What Controls Do Cyber Insurers Require in 2026? The 10 That Decide Your Application
The 10 security controls cyber insurers actually score in 2026 — what carriers ask, what passes, and the quiet answers that get applications declined.
Read articleCompliance
Cyber insurance carriers stopped accepting 'we have antivirus' years ago. Here is what they ask about endpoint protection and how each term maps.
"We have antivirus, we should be fine" was a defensible answer to a cyber insurance question in 2018. In 2026, the application no longer stops at "do you have antivirus." It asks whether every endpoint — including servers, not just laptops — runs endpoint detection and response, whether a real security team watches those endpoints around the clock, and what the mean time to respond is when something fires.
If you are the owner of a small business filling out a renewal for the first time and the question makes no sense, you are not behind. The vocabulary changed. This page explains the three terms carriers now use — antivirus, EDR, and MDR — in the exact frame the application uses, so you can answer accurately without overcommitting.
Antivirus is still useful. It is not what carriers are asking about when they ask about endpoint detection and response. If your only endpoint control is signature-based antivirus, the application scores that as a gap — and misstating it is the mistake that voids the policy at claim time.
Nearly every 2026 SMB cyber-insurance application in circulation has a version of the same question, phrased slightly differently by each carrier:
Do you have endpoint detection and response (EDR) or managed detection and response (MDR) deployed on every workstation and server? Is there a 24/7 security operations center behind it? What is your stated mean time to respond?
That is the pivot question. It is question two on the ten-control table already published on the Cyber Insurance Readiness Sprint page — among the controls carriers weight most heavily, alongside MFA, because human-operated ransomware in 2026 dwells on an endpoint long enough for a real analyst to catch it, if there is one watching.
Three things about how the question is scored:
Antivirus. Signature-based scanning that blocks known malware files. The oldest layer in the stack, still useful, but it stops at "have I seen this specific file before?" — which is not the frame ransomware crews operate in anymore. Deeper reading: Is antivirus enough for my small business? Why ransomware walks past it.
EDR (endpoint detection and response). Software that records what happens on an endpoint — process trees, network connections, file changes, persistence attempts — and alerts on behavior that looks like an attack rather than on a specific file signature. It sees the human-operated part of ransomware that antivirus misses. What it does not do on its own is decide what to do about the alert.
MDR (managed detection and response). EDR plus a real security operations team watching the alerts around the clock, triaging, and responding. The application asks for MDR (or EDR with 24/7 monitoring) because the alert without a human on the other end is a log, not a response. Deeper reading on the buyer lens: EDR vs MDR vs XDR: a 2026 buyer's guide.
| Antivirus | EDR | MDR | |
|---|---|---|---|
| What it does | Blocks known malware files by signature | Records endpoint behavior, alerts on attack patterns | EDR plus 24/7 human triage and response |
| Who responds when something fires | Nobody. The alert sits in a console or an email | Your IT person, during business hours, if they see it | A security operations team, within minutes, at any hour |
| How it reads on a carrier application | Scored as a gap in the "endpoint detection" question | Partial credit if configured and monitored; gap if unmonitored | Full credit on the endpoint-detection question; supports "24/7 SOC" and "stated MTTR" sub-questions |
| When it is genuinely enough | A single-user home office with nothing sensitive on the machine, low third-party risk, no compliance regime, no insurance requirement | An organization with an in-house security team already watching alerts | Everyone else — the default answer for a business filling out a 2026 cyber application |
Not everyone needs MDR. This is the section most articles skip because it does not sell.
Antivirus is a reasonable primary control if all of these are true:
The moment any of those change — the application form arrives, a client contract adds a security requirement, you take on regulated data — the AV-only answer stops being defensible. Not because antivirus became worse, but because the threat model the answer is scored against changed.
Three practical rules for the endpoint section of the application:
If the answers you write down do not match the environment when a forensics firm shows up post-incident, the policy is at risk. Truthful "no" on a control is survivable. Overstated "yes" on a control is the material misstatement that voids the claim.
Obsidian Ridge operates managed endpoint detection and response — the EDR-plus-a-real-team version — on every workstation and server, watched around the clock. If you need the pillar-page detail, see managed detection and response.
If you are inside a 30- or 60-day application or renewal window and need the evidence packet built — the answers, the exports, the proof — that work is a fixed-scope engagement: the Cyber Insurance Readiness Sprint, from $1,500, delivered in 7 business days. The Sprint produces the answer to the endpoint question, and the other nine, with the underlying evidence attached.
If you want to score yourself first, before talking to anyone, the free cyber insurance questionnaire walks the same ten controls in the carriers' own words.
If the application question was the prompt for this reading and you want to close the gap it exposed, start with the free carrier questionnaire — score yourself in your own words first. If you already know the gap and need the evidence packet built, that is the Cyber Insurance Readiness Sprint, from $1,500, delivered in 7 business days.
Last updated
July 28, 2026. We refresh this content as the threat landscape and tools evolve.
FAQ
Yes and no, depending on which Windows Defender you mean and how it is deployed. The built-in signature engine that ships with a consumer Windows license is antivirus and reads on the application as antivirus. The enterprise-grade version, when licensed at the higher Microsoft 365 tier and configured with the endpoint-detection features on and someone monitoring the alerts, can meet the EDR portion of the underwriting question. It does not on its own answer the '24/7 SOC behind it' sub-question — that requires the managed layer, whether that is an internal security team or an MDR service. The honest answer on the application depends on which of those you have.
EDR is the tool. MDR is the tool plus the team. The application asks about both because a tool nobody is watching is a data source, not a response capability. Some carriers will accept 'EDR plus internal 24/7 monitoring' as equivalent to MDR; most will not accept 'EDR, monitored during business hours' as MDR.
We cannot promise that. Underwriter decisions are theirs, not ours. What MDR does is change what you can truthfully attest to on the application — from 'no' or 'partial' on the endpoint-detection question to a clean 'yes' with evidence — which changes which carriers will quote, at which terms, and whether the ransomware endorsement's controls-warranty clause is triggered at claim time. Insurability and terms move on control quality. Premium is a downstream effect of that.
Yes, in two ways. First, external attack-surface scans run during underwriting — the carrier checks whether the internet-facing services you claim to have locked down are actually locked down. Second, at claim time, the forensics firm reconstructs the environment as it was at the moment of loss. If the environment does not match the application, the material-misstatement clause is a real risk.
Because the 2018 threat model — a malicious email attachment triggering a known malware signature — is not the 2026 threat model. Modern ransomware crews sign in with stolen credentials, use legitimate admin tools, disable protections, and stage activity for days before the encryptor runs. Antivirus and firewalls do not see that. EDR, watched by a real team, does. The application caught up to the threat model.
Related reading
The 10 security controls cyber insurers actually score in 2026 — what carriers ask, what passes, and the quiet answers that get applications declined.
Read articleA practical walkthrough of cyber insurance for first-time SMB buyers in 2026 — what the policy covers, what the questionnaire asks, the controls carriers review, and how to pass the application without overspending.
Read articleThe 22 cyber-insurance underwriting controls carriers ask about in 2026 — what each one asks, why carriers care, and how to answer without overcommitting your stack.
Read article