Your Cyber Insurance Renewal Is About to Get a Lot Nosier

Posted: August 28, 2026Category:

Your cyber insurance renewal is about to get a lot nosier. The questions insurers ask in 2026 aren’t a formality anymore – they decide whether you’re insurable at all.

What they now expect before they’ll cover you

  • MFA on everything – email, remote access, admin logins. Miss it and a claim can be declined outright.
  • EDR (Endpoint Detection & Response) – proper monitoring, not just antivirus.
  • Backups that are tested & offline, so ransomware can’t reach them.
  • Staff trained to spot a phishing email.
  • An incident response plan you’ve actually read.

The nasty bit

You can hold a policy, get hacked, and still have the claim knocked back because one box wasn’t ticked.

Insured on paper. Uninsurable in practice.

A proposal form is a declaration – you’re telling the insurer how the business actually runs, and they underwrite on the strength of it. When something happens, the investigation includes whether the controls you declared were really in place on the day.

Most people aren’t lying. They tick yes because they believe MFA is on, or that the backups get tested, because someone said so a few years back. Nobody has looked since.

What to do about it

We help Northland businesses get these controls in place & documented – so when you tick the box, it’s true. That’s the same ground SMB1001 Gold covers: 27 controls, checked by an outside body rather than self-declared.

There’s more detail on what each question means and what the evidence looks like on our cyber insurance compliance page.

Renewal coming up? Send it my way before you sign – let’s make sure you’re actually covered. Give us a ring on 09 222 7770, or take the free 2-minute readiness check first.

Contact us today