Cyber Insurance Questionnaire 2026: The 22 Controls Underwriters Are Asking About
The 22 controls cyber insurers verify in 2026: what each application question asks, why underwriters care, and the evidence behind a yes.
Read articleCompliance
A practical walkthrough of cyber insurance for first-time SMB buyers in 2026 — what the policy covers, what the questionnaire asks.
Cyber insurance for small business is no longer a niche product.
It sits on the renewal checklist next to workers' comp and the BOP, and for most SMBs it is now a contractual requirement somewhere:
The market a first-time buyer is walking into is not the market that existed five years ago. Carrier scrutiny on controls is high, and the questionnaire is now a controls audit dressed up as paperwork. The marketing brochure rarely matches the policy form.
This article covers:
Obsidian Ridge does not sell insurance. We help SMBs pass the questionnaire honestly and operate the controls behind the answers.
A first-time SMB cyber liability policy is two contracts stitched together: first-party pays your losses (forensics, breach notification, business interruption, ransom where legal, data restoration); third-party pays the losses you cause others (regulatory defense, PCI penalties, customer lawsuits).
Most SMBs under 50 employees carry $1 million in aggregate cover, and that policy typically runs about $1,000 to $3,000 per year when controls are documented. The 2026 questionnaire is now a controls audit — MFA on email, remote access, and admin accounts is the hard floor, and MDR or EDR plus tested backups drive premium credits.
Applying with gaps usually results in non-quote or worse terms. Fix the gaps first, then apply.
A standalone cyber liability policy is two contracts stitched together. First-party coverage pays your losses. Third-party coverage pays losses your customers suffer because of you.
Where most SMBs cash claims. Typical covered costs:
The third-party section is where the lawsuits and the regulators show up. Typical covered costs:
Both sections together are the base policy. Almost every meaningful loss type beyond ransomware sits in a rider.
Base cyber policies sit underneath a stack of endorsements. The riders that matter most for a first-time SMB buyer:
The two non-negotiables for most SMBs are the crime rider with explicit social-engineering language and a system-failure endorsement if business interruption coverage matters.
The base policy without the crime rider will not respond to a vendor-impersonation BEC, which is the single most common SMB cyber loss in the FBI IC3 2024 Annual Report.
Knowing the exclusions is more important than knowing the coverages, because exclusions decide what you do not collect when something goes wrong.
Read the exclusion section before you read the coverage section. The shape of the exclusions tells you what the policy is actually for.
Do not size a policy from a blog post — but walk into the broker conversation with the right anchors.
Most SMBs under 50 employees carry $1 million in aggregate cover; firms with 50 to 250 employees commonly carry $2 million to $5 million. A $1 million policy for a business with documented controls typically prices around $1,000 to $3,000 per year, with weak controls or a higher-risk vertical pushing past $5,000.
Pressure-test the limit against your revenue, sensitive-record volume, regulatory obligations, contract requirements, prior incident history, and business-interruption exposure if email or line-of-business systems go down.
The aggregate limit is half the conversation. Sublimits are the other half.
The ransomware sublimit, regulatory defense sublimit, and crime rider sublimit may all sit below the headline number — on a $1 million policy the social-engineering and crime sublimit commonly lands at $50,000 to $100,000, with standalone crime endorsements running $100,000 to $500,000.
A policy with tight ransomware and crime sublimits is a different product than the same aggregate limit at broader terms. A BOP's built-in cyber endorsement, by contrast, is usually capped around $25,000 to $100,000 — a floor, not primary coverage.
If you have never filled out a cyber application, the structure is similar across many SMB carrier forms. The order varies. The exact wording varies. These twelve questions are the ones most likely to drive the offer:
A few carriers ask additional questions on DMARC, conditional access, patching cadence, and vendor management. Those can shape the terms at the margins. The twelve above decide whether you get an offer at all.
If you read nothing else in this article, read this section. Underwriters score everything, but these four controls do much of the work on eligibility and terms.
MFA everywhere it matters. Email, remote access, privileged accounts. Missing it commonly triggers a 20 to 40 percent surcharge — or an outright non-quote, since many carriers now treat absent MFA as a hard stop rather than a pricing lever.
24/7 EDR or MDR. Real human SOC, documented escalation, named on-call responder.
It is one of the clearest ways to answer the monitoring question without pretending software alone is a response plan — and it earns a measurable premium credit, with broker guidance citing 20 to 50 percent total reduction when MDR is stacked with MFA, immutable backups, and an IR plan.
Immutable backups with a tested restore log. Cloud object lock or air-gap, restore log within 90 days. Backups that have never been restored are weak evidence.
Identity threat detection on the cloud productivity tenant. Token theft, mailbox rules, OAuth grants. This is appearing more often because so many SMB losses start in email and identity.
If you have all four, the application becomes much more evidence-driven and much less argumentative. If you have none, expect harder underwriting, weaker terms, lower sublimits, or a decline until the control gaps are closed.
The most expensive surprise in 2026 SMB policies is not always the premium — it is the ransomware endorsement.
These endorsements commonly carry coinsurance — typically a 10 to 25 percent insured share, though some policies use 50 percent — along with sublimits below the policy aggregate and controls-warranty language that bites when the insured cannot demonstrate, at the time of loss, that the named controls were operating.
Named controls often include MFA on key surfaces, EDR or MDR with monitoring, immutable tested backups, and a written IR plan.
A ransomware loss can therefore pay far less than the headline limit suggests. If the carrier also finds material misrepresentation on the application, the entire claim can be denied.
The clause lives in the ransomware endorsement, not the declarations page. Read it before binding. Map each named control to evidence you can produce on the day of loss — restore logs, EDR console exports, conditional access policy exports — not the day of the application.
Beyond the standard exclusion list, a handful matter most for first-time SMB buyers:
Material misrepresentation on the questionnaire is grounds for the carrier to rescind the policy after a loss. The rescission is retroactive — premiums are returned and claims are denied.
If MFA is on most accounts but not on the CEO's mailbox because it broke her travel routine, the honest answer is "MFA is required on all email accounts except one executive exception."
That answer may affect terms. It does not void the policy.
The other answer — "yes" — may save money at binding and lose the claim when the executive mailbox is the one that gets popped.
Honest answers, even when they affect pricing or terms, are the only viable strategy. The cost difference from an honest "no" is usually smaller than the loss from a denied claim.
First-time buyers commonly spend in the wrong places. The following sound like security but do not change a single answer on a 2026 questionnaire:
Carriers score operating controls and evidence. Not invoices, not certificates, not vendor logos.
If you are reading this with a renewal application open, or a first-application quote request from your broker, work in this order. Each step makes the next easier.
Enable MFA on Microsoft 365 or Google Workspace tenant-wide via Conditional Access or context-aware access. Add MFA on every remote-access path the IT vendor uses — VPN, RDP, RMM, jump hosts.
Add MFA on every privileged account, including break-glass accounts with a documented checkout procedure. This is usually one of the cheapest control moves and one of the most important underwriting answers.
A managed detection and response service with a real 24/7 SOC checks the EDR box, the 24/7 monitoring box, and the documented escalation box at the same time.
Adding identity threat detection on top covers the cloud productivity controls underwriters are starting to score separately. See Managed Detection and Response and Managed ITDR.
Pick a backup product that supports immutability natively — cloud object lock or air-gap. Schedule a monthly restore of a representative dataset. Keep the log. Carriers ask for the log at claim time. A backup that exists on paper but was never restored fails this control.
A 12-page written information security plan covering administrative, technical, and physical safeguards, with a named owner and a 12-month review date.
A one-page incident response plan that names who calls the carrier hotline, who declares an incident, who talks to staff, and who decides about closing operations. Keep both short enough that someone will actually read them during a crisis.
A managed security awareness training program with quarterly phishing simulations and tracked completion rates.
Carriers want completion data and click rates — not a training video shelved in a learning management system nobody opens. See Managed Security Awareness Training.
Five operational moves, a realistic execution window, and the main control categories on a 2026 questionnaire are now answered yes — with evidence.
The mechanics of buying a cyber policy for the first time:
Find a broker who specializes in cyber. This is not your general business insurance broker. Cyber underwriting is its own discipline, and a generalist broker will hand you the first carrier's form and a quote that does not reflect your controls.
Ask the broker how many cyber policies they placed last year and which carrier panel they work with.
Complete the questionnaire honestly. Where a control is partially in place, say so. Where you do not know, find out before answering rather than guessing.
Get three quotes. Carriers can price and sublimit the same risk differently. One quote is not enough information.
Read the policy and every rider before signing. Focus on co-insurance, sublimits, the war exclusion, the supply-chain wording, and the carrier's definition of "incident." The marketing summary is not the policy.
Bind with a clear understanding of who you call when something happens. The carrier's incident response hotline goes in your IR plan, on a laminated card in the office, and into the phones of everyone who could declare an incident.
Late notification is one of the most common reasons coverage is denied on otherwise-covered events.
Cyber pricing changes by revenue, industry, record count, geography, prior incidents, and the exact controls in place.
The broad market also moves: after the steep increases of 2021 and 2022, U.S. cyber rates declined roughly 5 to 7 percent in 2024 per NAIC data and have since stabilized for firms with documented controls — so a renewal hike today usually points at your controls or a claim, not the market.
Instead of relying on static price bands, ask the broker to explain:
A quote that looks unusually cheap or unusually expensive is a signal to ask why.
Outliers below the expected market often have low sublimits, high deductibles, or restrictive wording. Outliers above the expected market often reflect missing controls, prior incidents, or a vertical the carrier is pricing cautiously.
Most SMBs see renewal pressure even when nothing changes. The way to improve the conversation is to demonstrate control improvements year over year:
Fresh quotes from multiple markets can also expose whether the current carrier is pricing cautiously or whether the terms are broadly in line with the market.
Carriers also share loss intelligence. A claim paid in a prior policy period invites a specific question at the next renewal: what changed since the incident?
Answers like "we are more careful now" do not pass. Answers like "we moved to a 24/7 MDR provider in March, added MFA on the line-of-business admin accounts in April, and completed a tabletop in May" do.
The other 2026 reality: non-renewal is more common than it used to be when controls have slipped or after a claim. The firm has 30 to 60 days to find replacement coverage, and the next application asks about the prior non-renewal. The fix is operational, not paperwork.
We are not an insurance broker. We do not sell policies. We help SMBs:
Our Ridge Plus tier ($50 per person per month, everything in Ridge Core included) covers MFA enforcement support, 24/7 MDR, ITDR on the productivity tenant, and the managed SAT program. Those are the recurring control categories that appear across 2026 applications, operated and monitored, with the evidence package as a byproduct.
See pricing.
For first-time buyers or renewing buyers staring at a questionnaire, the Cyber Insurance Readiness sprint is a fixed-scope engagement (7 business days, $1,500–$3,500) that:
For a deeper walk through the underwriting controls, see the companion piece on the 22-control questionnaire.
To walk through your specific situation with us before applying, talk with us. The assessment tool gives you a faster posture snapshot against the controls underwriters care about, if you want a read before committing to anything.
Cyber insurance is not a substitute for controls. It is a backstop for the residual risk that remains after the controls are doing their job.
First-time buyers who treat the policy as the plan tend to learn the expensive way that the controls warranty in the fine print is doing more work than the declarations page. The fix is operational, and it is cheaper than trying to remediate under claim pressure.
Start with MFA, MDR, a tested backup, and an honest answer to twelve questions. The rest of the application gets easier from there.
Last updated
September 30, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
If you hold customer data, send wires, accept card payments, or rely on email and a handful of cloud apps to operate, the answer is yes.
General liability and errors-and-omissions policies do not respond to forensics, ransomware, breach notification, regulatory defense, or wire fraud.
The cost of coverage is usually smaller than a serious uninsured incident, and many enterprise customers and banks now require a current cyber certificate of insurance as a contractual condition.
Two buckets. First-party covers your losses — forensic investigation, legal counsel, breach notification, credit monitoring, business interruption, ransom payment where legal, and data restoration.
Third-party covers losses you cause others — regulatory defense and fines, PCI penalties, customer lawsuits, and network security liability.
Add-on riders typically cover social engineering and wire fraud, reputation harm, hardware bricking, and outage events that are not the result of an attack.
Most SMBs under 50 employees carry $1 million in aggregate cover; firms with 50 to 250 employees commonly carry $2 million to $5 million.
A $1 million policy for a business with documented controls typically runs about $1,000 to $3,000 per year, with weak controls or a higher-risk vertical pushing past $5,000.
Size the aggregate to your revenue, record volume, and contract requirements — then inspect sublimits, especially ransomware, social engineering, regulatory defense, and system failure, because they often matter more than the headline aggregate.
Yes. There is no third-party audit requirement. What carriers require is an honest answer to roughly twelve underwriting questions on a self-attestation.
The answers must hold up if the policy is ever invoked, so the practical effort is to make sure the controls you attest to are actually in place. That is operational work, not an audit.
If your controls are already in place, completing the questionnaire and binding coverage can be a short broker workflow. If you have gaps to close — adding MFA, deploying MDR, documenting backups — plan remediation time before applying.
Applying with gaps usually results in a non-quote, restricted terms, or a more expensive offer.
Non-quote is increasingly common when MFA, EDR, or tested backups are missing. The fix is not shopping harder. It is closing the control gaps that triggered the decline, then re-quoting in 30 to 60 days with documentation in hand.
Many carriers will reconsider on the same fiscal year once the named controls are operational and evidenced.
Base premium is driven by revenue, employee count, industry, sensitive-record count, and prior incident history.
From that base, named controls move the number: missing MFA commonly triggers a 20 to 40 percent surcharge or an outright non-quote, while managed detection (EDR/MDR) earns a measurable premium credit — broker guidance cites 20 to 50 percent total reduction when MDR is stacked with MFA, immutable backups, and an incident response plan.
Regulated verticals carry more loading: healthcare and financial services have historically paid roughly 50 percent above the market average, with legal closer to baseline but rising on business-email-compromise exposure.
Many business owner's policies (BOPs) include a small cyber endorsement, typically capped around $25,000 to $100,000 — rarely enough to cover a serious incident. Forensics, legal, notification, and recovery costs can exhaust that quickly.
Treat the BOP endorsement as a floor, and add a standalone cyber liability policy with limits sized to your exposure.
Sometimes, and with conditions.
Payment must be legal under OFAC sanctions rules, the carrier almost always requires pre-approval through its incident response panel, and ransomware endorsements commonly carry coinsurance — typically a 10 to 25 percent insured share, though some policies use 50 percent — plus sublimits below the policy aggregate if the insured cannot demonstrate that named controls (MFA, EDR or MDR, immutable backups, and a documented incident response plan) were operating at the time of loss.
Related reading
The 22 controls cyber insurers verify in 2026: what each application question asks, why underwriters care, and the evidence behind a yes.
Read articleCyber insurance carriers stopped accepting 'we have antivirus' years ago. Here is what they ask about endpoint protection and how each term maps.
Read articleA hands-on deep-dive on cyber-insurance control #15 — link rewriting, time-of-click URL analysis, and attachment sandboxing.
Read article