37forge.com
HOME / GUIDES / Compliance & Industry
FREE GUIDE · COMPLIANCE & INDUSTRY

Cyber insurance in 2026: the IT controls underwriters now require

5 min read·By William Edwards, Lead Engineer·Updated July 2026·37 Forge · McKinney TX

Cyber insurance in 2026 works like a security audit that happens before you ever file a claim. Your carrier will ask you to prove, in writing, that you run specific controls: multi-factor authentication on every account, monitored protection on every device and server, backups that stay isolated and get tested, and a written plan for the day something goes wrong. Answer with controls you cannot actually show, and the insurer can reduce or deny the claim later, at the exact moment you need the payout most.

Why the application became an audit

Insurance runs on math. Carriers paid out far more on ransomware and business email compromise over the past several years than they took in, so they rewrote the rules. The form that used to be one page of yes/no boxes now reads like a technical review of your network. Underwriters stopped taking your word for it. They want proof that each control was in place and enforced, and their forensic team will check those answers against what they find if you file a claim.

The controls underwriters check first

Requirements shift by carrier, industry, and company size, but the same short list shows up on almost every questionnaire.

Where small businesses get caught

Most owners do not fail the application because they lack expensive tools. They fail because a control is partial, undocumented, or quietly out of date. A few patterns come up again and again.

Any one of these can turn into a denied claim. The distance between "we have MFA" and "we can prove MFA was enforced on that account on that day" is where payouts disappear.

Build the proof before you renew

Give yourself a month or two ahead of renewal and assemble what underwriters call a proof packet. Pull the reports that show your controls are real: an MFA enforcement report listing which accounts and systems are covered, an EDR deployment summary showing coverage across your devices, backup logs with dated restore-test results, training completion records for the past year, and a dated incident response plan. If you work with a managed IT provider, they should hand you all of this without a blank stare. When your paperwork matches how your systems actually run, renewal gets calmer and a future claim moves faster.

Where a local partner helps

Meeting these requirements is ongoing work. Someone has to keep MFA enforced, watch the monitoring alerts, run the restore tests, and keep the documentation current so it still matches reality at renewal. That is the job we do for small and midsize businesses across McKinney and Collin County. As a veteran-owned MSP, we stand up the controls carriers expect, document them, and keep the proof ready so your coverage holds when you need it.

Facing a cyber insurance renewal?

Book a free 30-minute assessment with a local Collin County engineer. We will walk your controls, flag the gaps underwriters care about, and show you what to fix, whether or not you hire us.

Book an assessment →
© 2026 37 Forge LLC · Managed IT, Cybersecurity & Cloud · McKinney, TX · 214-432-0333