Cyber insurance requirements in 2026 are no longer a back-office formality. Carriers now verify specific controls before binding coverage, and missing controls increasingly result in higher premiums, narrower coverage, or claim denial.
Most small and mid-sized businesses in Edmonton encounter cyber insurance the same way: a renewal questionnaire arrives from the broker, the IT team scrambles to answer it, and the policy either binds at a premium higher than last year or comes back with new exclusions. The pattern is predictable because the underwriting model has changed. After several years of large ransomware loss ratios, carriers tightened standards. Today the questionnaire is not a formality. It is the underwriting decision.
This guide walks through what cyber insurers actually verify in 2026, the 12 controls that show up on almost every questionnaire, how those controls affect premium and insurability, the questions worth pre-answering before the broker calls, and what triggers claim denial after an incident.
Why cyber insurance changed
For most of the last decade, cyber insurance was easy to buy and inexpensive. The market then absorbed several years of catastrophic ransomware losses and reinsurance support tightened. Carriers responded by raising premiums, narrowing coverage, adding exclusions, and most importantly, verifying the security controls of the insured before binding.
The practical effect for a small business is that the answers on the renewal questionnaire are no longer self-reported with no follow-up. Carriers now perform external attack-surface scans, request screenshots and configuration evidence, and in some cases run automated control attestation through partner platforms. Misrepresentation on the questionnaire, intentional or not, is now a known basis for claim denial.
The 12 controls insurers actually verify
Questionnaires vary by carrier, but the underlying expectations have converged. The following 12 controls appear, with minor wording differences, on almost every 2026 questionnaire.
1. MFA on all remote access
Every remote access path must require multi-factor authentication. This includes VPN, RDP gateways, Citrix, ZTNA portals, web-based admin consoles, and any third-party remote support tooling. A single exception path with password-only access typically results in a coverage exclusion or denial.
2. MFA on all administrative and privileged accounts
Domain admins, Microsoft 365 global admins, hypervisor administrators, backup administrators, and firewall administrators all require MFA. Service accounts that cannot use MFA require compensating controls: vaulting, just-in-time elevation, or strict network restrictions.
3. EDR on all endpoints and servers
Antivirus alone is no longer accepted by most carriers. Endpoint Detection and Response with behavioral analysis, isolation capability, and centralized visibility is now baseline. Microsoft Defender for Endpoint, CrowdStrike Falcon, SentinelOne, and Sophos Intercept X are common picks. Coverage must extend to servers, not just workstations.
4. Immutable backups with offsite copy
Backups must be immutable for a defined retention window, stored offsite, and demonstrably tested. The 3-2-1 rule has been updated in practical underwriting to 3-2-1-1-0: three copies, two media types, one offsite, one immutable, zero unverified restores. Carriers increasingly ask for the date of the last successful restore test.
5. Tested incident response plan
A documented incident response plan with named roles and a tabletop exercise within the last 12 months. The plan must include cyber insurance notification timelines and the carrier’s incident response hotline.
6. Email security with anti-phishing controls
Spam filtering, attachment sandboxing, URL rewriting, DMARC enforcement, and inbound impersonation protection. For Microsoft 365 environments, Defender for Office 365 Plan 2 or an equivalent third-party product is now baseline.
7. Privileged Access Management
Some form of credential vault, just-in-time elevation, or session brokering for highly privileged accounts. For small businesses, this often means a lightweight PAM tool or, at minimum, isolated admin workstations and tier-zero account separation.
8. Vulnerability and patch management
Operating system and third-party patches applied within a defined SLA, edge appliance firmware kept current, and vulnerability scanning in place. Carriers now perform external scans during quoting and questions about known unpatched CVEs at the perimeter come up directly.
9. Security awareness training
An annual or quarterly training program for all employees, with phishing simulation tracking. Carriers do not usually verify content quality, but they do ask for completion rates and program cadence.
10. Network segmentation
Separation between user networks, server networks, guest WiFi, IoT, and management networks. Flat networks are a frequent finding in claim denials for ransomware events because they amplify blast radius. Even basic VLAN segmentation, properly enforced, materially changes underwriting.
11. 24×7 monitoring or managed SOC
Either an internal SOC or a managed detection and response service. For most SMBs in Alberta this is delivered through a managed SOC partner. Carriers ask for the provider name and the response SLA.
12. Data classification and retention policy
Documented data classification, retention requirements, and disposal procedures aligned to regulatory obligations. This control is the one most frequently weak in small business environments because it requires written policy, not just technical configuration.

How controls affect premium and insurability
Underwriting outcomes follow control maturity. Businesses without baseline controls often have coverage declined outright, especially for ransomware. Businesses with partial controls usually receive coverage at higher premiums with exclusions, most commonly for ransomware extortion payments, business interruption, and dependent-business losses. Businesses with all baseline controls verified typically receive standard pricing with fewer exclusions. Businesses with baseline plus advanced controls (PAM, segmentation, managed detection and response) receive preferred pricing with broader coverage and lower retentions.
The premium spread between weak and strong control posture for a small business in Edmonton can be material. Equally important is that strong control posture often means a policy actually pays in a covered event, where a weak posture risks the claim being challenged for misrepresentation.
What triggers claim denial
Three patterns drive claim denial in our experience.
The first is misrepresentation on the questionnaire. The questionnaire claimed MFA on all remote access, the incident investigation reveals one VPN account without MFA. The carrier disputes coverage on the basis of misrepresentation, not because the missing MFA caused the incident, but because the application was inaccurate.
The second is failure to maintain a stated control. The questionnaire reported EDR deployed, but at the time of the incident a meaningful number of endpoints had the agent uninstalled, never installed, or in a non-reporting state. Carriers increasingly require the insured to maintain controls, not just have them at policy inception.
The third is late notification. Policies typically require notification within a specific window after the insured knew or should have known about an incident. Delays driven by internal politics or hope-it-resolves-itself often jeopardize coverage. The carrier’s hotline should be the first call, before legal and before customers.

Preparing for the renewal questionnaire
The pre-renewal sequence that works for small business is short.
- Request a copy of last year’s submitted questionnaire and current policy from the broker.
- Walk every answer against the current environment. Verify, do not assume.
- Identify any control that has degraded since last submission (an MFA exception added, an EDR agent uninstalled on a server, a backup that has not been restore-tested in 18 months).
- Document the evidence the carrier will likely ask for: tenant configuration screenshots, EDR coverage reports, last restore test date, last tabletop exercise date.
- Fix or formally accept any remaining gaps before submission, with a written remediation plan if a fix cannot be done in time.
Done early, this sequence typically lowers the premium quote, expands coverage, and dramatically reduces the risk of claim dispute. Done at the last minute, it usually does the opposite.
FAQ
Do small businesses really need cyber insurance?
In 2026, for most businesses with customer data, regulated information, or material operational dependence on IT, yes. The cost of a single covered event commonly exceeds annual policy cost by orders of magnitude.
Can a managed service provider improve our insurability?
A capable provider can. The provider delivers and maintains the baseline controls carriers verify, documents evidence required for the questionnaire, and provides the 24×7 monitoring component many carriers now require.
What is the single most common reason for coverage refusal?
Incomplete MFA coverage, almost always on a legacy remote access path that everyone forgot existed.
Does cyber insurance cover ransom payments?
Some policies do, with conditions and sublimits. Many policies in 2026 carry ransomware-specific sublimits, retention increases, and conditions including approval by the carrier before any payment. Several jurisdictions are also moving toward restrictions on ransom payment, which the policy will reflect.
How long before renewal should we start preparing?
For a clean renewal, 60 to 90 days. For a business that needs to implement controls before renewal, 4 to 6 months is more realistic, especially if EDR, backup, or identity work is needed.
If you are renewing or applying for cyber insurance
Most small businesses approach the questionnaire reactively. The teams that get the best premium and broadest coverage approach it proactively, with control evidence ready and gaps fixed in advance. The work is finite and translates directly to lower premium, better coverage, and lower claim-denial risk.
Our team helps Edmonton businesses prepare for cyber insurance underwriting, close control gaps before renewal, and produce the evidence carriers actually verify. Book a cyber insurance readiness assessment. We will walk your environment against current underwriting expectations, identify gaps that will affect your renewal, and provide a remediation plan you can act on with or without us.