Live Threats
[STRUTS]Apache Struts zero-day (CVE-2026-3101) under mass exploitation — ransomware groups deploying web shells on Java web apps. Patch immediately.|
[LAZARUS]North Korean Lazarus Group targets SMB defense contractors via fake LinkedIn recruiter profiles delivering trojanized job documents.|
[DEEPFAKE]Deepfake CEO video call fraud stole $3.2M in a single transaction. AI voice and face synthesis now indistinguishable — targeting US SMBs.|
[CHROME]CVE-2026-2356 Chrome zero-day actively exploited to deliver spyware. Update to 136.0.7103.92 immediately on all devices.|
[HIPAA]HHS finalized major HIPAA Security Rule updates — mandatory encryption at rest, MFA, and annual pen testing effective December 31, 2026.|
[CISA KEV]CISA added 15 new KEV entries this week — six are priority patches for internet-facing systems including Struts, Chrome, Cisco, Fortinet, Ivanti, and VMware.|
[STRUTS]Apache Struts zero-day (CVE-2026-3101) under mass exploitation — ransomware groups deploying web shells on Java web apps. Patch immediately.|
[LAZARUS]North Korean Lazarus Group targets SMB defense contractors via fake LinkedIn recruiter profiles delivering trojanized job documents.|
[DEEPFAKE]Deepfake CEO video call fraud stole $3.2M in a single transaction. AI voice and face synthesis now indistinguishable — targeting US SMBs.|
[CHROME]CVE-2026-2356 Chrome zero-day actively exploited to deliver spyware. Update to 136.0.7103.92 immediately on all devices.|
[HIPAA]HHS finalized major HIPAA Security Rule updates — mandatory encryption at rest, MFA, and annual pen testing effective December 31, 2026.|
[CISA KEV]CISA added 15 new KEV entries this week — six are priority patches for internet-facing systems including Struts, Chrome, Cisco, Fortinet, Ivanti, and VMware.|
View All
Cyber Insurance Premiums Rising — What Insurers Are Now Requiring in 2026
ADVISORYINFO

Cyber Insurance Premiums Rising — What Insurers Are Now Requiring in 2026

Published April 10, 2026
5 min read
Source: Marsh McLennan / Coalition Insurance
SHARE:
Executive Summary

Cyber insurance carriers are tightening underwriting requirements in 2026. Businesses without EDR, MFA, immutable backups, and documented incident response plans are seeing premium increases of 30-60% or coverage denials.

The Changing Cyber Insurance Landscape

Cyber insurance has become an essential component of business risk management, but the market has changed dramatically in recent years. Following a wave of costly ransomware claims in 2021-2023, insurers significantly tightened their underwriting requirements and increased premiums. In 2026, the trend continues — insurers are requiring more robust security controls as a condition of coverage, and businesses that cannot demonstrate these controls are facing premium increases of 30-60% or outright coverage denials. Understanding what insurers now require is essential for any business seeking to obtain or renew cyber insurance.

What Insurers Are Now Requiring

Based on underwriting questionnaires from major cyber insurers including Coalition, Chubb, AIG, and Travelers, the following controls are now near-universally required: Endpoint Detection and Response (EDR) on all endpoints — traditional antivirus is no longer sufficient; Multi-factor authentication on all remote access systems (VPN, RDP) and email accounts; Immutable or air-gapped backups tested at least quarterly with documented results; A documented incident response plan that has been reviewed or tested within the past 12 months; Email security controls including DMARC, DKIM, and SPF; Privileged access management for administrative accounts; Network segmentation separating critical systems from general business traffic.

How to Prepare for Your Renewal

Before your cyber insurance renewal, conduct an internal assessment against the controls listed above. Document your current security posture and identify any gaps. Implement missing controls before your renewal date — insurers are increasingly verifying controls through technical questionnaires and sometimes direct technical assessments. When completing your renewal application, be accurate and thorough — misrepresentation of your security posture can result in claim denial. Work with your insurance broker to understand your specific insurer's requirements and ensure your application accurately reflects your security controls. Segler.Net can help you implement the required controls and document your security posture for insurance purposes.

Key Takeaways & Action Items
  • Review your cyber insurance policy renewal requirements before your next renewal date
  • Implement EDR on all endpoints — this is now a near-universal requirement
  • Enable MFA on all remote access and email — insurers are verifying this during underwriting
  • Test your backups quarterly and document the results — insurers want proof of tested backups
  • Develop a documented incident response plan — even a basic one satisfies most insurers
Share This

Need Help With This Threat?

Our San Antonio security team can assess your exposure, apply patches, and protect your business before attackers strike.

Stay ahead of the next threat

Get weekly security alerts — breaches, patch updates, compliance news, and threat intel — delivered free to your inbox every week.

Breach alerts
Patch roundups
Compliance news
No spam, ever
Talk with Us