Cyber Insurance Requirements 2026: The 12 Controls Every Carrier Asks About

By , CTO · Published · Last updated

TL;DR

  • The average cyber insurance renewal questionnaire grew from about 12 questions in 2020 to 80 or more in 2026, and the bar moved from "do you have antivirus" to "do your controls map to CIS Benchmark v8 and NIST CSF 2.0."
  • Twelve controls show up in nearly every 2026 questionnaire. MFA, privileged access, EDR, email security, immutable backups, vulnerability management, logging, network segmentation, an IR plan, vendor risk, security awareness training, and data protection.
  • For most small businesses, eight of the twelve are satisfied directly inside Microsoft 365 with the right Conditional Access, Defender, and Purview settings configured. The other four are governance and process work.
  • "MFA is enabled" is not the same answer as "MFA is enforced." Carriers know the difference and ask follow-up questions on three of the four most-flagged areas: MFA scope, backup immutability, and IR plan testing.
  • Coverage that gets dropped or repriced 30 to 50 percent at renewal usually fails on two or three specific controls, not all twelve. Knowing which ones in advance is the entire game.

You opened the renewal packet from your carrier and the questionnaire is twice as long as last year. Some of it reads like an IT audit. Some of it reads like a legal contract. And there's a tone in the cover letter that wasn't there in 2023, the one that says "answer carefully, because we will price this and we may decline."

You're not imagining it. The bar moved. This guide walks through what changed, the twelve controls behind every modern questionnaire, what passes versus what gets you flagged, and what's already coming for 2027 renewals. It's written for the person who has to answer the questionnaire, not the IT vendor who has to implement it.

How we got here: a short history of the cyber insurance reset

Cyber insurance didn't always look like this. In 2018 you could get a million dollars of coverage with a one-page application and a credit card. Then ransomware industrialized.

Between 2019 and 2021, claim payouts went vertical. Carriers paid ransoms, paid for forensics, paid for business interruption, paid for class-action settlements after data leaked. Loss ratios at some major underwriters crossed 100 percent, meaning claims paid out exceeded premiums collected. That's not a sustainable line of business.

So 2022 became the great tightening. Premiums climbed 50 to 100 percent year over year. Sub-limits dropped on ransomware. Coinsurance clauses appeared. The questionnaire grew teeth.

By 2024 carriers had figured out which controls actually correlate with not filing a claim, and they started requiring those controls instead of just asking about them. By 2026 the requirement set stabilized around two reference frameworks: CIS Microsoft 365 Foundations Benchmark v8 and NIST Cybersecurity Framework 2.0. Most carriers don't ask you to certify against either. They ask questions whose right answer happens to map to those frameworks. If you've already aligned to one, you're 80 percent done with the questionnaire.

The 12 controls every 2026 questionnaire asks about

Carriers vary on wording. The underlying controls don't. Here are the twelve that appear in some form on nearly every 2026 application or renewal, with the M365 setting that satisfies each one and the answer that passes.

1. MFA — what your carrier means and how M365 satisfies it

What they ask: "Is multi-factor authentication enforced for all users, all administrators, and all remote access?"

What passes: Yes, enforced via Conditional Access for 100 percent of users, with admin accounts on phishing-resistant MFA (FIDO2 keys or Windows Hello) and no legacy authentication protocols allowed.

M365 implementation: Conditional Access policies covering all users, with a separate stricter policy for admin role assignments. Legacy authentication blocked at both the Conditional Access layer and the Exchange Online authentication policy layer. The single most common gap we see is "MFA is on" but legacy protocols like IMAP and SMTP AUTH still let attackers walk past it. The full fix is in the cross-network walk-through on how to block legacy authentication in M365.

If you only deep-dive on one control, this is the one. The companion worksheet on how to answer the MFA section of a 2026 questionnaire walks through each carrier question in its exact wording and shows the answer that passes, with the evidence to attach.

2. Privileged access management — admins handled differently than users

What they ask: "Are administrative accounts separated from daily-use accounts? Is privileged access elevated only when needed?"

What passes: Yes. Each admin has a separate cloud-only admin account (jane.admin@) used only for admin work. Roles are assigned through Privileged Identity Management with just-in-time activation, not standing access. Service accounts are documented and locked to specific source IPs.

M365 implementation: Microsoft Entra ID P2 enables Privileged Identity Management. Global Admin role count under five, with two of those being break-glass emergency accounts excluded from Conditional Access. Daily-driver accounts hold no admin roles.

3. Endpoint detection and response — not the same as antivirus

What they ask: "Do you deploy EDR (endpoint detection and response) on all endpoints, including remote and BYOD devices?"

What passes: Yes. Microsoft Defender for Endpoint Plan 2 (or equivalent like CrowdStrike or SentinelOne) on every Windows and Mac endpoint, with telemetry centrally retained for at least 30 days and behavioral detection rules in active mode, not just audit mode.

M365 implementation: Defender for Endpoint comes in Microsoft 365 E5 or as an add-on to Business Premium. Plain Microsoft Defender Antivirus is not EDR and will get flagged as such if you say it is.

4. Email security — phishing, spoofing, and the gateway question

What they ask: "Do you operate a secure email gateway with anti-phishing, anti-spoofing, and link/attachment scanning?"

What passes: Yes. Microsoft Defender for Office 365 Plan 1 or 2, with Safe Links and Safe Attachments enabled in block mode (not audit), anti-phishing policies configured for impersonation protection on the executives, and DMARC at p=reject for the primary sending domain with SPF and DKIM aligned.

M365 implementation: Defender for Office 365, Exchange Online Protection, and DNS records for SPF, DKIM, and DMARC. The "DMARC at reject" answer is the part most SMBs miss. Many sit at p=none for years, which carriers now flag as "monitoring only, no enforcement."

5. Backup and recovery — the immutability question

What they ask: "Are backups offline or immutable, tested regularly, and recoverable within your stated RTO?" RTO means Recovery Time Objective: how long until you're back up.

What passes: Yes. M365 data (Exchange, SharePoint, OneDrive, Teams) backed up to a separate immutable target daily, retained for at least 30 days, with a documented restore test inside the last 12 months and an RTO of 24 hours or less for critical data. Immutable means an attacker who compromises your tenant cannot delete or encrypt the backup.

M365 implementation: Microsoft does not back up M365 in the way carriers mean. Native retention and recycle bins help, but they don't satisfy "immutable backup." Most SMBs use Veeam for Microsoft 365, Barracuda Cloud-to-Cloud, Datto SaaS Protection, or similar. The carrier wants the vendor name, the retention period, and the date of the last successful restore test.

6. Vulnerability and patch management — cadence and inventory

What they ask: "How quickly are critical vulnerabilities patched? Do you maintain an asset inventory?"

What passes: Critical CVEs patched within 14 days, high within 30 days, with monthly vulnerability scans and a current asset inventory covering every endpoint, server, and SaaS app. The numbers vary slightly by carrier; 14 and 30 days is the safe baseline.

M365 implementation: Defender Vulnerability Management (included with Defender for Endpoint Plan 2) gives you the scan and inventory in one place. Windows Autopatch covers the OS patching cadence for Business Premium tenants.

7. Logging and monitoring — retention period and SIEM

What they ask: "Are security logs centralized, retained, and monitored 24/7? What is your retention period?"

What passes: Yes. Sign-in logs, audit logs, and Defender alerts retained centrally for 12 months minimum, with monitoring either via an internal SOC, a managed detection and response service, or a SIEM with alerting rules. Pure "we have logs if we ever need them" answers fail.

M365 implementation: Native M365 audit log retention is 90 days on standard plans and 12 months on E5 / Audit add-on. For SMBs, the cleanest answer is forwarding logs to Microsoft Sentinel or a third-party SIEM with managed detection on top.

8. Network segmentation — admin networks and remote access

What they ask: "Is administrative access segmented from user access? Is remote access to internal systems gated through MFA and conditional checks?"

What passes: Yes. Admin work happens from a dedicated workstation or session that's separate from the daily user network. Remote access to M365 is governed by Conditional Access requiring compliant device, MFA, and either a known location or low sign-in risk score. VPN, where present, requires MFA and certificate-based device auth.

M365 implementation: Conditional Access does most of the heavy lifting at the M365 edge. The dedicated admin workstation piece is a process answer, not a setting.

9. Incident response plan — documented and tested

What they ask: "Do you have a documented incident response plan? When was it last tested? Who are the named roles?"

What passes: Yes. A written IR plan naming an incident commander, a communications lead, and an external forensics partner; tested through a tabletop exercise inside the last 12 months; reviewed and updated annually.

M365 implementation: This one isn't an M365 setting. It's governance. The carrier wants the document, the date of the last tabletop, and the names. "We have a plan" without a tabletop date in the last year fails on most 2026 forms.

10. Vendor risk management — third-party access reviews

What they ask: "Do you review the security of vendors with access to your systems or data? Do you obtain SOC 2 reports for critical vendors?"

What passes: Yes. Annual vendor review covering top 10 vendors by data sensitivity, SOC 2 Type II reports collected for any vendor processing regulated or sensitive data, and a documented offboarding process when vendor relationships end.

M365 implementation: Entra ID admin consent workflows for OAuth app registrations close one specific door. The rest is process: a vendor list, SOC 2 reports in a folder, and a calendar reminder once a year.

11. Security awareness training — annual plus simulations

What they ask: "Are employees trained on phishing and security awareness annually? Do you run phishing simulations?"

What passes: Yes. Annual training with completion tracking for 100 percent of employees, plus phishing simulations at least quarterly with results tracked and remedial training for repeat clickers.

M365 implementation: Defender for Office 365 Plan 2 includes Attack Simulation Training. KnowBe4, Hoxhunt, and Proofpoint Security Awareness are common third-party choices. The carrier wants completion rates, not just "we sent the email."

12. Data classification and protection — labels, DLP, and encryption

What they ask: "Is sensitive data identified, classified, and protected with DLP and encryption?"

What passes: Yes. Sensitivity labels applied to documents marked Confidential or higher, DLP policies blocking external sharing of regulated data (PII, PHI, payment card data), and encryption at rest and in transit confirmed for all M365 services.

M365 implementation: Microsoft Purview Information Protection for sensitivity labels, Microsoft Purview DLP for the policies. Encryption at rest is on by default for M365. The work is configuring the labels and policies to match the data you actually hold.

What "good" looks like: two 30-person businesses

Theory only goes so far. Here's how the bar plays out for two real-shaped small businesses, both around 30 employees, both renewing in 2026.

Business A. A regional accounting firm. Microsoft 365 Business Premium across the firm, Conditional Access enforcing MFA on everyone, FIDO2 keys for the four people with admin roles, no legacy authentication anywhere. Defender for Endpoint on every laptop. DMARC at p=reject. Veeam for M365 backing up daily to immutable storage with a quarterly restore test. A two-page IR plan listing the managing partner as incident commander and the firm's outside IT vendor as forensics support, with a tabletop run in October 2025. Quarterly KnowBe4 phishing simulations averaging an 8 percent click rate. Sensitivity labels on client tax files. Renewal premium: up 4 percent year over year, well below the 18 percent average for the segment. The carrier asked two follow-up questions and accepted the answers.

Business B. A 30-person manufacturing distributor. Microsoft 365 Business Standard (no Defender for Endpoint, no Conditional Access, no Purview). MFA "available" but not enforced; about 60 percent of users had it on. Free Microsoft Defender Antivirus only. SPF set up but no DKIM and no DMARC. Backups via the OneDrive recycle bin and "we have file history." No documented IR plan. No phishing simulations in the last 18 months. Renewal outcome: carrier non-renewed. Replacement coverage came in at 47 percent higher premium with a $50,000 ransomware sub-limit and a coinsurance clause. The broker fed back that fixing four specific controls (MFA enforcement, immutable backup, IR plan with a tabletop, and DMARC at reject) would have kept the original carrier and likely held premium flat.

The gap between A and B isn't budget. It's about $11,000 a year in additional licensing and tooling. The premium difference alone covers it.

The four questions carriers flag hardest in 2026

Of the 80-plus questions on a 2026 renewal questionnaire, four show up as most-flagged in broker feedback. These are the ones to answer carefully.

"Do you have MFA on email, VPN, and admin accounts?" The trap is the word "and." If MFA is enforced on email but not on VPN, the honest answer is no. Many SMBs answered "yes" in 2024 and got pushback at claim time when forensics revealed VPN had no MFA. Carriers now require evidence of all three, often a screenshot of the Conditional Access policies or a vendor attestation.

"Do you have backups that are protected from ransomware?" The word that matters is "protected." A backup an attacker can reach with the credentials they just stole is not protected. The right answer involves either offline storage or immutable storage with a separate identity boundary. "Backups in the same M365 tenant" usually fails this question.

"Do you have a documented incident response plan?" This isn't a yes/no anymore. Most 2026 forms add "please attach" or "please summarize the last test date and named roles." A document with a date inside the last year and three named roles is what passes.

"When was your last tabletop exercise?" The honest answer is the answer. If you've never done one, say so and commit to a date. Carriers will sometimes write a 90-day cure period into the policy. Lying to the questionnaire and getting caught at claim time is the worst possible outcome.

Mapping the controls to your renewal in one table

If you want one page to bring to your IT vendor or your broker, this is it.

Control M365 Setting Passes If
MFAConditional Access + block legacy auth100% of users, admins on FIDO2
Privileged accessEntra PIM, separate admin accountsJust-in-time, <5 standing GAs
EDRDefender for Endpoint P2All endpoints, behavioral mode on
Email securityDefender for O365 + DMARC rejectSafe Links/Attachments in block mode
BackupsThird-party immutable backupTested restore in last 12 months
Vuln managementDefender Vulnerability ManagementCritical patches in 14 days
LoggingSentinel or SIEM, audit retention 12moActive alerting, not just storage
SegmentationConditional Access + admin workstationAdmin separated from user network
IR planDocumented plan + tabletopTested in last 12 months
Vendor riskAnnual review + SOC 2 collectionTop 10 vendors documented
Awareness trainingAttack Sim Training or KnowBe4Annual + quarterly simulations
Data protectionPurview labels + DLPConfidential data labeled and DLP'd

Use this as the running tally before you submit. Anywhere the third column doesn't apply yet is something to fix or to disclose. If you want a longer working doc to track evidence collection, the cyber insurance compliance checklist is the one we hand to clients.

Beyond M365: the controls that aren't a setting

Four of the twelve aren't really an M365 question. The IR plan, vendor risk reviews, security awareness training, and the governance side of vulnerability management are all process and policy work. A carrier won't accept "we bought Defender" as the answer to "do you have a tested IR plan."

This is where many SMBs need outside help, and it's where M365Shield's scope intentionally ends. M365Shield handles your Microsoft 365 security baseline. For full compliance readiness, including incident response plans you can hand to a carrier, governance frameworks, board-ready security reporting, and executive security leadership, Iron Path Advisory provides fractional CIO and CISO services. The two together cover the technical and the governance halves of the questionnaire.

What's coming for 2027 renewals

The bar isn't done moving. Three shifts are already showing up on early-renewing carriers and will be standard by 2027.

Phishing-resistant MFA as the default expectation. SMS and authenticator app push notifications are losing favor because adversary-in-the-middle phishing kits defeat both. Expect "phishing-resistant MFA for all admins" to move from best practice to required, and "phishing-resistant MFA for all users" to start showing up as a premium-discount question.

AI and deepfake response plans. Wire fraud via deepfaked voice and video is climbing fast. Several carriers are now asking whether the IR plan covers deepfake-driven social engineering, including a documented out-of-band verification step for any wire instruction or vendor change. If your IR plan doesn't address it, add a paragraph.

Supply chain attestation. Software bill of materials and signed third-party attestations are starting to appear on questionnaires for businesses above 100 employees. SMBs aren't seeing it broadly yet, but if you operate in regulated industries (healthcare, finance, defense supply chain) you will.

Most of the 2027 changes build on the 2026 baseline rather than replacing it. If you're solid on the twelve, you're set up well for what's next. The plain-language version of the most-asked follow-ups is collected in the cyber insurance requirements FAQ, and the CIS Benchmark angle (the framework most carriers now reference by name) is broken down in the post on CIS Benchmark as a cyber insurance requirement.

Frequently asked questions

What if I can't meet a control before renewal?

Disclose it and propose a remediation date. Most carriers prefer a credible plan over a vague answer or a quiet "yes." A typical pattern: "MFA enforced on 92 percent of users today, full enforcement complete by [date]." Brokers can usually negotiate a 60- or 90-day cure period if the gap is small and the rest of the form is strong. Lying on the questionnaire is the option that gets coverage rescinded at claim time.

Will my premium drop if I implement these?

Sometimes. More often, premium stays flat or increases slowly while the rest of the market goes up faster. The win is in not getting non-renewed, not getting a 30 to 50 percent reprice, and not getting a $50,000 ransomware sub-limit dropped onto your policy. A few carriers offer explicit discounts for FIDO2 admin MFA, immutable backups, or 24/7 monitored detection. Ask your broker for the carrier's "credit list" if they have one.

Do I need to do all of this before my renewal date?

No. You need credible answers on the twelve, and a plan with dates for any gap. Renewal date pressure leads to rushed implementations that break things. A typical sequence: assess against the twelve about 90 days before renewal, fix the worst three or four gaps in the first 60 days, document everything in the last 30, and submit. Anything still open at submission goes on the disclosure with a target completion date.

Can my IT vendor verify all of this for me?

For the M365 controls, yes, and they should. Ask for a written attestation listing each control, the M365 setting that satisfies it, and the date verified. That document doubles as your audit trail if a claim ever happens. For the four governance controls (IR plan, vendor risk, training, governance) your IT vendor probably can't sign off; those need either internal ownership or a fractional CISO arrangement. The deployment evidence side is exactly what M365Shield produces as part of the baseline.

What's the single fastest gap to close before renewal?

Block legacy authentication. It takes about a week, costs nothing in licensing, closes the most common credential-stuffing path, and converts a "no" on the MFA question into a "yes." If you do nothing else, do that one.

Get the free Insurance Readiness Checklist

No spam. Unsubscribe anytime.

Find Out If Your Tenant Meets Insurance Requirements

Our free tenant assessment shows exactly which controls are already in place — and which ones are gaps.

Check My Risk