Have you looked closely at your cyber insurance renewal application lately? Or does it feel like the same form you filled out last year? Cyber insurance requirements have shifted, and the change has less to do with the coverage itself than with how carriers evaluate whether you qualify for it in the first place. What used to be a self-reported checklist has turned into something carriers verify before they ever quote a price. The real risk sits between what you say you have in place and what you can prove, in writing, when an adjuster asks.
The short version: Insurers used to take your word for it. Now they check. The gap between saying you have a control and proving it is where policies get denied. The fix starts before your next renewal, not during a claim.
Cyber Insurance Requirements Have Moved Past a Simple Checklist
For years, cyber insurance applications worked on the honor system. You answered a list of yes-or-no questions, signed off, and the underwriter took your word for it, largely because verifying every applicant’s actual environment wasn’t practical at scale. That system is disappearing fast across the SMB segment, as better tools make outside verification cheap enough to run on nearly every renewal. For the full walkthrough of how cybersecurity insurance evaluates your IT setup, see our earlier post. This one focuses on what’s changed this specific renewal cycle.
The Same Application Now Gets Tougher Verification
The form itself often looks nearly identical to last cycle’s. What’s different is what happens after you submit it. Insurers increasingly cross-check your answers against their own external scans of your network. Some run those scans before finalizing a quote rather than after a claim gets filed. A mismatch between what the form says and what the scan finds doesn’t just slow things down. It can change your premium, your coverage terms, or whether you get offered a renewal at all.
Meeting Requirements Now Means Proving Them
The problem isn’t that most businesses lack basic security tools. It’s that they can’t produce documentation showing those tools are configured correctly and deployed everywhere they’re supposed to be. Having a control and proving a control are two different things. That distinction is becoming the real dividing line in underwriting decisions this cycle.
Claims Data Explains Why Insurers Are Asking for More Proof
Insurers aren’t tightening requirements because they enjoy paperwork. The push toward verification tracks directly with what claims data shows about where losses are concentrated, and which gaps between attestation and reality tend to produce the largest payouts. It’s part of a wider pattern in small business IT challenges this year, where assumptions about security rarely hold up once someone checks them.
By the numbers:
| Cause of Loss | 2025 Figure |
|---|---|
| Business email compromise & funds transfer fraud | 58% of claims |
| Ransom demand growth, year over year | Up 47% |
Source: Coalition, 2026 Cyber Claims Report
Business Email Compromise Now Drives Most Claims
Coalition’s 2026 Cyber Claims Report tracked the cause behind most incidents last year. Business email compromise and funds transfer fraud together accounted for 58 percent of them. That’s a proprietary figure from an insurer, worth noting since Coalition has a stake in the underwriting conversation. But the scale of it lines up with what smaller carriers and brokers describe too. A single convincing email, sent to the right person at the right moment, causes more claims than any other attack type.
Ransomware Still Costs the Most Per Incident
Frequency isn’t the same as severity. Even as business email compromise drove more claims, ransom demands surged 47 percent year over year in the same period. That’s why insurers still treat ransomware readiness as its own heavily weighted question. A business that handles phishing well but has no tested backup plan is still carrying real exposure.
Where Insurers Have Raised the Bar This Year
Two specific areas account for most of the tightening SMBs are running into this renewal cycle.
MFA Verification Is Getting More Specific, Not Just Required
Multi-factor authentication stopped being a single checkbox a while ago. This cycle pushes that trend further. CISA’s guidance for SMBs names phishing-resistant methods, security keys and FIDO2 in particular, as the strongest MFA tier available. Insurers are increasingly asking which tier you’re running, not just whether MFA exists somewhere in your environment. Admin accounts, remote access, and anything touching sensitive client data get scrutinized first. Those are the accounts an attacker would target if they got past your front door.
External Scans Are Becoming the Default, Not the Exception
A growing number of underwriters now run their own external vulnerability scans as a standard part of the application process. That step used to be reserved for larger accounts with more complex environments. The scan checks what’s exposed to the outside world. That means open ports, outdated software, and misconfigured cloud storage, no matter what the form says. If your environment hasn’t been scanned from an outside perspective recently, you may be answering renewal questions with stale information.
Having MFA Isn’t the Same as Proving You Have It
None of this is theoretical. A real case from the past several years shows what happens when that gap gets exposed after a claim, not before.
A Real Case Where a Misrepresented Answer Voided a Policy
In Travelers Property Casualty Company of America v. International Control Services, Travelers and its policyholder agreed to rescind a cyber policy worth roughly $1 million. The policy was voided back to the date it started, after the insurer found multifactor authentication hadn’t been deployed the way the original application represented it.
A misrepresented answer on a renewal application can undo the entire policy, whether or not the misrepresentation was intentional or the product of an honest oversight.
Legal commentary on cyber coverage still cites this case as controlling precedent years later, in an industry where legal standards this settled don’t come along often. The underlying principle didn’t expire with the settlement.
Attestation and Documentation Are Not the Same Thing
Attesting to a control means checking a box that says it’s in place. Documenting a control means proving it works, with logs, configuration records, or a vendor’s deployment report.
| Attestation | Documentation | |
|---|---|---|
| What it is | A yes/no answer on a form | Evidence the answer holds up |
| Who accepts it | Underwriters, in the past | Underwriters, going forward |
| What backs it up | Your word | Logs, configs, vendor reports |
That second column is what insurers increasingly want before they’ll stand behind a claim. It’s also what most SMBs haven’t built a habit of maintaining.
Questions to Ask Before Your Next Renewal
None of this requires guessing what an insurer might find. Most of it can be checked in advance, on your own terms, before a renewal questionnaire forces the question.
Reviewing Your Current Security Setup
Before your next renewal conversation, walk through a few questions on your own.
- Coverage check. Which accounts have MFA enabled, and what method, app-based, SMS, or a phishing-resistant key, protects each one?
- Scan check. If your insurer scanned your network today, what would it find that your last application didn’t mention?
- Proof check. Do you have documentation, not just memory, showing when backups were last tested for a full restore?
- Ownership check. Who could answer a detailed underwriting question about your security controls without checking with someone else first?
These aren’t questions with a single right answer. They’re a starting point for understanding where your own setup stands before a carrier tells you.
What to Ask Your IT Partner Before You Sign
If you use an outside IT provider, renewal season is a good time to ask about their role in your compliance posture. A provider offering managed compliance services, or acting as your ITSO, should explain your controls plainly, not hand you a spreadsheet. ITSO stands for IT services organization, the term for ongoing security alignment work. Ask directly whether they can produce documentation, not just attestation, for the controls your renewal application asks about.
Getting Ahead of Stricter Cyber Insurance Requirements
Cyber insurance requirements will likely keep tightening as claims data builds and insurers get better at matching what businesses report to what their networks show underneath it. That means the businesses treating this like a one-time renewal task are the ones most likely to get caught flat-footed. The businesses that handle this well tend to share one habit. They can prove, in writing, that their security setup works the way they say it does.
Certified CIO is not an insurance company or licensed insurance broker. We provide IT services, cybersecurity assessments, and vendor introductions. All insurance policies are issued by third-party providers.
If you’d like a second set of eyes on your setup before renewal, reach out to our team. We’ll help you separate what you have from what you can prove.


