We are exhibiting at GISEC Global 2026 · 16-18 Sept · Expo City DubaiBook a booth session with our CEO
AccuSights
Products
Assess
Comply
Protect
Free Tools
Email Breach Checker
Cyber Hygiene Test
Regulator directory
Regulatory calendar
ADHICS
ADGM
CBUAE
CSC
DFSA
DHA
DHCC
DIFC
DOH
FSRA
NIAF
Malaffi
MOHAP
NABIDH
NCAP
SCA
VARA
Healthcare
Finance
AI & Machine Learning
Defence & Military
Government Contractor
Professional Services
Technology & SaaS
Retail & Hospitality
Real Estate & Construction
Architecture, Design & Construction
Cybersecurity in Dubai
Cybersecurity in Abu Dhabi
Cybersecurity in Sharjah
All emirates
Chambers of Commerce
MSP
Partner Program
About Us
Why AccuSights
Compliance Center
Blog
Threat Dashboard
Threat Headlines
Contact

Blog / Reputation and business risk

Reputation and business risk

Cyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied

Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.

Sam KhanSam Khan The Cyber MonkFounder and CEO2 September 2026 · 6 min read

The warehouse mailbox

The owner of a 22-person wholesale distributor renews the cyber policy every March. This year the renewal form is longer. Question 14: "Is multi-factor authentication enforced on all email accounts, including shared and service mailboxes?" He asks the IT provider, who says MFA was rolled out last year. He ticks yes. Question 22, offline backups tested within the last twelve months: the provider says the backup runs nightly. Yes. Question 31, endpoint detection and response on all devices: there is antivirus on everything. Close enough. Yes.

The premium goes up a little. The policy binds.

In August a supplier's email is compromised, and the attacker uses it to send the distributor's accounts team a new remittance form. The team is careful; they do not act on it. So the attacker tries another way in: the warehouse shared mailbox, orders@, which four people check from a shared PC, which has no MFA because the provider could not work out how to make the shared login prompt for a code without annoying the warehouse. The password was the company name and the year.

From that mailbox the attacker reads six weeks of purchase orders, then sends the accounts team a wire change that references a real order number. USD 212,000 goes to the wrong bank on a Thursday.

The claim is filed on Friday. The forensic report, which the carrier's own panel firm writes, notes on page four that the mailbox used had no MFA. The carrier's coverage letter arrives three weeks later and quotes question 14 back to him.

What the heck does this mean

Cyber insurance requirements are the controls a carrier expects you to have before it will sell you a policy, or pay a claim. They live in the application form, and the form is part of the contract.

A misrepresentation is an answer on that form that turns out to be false. If the incident ran through the control you misrepresented, the carrier can deny the claim or void the policy. Not out of spite; that is what the form was for.

MFA, multi-factor authentication, is the second step after the password. "On all email" means every mailbox, including the shared one on the warehouse PC, the scanner's mailbox and the old founder's account nobody closed.

Funds transfer fraud is the attacker tricking your people into paying a real invoice to the wrong bank account. It is the most common claim carriers see and the one most often traced back to a mailbox.

Offline backups are copies the attacker cannot reach from your network, tested by actually restoring something, with a record of the date.

The rule I give every owner: the form is not a marketing exercise. Every yes is a promise to an underwriter who will hire a forensic firm to check it on your worst day.

The numbers that matter

Business email compromise and funds transfer fraud together made up 58% of cyber insurance claims (Coalition 2026 Cyber Claims Report). The warehouse mailbox is the typical claim, not an unusual one.

Eighty-six percent of ransomware claimants refused to pay the ransom (Coalition 2026 Cyber Claims Report). The businesses that could refuse were the ones with backups they could restore from, which is exactly what question 22 was asking about.

MFA was missing where it mattered in 59% of frontline incident cases (Sophos, 2026). More than half the time the front door had a lock on it and the side door did not, and the forensic report will say which door was used.

What to do this week

  1. Print your last cyber application and read every yes as if you were the carrier's forensic firm. For each one, write down what evidence you would show. Where you cannot, that is a gap, and it is cheaper to fix it than to explain it in August. (CIS 6 Access Control Management)
  2. List every mailbox in your tenant, shared and service accounts included, and confirm MFA is enforced on each. Shared mailboxes can be accessed through individual logins with MFA; a shared password on a warehouse PC is a claim waiting to happen. (CIS 6 Access Control Management)
  3. Restore one file and one full system from your backup this week, from a copy that is not connected to your network, and write down how long it took and the date. That record is the answer to question 22 and to the ransom note. (CIS 11 Data Recovery)
  4. Check whether what is on your computers is antivirus or EDR, and who receives its alerts. If the answer is "the IT provider, probably," ask them in writing who looked at the console last Saturday. (CIS 10 Malware Defenses)
  5. Add a wire-change rule your accounts team can recite: any change to a supplier's bank details is confirmed by phone to a number already on file, never to one in the email, and the caller's name is logged. Put it in your supplier onboarding letter so suppliers expect the call. (CIS 6 Access Control Management)
  6. Keep a folder named for the policy year with the application, the evidence for each yes and the dates you tested things. When the renewal comes, you update the folder instead of guessing. (CIS 11 Data Recovery)

Where AccuSights fits

Our assessment reads your insurance application the way the carrier's forensic firm will, tests each yes, and gives you a dated evidence folder plus a short list of the gaps that would matter in a claim. The Cyber Hygiene Test takes three minutes and gives you a score you can share with your broker. A 15-minute call with an engineer usually settles which questions you can answer truthfully today.

We map the assessment to your regulators and to the insurer's questions, and our read-only compliance agent shows which controls are in place and which have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.

Questions people ask

Does cyber insurance require EDR? Most carriers now ask for it on the application, and many will not bind a policy above a modest limit without it. EDR, endpoint detection and response, is the software on every computer that spots attacker behavior rather than just known viruses. The question that follows on the form is who reviews its alerts, because an EDR console nobody looks at over a weekend does not satisfy the underwriter any more than it stops the attacker.

Can an insurer deny a claim for a misstatement on the application? Yes. The application is part of the contract, and an answer that turns out to be false about a control the incident depended on gives the carrier grounds to rescind the policy or deny the claim. Courts have sided with insurers where the misstatement was material, such as MFA declared on all email when a mailbox used in the attack had none. The defense is simple and boring: answer only what you can show, and keep the evidence with the application.

How much does cyber insurance cost for a small business? It depends on revenue, industry, the limit you buy and, increasingly, the controls you can prove. Two businesses of the same size can receive quotes far apart because one has MFA everywhere, offline tested backups and EDR with someone watching it, and the other has a ticked box. In our experience the posture is the lever an owner controls; the rest is set by the market.

The policy pays for the controls you had, not the ones you meant to have; make the form true and the claim takes care of itself.

Questions people ask

Does cyber insurance require EDR?

Most carriers now ask for it on the application, and many will not bind a policy above a modest limit without it. EDR, endpoint detection and response, is the software on every computer that spots attacker behavior rather than just known viruses. The question that follows on the form is who reviews its alerts, because an EDR console nobody looks at over a weekend does not satisfy the underwriter any more than it stops the attacker.

Can an insurer deny a claim for a misstatement on the application?

Yes. The application is part of the contract, and an answer that turns out to be false about a control the incident depended on gives the carrier grounds to rescind the policy or deny the claim. Courts have sided with insurers where the misstatement was material, such as MFA declared on all email when a mailbox used in the attack had none. The defense is simple and boring: answer only what you can show, and keep the evidence with the application.

How much does cyber insurance cost for a small business?

It depends on revenue, industry, the limit you buy and, increasingly, the controls you can prove. Two businesses of the same size can receive quotes far apart because one has MFA everywhere, offline tested backups and EDR with someone watching it, and the other has a ticked box. In our experience the posture is the lever an owner controls; the rest is set by the market.

Controls this post maps to

CIS 6 Access Control ManagementCIS 11 Data RecoveryCIS 10 Malware Defenses

CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Check, then repeat. We provide read-only insight so you prioritize the right things and keep an eye on them.

We have no access and do not remediate. You or your IT partner fix; we show you where, mapped to your regulators. Thirty minutes with an engineer draws the map for your organization.

Compliance is not security. The audit is not the exam; the attacker is.