AccuSights
PartnersBlogAbout
Book my 30-minute demo

Blog / Reputation and business risk

Reputation and business risk

Cyber Insurance in 2026: The Renewal Form, the Premium and the Claim That Gets Denied

Cyber insurance requirements in 2026: what the renewal form asks, why premiums moved, and how a ticked box about MFA on a shared mailbox gets a claim denied.

Sam KhanSam Khan The Cyber ExpertFounder and CEOSeptember 2, 2026 · 6 min read

The warehouse mailbox

The owner of a 22-person wholesale distributor renews the cyber policy every March. This year the renewal form is longer. Question 14: "Is multi-factor authentication enforced on all email accounts, including shared and service mailboxes?" He asks the IT provider, who says MFA was rolled out last year. He ticks yes. Question 22, offline backups tested within the last twelve months: the provider says the backup runs nightly. Yes. Question 31, endpoint detection and response on all devices: there is antivirus on everything. Close enough. Yes.

The premium goes up a little. The policy binds.

In August a supplier's email is compromised, and the attacker uses it to send the distributor's accounts team a new remittance form. The team is careful; they do not act on it. So the attacker tries another way in: the warehouse shared mailbox, orders@, which four people check from a shared PC, which has no MFA because the provider could not work out how to make the shared login prompt for a code without annoying the warehouse. The password was the company name and the year.

From that mailbox the attacker reads six weeks of purchase orders, then sends the accounts team a wire change that references a real order number. USD 212,000 goes to the wrong bank on a Thursday.

The claim is filed on Friday. The forensic report, which the carrier's own panel firm writes, notes on page four that the mailbox used had no MFA. The carrier's coverage letter arrives three weeks later and quotes question 14 back to him.

What the heck does this mean

Cyber insurance requirements are the controls a carrier expects you to have before it will sell you a policy, or pay a claim. They live in the application form, and the form is part of the contract.

A misrepresentation is an answer on that form that turns out to be false. If the incident ran through the control you misrepresented, the carrier can deny the claim or void the policy. Not out of spite; that is what the form was for.

MFA, multi-factor authentication, is the second step after the password. "On all email" means every mailbox, including the shared one on the warehouse PC, the scanner's mailbox and the old founder's account nobody closed.

Funds transfer fraud is the attacker tricking your people into paying a real invoice to the wrong bank account. It is the most common claim carriers see and the one most often traced back to a mailbox.

Offline backups are copies the attacker cannot reach from your network, tested by actually restoring something, with a record of the date.

The rule I give every owner: the form is not a marketing exercise. Every yes is a promise to an underwriter who will hire a forensic firm to check it on your worst day.

The numbers that matter

Business email compromise and funds transfer fraud together made up 58% of cyber insurance claims (Coalition 2026 Cyber Claims Report). The warehouse mailbox is the typical claim, not an unusual one.

Eighty-six percent of ransomware claimants refused to pay the ransom (Coalition 2026 Cyber Claims Report). The businesses that could refuse were the ones with backups they could restore from, which is exactly what question 22 was asking about.

MFA was missing where it mattered in 59% of frontline incident cases (Sophos, 2026). More than half the time the front door had a lock on it and the side door did not, and the forensic report will say which door was used.

What to do this week

  1. Print your last cyber application and read every yes as if you were the carrier's forensic firm. For each one, write down what evidence you would show. Where you cannot, that is a gap, and it is cheaper to fix it than to explain it in August. (CIS 6 Access Control Management)
  2. List every mailbox in your tenant, shared and service accounts included, and confirm MFA is enforced on each. Shared mailboxes can be accessed through individual logins with MFA; a shared password on a warehouse PC is a claim waiting to happen. (CIS 6 Access Control Management)
  3. Restore one file and one full system from your backup this week, from a copy that is not connected to your network, and write down how long it took and the date. That record is the answer to question 22 and to the ransom note. (CIS 11 Data Recovery)
  4. Check whether what is on your computers is antivirus or EDR, and who receives its alerts. If the answer is "the IT provider, probably," ask them in writing who looked at the console last Saturday. (CIS 10 Malware Defenses)
  5. Add a wire-change rule your accounts team can recite: any change to a supplier's bank details is confirmed by phone to a number already on file, never to one in the email, and the caller's name is logged. Put it in your supplier onboarding letter so suppliers expect the call. (CIS 6 Access Control Management)
  6. Keep a folder named for the policy year with the application, the evidence for each yes and the dates you tested things. When the renewal comes, you update the folder instead of guessing. (CIS 11 Data Recovery)

Where AccuSights fits

Our assessment reads your insurance application the way the carrier's forensic firm will, tests each yes, and gives you a dated evidence folder plus a short list of the gaps that would matter in a claim. The Cyber Hygiene Test takes three minutes and gives you a score you can share with your broker. A 15-minute call with an engineer usually settles which questions you can answer truthfully today.

Our team implements these controls at a reasonable rate, from MFA on every mailbox and data loss prevention to scanning, EDR and protection of assets, and Protect keeps an engineer and an AI watching the console 24/7, so "who reviews the alerts" has an answer on a Saturday.

Questions people ask

Does cyber insurance require EDR? Most carriers now ask for it on the application, and many will not bind a policy above a modest limit without it. EDR, endpoint detection and response, is the software on every computer that spots attacker behavior rather than just known viruses. The question that follows on the form is who reviews its alerts, because an EDR console nobody looks at over a weekend does not satisfy the underwriter any more than it stops the attacker.

Can an insurer deny a claim for a misstatement on the application? Yes. The application is part of the contract, and an answer that turns out to be false about a control the incident depended on gives the carrier grounds to rescind the policy or deny the claim. Courts have sided with insurers where the misstatement was material, such as MFA declared on all email when a mailbox used in the attack had none. The defense is simple and boring: answer only what you can show, and keep the evidence with the application.

How much does cyber insurance cost for a small business? It depends on revenue, industry, the limit you buy and, increasingly, the controls you can prove. Two businesses of the same size can receive quotes far apart because one has MFA everywhere, offline tested backups and EDR with someone watching it, and the other has a ticked box. In our experience the posture is the lever an owner controls; the rest is set by the market.

The policy pays for the controls you had, not the ones you meant to have; make the form true and the claim takes care of itself.

Controls this post maps to

CIS 6 Access Control ManagementCIS 11 Data RecoveryCIS 10 Malware Defenses

CIS Controls v8.1. These are the same controls our assessment scores and the console watches.

Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →

Where AccuSights fits

Our team implements these controls at a reasonable rate, from DLP to scanning to protection of assets.

Thirty minutes with an engineer, your environment on the screen, and a fixed-fee scope before the call ends. Prefer to see where you stand first? The hygiene test takes three minutes.

Compliance is not security. The audit is not the exam; the attacker is.