Multi-factor authentication used to be the single question cyber insurance applications asked. Now it's the starting point of a much longer list — and businesses that renewed a policy last year assuming MFA covers them are getting an unpleasant surprise at renewal time.
Insurers have tightened requirements because claims data forced them to. Ransomware payouts didn't decline just because more businesses adopted MFA; attackers adapted, targeting the gaps MFA doesn't cover — compromised session tokens, help-desk social engineering to bypass MFA resets, and unmanaged endpoints that never had it enabled in the first place. Underwriters responded by expanding the questionnaire.
Here's what a typical 2026 renewal application asks beyond MFA:
Privileged access management. Insurers want to know whether administrative accounts are separated from everyday user accounts, and whether admin access requires additional verification steps beyond standard MFA.
Endpoint detection and response (EDR), not just antivirus. Traditional signature-based antivirus is now treated as close to meaningless on these forms. Insurers ask specifically whether you have EDR or MDR (managed detection and response) deployed across all endpoints, including remote and personal devices used for work.
Immutable, tested backups. Not just "we have backups" — insurers increasingly ask whether backups are immutable (can't be altered or deleted by an attacker who gains access) and whether restoration has actually been tested within the last 12 months.
Email security beyond spam filtering. Specifically: DMARC enforcement, not just SPF and DKIM records that exist but aren't actively rejecting spoofed mail.
A documented incident response plan, ideally one that's been tested with a tabletop exercise — not a document written once and never revisited.
Patch management cadence with evidence. "We patch regularly" isn't enough; insurers want to see a defined SLA (e.g., critical patches within 72 hours) and some proof it's actually followed.
What happens if you can't answer yes to these? At best, a higher premium. At worst, a declined application, or a claim denial after an incident if the insurer discovers the answers on your renewal application weren't accurate. That last scenario is the one worth taking seriously — insurers do investigate control gaps during claims, and misrepresentation on an application is grounds to deny a payout entirely.
The practical takeaway: treat your cyber insurance renewal as a genuine security audit, not paperwork. Walk through the actual questionnaire with whoever manages your IT, and if the honest answer to any question is "not really," that's the priority list for the next 90 days — not something to word carefully on the form.