A few years ago cyber insurance was a market with a low entry barrier — fill out a questionnaire, pay a premium, done. That has changed in 2026. After a wave of large ransomware losses and corresponding insurer losses, intake conditions have become significantly stricter. Deductibles rise, sublimits tighten, and most importantly: the promised protections are scrutinised when a claim hits.
Anyone who ticked “MFA is enabled everywhere” on the questionnaire but in the claim turns out to have run the managing director’s account without MFA for convenience — the insurer can reject the claim in whole or in part. We see this in consulting practice more often than most managers think.
This article summarises what insurers typically demand in 2026 — and what is examined in detail.
MFA Everywhere — the Number-One Requirement
Multi-factor authentication is no longer negotiable in 2026. Insurers explicitly ask about:
- E-mail access (Microsoft 365, Google Workspace, on-prem Exchange Outlook Web App)
- VPN and remote access (every tunnel, every RDP gateway)
- Admin accounts (domain admins, cloud tenant admins, server root access)
- Privileged application access (ERP, CRM, finance)
“MFA active for most users” is not enough. It must be documentable that MFA is enforced for all relevant accounts — no exceptions for “important people”. Anyone still using SMS-MFA should plan the move to app-based or hardware-token MFA; several insurers no longer accept SMS-MFA. See also Passkeys in the mid-market: passwordless.
Patch Management Documented — Audit Trail Required
“We patch regularly” is on every questionnaire — but in 2026 insurers want to know:
- What process? Manual, automated, staggered?
- What tools? WSUS, SCCM, Intune, Ansible, RMM solution?
- What SLAs? Critical patches within 14/30/90 days?
- Where is the audit trail? A list of “patch X applied on date Y to system Z” must be reproducible.
Without a documented patch process you risk a benefit reduction in claims involving “known unpatched vulnerabilities”. An RMM solution with central patch reporting helps not only operationally but also in insurance terms.
EDR / XDR — Standard AV is No Longer Enough
A classic anti-virus on endpoints is no longer sufficient protection for most insurers in 2026. Expected is an EDR (Endpoint Detection & Response) or XDR solution. Concretely:
- Behaviour-based detection (not just signature-based)
- Central management with logging
- Response functions (isolation of affected endpoints, automated response to indicators)
- 24/7 SOC or MDR service is not mandatory everywhere, but increasingly requested
In SMBs the most common path is an EDR product from the existing AV vendor (Bitdefender GravityZone, Sophos Intercept X, ESET Inspect, Microsoft Defender for Business). Important: it must also be actively reviewed — an EDR solution without anyone looking at the alerts is mere compliance theatre.
Backup with Air Gap or Immutable — Mandatory Component
Ransomware claims in recent years have shown: online backups that share the fate of the production systems are useless. Insurers in 2026 nearly always require:
- At least one backup copy offline or immutable (air gap, write-once, S3 Object Lock)
- Regular restore tests — and documentation of them
- 3-2-1 rule as minimum standard (3 copies, 2 media, 1 off-site)
See our in-depth practice articles: Immutable backups against ransomware, Ransomware 2026: protection measures and for backup vault key handling our parallel article Backup encryption: key management done right.
Employee Training Verifiable
“We train our employees” is not enough. In 2026 insurers ask:
- What content? (Phishing, password hygiene, social engineering, data protection)
- What frequency? (Onboarding plus annual refresher as minimum)
- How proven? (Attendance lists, e-learning reports)
- Phishing simulations? Increasingly named as a threshold — at least twice a year, with evaluation and follow-up training of click rates
For SMBs providers like SoSafe, Hoxhunt, Knowbe4 or affordable local alternatives are sufficient — the main thing is that proof exists.
Incident Response Plan — Written, Rehearsed
The plan for what to do in a claim must be in writing by 2026. Minimum content that insurers check:
- Escalation chain — who calls whom when?
- External contacts — insurer hotline, IT service provider, IT forensics provider, BSI reporting obligations
- Initial measures — isolating affected systems, preserving evidence, communication
- Restart sequence — which systems go back online first?
- Rehearsed? An unrehearsed plan does not count for many insurers; at least an annual table-top exercise is expected
Network Segmentation — No More Flat Network
A point often underestimated: flat networks where every endpoint can reach every server are accelerators in a ransomware incident. Insurers in 2026 demand:
- VLAN segmentation between client and server networks, between production and office
- Access restriction to critical servers (domain controllers, backup servers, databases) via firewall rules
- No direct SMB/RDP from the client network onto production servers
In practice that means OPNsense or other firewalls at important boundaries, micro-segmentation in larger environments. See OPNsense VLAN routing: best practices.
Emergency Restore Test Documented
Perhaps the most frequently “forgotten” point: regular documented restore tests. Not “we tried once”, but:
- Date, system tested, data state tested
- Restore time (RTO) — target vs. actual
- Data loss (RPO) — target vs. actual
- Anomalies, corrective measures
Insurers want to see that the RTO/RPO values stated in the questionnaire are realistic. Anyone who ticks “RTO four hours” but takes three days in a claim will have to justify it.
The Questionnaire Gets Longer — and More Detailed
What was a two-page questionnaire in 2020 is in 2026 often a 15-20 page document plus additional audit questions. Typical additional items:
- Cloud setup (Which providers? Which access? IAM setup?)
- Supply chain risks (Which critical software suppliers? When was SBOM last reviewed?)
- Third-country data transfers (GDPR aspects)
- NIS2 status — many insurers explicitly ask whether NIS2 obligations apply and how they are implemented (see NIS2 SMB obligations 2026)
The answers are not only the entry door to insurance, but are examined verbatim in a claim. Anyone who answers incorrectly (even by accident) risks the benefit.
Practical Recommendation: Fill Honestly Once, Then Close Gaps
From our consulting practice: the most effective preparation for cyber insurance is to fill out the questionnaire once honestly — even if it is not yet submitted. The “no” answers automatically yield the to-do list. The most common gaps in German SMBs in 2026:
- MFA missing for admin accounts or VPN
- Patch management not documented
- No EDR (just classic AV)
- Backups online and without immutability
- Last training years ago, no documentation
- No written IR plan
- Flat network without segmentation
Each of these can be remedied with manageable effort. Anyone who closes them not only gets cyber insurance on better terms — they have already worked through the most important ransomware resilience list.
Conclusion
Cyber insurance is no longer a “comfort policy” in 2026, but a complementary component of a serious security strategy. Insurers check what is in place — before signing and in claims. Deductibles and sublimits rise, and requirements get more detailed.
The good news: the required measures are all technically sensible — they really protect the company, not just formally. Anyone who implements them sleeps better, with or without a policy. DATAZONE supports SMBs in building these minimum standards and preparing cyber insurance questionnaires — with a focus on what actually reduces risk, not pure compliance theatre.
More articles
ISO 9001 for IT Service Providers: Realistic Preparation
ISO 9001 without theatrics: document processes, schedule internal audits sensibly, budget honestly -- a pragmatic guide for IT service providers with 10 to 20 staff.
TrueNAS Made in USA: Honestly Assessing the Data Privacy Debate for EU Customers
TrueNAS is developed in the US -- is that a GDPR problem? An honest look at CLOUD Act, telemetry, source-available code and support contracts for EU customers.
GDPR Data Processing Agreements: 3 Typical SMB Mistakes
DPA, sub-processors, third-country transfers: the three most common GDPR mistakes in SMBs and how to close them with a solid DPA register.