Endpoint Authority

Cyber Insurance Endpoint Requirements for SMB Policyholders

Insurers now demand five baseline security controls that SMBs must prove in place to get coverage.

Senior Writer · · 10 min read
Cover illustration for “Cyber Insurance Endpoint Requirements for SMB Policyholders”
Compliance Outcomes · September 30, 2026 · 10 min read · 2,300 words

Cyber insurance used to require a short form, a few yes-or-no questions, and a check for the premium. That process is gone. Carriers have moved from low-bar checkbox applications to detailed security-maturity audits, and businesses that haven't updated their security posture in the past two years may be operating under a policy that no longer reflects what insurers actually expect.

How cyber insurance underwriting shifted to security audits

The change tracks the money. Ransomware claims climbed hard between 2021 and 2024, carriers paid out more than they'd priced for, and a good number simply left the SMB segment rather than keep absorbing the losses. The carriers that stayed did the opposite of what a business might hope: they hired underwriting staff with actual technical backgrounds and made the applications longer and harder to bluff through.

The application process now, in a lot of cases, asks more detailed security questions than the vendor questionnaires large enterprises send their own suppliers, a real shift in who's asking the harder questions.

For an SMB, the consequence is straightforward and comes in only a few flavors. A company that can't show specific controls in place ends up paying a lot more for the same coverage, getting exclusions written into the policy, or getting turned down outright. One industry analysis of the 2026 cyber insurance market found premium increases in a significant range for businesses that can't meet the newer standards. Marsh McLennan's 2024 report found that a large share of applications get denied on the first submission, and the top two reasons were both familiar: missing multi-factor authentication and endpoint protection that didn't meet the bar.

Why insurers price SMBs as the primary target

None of this is arbitrary. Insurers tightened up on SMBs specifically because small businesses have become the primary target for ransomware operators, and that means the pool of companies insurers are covering has gotten a lot riskier to underwrite.

The logic from the criminal side is simple enough. SMBs run weaker defenses than large enterprises, work with smaller IT budgets, and yet still sit on customer data, financial records, and business intelligence worth stealing or holding for ransom. That combination makes them the easier mark.

The numbers back this up. The Verizon 2025 DBIR found ransomware accounted for a far larger share of SMB breach incidents than large-enterprise incidents. And the same report traced how these attacks usually start: credential theft through infostealer malware, often weeks or months before the actual encryption event hits. By the time a business notices something's wrong, an attacker may have already been inside the network for a season.

Two other forces have widened the exposure further. Ransomware-as-a-service has turned a sophisticated crime into a subscription product, letting affiliates pay a fee or split the revenue to run someone else's attack platform. That's dropped the technical skill required to run a ransomware campaign while growing the number of people running them. Layer AI on top of that: AI-generated phishing now makes up a large majority of detected phishing emails, and AI-enabled fraud jumped sharply through 2025. All of it sits on a longer trend, with cyber attacks overall up more than 160% since 2020. Insurers are pricing a threat they can measure.

The five controls that now form the non-negotiable baseline for coverage

Diagram: The Five Non-Negotiable Controls for Cyber Insurance Coverage. Visualizes: Visualize the five baseline security controls that insurers now require as a floor for cyber insurance coverage, showing them as a ranked or ordered stack with the…

Five specific controls now make up the floor for coverage: enforced multi-factor authentication, endpoint detection and response (EDR) or managed detection and response (MDR) across every endpoint, backups that are immutable and actually tested, a written and rehearsed incident response plan, and verification of vendor security. Carriers ask about all five directly, and in a growing number of cases, they want proof beyond an answer on a form.

Enforced MFA, everywhere

Coalition's 2024 Cyber Threat Index found that the vast majority of insurance claims involved organizations that had no MFA in place. The word carrying the weight here is "enforced." MFA that exists as an option employees can skip doesn't satisfy most underwriters anymore. Applications now ask directly whether users can bypass it, and the only acceptable answer is no.

Scope matters as much as enforcement. Coverage is required across email, VPN, RDP, cloud applications, and all admin accounts, and coverage limited to email only is a common gap that appears at claim time. A business that locked down email years ago and stopped there often has that gap appear during claim review, exactly when it matters most. Some carriers have also started moving away from SMS-based MFA as an accepted method, pushing businesses toward app-based or hardware authentication instead.

EDR or MDR on every endpoint

Roughly 96% of cyber insurers now mandate EDR or MDR deployed across every endpoint: laptops, desktops, servers, and often cloud workloads too. Traditional antivirus doesn't clear that bar anymore. Insurers want tools that watch for suspicious behavior as it happens, not software that only blocks threats it already recognizes from a signature catalog.

The coverage has to be total. One unmanaged laptop sitting outside the monitoring net is enough to disqualify an otherwise solid application. For SMBs without a security team on staff, this used to be the hardest requirement to meet. MDR solves that specific problem: it's a managed service that provides round-the-clock monitoring on the business's behalf, and insurers accept it as satisfying the requirement without the business having to hire anyone.

Backups that are immutable, offsite, and tested

An external hard drive doesn't count anymore, and neither does a backup sitting in the same cloud environment as the systems it's protecting. Ransomware specifically hunts for backup targets and encrypts them first, so a backup that lives next to the production environment is often the first thing an attacker destroys. Underwriters now ask pointed questions: what's the recovery time objective, when was the last test restore actually run, and are the backup credentials kept separate from the primary admin accounts. Some carriers are now asking for quarterly restoration test documentation rather than an annual check-in.

Underwriters focus on one question: whether the business can recover its data without paying the ransom, because working backups take away the attacker's main source of leverage.

A written, tested incident response plan

A plan that's never been rehearsed tends to fall apart the moment it's needed. Underwriters now ask when the plan was last reviewed and whether the business has actually run a tabletop exercise, beyond confirming a document exists somewhere in a shared drive. The bar has moved well past "call IT if something breaks." Carriers expect defined roles, breach notification procedures, containment steps, and documented lessons pulled from past exercises or real incidents.

Guardz 2025 research found that only a minority of SMBs have a formal incident response plan of any kind. Most businesses reading this are already behind on a control insurers now treat as standard.

Vendor security verification

This is the requirement that catches SMBs off guard most often. Insurers now ask about the security posture of the vendors and SaaS tools a business relies on, alongside the business's own network. SOC 2 Type II reports, or something equivalent, are being requested even from small businesses, particularly around cloud platforms, payroll providers, and any tool that touches sensitive data. A vendor that can't produce that documentation risks getting flagged during underwriting, so it pays to review the vendor stack before the renewal conversation starts, not in the middle of it.

Why partial implementation gets claims denied

Holding a policy and actually satisfying its terms are two separate things, and the gap between them is where the real danger sits. The riskiest position a business can be in is believing it's covered while having answered the application loosely, unable to prove those controls were actually implemented if a claim ever gets filed.

Call it the partial implementation trap. Five controls, including EDR or MDR across all endpoints, form the baseline that most carriers will specifically ask about and in many cases require proof of. It answers "yes" to backups that exist but have never once been test-restored. Each of these creates a documented misrepresentation, and carriers use exactly that kind of gap to deny claims.

Over two-fifths of cyber insurance claims filed in 2024 got denied, most often because the required controls were either missing entirely or couldn't be verified once the incident happened. A higher premium isn't the worst-case outcome here, either. If a carrier pays out a claim and later discovers a control was misrepresented on the application, it can go after the business to recover that money. At that point, the business is covering both the original breach costs and a legal fight with its own insurer.

The fallout doesn't stop at the insurance relationship. Industry data shows 67% of vendors lost contract opportunities in 2024 because their coverage was found insufficient. A denied claim or a thin policy can cost business relationships that have nothing to do with the breach itself.

Carriers have adjusted for this by asking for documentation instead of taking a business's word for it: network diagrams, written security policies, employee training records, vendor agreements, incident response plans, and evidence the security tools are actually deployed. The right move before applying is to audit the business's actual control state first, document what's really in place, and where gaps appear, work with a broker to sort out which ones will sink the application and which can be fixed inside the underwriting window.

How requirements vary by industry and coverage tier

The five baseline controls apply no matter the industry, but regulated sectors carry additional requirements and higher minimum coverage limits layered on top. The baseline is a floor. It isn't the finish line for every business.

Healthcare has to meet HIPAA and HITECH standards: encrypted patient data, access controls around medical records, formal breach notification procedures, and minimum coverage limits that climb for larger organizations. Retailers need PCI-DSS compliance, quarterly vulnerability scans, and network segmentation, with limits that stay lower for small retailers and rise considerably for larger chains.

Manufacturers need separation between IT and OT networks along with secured remote access, with limits scaling to organization size. Professional services firms face a lighter add-on: client data encryption and a solid email security baseline, with limits lower for small firms and higher for larger ones.

Coverage tier matters just as much as industry. Larger policies typically call for penetration testing and formal security audits regardless of sector. And one requirement is appearing across carrier applications heading into 2026 regardless of industry: Privileged Access Management. That means admin accounts kept separate from daily-use accounts, privileged access that's logged and monitored, just-in-time access provisioning instead of standing permissions, and a password vault for service accounts. Businesses should confirm the specifics with a broker, since requirements shift by carrier and change often enough that last year's checklist isn't a safe guide.

Sequencing implementation from a partial or zero baseline

Diagram: Implementation Sequence: From Zero to Insurable. Visualizes: Show the four-phase implementation sequence the article prescribes for a business rebuilding its security posture before a renewal: Phase 1 — Identity controls (MFA enforcement +…

A business staring down a renewal without a current security program needs an order of operations rather than a scattered list of fixes. The sequence that addresses the most common causes of claim denial first runs: identity and endpoint controls, then backups and the incident response plan, then vendor verification.

Identity comes first because credential theft is the most common way attackers get in the door. MFA enforcement and privileged access controls deliver value almost immediately, and they're cheap to roll out, often achievable within days rather than weeks.

EDR or MDR deployment across every endpoint comes next, and it has to cover every device with no exceptions. For a business without a security operations team, MDR provides the needed staffing while still satisfying what insurers ask for. Budget one to two weeks for the rollout.

Backups need to move offsite or air-gapped, with credentials kept separate from the primary admin accounts and a documented recovery time objective. Set up a quarterly test schedule right away, so there's actual documentation to show at renewal instead of a policy that's never been exercised.

The incident response plan doesn't need to run long. Underwriters want defined roles, clear breach notification steps, and proof that at least one tabletop exercise has happened, and a plan meeting that bar can get drafted and tested in a short sprint. Vendor audit comes last in the sequence: inventory the critical vendors, cloud platforms, payroll systems, any SaaS tool touching sensitive data, and request SOC 2 Type II reports from each one. Flag anything that can't produce documentation.

Timeline matters more than most businesses expect going in. Applications where all the controls are already in place move through underwriting fast. Applications that need security improvements first take considerably longer, so starting well before coverage is actually needed makes a real difference.

That kind of patchwork adds configuration overhead, stretches out implementation timelines, and tends to leave seams that an insurer's audit will find. An integrated platform that handles device management, endpoint security, identity protection, and compliance documentation in one deployment can shrink that timeline substantially, getting a business to an insurable posture without stitching together a stack piece by piece.

What to document before the application and during underwriting

Underwriters don't take a business's word for its security posture anymore. They want documents that back up every claim on the application: network diagrams showing how systems connect, written security policies, employee training records, signed vendor agreements, the incident response plan itself, and evidence that the security tools listed on the form are actually deployed and running.

Businesses that gather this before applying, rather than scrambling once an underwriter asks, tend to move through the process faster and end up with fewer surprises in the final terms. The application itself is really an audit with a premium attached to the results. Treating it that way, well before the renewal date, is what keeps a policy worth the paper it's printed on.

Sources

  1. Cyber Insurance Requirements (2026 Guide)
  2. Cyber Insurance Readiness for SMBs: 2026 Requirements - Fairdinkum
  3. What Your Business Needs to Qualify for Cyber Insurance in 2026 - Prescient Solutions

More in Compliance Outcomes