Blog / Reputation and business risk
Reputation and business risk
Cyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied
Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.
The warehouse mailbox
The owner of a 22-person wholesale distributor renews the cyber policy every March. This year the renewal form is longer. Question 14: "Is multi-factor authentication enforced on all email accounts, including shared and service mailboxes?" He asks the IT provider, who says MFA was rolled out last year. He ticks yes. Question 22, offline backups tested within the last twelve months: the provider says the backup runs nightly. Yes. Question 31, endpoint detection and response on all devices: there is antivirus on everything. Close enough. Yes.
The premium goes up a little. The policy binds.
In August a supplier's email is compromised, and the attacker uses it to send the distributor's accounts team a new remittance form. The team is careful; they do not act on it. So the attacker tries another way in: the warehouse shared mailbox, orders@, which four people check from a shared PC, which has no MFA because the provider could not work out how to make the shared login prompt for a code without annoying the warehouse. The password was the company name and the year.
From that mailbox the attacker reads six weeks of purchase orders, then sends the accounts team a wire change that references a real order number. USD 212,000 goes to the wrong bank on a Thursday.
The claim is filed on Friday. The forensic report, which the carrier's own panel firm writes, notes on page four that the mailbox used had no MFA. The carrier's coverage letter arrives three weeks later and quotes question 14 back to him.
What the heck does this mean
Cyber insurance requirements are the controls a carrier expects you to have before it will sell you a policy, or pay a claim. They live in the application form, and the form is part of the contract.
A misrepresentation is an answer on that form that turns out to be false. If the incident ran through the control you misrepresented, the carrier can deny the claim or void the policy. Not out of spite; that is what the form was for.
MFA, multi-factor authentication, is the second step after the password. "On all email" means every mailbox, including the shared one on the warehouse PC, the scanner's mailbox and the old founder's account nobody closed.
Funds transfer fraud is the attacker tricking your people into paying a real invoice to the wrong bank account. It is the most common claim carriers see and the one most often traced back to a mailbox.
Offline backups are copies the attacker cannot reach from your network, tested by actually restoring something, with a record of the date.
The rule I give every owner: the form is not a marketing exercise. Every yes is a promise to an underwriter who will hire a forensic firm to check it on your worst day.
The numbers that matter
Business email compromise and funds transfer fraud together made up 58% of cyber insurance claims (Coalition 2026 Cyber Claims Report). The warehouse mailbox is the typical claim, not an unusual one.
Eighty-six percent of ransomware claimants refused to pay the ransom (Coalition 2026 Cyber Claims Report). The businesses that could refuse were the ones with backups they could restore from, which is exactly what question 22 was asking about.
MFA was missing where it mattered in 59% of frontline incident cases (Sophos, 2026). More than half the time the front door had a lock on it and the side door did not, and the forensic report will say which door was used.
What to do this week
- Print your last cyber application and read every yes as if you were the carrier's forensic firm. For each one, write down what evidence you would show. Where you cannot, that is a gap, and it is cheaper to fix it than to explain it in August. (CIS 6 Access Control Management)
- List every mailbox in your tenant, shared and service accounts included, and confirm MFA is enforced on each. Shared mailboxes can be accessed through individual logins with MFA; a shared password on a warehouse PC is a claim waiting to happen. (CIS 6 Access Control Management)
- Restore one file and one full system from your backup this week, from a copy that is not connected to your network, and write down how long it took and the date. That record is the answer to question 22 and to the ransom note. (CIS 11 Data Recovery)
- Check whether what is on your computers is antivirus or EDR, and who receives its alerts. If the answer is "the IT provider, probably," ask them in writing who looked at the console last Saturday. (CIS 10 Malware Defenses)
- Add a wire-change rule your accounts team can recite: any change to a supplier's bank details is confirmed by phone to a number already on file, never to one in the email, and the caller's name is logged. Put it in your supplier onboarding letter so suppliers expect the call. (CIS 6 Access Control Management)
- Keep a folder named for the policy year with the application, the evidence for each yes and the dates you tested things. When the renewal comes, you update the folder instead of guessing. (CIS 11 Data Recovery)
Where AccuSights fits
Our assessment reads your insurance application the way the carrier's forensic firm will, tests each yes, and gives you a dated evidence folder plus a short list of the gaps that would matter in a claim. The Cyber Hygiene Test takes three minutes and gives you a score you can share with your broker. A 15-minute call with an engineer usually settles which questions you can answer truthfully today.
We map the assessment to your regulators and to the insurer's questions, and our read-only compliance agent shows which controls are in place and which have drifted, so you prioritize the right things and keep an eye on them. We have no access and do not remediate; you or your IT partner fix, and we show you where.
Questions people ask
Does cyber insurance require EDR? Most carriers now ask for it on the application, and many will not bind a policy above a modest limit without it. EDR, endpoint detection and response, is the software on every computer that spots attacker behavior rather than just known viruses. The question that follows on the form is who reviews its alerts, because an EDR console nobody looks at over a weekend does not satisfy the underwriter any more than it stops the attacker.
Can an insurer deny a claim for a misstatement on the application? Yes. The application is part of the contract, and an answer that turns out to be false about a control the incident depended on gives the carrier grounds to rescind the policy or deny the claim. Courts have sided with insurers where the misstatement was material, such as MFA declared on all email when a mailbox used in the attack had none. The defense is simple and boring: answer only what you can show, and keep the evidence with the application.
How much does cyber insurance cost for a small business? It depends on revenue, industry, the limit you buy and, increasingly, the controls you can prove. Two businesses of the same size can receive quotes far apart because one has MFA everywhere, offline tested backups and EDR with someone watching it, and the other has a ticked box. In our experience the posture is the lever an owner controls; the rest is set by the market.
The policy pays for the controls you had, not the ones you meant to have; make the form true and the claim takes care of itself.
Questions people ask
Does cyber insurance require EDR?
Most carriers now ask for it on the application, and many will not bind a policy above a modest limit without it. EDR, endpoint detection and response, is the software on every computer that spots attacker behavior rather than just known viruses. The question that follows on the form is who reviews its alerts, because an EDR console nobody looks at over a weekend does not satisfy the underwriter any more than it stops the attacker.
Can an insurer deny a claim for a misstatement on the application?
Yes. The application is part of the contract, and an answer that turns out to be false about a control the incident depended on gives the carrier grounds to rescind the policy or deny the claim. Courts have sided with insurers where the misstatement was material, such as MFA declared on all email when a mailbox used in the attack had none. The defense is simple and boring: answer only what you can show, and keep the evidence with the application.
How much does cyber insurance cost for a small business?
It depends on revenue, industry, the limit you buy and, increasingly, the controls you can prove. Two businesses of the same size can receive quotes far apart because one has MFA everywhere, offline tested backups and EDR with someone watching it, and the other has a ticked box. In our experience the posture is the lever an owner controls; the rest is set by the market.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Mobile Banking Malware: The Phone That Approves Your Payments Now Works for Someone Else
Mobile banking malware on one phone can overlay the bank app and forward one-time codes. How it gets in and how to keep it off the phones that approve payments.
ThreatsDeepfake Voice and Video Fraud: When the Managing Director on the Phone Is Not the Managing Director
Deepfake fraud against a business starts with a cloned voice and an urgent payment. What changed in 2026, what did not, and the callback rule that beats both.
Reputation and business riskWhat a Breach Really Costs a 30-Person Business (It Is Not the USD 4.99 Million Headline)
The cost of a data breach, small business edition: not the USD 4.99 million headline but eleven days of lost closings, a bank that drops you, and payroll.
