ClickCerts
Back to all posts

Your Cyber Insurance Renewal Just Got Harder. Here’s What the Application Actually Asks For Now.

41% of cyber insurance applications get denied. The 10 categories carriers actually evaluate, what they want to see, and how to close gaps before you submit.

July 23, 2026ClickCerts Team
Your Cyber Insurance Renewal Just Got Harder. Here’s What the Application Actually Asks For Now.

A checklist for any business filling out a cyber insurance application or renewal in 2026. MSPs: this post is built for forwarding to your customers.

If you’re renewing your cyber insurance this year, you’re about to fill out a longer, harder application than the one you filled out 18 months ago. The questions are more specific. The carrier wants screenshots and policy exports, not verbal attestations. And if your answers don’t line up with what they expect, your renewal either gets denied or comes back with a premium that doubles.

This isn’t hypothetical. According to Marsh McLennan’s 2024 data, 41% of cyber insurance applications get denied on first submission. The top two reasons are missing multi-factor authentication and inadequate endpoint protection. Coalition’s 2024 Cyber Threat Index found that 82% of denied claims involved organizations without MFA. Symquest’s analysis reports that 44% of cyber insurance claims overall are rejected due to inadequate security controls, meaning the insurance was bought, the breach happened, and the carrier walked away from the claim.

This ClickCert post walks through what cyber insurance applications actually ask for in 2026, what answers move the needle on premiums and approvals, and how to prepare before you submit. It’s organized so you can scan to the section that matches whatever your application is asking about.

MSPs reading this: this content is built to be forwarded to your customers. The middle sections are written customer-facing. Send it to anyone whose renewal is coming up.

Why the questions got harder Cyber insurance carriers got hammered between 2020 and 2022. Ransomware claim severity exploded. Loss ratios at major carriers crossed 100%, meaning they were paying out more in claims than they were collecting in premiums. The market response was predictable. Premiums spiked, coverage shrank, and underwriting got dramatically stricter.

By 2024, premium increases had moderated. By late 2025, some segments saw modest premium relief, conditional on demonstrably stronger controls. But the underwriting rigor never went back. Carriers learned that the way to limit losses isn’t to charge more, it’s to only insure organizations that have actually done the work. The application became the gate, and the gate keeps getting narrower.

The specific shift, in plain terms: questionnaires used to be checkbox attestations. Today’s applications increasingly demand evidence. Screenshots of MFA enforcement policies. Coverage reports showing EDR is deployed across all endpoints. Policy exports. Test restore reports for backups. Tabletop exercise summaries from your last incident response drill. Beazley’s standard cyber application now asks specifically whether you require MFA for remote access and web-based email, what endpoint security solutions you use including EDR or MDR, and whether you have an incident response plan for intrusions and malware. Most major carriers ask similar questions.

If your answers don’t come with proof, expect either a longer underwriting cycle, a higher premium, or a denial.

The categories the application will cover

Almost every modern cyber insurance application from carriers like Coalition, Travelers, Beazley, AIG, Chubb, and Marsh-affiliated underwriters covers the same eight to ten core categories. The exact wording varies, but the substance is consistent. Walk through each below, with what carriers ask, what answer they want to see, and what action closes the gap if you’re not there yet.

1. Multi-factor authentication (MFA) What carriers ask: Do you require MFA for remote access (VPN, RDP)? Do you require MFA for email (Microsoft 365, Google Workspace)? Do you require MFA for privileged or administrator accounts? Do you require MFA for cloud platforms and admin consoles? Some carriers also ask about MFA on backup systems specifically, since attackers target backups during ransomware events.

What they want to see: MFA enforced organization-wide, not just available. Phishing-resistant MFA (FIDO2 hardware keys or platform authenticators) is increasingly preferred for privileged accounts. Carriers want to see the enforcement policy itself, not just “yes we have MFA.”

What to do if you’re not there: MFA is the single most important gap to close before submitting. It’s also one of the fastest. Microsoft 365 and Google Workspace can enforce MFA from their admin consoles. VPN and RDP MFA take a few days. Plan one to two weeks for full deployment. Costs run $3 to $6 per user per month for most enterprise MFA tools. Tools like Microsoft Authenticator, Duo, Okta, and Google Authenticator all meet carrier requirements. Start with admin accounts, then email, then remote access.

2. Endpoint detection and response (EDR) What carriers ask: What endpoint security do you use? Is it deployed on all endpoints, including servers, workstations, and laptops? Does it provide real-time monitoring and automated response? Is it actively managed (24/7) or just installed?

What they want to see: A real EDR or MDR product, not legacy antivirus. Examples carriers commonly accept: CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, Sophos Intercept X, Huntress. Active monitoring (either by your in-house team or by a managed detection and response vendor) is increasingly required for organizations above a certain size. Carriers want a coverage report listing protected endpoints by OS and policy.

What to do if you’re not there: If you’re still running traditional antivirus, plan for a four to six week deployment of a real EDR product. If you don’t have a security operations center capable of monitoring it, look at MDR services that bundle the tool with 24/7 monitoring. EDR runs $5 to $15 per device per month; MDR services run higher but solve the monitoring problem.

3. Backups and recovery What carriers ask: How frequently are backups performed? Are backups stored offline or immutable? Are backups MFA-protected? Have you tested restores in the last 12 months? How long does it take to restore from backup?

What they want to see: Immutable or offline backups (a copy that ransomware can’t encrypt because it’s logically isolated or write-once). Coalition reports that 94% of organizations hit by ransomware see attackers attempt to target backups, which is exactly why carriers care. Test restore reports from within the past year. Documented recovery time objectives. MFA on the backup system itself.

What to do if you’re not there: Modern business backup products (Veeam, Datto, Acronis, Rubrik, others) all support immutable backups. If you’re using only file-level cloud sync (Dropbox, OneDrive) as your backup, that doesn’t count, those are sync products and ransomware encrypts them too. Get a real backup product with immutability, run a documented test restore, and keep the report for your application.

4. Security awareness training What carriers ask: Do all employees receive security awareness training? At what frequency? Do you maintain records of training completion? Was training last delivered within the past 12 months?

What they want to see: Annual training as the absolute minimum, with quarterly increasingly preferred. Phishing simulations either bundled with training or run separately. Documented completion records. Marsh McLennan research has identified security awareness training as one of the controls most strongly associated with reduced claim likelihood, alongside MFA and EDR.

What to do if you’re not there: This is the gap most companies discover during the application and scramble to close. Annual training is the fastest fix, quarterly is the right answer. Look for a platform that produces serial-numbered certificates and exportable completion records, because the carrier may want to see them. ClickCerts is built specifically for this requirement; quarterly courses, certificate-based completion records, and audit-ready reporting. We handle this control cleanly so you can check it off and focus your time on the harder controls. Worth flagging that we’re not a complete cyber insurance compliance solution; we satisfy the training and phishing-awareness requirement, not the other nine categories on the application.

5. Incident response plan What carriers ask: Do you have a written incident response plan? Has it been reviewed in the past year? Has it been tested through a tabletop exercise? Who is the designated incident commander? What is your escalation path?

What they want to see: A real document, not a paragraph in your handbook. Tested in the past 12 months through at least a tabletop exercise. Updated to reflect current systems and current threats. Many carriers ask for a copy or for a summary of the last tabletop exercise.

What to do if you’re not there: NIST publishes a free incident response template (SP 800-61) that’s a perfectly good starting point. The plan should cover detection, containment, eradication, recovery, and lessons learned. Run a tabletop exercise (a structured discussion walking through a hypothetical scenario) within the next 60 days and document it. If you have an MSP or MSSP, this is a service they should be running for you, and they should produce the documentation.

6. Patching and vulnerability management What carriers ask: How quickly do you apply critical security patches? Do you have a documented patching SLA? Do you run vulnerability scans? How frequently? How quickly do you remediate critical vulnerabilities?

What they want to see: Critical patches deployed within 14 days. Quarterly vulnerability scanning at minimum, monthly preferred. End-of-life software either removed or explicitly isolated. Change tickets and scan reports as evidence.

What to do if you’re not there: If your patching is informal (“we try to keep things updated”), formalize it. Most managed antivirus and RMM tools include patch management. The application is going to ask for specific time windows, so define them. “Critical patches within 14 days, high within 30, medium within 90” is a defensible standard.

7. Privileged access management What carriers ask: How many privileged or administrator accounts do you have? Are they separate from daily-use accounts? Do they require MFA? Do you use a privileged access management (PAM) tool? How are admin credentials stored?

What they want to see: Admin accounts that are separate from regular user accounts (so an admin’s daily email and browsing happen on a non-privileged account). MFA enforced on all admin accounts. A defensible inventory of who has admin access. A password manager or PAM tool for storing admin credentials, not a spreadsheet.

What to do if you’re not there: At minimum, separate admin accounts from daily-use accounts and put MFA on all of them. A full PAM tool (CyberArk, BeyondTrust, Delinea) is overkill for most small and midsize businesses, but a business password manager (1Password Business, Bitwarden Business) plus separation of admin accounts gets most of the way there for a fraction of the cost.

8. Email security What carriers ask: What email security do you use beyond what’s built into your email platform? Do you have advanced threat protection? Anti-phishing? DMARC enforcement on your sending domain?

What they want to see: Either Microsoft Defender for Office 365 (or the equivalent in Google Workspace), or a third-party email security gateway like Proofpoint, Mimecast, Abnormal Security, or IRONSCALES. DMARC configured on your sending domain in enforcement mode (p=quarantine or p=reject), not just monitoring.

What to do if you’re not there: Microsoft 365 Business Premium and Google Workspace Business Plus both include strong email security in their pricing. If you’re on a lower tier, the upgrade is often the cheapest way to satisfy this control. DMARC configuration takes a few hours of DNS work.

9. Vendor and supply chain risk What carriers ask: Do you maintain an inventory of third-party vendors with access to your systems or data? Do you require security questionnaires or attestations from vendors? Do you have written agreements covering security and data handling?

What they want to see: A vendor inventory. Risk-tiered review of vendors by what data they touch. Written contracts (data processing agreements, business associate agreements where applicable). For higher-risk vendors, recent SOC 2 reports or equivalent attestations.

What to do if you’re not there: Start by listing every vendor with access to your systems or sensitive data. For each, capture what they have access to and whether you have a security agreement in place. This is a documentation exercise more than a tool exercise. The application probably won’t ask for the inventory itself, but they’ll ask if you have one and if you can produce it on request.

10. Encryption What carriers ask: Is sensitive data encrypted at rest? Is it encrypted in transit? Are mobile devices encrypted?

What they want to see: Yes to all three. Disk-level encryption (BitLocker on Windows, FileVault on macOS) on all laptops and workstations. TLS 1.2 or higher for data in transit. Database-level encryption for sensitive data stores.

What to do if you’re not there: BitLocker and FileVault are free and built in. If they’re not enabled, deploy them via group policy or MDM within a week. TLS configuration on web services is usually already in place; verify it. Database encryption is more involved and depends on what you’re running.

What to do before submitting the application

Three things to put in place before you start filling out the form.

Build a proof pack. Carriers increasingly want evidence with the application, not just attestations. Assemble a folder with: MFA enforcement policy screenshots, EDR coverage reports, backup test restore reports, tabletop exercise summaries, training completion records, vendor inventory, and copies of your incident response plan. Submitting a complete proof pack with the application typically compresses underwriting from weeks to days.

Pre-underwriting review. Walk through the application with someone who knows what carriers actually verify (your broker, your MSP, or a fractional CISO). They’ll spot the questions where your proposed answer is going to trigger a follow-up or a denial, and you can fix the gap before you submit. This is often the difference between a one-shot approval and a three-month back-and-forth. Plan 60 to 90 days. If you’re missing controls, you can’t close the gaps in the week before your renewal date. Most security control deployments take one to eight weeks. Start the prep work three months before your renewal so you have time to fix what’s broken before the application is in front of an underwriter.

Where MSPs come in

If you have a managed service provider, the work above is mostly their job. MFA, EDR, backups, patching, email security, vendor management, encryption: these are core MSP services. The MSP should be able to produce the evidence pack on demand because they’re managing the controls. If they can’t, the conversation isn’t about cyber insurance, it’s about whether you have the right MSP.

Some specific things to ask your MSP before your next renewal. Do you have an MFA enforcement report you can pull for me? Can you give me an EDR coverage report? When was our last test restore from backup, and can I see the report? Can you walk me through our incident response plan and tell me when we last tested it? What’s our current patching SLA, and what evidence do we have that we’re hitting it? If the answers come back fluently, you have the right MSP. If they don’t, you have a finding for your renewal.

Security awareness training is the one piece that often falls outside the MSP’s normal scope. Some MSPs offer it as a service line, some don’t. If yours doesn’t, ask why. Adding training to an MSP relationship is straightforward and closes the carrier’s most common application question.

+++++ The cyber insurance application has become a security audit in disguise. The questions map directly to the controls that prevent the claims carriers are tired of paying. If you can answer them with evidence, you’ll get coverage at a reasonable rate. If you can’t, you’ll either pay more or get denied.

The good news is the list isn’t long. Ten categories, all of which are basic security hygiene, all of which most businesses should have in place anyway. The application just makes it explicit. Walk through the list, identify the gaps, and start closing them now. You’ll get a better renewal outcome and a more secure business in the same exercise.

And if your renewal is in 60 days and you’re reading this with a sinking feeling, the place to start is MFA. It’s the gap that drives the most denials and the fastest one to close. Everything else can be staged.

MSPs: forward this freely. We built it to be a customer-facing resource. Email sales@clickcerts.com if you’d like to talk about the security awareness training piece specifically. Related reading: “You Don’t Need 1,000 Training Modules. You Need Your Team Trained.” for more on what training programs actually need to do, and “60% of Breaches Start with a Click. Here’s How to Stop Yours.” for the underlying threat data.

Subscribe

Updates that don’t suck.

A short note when we ship something worth knowing about. No spam, no drip campaigns.