Key Takeaway: Cyber insurance carriers now verify MFA enrollment percentages, EDR deployment coverage, and backup restore test dates. The three controls that cause instant denial: MFA not enforced on all accounts, EDR below 95% deployment, and backup that has never been tested. The MSP that helps clients navigate this process is delivering genuine advisory value.
Cyber insurance has become a security audit disguised as an application. The questionnaires are longer, the technical controls are more specific, and carriers are denying claims when those controls were not in place at the time of the incident. The MSP that helps clients navigate this process is delivering genuine value. The MSP that ignores it is leaving clients exposed to denied claims after the breach they were supposed to prevent.
This guide covers what carriers actually require in 2026, what gets applications denied, and how MSPs can use the cyber insurance renewal process as a client retention and advisory tool.
What Changed and Why
The ransomware wave of 2021 to 2023 pushed insurance loss ratios to unsustainable levels. Carriers that survived learned the lesson: they needed verified controls, not self-reported checklists. The application process has transformed from a questionnaire into a technical audit. Carriers now verify MFA enrollment percentages, EDR deployment coverage, and backup restore test dates. They pull DMARC records directly from DNS. They check BitSight and SecurityScorecard scores for public-facing posture.
According to analysis from BlueRadius Cyber, which has worked with dozens of MSPs through the underwriting process, the major carriers: Coalition, At-Bay, Corvus, Chubb, Travelers, and Hartford have converged on roughly the same set of required controls. Miss one and you risk denial, a premium surcharge, or a future claim denial.
The Non-Negotiable Controls: Instant Denial Without These
Multi-factor authentication (MFA). Required on email (Microsoft 365, Google Workspace), VPN, RDP, all admin and privileged accounts, and cloud management consoles. Carriers verify enrollment percentage, not just whether MFA is available. They want to see 95% or higher enforcement documented in your identity provider. The common failure: MFA enabled on email but not on the firewall admin panel, the RMM console, or the backup dashboard. One missed system is enough for a denial.
Endpoint detection and response (EDR). Required on every workstation and server, including Macs. Basic antivirus does not qualify. Carriers want behavioral detection, automated response, and ideally a managed SOC or MDR component. Products that pass: SentinelOne, CrowdStrike, Huntress with Defender for Business, Sophos MDR. Carriers verify deployment coverage percentage. 60% deployment is not sufficient. They want 95% or higher.
Immutable or air-gapped backup. Required: at least one backup copy that cannot be encrypted or deleted by ransomware. Carriers specifically ask whether backups are immutable or air-gapped. A NAS in the server closet on the same network as the endpoints does not qualify. Cloud backup with immutable retention (Axcient, Datto, Veeam with immutability enabled) is the standard. Carriers also ask when the last restore test was conducted. A backup that has never been tested is a red flag.
The Controls That Strongly Affect Pricing
Email security. DMARC enforcement at p=reject or p=quarantine, anti-phishing training with simulated campaigns, and inbound email filtering beyond basic spam. Carriers check DNS records directly. They will look up your client’s DMARC policy. If it is not set to reject or quarantine, expect a premium surcharge.
Patch management. A documented patching cadence with defined SLAs: critical vulnerabilities remediated within 14 days, high within 30 days. Carriers want evidence of remediation, not just scan reports. Mean time to remediate under 30 days for critical vulnerabilities is the standard.
Security awareness training. Ongoing training with phishing simulations at least quarterly. Products that pass: KnowBe4, Proofpoint Security Awareness, Huntress SAT. One-time annual training is not sufficient. Carriers want to see campaign metrics showing improvement over time.
Incident response plan. A written plan with defined roles, communication procedures, and escalation paths. Reviewed annually. Carriers want a document they can review, not a promise that you would figure it out. A tabletop exercise conducted in the past 12 months is increasingly required.
The Controls Becoming Standard
These are not universal requirements yet, but a growing number of carriers ask about them. MSPs that implement them now are positioning clients ahead of the curve.
Privileged access management (PAM). Separate admin accounts from daily-use accounts. No shared credentials. Just-in-time access for administrative tasks. Session recording or monitoring for privileged access.
Network segmentation. Critical systems isolated from general user traffic. Documented network architecture. Particularly important for clients in regulated industries or with point-of-sale systems.
DNS filtering. Block known malicious domains at the network level. This is already in most MSP security stacks. Document it for the insurance application.
Vulnerability scanning. Regular automated scans, not just annual penetration tests. Monthly minimum, weekly preferred. Evidence of remediation, not just scan reports.
The MSP Attestation Letter
The MSP attestation letter, in which the MSP certifies the security posture of a client’s environment to the insurance carrier, is becoming a standard part of the renewal process. Carriers are asking for it. Clients are asking their MSPs to sign it.
The MSP that can sign an attestation letter honestly is demonstrating that it knows what controls are in place and is accountable for them. The MSP that cannot sign it honestly should not sign it at all. Signing an attestation letter that misrepresents the client’s security posture creates liability for the MSP if a claim is later denied because the controls were not actually in place.
The attestation letter is also a retention tool. The client who knows their MSP will sign the attestation letter at renewal has one less reason to shop around. The client who discovers their MSP cannot or will not sign it has a reason to look for a provider who can.
How to Use Cyber Insurance Renewal as an Advisory Opportunity
The cyber insurance renewal cycle is one of the best advisory opportunities available to MSPs. Every client renews annually. Every renewal requires a security assessment. Every gap identified in the assessment is a service opportunity.
The MSP that proactively reaches out to clients 90 days before their renewal, conducts a pre-underwriting assessment, identifies gaps, and presents a remediation plan is delivering genuine vCIO value. The MSP that waits for the client to call when their renewal is denied is reactive.
The pre-underwriting assessment should cover every control on the carrier checklist: MFA enrollment, EDR coverage, backup immutability and restore testing, DMARC configuration, patch compliance, security awareness training completion, and incident response plan status. Document the findings. Present them to the client with a clear remediation plan and timeline.
Frequently Asked Questions
What is the most common reason cyber insurance claims are denied?
Misrepresentation on the application. The client stated that MFA was enforced on all accounts. The investigation after the breach revealed that MFA was not enforced on the RDP server that was compromised. The carrier denied the claim because the application did not accurately represent the security posture at the time of the incident. The MSP that helps clients accurately represent their security posture on the application is protecting them from this outcome.
How do I document security controls for the insurance application?
Pull evidence from the tools you already use. MFA enrollment reports from Microsoft Entra ID or Google Admin. EDR deployment reports from your endpoint security console. Backup job reports and restore test logs from your backup platform. DMARC policy from DNS. Phishing simulation results from your security awareness training platform. The evidence should be current, not a point-in-time snapshot from six months ago.
What if a client cannot afford to implement all the required controls?
Have an honest conversation about the risk. A client who cannot afford the controls required for cyber insurance coverage is a client who is carrying uninsured risk. The MSP’s job is to make that risk visible and help the client make an informed decision. Some clients will choose to accept the risk. That is their decision to make. The MSP’s job is to ensure they are making it with full information.
About Brent Lacy: Brent Lacy is a technology advisor and the voice behind Rewired MSP. He helps MSPs operate with greater maturity and helps business owners make IT choices that make them more secure and more efficient. He is the author of Rewired MSP: Mastery, Scalability & Performance, vCIO Rewired: Virtually Conquering IT Obstacles, and Near Miss: Preventable IT Failures Threatening Your Business Security.
Related Reading
- The Attestation Letter Your MSP Should Be Willing to Sign
- The Denied Claim: What Business Owners Are Learning Too Late About Cyber Insurance
- MSP Cybersecurity Hub
- MFA and Digital Identity: What Your IT Provider Should Be Doing
- Backup Is Not Business Continuity: What Every Business Owner Must Know