Field notes · 11 min read ·
ShareCyber-insurance readiness for the mid-market (2026)
Your renewal audit is the deadline. Underwriters now verify controls, not just questionnaire checkboxes — close the gaps before the questionnaire lands, not the week it's due.
For a mid-market organization — call it 50 to 2,500 seats, often in a regulated sector — the annual cyber-insurance renewal has quietly turned into something it wasn't five years ago: a security-controls audit. The questionnaire got longer, the questions got more specific, and — the part that catches people — the answers increasingly get verified rather than taken on trust. The renewal is no longer a form your broker fills in from memory. It's an inspection of whether the controls you say you have are the controls you actually enforce.
This post is the Field Notes take on getting ready for that inspection. We'll cover what changed in underwriting, what the current controls baseline looks like (the durable part, which doesn't hinge on any one broker's number), where the gaps that reprice renewals and contest claims actually live, and how to close them as a scoped readiness project instead of a scramble the week before renewal. Every market statistic below is attributed to a named, dated source — because cyber-insurance market data is analyst and broker estimates, not gospel, and it deserves to be read that way.
What changed: from questionnaire to evidence
The durable shift — the one that doesn't depend on any single market forecast — is that underwriting moved from a self-attested checkbox questionnaire to evidence-based verification. A decade ago, a cyber policy application asked a handful of yes/no questions and largely trusted the answers. Today's application asks specific, control-level questions and, for anything above a small policy, asks you to prove them: show the Conditional Access policy that enforces MFA, the EDR console covering every endpoint, the backup job that's immutable, the log from the last restore test, the incident-response plan with a date on the last tabletop exercise.
That change happened because the claims experience taught carriers that self-reported controls and enforced controls were frequently different things. An organization that answered "yes, we use MFA" often meant "MFA on the main email system" — not on the legacy VPN, not on the shared admin account, not on the cloud tenant's global admins. Attackers found those exact gaps. So underwriters stopped trusting the checkbox and started asking for the evidence behind it.
What the 2025 claims data actually says
The controls narrative is backed by where the losses came from. Read these as what they are — one large carrier's book, clearly dated and attributed:
- Per Coalition's 2026 Cyber Claims Report, covering full-year 2025 data across more than 100,000 policyholders, business email compromise (BEC) and funds-transfer fraud together accounted for 58% of all claims — email-borne financial fraud, not exotic zero-days, is the dominant loss driver.
- In the same report, initial ransom demands surged 47% year over year to an average above $1M, while a record 86% of businesses refused to pay — Coalition attributes the refusal rate to organizations having viable backups and workable incident-response plans, which is precisely the control set underwriters now inspect.
- Coalition also reports that 70% of ransomware events involved "dual extortion" — encryption plus data exfiltration — which is why immutable backups alone no longer satisfy underwriters: a good backup restores your systems, but it doesn't undo the theft.
That shift away from paying isn't Coalition's read alone. Gallagher's 2026 Cyber Insurance Market Outlook reports ransom-payment rates fell to roughly 28–32% of victims in 2025, down from 37% in 2024 — a second, independent read on the same trend the control set is driving.
On the money side, the picture is a softening market on price and a rising bar on controls at the same time. Marsh reported US cyber-insurance rates fell about 5% on average in Q4 2024 — and the softening has not stopped since, with US cyber rates down 3% in Q4 2025 and 2% in Q1 2026, an unbroken run of quarterly declines. Meanwhile S&P Global Ratings, in its 2025 outlook, projects global cyber-insurance premiums to reach roughly $23 billion by 2026, up from about $14 billion at the end of 2023. The takeaway isn't a single magic number — it's the direction: buying the coverage got cheaper, but qualifying for it, and keeping a claim payable, got harder. Many carriers are competing on price while tightening the control conditions attached to that price.
What controls do cyber-insurance carriers require in 2026?
This is the durable spine of the whole topic, and it doesn't move much year to year. State it as the current common baseline — hedged, because carriers differ — and you have a defensible readiness target regardless of whose market forecast you believe:
- Phishing-resistant / MFA everywhere. Enforced multi-factor authentication across email, remote access (VPN and any published app), cloud-admin, and all privileged accounts. Larger and more mature programs are moving to phishing-resistant methods (FIDO2, Windows Hello for Business) for the privileged tier specifically.
- EDR / managed detection on all endpoints. Endpoint detection and response — or a managed detection-and-response service — deployed on every server and workstation, not a sampling. Coverage gaps are a common finding.
- Immutable and tested backups. Backups that ransomware can't encrypt or delete, and — the part that's often missing — a documented, dated restore test proving they actually work.
- A documented and exercised incident-response plan. Not a template in a drawer. A plan with named roles, contact trees, and evidence it's been run through a tabletop exercise in the last year.
- Timely patching and vulnerability management. A defined cadence for critical patches and a process for tracking and closing known exploited vulnerabilities.
- Email security. Filtering and anti-spoofing controls, given that BEC drives the majority of claims per the Coalition data above.
- Security-awareness training. Regular training with phishing simulation, evidenced by completion and click-rate reporting.
On top of that baseline, larger policies — higher limits, higher-risk industries — increasingly expect external penetration testing on a defined cadence. It's not universal at the smaller end, but the higher your requested limit, the more likely the underwriter asks for it.
The readiness checklist
Here's the practical version: each control, what an underwriter is actually looking for behind the yes/no box, and the gap we most commonly find when we assess a mid-market environment against it.
| Control | What underwriters look for | Common gap |
|---|---|---|
| MFA everywhere | Enforced on email, VPN/remote, cloud-admin, and all privileged accounts — with a policy that proves it | MFA on primary email only; legacy VPN, shared admin accounts, or basic-auth mailboxes still exempt |
| Privileged access | Separate admin accounts, least privilege, ideally just-in-time elevation on Tier-0 | Daily-use accounts holding standing Domain Admin; service accounts with unused elevated rights |
| EDR / MDR | Coverage on 100% of endpoints and servers, centrally managed, alerting live | Legacy AV on some machines; unmanaged servers, kiosks, or contractor devices outside the console |
| Immutable backups | Backups that can't be encrypted or deleted by an intruder, plus a dated restore test | Backups exist but are reachable with domain credentials; no evidence a restore was ever tested |
| Incident-response plan | Documented plan with roles and contacts, exercised via tabletop in the last 12 months | Generic template, never exercised; no named decision-makers; no carrier/breach-counsel contacts |
| Patch / vuln management | Defined cadence for critical patches; tracking of known exploited vulnerabilities | Ad-hoc patching; no inventory of what's unpatched; internet-facing services behind on updates |
| Email security | Advanced filtering, anti-spoofing (SPF/DKIM/DMARC), impersonation protection | DMARC in monitoring-only or absent; no external-sender warnings; weak BEC controls |
| Security-awareness training | Regular training plus phishing simulation, with completion and click-rate reporting | Annual one-off video; no simulation data to show the underwriter |
| Penetration testing (larger limits) | External test on a defined cadence with remediation tracked to closure | Never tested, or a stale report with findings still open |
Where renewals get repriced and claims get contested
The single highest-value place to look is the word "everywhere" on the MFA question. Underwriting questions are written broadly — "Do you enforce MFA for remote access and privileged accounts?" — and the honest answer for most mid-market environments is "mostly." Mostly is where the trouble lives:
- The legacy VPN or published app that predates the MFA rollout and got an exemption "temporarily" in 2022.
- The shared admin account that several people use and that can't easily take an MFA prompt, so it was excluded.
- Basic-authentication mailboxes or service accounts that bypass modern authentication entirely.
- Cloud-tenant global admins that were set up before Conditional Access was configured and never got pulled into the policy.
Each of those is a path an attacker can take, and each is a place where an attested control isn't actually enforced. At renewal, if the underwriter's verification catches the gap, the policy gets repriced or the requested limit gets trimmed. At claim time — worse — if the incident came through one of those paths and the application said MFA was enforced everywhere, the carrier has grounds to reduce or deny on misrepresentation. This isn't a hypothetical edge case; it's the most common way a paid-up policy fails to pay. The privileged-access side of this overlaps directly with the work we describe in AD Tier-0 in 90 days: mid-market edition — separated admin accounts and just-in-time elevation are exactly what closes the privileged-MFA gap underwriters ask about.
The fix: a scoped readiness project, not a renewal-week scramble
The wrong way to handle this is to receive the renewal questionnaire, realize the answers aren't clean, and spend the two weeks before the deadline either scrambling to deploy controls or — the tempting shortcut — answering optimistically and hoping it's never tested. The right way is a small, scoped project that runs 90 to 120 days ahead of renewal and turns the whole thing into a known quantity. Two phases.
Phase 1 — Controls gap assessment (1–2 weeks)
Map the current state against what underwriters actually ask. Concretely, that means going control by control down the checklist above and finding the real answer, not the hoped-for one:
- MFA enforcement audit. Every authentication path — email, VPN, published apps, cloud-admin, privileged accounts — and whether MFA is genuinely enforced or exempted. This is where most of the risk surfaces.
- EDR coverage reconciliation. Endpoint inventory against the EDR/MDR console. Every gap named: unmanaged servers, kiosks, contractor and BYOD devices, decommissioned-but-still-live machines.
- Backup posture and restore evidence. Are backups immutable? Reachable with domain credentials? When was the last tested restore, and is there a log to show the underwriter?
- IR-plan review. Does a plan exist, does it have named roles and current contacts, and has it been exercised in the last year?
- Patching, email security, and training evidence. The cadence, the reporting, and whether you can produce the artifacts an underwriter may ask for.
The deliverable is a plain-language gap report: for each control, "enforced and evidenced," "partial," or "gap," with the specific exposure noted. That report is also what lets you answer the renewal questionnaire honestly — which is the whole point.
Phase 2 — Prioritized remediation plan (a Statement of Work, not a checklist)
The gap report feeds a remediation plan sequenced by risk and effort. Some fixes are fast (pull the last basic-auth mailbox onto modern authentication; add the exempted VPN to the Conditional Access policy). Some take weeks (deploy EDR fleet-wide, make backups immutable and prove a restore, stand up and exercise an IR plan). The plan states what gets done, in what order, by when, and at what fixed fee — so the higher-effort items are underway with runway before the renewal, not started the week it's due. Patching and vulnerability items often overlap with other time-sensitive work; if you're already triaging something like the Kerberos RC4 enforcement change, sequence them together rather than running two separate fire drills. Cloud-admin sprawl — a common source of ungoverned privileged accounts — is worth cleaning up in the same window; see Copilot governance and tenant sprawl for the tenant-side view of that problem.
What this is — and what it isn't
Honesty about scope is part of the trust model, so here's the boundary drawn clearly:
- Vendor-neutral and labor-only. We assess the controls and remediate them. We recommend the right configuration for your environment; you procure the tooling directly.
- We don't sell you the insurance. Your broker places the policy. We make the answers on the application true.
- We don't resell the EDR, backup, or MFA licensing. No product markup, no channel margin on the tools. The engagement is engineering hours against a fixed scope.
- We're not your breach counsel or your claims adjuster. Readiness reduces the odds of a contested claim; it doesn't replace the legal and forensic response if an incident happens.
If the readiness work overlaps a formal compliance program — CMMC, HIPAA, SOC 2 — the control sets rhyme, and it's worth scoping them together rather than paying twice for the same MFA and EDR evidence. Our CMMC Level 2 pre-assessment write-up covers how that fixed-fee, evidence-first pattern works when a formal framework is also in play.
Common mistakes we see at mid-market scale
Answering the questionnaire optimistically
The most expensive mistake is treating the application as a marketing document — answering "yes, everywhere" when the honest answer is "yes, mostly." It reads fine at renewal and detonates at claim time. Answer what you can prove.
Treating "we have MFA" as done
MFA on the primary email tenant is not MFA everywhere. The paths that matter for a claim are the ones that got exempted — the legacy VPN, the shared admin account, the service account. Enforcement, not deployment, is the bar.
Backups without a tested restore
A backup you've never restored is a hypothesis. Underwriters increasingly ask for restore evidence, and with dual extortion in 70% of ransomware events per Coalition's 2026 data, "we have backups" doesn't even address the data-theft half of the problem. Test the restore; keep the log.
An IR plan nobody has read
A downloaded template with no named roles and no exercise date satisfies the letter of the question and none of its intent. The first time you run the plan should not be during a live incident.
Starting the week the renewal is due
The high-value fixes — fleet-wide EDR, immutable backups with a proven restore, MFA on every path — take weeks, not days. Starting late means either answering inaccurately or accepting a repriced policy. Ninety to 120 days of runway converts a scramble into a scoped project.
Related reading
- The privileged-access side of the MFA-everywhere gap: AD Tier-0 in 90 days: mid-market edition — separated admin accounts and just-in-time elevation are what close the privileged-MFA finding.
- A time-sensitive patching/identity change worth sequencing alongside readiness work: Kerberos RC4 April 2026 enforcement: mid-market triage.
- Cloud-admin and tenant sprawl — a common source of ungoverned privileged accounts: Copilot governance and tenant sprawl in 2026.
- When a formal compliance framework overlaps the same controls: CMMC Level 2 pre-assessment: what $15K buys.
- Who does the remediation when your own team is stretched thin: IT layoffs, stalled migrations, and the senior bench.
- Service hub: Identity, Security & Compliance.
Sources and further reading
- Coalition — 2026 Cyber Claims Report (full-year 2025 data; BEC/FTF share, ransom-demand growth, dual-extortion rate)
- Reinsurance News — S&P Global Ratings projects cyber premiums to reach $23bn by 2026
- Marsh — US cyber insurance market update (Q4 2024 rate movement)
- Gallagher (AJG) — 2026 Cyber Insurance Market Outlook
The 30-second version
Cyber-insurance renewal for a 50–2,500-seat regulated org has become a security-controls audit. Underwriting moved from a self-attested checkbox to evidence-based verification, and the common 2026 baseline — MFA enforced everywhere, EDR on every endpoint, immutable and tested backups, an exercised IR plan, patching, email security, and awareness training, plus pen testing on larger limits — is what carriers now check. The claims data backs the emphasis: per Coalition's 2026 report, BEC and funds-transfer fraud drive 58% of claims and 70% of ransomware events involve dual extortion. The failure mode isn't missing controls; it's the gap between "we said MFA is everywhere" and "MFA is enforced on every privileged and remote path" — which reprices renewals and denies claims on misrepresentation. The fix is a scoped readiness project 90–120 days out: a controls gap assessment, then a prioritized, fixed-fee remediation plan. Vendor-neutral, labor-only — we assess and remediate the controls; we don't sell you the insurance or the EDR license.
If your renewal is on the calendar and you'd like a senior engineer to run the gap assessment before the questionnaire lands, the project intake form takes about three minutes. Two-business-day response with scope and a fixed-fee range.
Pro IT NW does senior-led identity and security work for mid-market and regulated organizations. Vendor-neutral. Labor-only. We don't sell cyber-insurance policies, and we don't resell EDR, backup, or MFA licensing — we assess your controls against what underwriters actually verify, remediate the gaps, and you procure the tooling directly.
Related service
Start a projectWritten by the team at Pro IT NW · Senior-led Microsoft project consultancy · Seattle / USA-wide.