Let’s talk about IT

Your cyber insurance won't pay if you can't prove it: The 2026 underwriting reality

Nick Saccomondo
Cyber insurance renewal documents on desk with laptop showing MFA dashboard

Posted date: May 27, 2026

Key Takeaways

  • Underwriting has shifted from questionnaire to evidence audit. In 2026, insurers want exportable reports proving every control you claim — not just a signed attestation.
  • MFA gaps are the #1 reason claims get denied. Coalition’s data shows 82% of denied claims involved organizations with incomplete MFA coverage — often a single overlooked account.
  • Premiums are up 40–100% for organizations that can’t document baseline controls at renewal, with some pushed into surplus lines markets at triple the standard rate.
  • The risk is drift, not negligence. Controls configured 18 months ago quietly slip — a new VPN, a forgotten service account, an unmanaged acquired entity.
  • Standardized identity, device management, and security baselines across every entity are what underwriters now price against. If you can’t pull the evidence package in an afternoon, your renewal will hurt.

In late 2025, a mid-market manufacturer filed a $2.3 million ransomware claim. Their cyber insurer denied it.

The reason? One VPN account had MFA disabled — and the organization had attested, in writing, that multi-factor authentication was enforced across all remote access.

One account. One attestation. $2.3 million on the table.

That denial isn’t an outlier. It’s the new normal — and if your renewal is coming up in 2026, it’s the most important shift you need to understand.

Underwriting in 2026: From questionnaire to evidence audit

For years, cyber insurance applications were trust exercises. You checked the boxes, signed the attestation, and received your renewal. Those days are over.

In 2026, underwriters aren’t asking if you have MFA, EDR, or immutable backups. They want exportable reports proving it — and the forensics teams they hire after an incident are looking for the same evidence.

Coalition’s 2024 Cyber Claims report found that 82% of denied claims involved organizations that lacked properly implemented MFA across their environment — not organizations without any MFA, but organizations with gaps. A privileged account excluded. A legacy VPN account missed. A service account overlooked.

The financial consequences are landing fast. Renewals are coming back with 40–100% premium increases for organizations that can’t produce documentation, and some are being pushed out of the standard market entirely — into surplus lines carriers charging triple the standard rate, often with reduced limits and higher retentions.

Vague answers are getting expensive.

What underwriters now want to see

The bar has moved beyond “do you have it?” to “show us.” A solid 2026 evidence package includes:

  • MFA coverage reports by user, group, and authentication method — including email, VPN, remote desktop, cloud admin consoles, privileged accounts, and service accounts. Gaps are increasingly treated as material misrepresentation.
  • Conditional access policy exports showing what’s enforced across the tenant.
  • Intune (or equivalent) device compliance dashboards confirming encryption, OS version, EDR agent status, and policy enforcement on every managed endpoint.
  • EDR/XDR coverage reports showing 100% deployment with healthy reporting — not just a license count.
  • Immutable backup logs and restore test results with dates.
  • Patch compliance reports with remediation timelines.
  • Training completion and phishing simulation results by user and department.
  • A documented incident response plan with named roles and tested tabletops.

Every control needs a report, not just a policy. If your IT team can pull all of that in an afternoon, you’re ready. If they can’t, you’ve found your gap.

Why claims get denied: Configuration drift

The denial story we opened with wasn’t caused by negligence. It was caused by drift — the slow, invisible gap between what was configured 18 months ago and what’s actually running today.

Drift looks like:

  • A new VPN account that never got rolled into the MFA policy.
  • A service account created for an integration that was scoped “temporarily” two years ago.
  • A new acquisition with its own identity environment that hasn’t been folded into central conditional access.
  • A long-tenured admin whose privileges were never right-sized after a role change.

None of these get flagged on a renewal questionnaire. All of them get flagged in a post-incident forensic audit — and that’s when the claim gets denied.

What standardization looks like in practice

The organizations weathering this market best are the ones that have standardized identity, device management, and security baselines across their entire environment — not just their headquarters.

This is especially relevant for companies operating in highly regulated industries with multiple entities, portfolio companies, or office locations. Every entity needs to operate under the same controls, or the weakest one becomes the underwriter’s reason to deny.

We saw this firsthand with a capital management client managing a growing portfolio of acquired companies. Each acquisition came with its own fragmented IT environment — different identity systems, inconsistent endpoint controls, ad-hoc security. The kind of environment that wouldn’t survive an underwriter’s evidence request, let alone a forensic audit.

“A lot of these companies had a ‘Joe’ — someone doing IT when asked, but not actively monitoring or securing the environment. That’s where risk builds. Our job is to implement proactive oversight and standards across the portfolio.”

— Brendan Thompson, Director of AI, Architecture and Engineering, Macro Technology Group

Macro consolidated those environments into a single Microsoft 365 tenant, aligned everyone under Entra ID, deployed Intune for centralized device management, enforced BitLocker, and rolled out conditional access policies across every user and every device. The result is exactly what underwriters now want to see: one identity plane, one device plane, one security baseline, fully reportable. Read the full breakdown in the case study: How a Capital Management Firm Standardized IT Across Portfolio Companies.

That’s the operating posture cyber insurance is now priced against.

The bottom line: Insurability is an IT discipline now

Cyber insurance used to be a finance department renewal. In 2026, it’s an IT deliverable. If your renewal is in the next six to nine months, do three things now:

  • Pull your evidence package today. If you can’t produce exportable reports for MFA, EDR, backups, and conditional access, you’ve found your gap.
  • Audit for drift. Walk every authentication path, every device fleet, every privileged account. Find the exceptions before an underwriter — or an attacker — does.
  • Standardize across every entity. One identity plane, one set of controls. Anything less is a denial waiting to happen.

The organizations getting reasonable renewals in 2026 aren’t the ones with the biggest budgets. They’re the ones who can prove what they have.

Are you 100% confident your environment is ready for a 2026 cyber insurance renewal — or could there be gaps?

Book a cyber insurance readiness review with Macro. We’ll walk your environment against current underwriter requirements, identify the documentation gaps, and build the evidence package your renewal demands.

Book a readiness review schedule a meeting with Macro