Renewing cyber insurance in 2026? The controls insurers are checking mid-year
Cyber insurers keep raising the bar. The mid-2026 renewal checklist — MFA, EDR, tested backups and Essential Eight evidence — to sort before your premium is set.
Cyber insurers spent the last two years tightening what they'll cover. Heading into renewal season, here's the checklist to work through 90 days early — before your premium is set for you.
We wrote at the start of the year about the controls insurers now demand. Half a year on, the pattern at renewals is consistent: the questionnaire is longer, the attestation is stricter, and the gap between "we have that, roughly" and "we can prove that" is now worth real money — in premium, in excess, and in whether a claim gets paid at all.
What are insurers actually checking in 2026?
The 2026 renewal questionnaire keeps circling six controls. Treat this as the checklist:
MFA everywhere that matters.
Email, remote access, admin accounts, and increasingly the line-of-business systems too. "Mostly" is scored as no.
Endpoint detection and response.
Old-school antivirus no longer ticks the box — insurers want behaviour-based EDR, and many ask who monitors it.
Backups that would survive the attacker.
Offline or immutable copies, separated credentials, and a restore actually tested — with a date you can cite.
Patching with a cadence.
Not "we patch", but how fast for critical vulnerabilities, and what covers the stragglers.
An incident response plan.
Written, current, and ideally exercised — insurers know a practised response cuts their payout dramatically.
Framework evidence.
In Australia that increasingly means Essential Eight alignment, with maturity you can show, not assert.
The attestation trap
The most expensive mistake at renewal is not a missing control — it is claiming one you cannot prove. Attestations are contract terms: if a claim investigation finds MFA was not actually on the account that got breached, or the "tested" backup was never tested, insurers can and do deny. Answer the questionnaire from evidence, not optimism. If the honest answer is no, fixing the control before renewal beats fudging it every time.
Why start 90 days out?
Because the fixes take weeks, not days. Rolling MFA across every system, deploying EDR fleet-wide, restructuring backups to immutable copies, running a restore test — each is straightforward with lead time and painful in a deadline week. Start 90 days out and you arrive at renewal with better answers and leverage; start the week the questionnaire lands and you pay this year's premium for last year's posture.
Frequently asked questions
Can our IT provider fill in the insurance questionnaire?
They should at least review it — most denied claims trace back to well-meaning wrong answers. We complete these alongside clients so every yes is backed by something we can produce in a claim.
Will Essential Eight alignment actually lower our premium?
Increasingly, yes — several underwriters price against maturity levels, and some ask for the assessment date. Even where it does not move the premium, it moves insurability and excess.
We got declined last year — what now?
Declines are usually about one or two missing controls, most often MFA gaps or untested backups. Fix those, document them, and reapply — we have taken clients from declined to covered inside a quarter.
Does having a SOC matter to insurers?
Monitored detection and response is one of the strongest answers on the form — it directly shortens the incidents insurers pay for. Our in-house 24/7 SOC is exactly what that question is asking about.
Get renewal-ready
Bring us the questionnaire — or better, beat it. A free cybersecurity health check maps your answers to the six controls above and shows what to fix while there is still time to fix it.
Related Key IT services
More insights
Cyber insurance in 2026
Cyber insurers have tightened up. The security controls you now need to get covered — and to have a…
Read article →RansomwareRansomware hits Australian construction
An Australian construction consultancy was listed by a ransomware crew this month. Why project…
Read article →Windows 10Windows 10 ESU: free vs paid
Consumer Windows 10 security updates now run to 2027 — but business terms are unchanged. What's…
Read article →Book your free IT & Cyber Security Review
See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.