Skip to content
Eudora Technology
Home  / Insights
Cybersecurity

Cyber Insurance: What Underwriters Actually Ask For

Farmers Insurance office in Eugene, Oregon
Photo: Farmers Insurance office in Eugene, Oregon by Rick Obst, CC BY 4.0, via Wikimedia Commons

Before you fill in a cyber insurance application, spend a fortnight collecting five pieces of evidence: a screenshot showing multi-factor authentication enforced on email and remote access, your endpoint protection console’s coverage report, a dated record of a successful backup restore, your written incident response plan with the phone numbers filled in, and a list of who holds administrator rights. Those five documents answer most of the questionnaire and determine most of the price. Everything else is detail.

What this article is and is not

This is a description of how cyber insurance underwriting generally works, written from the technical side. It is not insurance, legal or financial advice, and it cannot tell you what any particular policy covers. Your broker and the policy wording decide that, and the wording differs markedly between insurers.

Travel insurance of Beleximgarant
An insurance policy is a document about evidence. Cyber underwriting has moved the same way: the question is no longer whether you have a control, but whether you can show it was on.Photo: Beleximgarant insurance policy 2019 by Rakoon, CC0, via Wikimedia Commons

What underwriters are really pricing

An underwriter is answering one question: how likely is this business to produce a claim, and how big would it be. They do that with claims data across thousands of policies rather than an opinion about your industry. That is why the questionnaire is weighted towards a small set of controls that claims history shows prevent or limit loss, and why the softer parts of your security programme barely move the price.

The cost side of the equation is well documented. IBM’s 2026 Cost of a Data Breach Report put the global average cost of a breach at USD 4.99 million, a 12% rise on the previous year and the highest in the report’s history. IBM also found that roughly one in four malicious breaches were AI-enabled and those cost around USD 6 million. Those figures are skewed by very large organisations, so they are not a forecast of your loss. They are the reason insurers care about the tail.

The practical consequence is that your premium is driven less by what you spend on security and more by whether four or five specific things are true and provable. A business with enforced multi-factor authentication, endpoint detection on every machine, tested offline backups and a written response plan looks materially different in a pricing model from one without, regardless of headcount or sector.

The market as it stands in 2026

Conditions currently favour buyers. Marsh’s Global Insurance Market Index reported that global commercial insurance rates fell 6% in the second quarter of 2026, the eighth consecutive quarter of composite decreases, with cyber down 4% in the same quarter. That makes twelve consecutive quarters of cyber rate declines, which Marsh attributes to stable capacity and continuing high levels of competition between insurers.

Line of businessGlobal rate change, Q2 2026Context from the same index
Composite, all lines-6%Eighth consecutive quarter of decreases, after -5% in Q1
Property-12%The sharpest decline, against -9% in the previous two quarters
Casualty+2%The only major line rising, driven by US claims severity
Financial and professional lines-3%Moderating from -5% the previous quarter
Cyber-4%Twelfth consecutive quarter of declines
Global commercial insurance rate movements, second quarter of 2026. Source: Marsh Global Insurance Market Index, Q2 2026.

Falling rates do not mean an easier application. The same market reports describe underwriting outcomes as increasingly driven by exposure quality and risk management, which is the industry’s way of saying that the discount goes to businesses that can demonstrate control, and the decline goes to those that cannot. Competition has lowered the price of a good risk, not widened the definition of one.

Uptake in the UK is now close to half of all businesses. The Cyber Security Breaches Survey 2025/2026 found 47% of businesses insured against cyber risks in some way, with 55% of small and 61% of medium businesses covered, against 35% of charities. Among high-income charities the figure reached 75%, up from 64% the year before.

Share of UK organisations with some form of cyber insurance, 2025/2026
All businesses47%
Small businesses55%
Medium businesses61%
All charities35%
High-income charities75%
Base: 2,112 businesses and 1,085 charities. Source: Cyber Security Breaches Survey 2025/2026, DSIT and the Home Office.

The control questions, and the evidence that answers them

Questionnaires vary, but the control areas repeat. Here is what each question is actually asking and what satisfies it.

Control areaWhat the form asksEvidence that satisfies itWhere it comes from
Multi-factor authenticationIs MFA enforced for email, remote access, administrator accounts and cloud services?A screenshot of the conditional access or security policy showing enforcement, plus the count of users excludedYour identity platform’s admin console
Endpoint detection and responseIs EDR deployed on every endpoint and server, and who monitors the alerts?A coverage report listing machines with the agent installed, and the total device count to compare it againstYour EDR or managed detection vendor’s console
BackupsAre backups immutable or offline, and when did you last test a restore?A dated restore test record naming what was restored and how long it tookYour own test, written up at the time
Privileged accessHow many administrator accounts exist, and are they separate from daily accounts?A list of privileged accounts with named owners and a note of the last review dateYour identity platform, exported quarterly
PatchingWhat is your remediation timeline for critical and internet-facing vulnerabilities?A one-page policy with actual day counts, plus evidence the cadence is followedYour patch management policy and update reporting
Incident responseDo you have a written, tested plan, and who do you call?The plan itself, with real phone numbers, plus the date of the last tabletop exerciseWritten once, reviewed annually
Email securityDo you run email filtering, and have you implemented SPF, DKIM and DMARC?Your DMARC record and policy, plus the filtering product in useA DNS lookup and your mail platform
TrainingDo staff receive security awareness training, and how often?Attendance or completion records with datesWhatever you actually run, recorded at the time
Third-party riskDo you assess the security of suppliers with access to your systems or data?Your supplier register with tiers and review datesBuilt once, maintained annually
The control areas that recur across cyber insurance applications and the evidence that answers each. Control framing drawn from CISA’s Cross-Sector Cybersecurity Performance Goals and the risk management areas covered in the Cyber Security Breaches Survey 2025/2026.

If you want a free framework to organise this against, CISA’s Cross-Sector Cybersecurity Performance Goals are a reasonable fit. They were written as a prioritised baseline for organisations without large security teams, and they cover most of what an underwriter asks about, in plain language, with no licence fee.

The two answers that most often need qualifying are MFA and EDR coverage. Almost nobody is genuinely at 100% on either, because there is always a service account, a legacy application or a machine in a cupboard. Say so, give the number, and say what compensates for it. Our multi-factor authentication guide covers how to shrink that exclusion list before you apply.

Photo: Karolin Köster (EU2017EE)
Insurers, regulators and security teams have converged on the same short list of controls. That convergence is useful: preparing for an application and improving your security are now largely the same exercise.Photo: EU cyber security conference 2017 by EU2017EE Estonian Presidency, CC BY 2.0, via Wikimedia Commons

Where applications get loaded or declined

Three patterns come up repeatedly in applications that get loaded with a higher premium, a larger retention, or a refusal to quote.

  1. Remote access without phishing-resistant authentication. A VPN or remote desktop service reachable from the internet with password-plus-code is the single most common loading. Fixing it is usually a configuration change, not a purchase.
  2. Backups that live in the same place as the data. If ransomware can reach your backups, your recovery plan is a payment. Immutable or offline copies are the test, and our ransomware protection guide covers what that means in practice for a small estate.
  3. Unsupported software on internet-facing systems. An end-of-life operating system or appliance with a public IP address is an automatic question, and sometimes an automatic decline.

There is a fourth, subtler one: inconsistency. If the application says MFA is enforced everywhere and the attached policy screenshot shows nine excluded accounts, the file goes to a human for review and the process slows by weeks. Underwriters are not looking for perfection. They are looking for a business that knows its own estate.

What cover usually includes, and what it usually excludes

Cover differs between insurers far more than buyers expect, and the only authoritative description of what you have bought is your policy wording. That said, the structure is usually recognisable. First-party cover deals with your own losses: incident response costs, forensics, legal advice, notification, business interruption, data restoration and, subject to conditions and sanctions rules, extortion payments. Third-party cover deals with claims against you from customers or regulators, including defence costs.

The exclusions are where the surprises live. Common ones include losses arising from unsupported software, failure to apply patches within a stated timeframe, acts of war or state-sponsored attack, prior known circumstances, and loss of value rather than loss of data. The war and state-actor exclusions have been rewritten repeatedly across the market in recent years and the wording varies considerably, which is exactly the sort of detail to put to a broker rather than infer from an article.

Questions worth asking your broker
  • What is the retention, and is there a separate waiting period before business interruption cover starts?
  • Is the incident response panel fixed, and can we use our own responders?
  • How is business interruption calculated, and from what point?
  • What exactly does the unsupported-software exclusion cover, and does it apply per system?
  • How is the war or state-sponsored attack exclusion worded in this policy?
  • Does cover extend to an outage at a supplier, and if so which suppliers?

The UK National Cyber Security Centre’s own guidance on cyber insurance makes the point that insurance complements risk management rather than replacing it, and that organisations should understand what a policy requires of them before they rely on it. That is the right frame. A policy is a financing instrument for the tail of your risk, not a control.

Answer the questions carefully, because the answers are part of the contract

The application is not a survey. Depending on how the policy is written, your answers may operate as representations or warranties, and a material inaccuracy can affect a claim. This is the part where technical people accidentally cause commercial problems, usually by rounding up.

  • Give numbers, not adjectives. ‘MFA enforced on 94 of 97 accounts, three service accounts excluded and restricted to internal IP ranges’ is a better answer than ‘yes’.
  • Date your evidence. A restore test from fourteen months ago is not a tested backup. Run one this month and write it up.
  • Keep what you sent. Save the completed application and its attachments with the renewal file. At claim time, the question is what you said and when.
  • Tell your broker when something changes materially. Switching off a control you declared, or acquiring a business with a different estate, is worth a note mid-term rather than a conversation after an incident.
Farmers Insurance at 4810 S Emerson Ave, Indianapolis, IN 46203
The renewal conversation goes better when last year’s evidence pack is still on file and this year’s version only needs updating.Photo: Farmers Insurance office – June 2022 – Sarah Stierch by Missvain, CC BY 4.0, via Wikimedia Commons

Ransomware, payments and the numbers behind the premium

Ransomware drives the shape of the cyber market, so it is worth knowing where the numbers actually sit. Chainalysis, which traces payments on public blockchains, reported in its 2026 Crypto Crime Report that ransomware actors received more than USD 820 million in on-chain payments during 2025, an 8% decline on its revised 2024 estimate of USD 892 million. Over the same period the number of victims named on leak sites rose roughly 50%, to nearly 8,000 events.

The two trends together explain a lot. The share of victims who paid fell to a record low of 28%, while the median payment rose 368%, from USD 12,738 in 2024 to USD 59,556 in 2025. Fewer organisations pay, so attackers chase larger targets and demand more from the ones who do. For a small business the practical reading is that recovery capability, not payment capability, is what keeps you out of that statistic.

Median ransomware payment, Chainalysis 2026 Crypto Crime Report
2024$12,738
2025$59,556
On-chain median payment size. Total payments fell 8% to USD 820 million across the same period, while the share of victims paying dropped to 28%. Source: Chainalysis, Crypto Ransomware: 2026 Crypto Crime Report.

On payments themselves, be clear about what insurance does and does not do. Where a policy includes extortion cover it is subject to conditions, insurer consent and sanctions screening, and insurers will not fund a payment to a sanctioned entity. The decision is never purely financial and never purely yours. The useful preparation is the dull kind: offline backups you have restored from, a response plan with real numbers in it, and a clear view of how long you could operate without your main systems.

Getting ready in six weeks

Six weeks, mostly spent collecting things you already have.

  1. Week one. Export the user list from your identity platform and record how many accounts have MFA enforced, how many are excluded and why.
  2. Week two. Pull the endpoint protection coverage report and reconcile it against your actual device count. Install the agent on whatever is missing.
  3. Week three. Run a restore test. Pick a real file set, restore it, time it, and write a half-page note with the date.
  4. Week four. Write the incident response plan if you do not have one. Two pages: who decides, who calls whom, which systems come back first, and the out-of-hours numbers.
  5. Week five. Check your DMARC record and your patching policy. Both are on most questionnaires and both are quick to document.
  6. Week six. Assemble the evidence pack in one folder, then talk to a broker. Going to market with the pack ready is what turns a four-week quote cycle into a one-week one.

Nothing in that list is insurance work. It is the same short list of controls that reduces your chance of an incident, which is the quietly useful thing about cyber underwriting: the questionnaire has become a reasonable security to-do list. If you want help assembling the pack or closing the gaps it exposes, our cybersecurity services cover both, remotely. And since phishing remains the most common route to a claim, our guide to stopping phishing attacks is a sensible companion to this one.

Frequently asked questions

Is cyber insurance worth it for a business of thirty people?

Usually, but for the response capability as much as the indemnity. The part small businesses actually use is the incident response panel: forensic responders, legal support and notification help, available within hours of a call. Buying that capability retail during an incident is slow and expensive. Whether the limits and wording suit you is a conversation for a broker.

Why are premiums falling if attacks are rising?

Because capacity and competition, not loss frequency alone, set price. Marsh recorded cyber rates down 4% globally in the second quarter of 2026, a twelfth consecutive quarterly decline, attributed to stable capacity and strong insurer competition. The discount is concentrated on risks that can demonstrate controls, so a weak application can still be loaded in a soft market.

Will an insurer actually check our controls?

Increasingly yes, in two ways. Applications ask for evidence such as console screenshots and coverage reports rather than yes or no answers, and many insurers run external scans of your internet-facing estate before quoting. Expect anything exposed and unpatched to appear in that scan whether you declared it or not.

Does having insurance mean we can skip security spending?

No, and the two interact in the other direction. The NCSC’s guidance treats insurance as a complement to risk management, and policies commonly exclude or restrict losses tied to unsupported software or missed patching. The controls that get you a good premium are the same ones that keep you from claiming.

What if we have already had an incident?

Disclose it. Prior known circumstances are a standard exclusion, and an undisclosed incident is a far bigger problem than a disclosed one. Insurers write business for organisations that have been breached all the time, particularly where you can show what changed afterwards. A clear account of the incident and the remediation often reads better than a blank history.

If you would rather walk into a renewal with the evidence pack assembled and the obvious gaps already closed, we can run the six-week preparation with you and document the result. Get in touch with Eudora Technology to talk about your project.

Sources

  1. Global Insurance Market Index, Q2 2026 Marsh · Q2 2026
  2. Cyber Security Breaches Survey 2025/2026 UK Department for Science, Innovation and Technology and Home Office · 2026
  3. Crypto Ransomware: 2026 Crypto Crime Report Chainalysis · 2026
  4. Cost of a Data Breach Report 2026 IBM · 2026
  5. Cross-Sector Cybersecurity Performance Goals CISA · retrieved October 2026
  6. Cyber insurance guidance UK National Cyber Security Centre · retrieved October 2026
Keep reading

Related insights