Cyber Insurance Is Becoming a Security Standard and Most Companies Are Not Ready for the Audit

For most of the past decade cyber insurance operated on an honour system. A company completed a questionnaire stating that it had MFA enabled, that it ran regular backups and that it conducted annual security awareness training. The underwriter accepted these answers largely at face value, issued a policy and moved on. The loss ratios that resulted from this approach were, to put it charitably, not sustainable.

The market has corrected.

In 2026 the major cyber insurers are no longer treating the application questionnaire as the primary underwriting instrument. They are using a combination of external attack surface scans, third party risk intelligence and in many cases direct technical assessments conducted by their own security teams before binding coverage. The implications for organisations that have been describing their security programmes more optimistically than the evidence supports are significant.

The Shift in Underwriting Methodology

The change has been gradual but it accelerated sharply after the 2021 and 2022 ransomware wave produced loss ratios above 70% across the market, meaning insurers were paying out more than 70 cents for every dollar of premium collected. Lloyd’s of London introduced binding guidance for its cyber syndicates in 2022. By 2025 the technical assessment requirement had become standard practice among the top ten carriers by premium volume.

Controls Assessed and Their Weight in Underwriting Decisions

Security ControlUnderwriting WeightMost Common Failure Mode Found by Assessors
MFA on all remote access and emailVery HighMFA deployed on primary systems but absent on secondary tools and legacy applications
Privileged access managementVery HighLocal admin rights not removed from standard user accounts
Endpoint detection and responseHighEDR deployed but running in monitoring-only mode rather than active blocking
Immutable offsite backupsVery HighBackups exist but are connected to the same network segment and could be encrypted in a ransomware event
Patch management — critical CVEs under 30 daysHighPatch process exists but exceptions accumulate and are never formally closed
Network segmentationMedium-HighFlat network architecture with no meaningful separation between corporate and operational systems
Incident response plan tested in past 12 monthsHighWritten plan exists but has never been exercised in a tabletop or simulation
Email security — DMARC, DKIM and SPFMediumSPF published but DMARC set to monitor-only with no enforcement policy

Table 1: Security controls assessed during insurer technical reviews with common failure modes identified in 2025 to 2026 assessments

The Misrepresentation Risk Nobody Is Talking About

There is a legal dimension to this shift that has received almost no attention in mainstream business media. Cyber insurance policies contain a warranty clause that requires the insured to accurately represent their security posture at the time of application and to maintain that posture throughout the policy period. If a material misrepresentation is discovered at the time of a claim the insurer can deny coverage in its entirety.

This is not a theoretical risk. It has happened. In 2023 a US court upheld an insurer’s decision to deny a $1.6 million ransomware claim after the insured’s application stated that MFA was deployed across all systems when in fact it was only deployed on the primary email platform. The ransomware entered through a legacy remote desktop protocol service that did not require MFA. The court found that the application was materially false and that the policy was void.

The precedent is now established. Organisations that complete renewal applications without conducting an honest technical assessment of their actual control state are not just accepting underinsurance risk. They are accepting the risk that a claim will be denied at the worst possible moment.

What a Realistic Preparation Process Looks Like

The organisations navigating this new environment successfully are treating the insurer’s technical assessment as a dry run for an actual audit rather than as an administrative hurdle. They commission an external attack surface assessment six to eight weeks before their renewal date and use the findings to close the gaps that an underwriter’s assessor would identify.

The second step is to conduct an honest internal review of every control listed on the application questionnaire. For each control the question is not whether you have it but whether it works as described in every context where it is supposed to apply. The distinction between having MFA and having MFA everywhere is the difference between a valid policy and a denied claim.

The third step is to ensure the risk manager completing the application has access to the actual technical evidence for each control rather than relying on verbal confirmation from IT. The person signing the application is attesting to its accuracy. That attestation should be grounded in documented evidence rather than optimistic assumptions.

The cyber insurance market is becoming one of the most effective drivers of genuine security improvement in the industry, not because carriers are altruistic but because the economics now require it. For organisations willing to engage honestly with the process that is an opportunity. For those that are not it is a significant and approaching liability.

Leave a Reply

Your email address will not be published.