Skip to content
Pro IT NW

Field notes · 11 min read ·

Share

Cyber-insurance readiness for the mid-market (2026)

Your renewal audit is the deadline. Underwriters now verify controls, not just questionnaire checkboxes — close the gaps before the questionnaire lands, not the week it's due.

For a mid-market organization — call it 50 to 2,500 seats, often in a regulated sector — the annual cyber-insurance renewal has quietly turned into something it wasn't five years ago: a security-controls audit. The questionnaire got longer, the questions got more specific, and — the part that catches people — the answers increasingly get verified rather than taken on trust. The renewal is no longer a form your broker fills in from memory. It's an inspection of whether the controls you say you have are the controls you actually enforce.

This post is the Field Notes take on getting ready for that inspection. We'll cover what changed in underwriting, what the current controls baseline looks like (the durable part, which doesn't hinge on any one broker's number), where the gaps that reprice renewals and contest claims actually live, and how to close them as a scoped readiness project instead of a scramble the week before renewal. Every market statistic below is attributed to a named, dated source — because cyber-insurance market data is analyst and broker estimates, not gospel, and it deserves to be read that way.

The risk to name honestly: a claim can be reduced or denied when the insured misrepresented a control — for example, attesting that MFA was enforced everywhere when it wasn't actually enforced on every privileged and remote path. The gap between "we said we have MFA" and "MFA is enforced on every admin, VPN, email, and cloud-admin login" is where a covered incident becomes a contested claim.

What changed: from questionnaire to evidence

The durable shift — the one that doesn't depend on any single market forecast — is that underwriting moved from a self-attested checkbox questionnaire to evidence-based verification. A decade ago, a cyber policy application asked a handful of yes/no questions and largely trusted the answers. Today's application asks specific, control-level questions and, for anything above a small policy, asks you to prove them: show the Conditional Access policy that enforces MFA, the EDR console covering every endpoint, the backup job that's immutable, the log from the last restore test, the incident-response plan with a date on the last tabletop exercise.

That change happened because the claims experience taught carriers that self-reported controls and enforced controls were frequently different things. An organization that answered "yes, we use MFA" often meant "MFA on the main email system" — not on the legacy VPN, not on the shared admin account, not on the cloud tenant's global admins. Attackers found those exact gaps. So underwriters stopped trusting the checkbox and started asking for the evidence behind it.

What the 2025 claims data actually says

The controls narrative is backed by where the losses came from. Read these as what they are — one large carrier's book, clearly dated and attributed:

  • Per Coalition's 2026 Cyber Claims Report, covering full-year 2025 data across more than 100,000 policyholders, business email compromise (BEC) and funds-transfer fraud together accounted for 58% of all claims — email-borne financial fraud, not exotic zero-days, is the dominant loss driver.
  • In the same report, initial ransom demands surged 47% year over year to an average above $1M, while a record 86% of businesses refused to pay — Coalition attributes the refusal rate to organizations having viable backups and workable incident-response plans, which is precisely the control set underwriters now inspect.
  • Coalition also reports that 70% of ransomware events involved "dual extortion" — encryption plus data exfiltration — which is why immutable backups alone no longer satisfy underwriters: a good backup restores your systems, but it doesn't undo the theft.

That shift away from paying isn't Coalition's read alone. Gallagher's 2026 Cyber Insurance Market Outlook reports ransom-payment rates fell to roughly 28–32% of victims in 2025, down from 37% in 2024 — a second, independent read on the same trend the control set is driving.

On the money side, the picture is a softening market on price and a rising bar on controls at the same time. Marsh reported US cyber-insurance rates fell about 5% on average in Q4 2024 — and the softening has not stopped since, with US cyber rates down 3% in Q4 2025 and 2% in Q1 2026, an unbroken run of quarterly declines. Meanwhile S&P Global Ratings, in its 2025 outlook, projects global cyber-insurance premiums to reach roughly $23 billion by 2026, up from about $14 billion at the end of 2023. The takeaway isn't a single magic number — it's the direction: buying the coverage got cheaper, but qualifying for it, and keeping a claim payable, got harder. Many carriers are competing on price while tightening the control conditions attached to that price.

What controls do cyber-insurance carriers require in 2026?

This is the durable spine of the whole topic, and it doesn't move much year to year. State it as the current common baseline — hedged, because carriers differ — and you have a defensible readiness target regardless of whose market forecast you believe:

  • Phishing-resistant / MFA everywhere. Enforced multi-factor authentication across email, remote access (VPN and any published app), cloud-admin, and all privileged accounts. Larger and more mature programs are moving to phishing-resistant methods (FIDO2, Windows Hello for Business) for the privileged tier specifically.
  • EDR / managed detection on all endpoints. Endpoint detection and response — or a managed detection-and-response service — deployed on every server and workstation, not a sampling. Coverage gaps are a common finding.
  • Immutable and tested backups. Backups that ransomware can't encrypt or delete, and — the part that's often missing — a documented, dated restore test proving they actually work.
  • A documented and exercised incident-response plan. Not a template in a drawer. A plan with named roles, contact trees, and evidence it's been run through a tabletop exercise in the last year.
  • Timely patching and vulnerability management. A defined cadence for critical patches and a process for tracking and closing known exploited vulnerabilities.
  • Email security. Filtering and anti-spoofing controls, given that BEC drives the majority of claims per the Coalition data above.
  • Security-awareness training. Regular training with phishing simulation, evidenced by completion and click-rate reporting.

On top of that baseline, larger policies — higher limits, higher-risk industries — increasingly expect external penetration testing on a defined cadence. It's not universal at the smaller end, but the higher your requested limit, the more likely the underwriter asks for it.

The honest framing: none of these controls is exotic, and none is optional anymore. The failure mode isn't "we didn't know we needed MFA." It's "we had MFA, but not on the one path the attacker used, and our application said we had it everywhere." Readiness is about closing the distance between the attestation and the enforcement — before the questionnaire, not after the breach.

The readiness checklist

Here's the practical version: each control, what an underwriter is actually looking for behind the yes/no box, and the gap we most commonly find when we assess a mid-market environment against it.

ControlWhat underwriters look forCommon gap
MFA everywhere Enforced on email, VPN/remote, cloud-admin, and all privileged accounts — with a policy that proves it MFA on primary email only; legacy VPN, shared admin accounts, or basic-auth mailboxes still exempt
Privileged access Separate admin accounts, least privilege, ideally just-in-time elevation on Tier-0 Daily-use accounts holding standing Domain Admin; service accounts with unused elevated rights
EDR / MDR Coverage on 100% of endpoints and servers, centrally managed, alerting live Legacy AV on some machines; unmanaged servers, kiosks, or contractor devices outside the console
Immutable backups Backups that can't be encrypted or deleted by an intruder, plus a dated restore test Backups exist but are reachable with domain credentials; no evidence a restore was ever tested
Incident-response plan Documented plan with roles and contacts, exercised via tabletop in the last 12 months Generic template, never exercised; no named decision-makers; no carrier/breach-counsel contacts
Patch / vuln management Defined cadence for critical patches; tracking of known exploited vulnerabilities Ad-hoc patching; no inventory of what's unpatched; internet-facing services behind on updates
Email security Advanced filtering, anti-spoofing (SPF/DKIM/DMARC), impersonation protection DMARC in monitoring-only or absent; no external-sender warnings; weak BEC controls
Security-awareness training Regular training plus phishing simulation, with completion and click-rate reporting Annual one-off video; no simulation data to show the underwriter
Penetration testing (larger limits) External test on a defined cadence with remediation tracked to closure Never tested, or a stale report with findings still open

Where renewals get repriced and claims get contested

The single highest-value place to look is the word "everywhere" on the MFA question. Underwriting questions are written broadly — "Do you enforce MFA for remote access and privileged accounts?" — and the honest answer for most mid-market environments is "mostly." Mostly is where the trouble lives:

  • The legacy VPN or published app that predates the MFA rollout and got an exemption "temporarily" in 2022.
  • The shared admin account that several people use and that can't easily take an MFA prompt, so it was excluded.
  • Basic-authentication mailboxes or service accounts that bypass modern authentication entirely.
  • Cloud-tenant global admins that were set up before Conditional Access was configured and never got pulled into the policy.

Each of those is a path an attacker can take, and each is a place where an attested control isn't actually enforced. At renewal, if the underwriter's verification catches the gap, the policy gets repriced or the requested limit gets trimmed. At claim time — worse — if the incident came through one of those paths and the application said MFA was enforced everywhere, the carrier has grounds to reduce or deny on misrepresentation. This isn't a hypothetical edge case; it's the most common way a paid-up policy fails to pay. The privileged-access side of this overlaps directly with the work we describe in AD Tier-0 in 90 days: mid-market edition — separated admin accounts and just-in-time elevation are exactly what closes the privileged-MFA gap underwriters ask about.

The fix: a scoped readiness project, not a renewal-week scramble

The wrong way to handle this is to receive the renewal questionnaire, realize the answers aren't clean, and spend the two weeks before the deadline either scrambling to deploy controls or — the tempting shortcut — answering optimistically and hoping it's never tested. The right way is a small, scoped project that runs 90 to 120 days ahead of renewal and turns the whole thing into a known quantity. Two phases.

Phase 1 — Controls gap assessment (1–2 weeks)

Map the current state against what underwriters actually ask. Concretely, that means going control by control down the checklist above and finding the real answer, not the hoped-for one:

  1. MFA enforcement audit. Every authentication path — email, VPN, published apps, cloud-admin, privileged accounts — and whether MFA is genuinely enforced or exempted. This is where most of the risk surfaces.
  2. EDR coverage reconciliation. Endpoint inventory against the EDR/MDR console. Every gap named: unmanaged servers, kiosks, contractor and BYOD devices, decommissioned-but-still-live machines.
  3. Backup posture and restore evidence. Are backups immutable? Reachable with domain credentials? When was the last tested restore, and is there a log to show the underwriter?
  4. IR-plan review. Does a plan exist, does it have named roles and current contacts, and has it been exercised in the last year?
  5. Patching, email security, and training evidence. The cadence, the reporting, and whether you can produce the artifacts an underwriter may ask for.

The deliverable is a plain-language gap report: for each control, "enforced and evidenced," "partial," or "gap," with the specific exposure noted. That report is also what lets you answer the renewal questionnaire honestly — which is the whole point.

Phase 2 — Prioritized remediation plan (a Statement of Work, not a checklist)

The gap report feeds a remediation plan sequenced by risk and effort. Some fixes are fast (pull the last basic-auth mailbox onto modern authentication; add the exempted VPN to the Conditional Access policy). Some take weeks (deploy EDR fleet-wide, make backups immutable and prove a restore, stand up and exercise an IR plan). The plan states what gets done, in what order, by when, and at what fixed fee — so the higher-effort items are underway with runway before the renewal, not started the week it's due. Patching and vulnerability items often overlap with other time-sensitive work; if you're already triaging something like the Kerberos RC4 enforcement change, sequence them together rather than running two separate fire drills. Cloud-admin sprawl — a common source of ungoverned privileged accounts — is worth cleaning up in the same window; see Copilot governance and tenant sprawl for the tenant-side view of that problem.

What this is — and what it isn't

Honesty about scope is part of the trust model, so here's the boundary drawn clearly:

  • Vendor-neutral and labor-only. We assess the controls and remediate them. We recommend the right configuration for your environment; you procure the tooling directly.
  • We don't sell you the insurance. Your broker places the policy. We make the answers on the application true.
  • We don't resell the EDR, backup, or MFA licensing. No product markup, no channel margin on the tools. The engagement is engineering hours against a fixed scope.
  • We're not your breach counsel or your claims adjuster. Readiness reduces the odds of a contested claim; it doesn't replace the legal and forensic response if an incident happens.

If the readiness work overlaps a formal compliance program — CMMC, HIPAA, SOC 2 — the control sets rhyme, and it's worth scoping them together rather than paying twice for the same MFA and EDR evidence. Our CMMC Level 2 pre-assessment write-up covers how that fixed-fee, evidence-first pattern works when a formal framework is also in play.

Common mistakes we see at mid-market scale

Answering the questionnaire optimistically

The most expensive mistake is treating the application as a marketing document — answering "yes, everywhere" when the honest answer is "yes, mostly." It reads fine at renewal and detonates at claim time. Answer what you can prove.

Treating "we have MFA" as done

MFA on the primary email tenant is not MFA everywhere. The paths that matter for a claim are the ones that got exempted — the legacy VPN, the shared admin account, the service account. Enforcement, not deployment, is the bar.

Backups without a tested restore

A backup you've never restored is a hypothesis. Underwriters increasingly ask for restore evidence, and with dual extortion in 70% of ransomware events per Coalition's 2026 data, "we have backups" doesn't even address the data-theft half of the problem. Test the restore; keep the log.

An IR plan nobody has read

A downloaded template with no named roles and no exercise date satisfies the letter of the question and none of its intent. The first time you run the plan should not be during a live incident.

Starting the week the renewal is due

The high-value fixes — fleet-wide EDR, immutable backups with a proven restore, MFA on every path — take weeks, not days. Starting late means either answering inaccurately or accepting a repriced policy. Ninety to 120 days of runway converts a scramble into a scoped project.

Related reading

Sources and further reading

The 30-second version

Cyber-insurance renewal for a 50–2,500-seat regulated org has become a security-controls audit. Underwriting moved from a self-attested checkbox to evidence-based verification, and the common 2026 baseline — MFA enforced everywhere, EDR on every endpoint, immutable and tested backups, an exercised IR plan, patching, email security, and awareness training, plus pen testing on larger limits — is what carriers now check. The claims data backs the emphasis: per Coalition's 2026 report, BEC and funds-transfer fraud drive 58% of claims and 70% of ransomware events involve dual extortion. The failure mode isn't missing controls; it's the gap between "we said MFA is everywhere" and "MFA is enforced on every privileged and remote path" — which reprices renewals and denies claims on misrepresentation. The fix is a scoped readiness project 90–120 days out: a controls gap assessment, then a prioritized, fixed-fee remediation plan. Vendor-neutral, labor-only — we assess and remediate the controls; we don't sell you the insurance or the EDR license.

If your renewal is on the calendar and you'd like a senior engineer to run the gap assessment before the questionnaire lands, the project intake form takes about three minutes. Two-business-day response with scope and a fixed-fee range.


Pro IT NW does senior-led identity and security work for mid-market and regulated organizations. Vendor-neutral. Labor-only. We don't sell cyber-insurance policies, and we don't resell EDR, backup, or MFA licensing — we assess your controls against what underwriters actually verify, remediate the gaps, and you procure the tooling directly.

Related service

Start a project

Written by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle / USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back inside two business days with scope and a fixed-fee range.