • MFA enforced on all email accounts (including service accounts, if they can receive email)
  • MFA enforced on VPN and remote access — no exceptions for “senior users” or service accounts
  • MFA enforced on cloud platforms (Microsoft 365, Google Workspace, AWS, Azure, GCP)
  • MFA enforced on all privileged/administrative accounts
  • Phishing-resistant MFA (FIDO2 or hardware security keys) preferred for privileged access; some carriers now require it for policies above $5M

The documentation: an administrative console screenshot or exported report showing enforcement status across account categories. Carriers want to see that enforcement is a system setting, not a user preference.

The coverage risk: most policies now explicitly exclude breaches resulting from compromised credentials where MFA was not enabled on the affected account. If an attacker gets in through a service account that bypassed MFA enforcement, your claim may be denied under the standard exclusion.

2. Endpoint Detection and Response (EDR) — Active Monitoring, Not Antivirus

Traditional antivirus is not accepted by most carriers as EDR. The underwriting question in 2026 is whether you have behavioral detection, automated containment, and forensic capability — not signature-based malware scanning.

What underwriters require:

  • EDR deployed on all user-facing endpoints (workstations, laptops)
  • EDR coverage on servers, including domain controllers
  • Active threat hunting or managed detection and response (MDR) — a human SOC monitoring alerts in near-real-time, not just automated rules
  • Documented coverage percentage: carriers want to see that EDR is on ≥ 95% of in-scope endpoints, not just “most” of them

The documentation: a deployment report from your EDR console showing endpoint coverage by count and percentage, and confirmation that alerts are being actively monitored.

Carriers that require MDR (24/7 SOC) for larger financial services policies have cited the gap between alert generation and human response as the key factor in whether ransomware attacks are contained before they encrypt critical systems.

3. Immutable Backups — With Restore Testing Documented

Ransomware operators target backups first. Backup logs that show backups are running are no longer sufficient evidence — carriers want to see that backups cannot be deleted or encrypted by a ransomware actor, and that restore functionality has been tested within the last 12 months.

What underwriters require:

  • Offline or air-gapped backup copies, or backups in immutable storage (cloud object locks, tape, separate cloud tenant with no trust relationship to production)
  • Documented restore tests: date, scope, recovery time achieved vs. recovery time objective, any gaps identified
  • Backup coverage for critical systems and data classified as essential for business continuity

The documentation: backup logs showing frequency and coverage, plus restore test records from the past 12 months. A policy that says “we perform quarterly backups” without corresponding restore test results is not sufficient.

4. Written Incident Response Plan — Tested, Not Just Filed

An incident response plan that exists in a shared drive but has never been activated or tested is no longer adequate documentation for cyber insurance underwriting. Carriers increasingly require evidence that the plan has been exercised.

What underwriters require:

  • A dated incident response plan (last updated within the past 12 months is standard; 18–24 months is marginal)
  • Tabletop exercise records: scenario description, participants, gaps identified, remediation actions
  • Defined roles for: incident coordinator, legal/privacy, communications, executive notification, forensic investigation

For financial services firms, the IR plan needs to address regulatory notification timelines specifically:

  • NYDFS cybersecurity Part 500: 72-hour notification to the Superintendent
  • SEC Regulation S-P (amended): 30-day notification obligation for investment advisers
  • FFIEC 36-hour incident notification rule: applies to banking organizations for “computer-security incidents”
  • CIRCIA: 72-hour reporting for covered critical infrastructure entities

A plan that doesn’t address your specific regulatory notification obligations is less credible as an underwriting document than one that maps regulatory timelines explicitly.

What Financial Services Firms Get Asked That Others Don’t

General industry requirements apply to every applicant. Financial services firms face additional questions that reflect the sector’s specific threat profile and regulatory environment.

SOC 2 Type 2 and Penetration Testing

For financial services policies above approximately $3–5 million in limits, most carriers now request either a SOC 2 Type 2 report or penetration testing results from the past 12–18 months. Some require both.

The distinction matters: a SOC 2 Type 1 report (point-in-time assessment) is less useful than Type 2 (operational effectiveness over a period), and carriers are aware of the difference. If your organization has a Type 1 but not a Type 2, the underwriter will note the gap.

Penetration testing results should show scope, methodology, critical findings, and remediation status of identified vulnerabilities. A penetration test that identified critical vulnerabilities and has no remediation documentation creates underwriting exposure.

Network Segmentation

Financial institutions process high-value transactions in production environments that should be isolated from general corporate networks. Underwriters ask specifically about network segmentation between:

  • Payment processing environments and general corporate networks
  • Customer data environments and administrative systems
  • Core banking systems and internet-accessible services

The NYDFS Part 500 Phase 3 requirements — including asset inventory and access controls — overlap significantly with what cyber insurance underwriters are asking about network segmentation and privileged access. Credit unions and community banks that have completed their NYDFS Phase 3 compliance work are well-positioned to provide the segmentation documentation carriers want.

Fraud Coverage vs. Cyber Coverage — Know the Boundary

Financial institutions frequently discover during a claim that what they thought was a cyber insurance event is actually a crime policy event, or that there’s a gap in coverage at the boundary between the two.

Business email compromise is the most common example. When an employee is deceived into wiring funds to a fraudulent account, the loss may be covered by the crime policy (social engineering fraud rider) rather than the cyber policy — but only if the crime policy has a social engineering endorsement, which is not automatic.

Before your renewal, map your loss scenarios to your specific policy language:

  • Ransomware/encryption incident: Cyber policy (business interruption, data recovery, forensics, notification)
  • BEC — employee deceived into wiring funds: Crime policy with social engineering rider (NOT typically cyber)
  • Data breach — customer PII exfiltrated: Cyber policy (notification, regulatory response, credit monitoring)
  • Third-party vendor breach affecting your customers: Cyber policy, but check third-party liability sublimits
  • Nation-state attack: Check the war/nation-state exclusion language in your specific carrier’s policy — this varies significantly and is the largest unresolved coverage risk in the market

The Nation-State Exclusion Problem

Financial institutions are disproportionate targets for nation-state cyber operations. The risk: most cyber policies include a war or nation-state exclusion, and the scope of that exclusion differs dramatically by carrier.

The NotPetya litigation (Merck v. Ace American, Mondelez International) established that “war exclusions” as written in property and cyber policies were intended for physical kinetic conflict, not malware campaigns. But carriers responded by rewriting exclusion language to specifically address state-sponsored cyber operations — and those revised exclusions have different trigger standards at different carriers.

For financial services firms, this means:

  • Read the war/nation-state exclusion in your policy, not just the coverage summary
  • Ask your broker specifically how your carrier defines “nation-state” attribution and what standard is applied before the exclusion triggers
  • Consider whether a sublimit approach (some coverage remains even if the exclusion is disputed) is preferable to a structure where the exclusion would eliminate all coverage for a major incident

The Evidence File — What to Organize Before Renewal

Cyber insurance renewal in 2026 works better if you assemble your evidence file before the application, not in response to underwriter follow-up questions. The following documents are requested at virtually every renewal for financial services organizations:

DocumentContentFreshness Requirement
MFA enforcement reportAdmin console export showing enforcement by account typeWithin 30 days of application
EDR deployment reportCoverage percentage by device categoryWithin 30 days of application
Backup logsBackup frequency, coverage, and restore test resultsRestore tests within 12 months
Incident response planWritten plan with regulatory notification timelinesUpdated within 12 months
Tabletop exercise recordScenario, participants, gaps identified, remediationWithin 18 months
Security training recordsTraining completion rates, topics coveredAnnual completion within 12 months
Penetration test resultsScope, findings, remediation statusWithin 12–18 months (for $3M+ policies)
SOC 2 Type 2 reportIssued by qualified auditorWithin 12 months
Network segmentation documentationDiagram showing production/corporate isolationCurrent

Collecting these documents before the renewal application accomplishes two things: it surfaces controls gaps while you still have time to remediate, and it shortens the underwriting timeline by avoiding multiple rounds of follow-up document requests.

How Incident Response Documentation Helps Before and After a Claim

The incident response plan isn’t just an underwriting document. It’s also your most important evidence when you file a claim.

A claim filed with a complete evidence package — forensic investigation timeline, regulatory notification records, breach scope documentation, cost documentation — processes faster and with fewer coverage disputes than a claim where the carrier has to reconstruct what happened from incomplete records.

The Incident Response & Breach Notification Kit includes the documentation templates that both satisfy underwriter requirements and provide the evidence structure needed when a claim is filed: written IR plan, tabletop scenario templates, breach notification checklists, and regulatory reporting worksheets mapped to FFIEC, NYDFS, SEC Reg S-P, and state breach notification timelines.

The ransomware incident response playbook covers the first 24 hours in detail — which is also the period that determines whether the event is contained at the cost of forensic fees or escalates to a notification event that activates the full claims process.

So What?

The cyber insurance market in 2026 is functionally a security audit built into your annual renewal process. That’s not a bad thing for organizations with mature controls — it’s a pricing advantage and a signal that your program is working.

For organizations that have been treating the questionnaire as a formality: the underwriting question “is MFA enforced?” now requires a screenshot, not a checkbox. The gap between “we have MFA” and “we can prove MFA is enforced across all accounts and systems” is exactly where claims get denied and renewals get declined.

The practical checklist for your next renewal:

  • MFA: Run an admin report showing enforcement status across email, remote access, cloud, and privileged accounts — before the application
  • EDR: Pull a deployment report showing endpoint coverage percentage and confirm active 24/7 monitoring is in place
  • Backups: Document your last restore test with date, scope, and result; make sure at least one copy is air-gapped or immutable
  • IR Plan: Confirm it’s been updated in the last 12 months, includes your specific regulatory notification timelines, and has been exercised with a tabletop in the last 18 months
  • Evidence file: Assemble all documentation before the renewal application so you’re not answering follow-up requests under time pressure

If any of those items surface gaps, remediate before renewal, not after. Underwriting decisions made at the time of application affect your coverage structure for the entire policy period.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What are the minimum cyber insurance requirements in 2026?
In 2026, cyber insurance underwriters universally require four controls before binding coverage: enforced multi-factor authentication (MFA) on email, remote access, and administrative accounts; endpoint detection and response (EDR) deployed across all devices; immutable or offline backup copies with documented restore testing; and a written incident response plan. These are threshold requirements — applications missing any of these are typically denied on first submission.
What's the difference between having MFA available and having MFA enforced?
Having MFA available means the system supports it but users can bypass or opt out. Having MFA enforced means users cannot complete authentication without MFA — there is no bypass path for any account in scope. Underwriters in 2026 ask specifically whether MFA is enforced, and many now request a screenshot or administrative report showing enforcement status across email, VPN, remote desktop, cloud platforms, and administrative accounts. An organization that 'offers' MFA but doesn't enforce it faces the same underwriting outcome as one that doesn't have it at all.
Can cyber insurance cover a ransomware attack that exploits a known vulnerability?
Increasingly, no. Most policies now include exclusions for breaches resulting from exploitation of vulnerabilities for which a patch was available for more than a defined period (commonly 30-90 days) prior to the incident. Some policies also exclude breaches where known vulnerable systems had not been patched within the carrier's specified window. Patch management documentation — showing when patches were identified and applied — has moved from a background question to an active coverage condition.
What documentation does a financial services firm need to prepare for cyber insurance renewal?
Underwriters typically require: MFA enforcement screenshots showing coverage across email, remote access, and admin accounts; EDR deployment report showing endpoint coverage percentage; backup logs with restore test results and dates from the past 12 months; current incident response plan (dated within the past year); security awareness training completion records; and for larger policies, penetration testing results or SOC 2 Type 2 report. Financial services firms often also need evidence of network segmentation between production and administrative environments.
How much cyber insurance coverage does a fintech or community bank typically need in 2026?
Financial services firms generally need $3 million to $10 million in coverage given regulatory notification requirements, PCI-DSS exposure, and customer data breach liability. NYDFS-regulated entities face specific breach notification obligations within 72 hours to the department; SEC-regulated entities face a 30-day reporting requirement under the amended Regulation S-P. The cost of regulatory response, forensics, and notification (depending on customer count) can exceed $3 million even for mid-size institutions. Coverage selection should be modeled against your worst-case customer notification volume and likely forensic and regulatory response costs.
What coverage exclusions are most common in cyber insurance policies for financial institutions?
The most commonly invoked exclusions in cyber insurance claims for financial institutions include: war and nation-state exclusions (increasingly tested after Merck and other NotPetya litigation), breaches resulting from compromised credentials where MFA was not enabled, social engineering fraud losses that fall under a crime policy rather than cyber policy, and losses from unpatched vulnerabilities. Read the nation-state and war exclusions carefully — different carriers draw the line differently, and financial institutions are disproportionately targeted by nation-state actors.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Incident Response & Breach Notification Kit

Step-by-step incident response playbooks and breach notification templates for all 50 states.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.