A few years ago, a small business could obtain cyber liability insurance by completing a one-page questionnaire and paying a few hundred dollars per year. That era is over. In 2026, insurers are approaching cyber underwriting much like commercial property underwriting. They want to assess the risk before they price it. According to recent industry data, more than 73% of small businesses fail their cyber insurance assessments in 2026, resulting in either a denial or a premium increase that can exceed 300%. Only 38% of small businesses currently carry cyber insurance.
The businesses that qualify for coverage, particularly at favorable rates in a market where pricing has softened for well-prepared accounts, have implemented five specific security controls that insurers now treat as baseline requirements. These are not optional enhancements. They are increasingly the minimum standard for obtaining coverage from many carriers in the current market.
1. Multi-Factor Authentication on All Remote Access and Privileged Accounts
Multi-factor authentication (MFA) is the single most frequently cited control by cyber underwriters, and its absence is one of the most common reasons small businesses fail cyber insurance assessments. MFA requires a second form of verification, such as a code sent to a phone, biometric confirmation, or hardware token, in addition to a password before granting access to systems or accounts. For cyber insurers, MFA on remote access and administrative accounts helps address one of the most common attack vectors in ransomware incidents: compromised credentials.
The requirement extends beyond just email. Insurers now expect MFA on remote desktop protocol (RDP) connections, virtual private networks (VPNs), cloud services, and any administrative or privileged accounts that have elevated access to company systems. A business that has enabled MFA on email but left RDP access protected only by a password is failing the underwriting requirement even if it does not know it.
2. Endpoint Detection and Response Software on All Devices
Traditional antivirus software identifies known malicious files based on a database of signatures. Endpoint detection and response (EDR) software monitors device behavior in real time, identifying suspicious activity patterns that indicate an attack in progress — including the file encryption behavior that characterizes ransomware before it has completed its work. The difference is the difference between a lock that stops someone from walking in and a security system that detects someone moving through the house.
Insurers require EDR rather than basic antivirus because the threat landscape has evolved beyond what signature-based detection can address. AI-generated phishing emails, polymorphic malware that changes its signature to avoid detection, and living-off-the-land attacks that use legitimate system tools for malicious purposes are all designed to evade traditional antivirus. EDR is the minimum technical control that provides meaningful detection capability against these attack types.

3. Regular Encrypted Backups Stored Separately From the Primary Network
Ransomware attacks are designed to reach and encrypt backup files as well as primary data, rendering them useless as a recovery mechanism. The underwriting requirement is not simply that backups exist. Backups should be encrypted, tested regularly, and stored in a location that cannot be reached from the primary network or accessed using the same credentials as production systems. Cloud backups stored in a separate tenant with separate credentials, or offline backups that are physically disconnected from the network, can meet this requirement. Backups stored on a network drive that is accessible using the same credentials as production systems do not.
The practical test underwriters apply is whether a complete ransomware event, one that encrypts all accessible data on the primary network, would leave the business with recoverable data to restore from. If the answer is yes, the backup architecture is adequate. If the answer is uncertain, it is not.
4. Documented Employee Security Training With Phishing Simulation
Human error remains a primary entry point for cyber incidents. Phishing emails, which are designed to trick employees into providing credentials or clicking malicious links, are among the most common initial attack vectors affecting small businesses. Insurers increasingly require documented security awareness training programs that include periodic phishing simulations, rather than relying solely on annual training completion certificates.
The distinction matters. An annual training module that employees click through and forget produces no measurable reduction in phishing susceptibility. A quarterly phishing simulation program that sends realistic test emails to employees, tracks click rates, and provides targeted training to employees who fail the simulations produces documented improvement in the behavior that determines whether an attack succeeds. Insurers who see phishing simulation data showing improvement trends over time provide more favorable underwriting treatment than those reviewing a single training completion report.
5. A Written Incident Response Plan
An incident response plan is a documented procedure outlining what a business will do during the first 24 to 72 hours after discovering a cyber incident. It identifies who is responsible for key decisions, which external parties, such as legal counsel, forensic investigators, breach notification services, and the cyber insurer, should be contacted and in what order, and which technical steps should be taken to contain the incident before it spreads. Insurers require these plans because the cost of a cyber incident is influenced not only by the nature of the attack, but also by how effectively the business responds.
Businesses that respond to a ransomware incident without a plan typically take significantly longer to contain the attack, notify affected parties, and restore operations than those with documented procedures. Every additional hour of business interruption is additional cost. Every delayed notification is additional regulatory exposure. The written plan does not need to be elaborate, It needs to be specific about who does what and how to reach them at 2 AM on a Saturday.
The commercial insurance team at Tooher-Ferraris helps businesses evaluate their cyber security posture against current underwriting requirements and structure cyber coverage that reflects their actual risk profile. Learn more at https://toofer.com/commercial-insurance/ and https://toofer.com/specialty-programs/.
The Cybersecurity and Infrastructure Security Agency (CISA) publishes free resources on small business cybersecurity requirements at cisa.gov. The FTC’s cybersecurity guidance for small businesses is available at ftc.gov.
Frequently Asked Questions
What happens if my business fails a cyber insurance assessment?
The outcomes range from a flat denial of coverage to conditional coverage with exclusions for the controls that are missing, or a significant premium surcharge until the controls are implemented. For businesses that already carry cyber insurance, failure to maintain the controls disclosed on the application at inception can result in claim denial even on an active policy. The most cost-effective approach is implementing the required controls before applying for coverage, not after receiving a denial.
How much does cyber insurance cost for a small business in 2026?
For a small business with 10 to 30 employees, a $1 million cyber liability policy typically costs between $1,200 and $5,000 per year in 2026, depending on the industry and security posture. Businesses that implement all five core controls have seen premiums stabilize or fall by 50% to 60% compared with businesses without those controls. Industry also matters significantly. Businesses that handle large volumes of sensitive personal data, including healthcare, financial services, and legal firms, generally pay more than businesses with lower data sensitivity profiles.
Is cyber insurance required for small businesses?
Cyber insurance is not universally required by law, but it is increasingly required by contract. Many vendor agreements, client contracts, and lease agreements now specify minimum cyber liability coverage as a condition of doing business. Businesses that experience a breach without cyber insurance are also responsible for the costs of forensic investigations, breach notifications, legal fees, regulatory fines, and lost business income. These expenses can place significant financial strain on uninsured small businesses and, in some cases, threaten their ability to remain in operation.
Ready to evaluate your cyber security posture and coverage options? The team at Tooher-Ferraris has been helping businesses manage cyber risk since 1932. Contact us today to schedule a no-obligation consultation — https://toofer.com/contact-us/





