Security & compliance · Field guide

Cyber-insurance requirements for small business in 2026.

Cyber-insurance has quietly tightened. Insurers now expect real security controls — MFA, EDR, tested backups, and more — just to issue a policy, renew it, or pay a claim. Here's the plain-English version of what they're asking for, why, and how to make sure you actually qualify.

By the CornerBeacon team · Published June 19, 2026 · 7 min read

A few years ago, a cyber-insurance application was a short form and a signature. That era is over. After a wave of ransomware and email-fraud claims, underwriters got strict — and small businesses are now held to many of the same security standards as large ones. The application has become a security questionnaire, and the answers you give shape both whether you get covered and whether a future claim gets paid.

None of this is meant to scare you off coverage — cyber insurance is more valuable than ever. The point is that the policy now assumes you're running a baseline of modern controls. Below is what insurers commonly ask for, in plain English, and why each one is on the list.

What insurers now commonly require

Every carrier is different, and the exact wording on your application will vary. But across the market, a fairly consistent baseline has emerged. These are the controls that show up again and again on questionnaires for issuing a policy, renewing it, and validating a claim.

Multi-factor authentication (MFA)

A second proof of identity — a code or app prompt — on top of a password, especially for email, VPN, and remote access. Why insurers want it: stolen and reused passwords are behind a huge share of breaches. MFA is cheap and stops most of them, so it's become close to non-negotiable. If you attest to having MFA and it isn't actually turned on, a claim can be reduced or denied.

Endpoint protection / EDR

Modern security software on every computer and server — endpoint detection and response (EDR) — that watches behavior, catches what traditional antivirus misses, and can isolate a device that's under attack. Why insurers want it: it shortens the window between an infection starting and something stopping it, which directly limits the size of a claim.

Managed detection & response (MDR)

EDR generates alerts; MDR puts a human team behind those alerts, watching around the clock and responding on your behalf. Why insurers want it: attacks don't keep business hours. Someone actively watching at 2 a.m. is the difference between an isolated laptop and an encrypted network.

Tested backups & disaster recovery

Regular, secured backups — ideally with copies kept offline or otherwise out of an attacker's reach — plus a plan to actually restore from them. The key word is tested. Why insurers want it: reliable backups are what let you recover without paying a ransom, which is the cheapest possible outcome for everyone. A backup nobody has ever restored from doesn't count.

Security-awareness training & phishing testing

Short, regular training for staff, usually paired with simulated phishing emails to see who clicks. Why insurers want it: most breaches start with a person, not a server. A trained team that pauses before clicking is one of the most cost-effective controls there is.

Patch & vulnerability management

Keeping operating systems, software, and firmware updated on a routine schedule, and knowing where the gaps are. Why insurers want it: attackers lean on known holes that already have fixes available. Timely patching closes the doors before someone walks through them.

An incident-response plan

A written plan for what happens when something goes wrong — who to call, how to contain it, how to notify the right people, and how to get back to work. Why insurers want it: a calm, practiced response limits damage and cost. A scramble makes everything worse, and slower.

The trap: quietly non-compliant until claim time

Here's the part that catches owners off guard. Many small businesses sign the application, check the boxes, and assume they're covered. Then a breach happens — and the insurer reviews whether the controls you attested to were actually in place. If MFA wasn't really on, or backups were never tested, a claim can be reduced or denied. The worst time to discover a gap is the day you need the policy to pay. The good news: every one of these requirements is fixable before that day.

The "are you covered?" checklist

Run through this honestly. If you can't confidently say yes to each, that's exactly where to start.

How an MSP gets you compliant

Here's the encouraging part: the controls insurers want are the same controls a good managed service provider deploys as a matter of course. There's no separate "insurance-compliance" project — it's just good security, done properly.

If you work with an MSP or security provider, ask them to map their plan against the list above and to sit with you when the renewal questionnaire lands — your answers need to match what's actually running, or a future claim can be disputed on a technicality. (A note on us: CornerBeacon isn't an MSP — we're an AI-native app development company that designs, builds, and runs custom apps and automation. For the businesses we build for, we keep the essential IT foundation solid: a security baseline of MFA, patching, and email protection, plus backups. See IT foundation.)

And because the same controls underpin other frameworks, getting insurance-ready usually moves you toward HIPAA, CMMC, and similar requirements at the same time — useful if you're in healthcare, defense supply chains, or any regulated corner of New England. One set of controls, several boxes checked.

You don't need to become a security expert. You need a partner who already runs these controls every day, and who can sit beside you when the application lands on your desk.

Questions owners ask

FAQ

What do cyber-insurers require from small businesses in 2026?

Requirements vary by carrier, but a common baseline has emerged. To issue or renew a policy — and to pay a claim without dispute — insurers now typically expect MFA on email and remote access, endpoint protection or EDR, some form of managed detection and response, regularly tested backups and a disaster-recovery plan, security-awareness training with phishing testing, patch and vulnerability management, and a written incident-response plan. These show up as questions on the application, and answering them inaccurately can put a future claim at risk.

Do I need MFA to get cyber insurance?

In practice, yes. Multi-factor authentication is one of the most consistent requirements across carriers, especially on email, VPN, and remote access. Because stolen passwords drive so many breaches, MFA is one of the cheapest, highest-impact controls — and many applications now treat it as a baseline. If you attest that you have MFA and you don't, a claim can be reduced or denied, so it's worth confirming it's actually turned on everywhere it's expected.

Can an MSP help me qualify for cyber insurance?

Yes. A managed service provider deploys and manages the exact controls insurers ask about — MFA, EDR, managed detection and response, tested backups, patching, and training — and can help you answer the insurance questionnaire accurately. Ask any provider you work with to map their plan against your insurer's questionnaire — inaccurate answers are what put claims at risk.

What is EDR and MDR?

EDR (endpoint detection and response) is modern protection software on each computer and server that watches behavior, catches threats traditional antivirus misses, and can isolate a device under attack. MDR (managed detection and response) adds a human team that monitors those alerts around the clock and responds on your behalf. Insurers favor both because they shorten the time between a breach starting and someone stopping it — which is what limits the cost of a claim.

Not sure you'd pass your insurer's checklist?

Book a free build consult. CornerBeacon designs, builds, and runs custom apps and automation — and keeps the essential IT foundation (MFA, patching, email protection, backups) solid for the businesses we build for. Prefer to read first? Grab our free AI Playbook.

Book a free build consult
CallBook a build consult