TL;DR: Consolidated 2026 broker data shows a hard reset in cyber-insurance underwriting standards. 96% of cyber insurers now mandate enforced multi-factor authentication across email, VPN, RDP, cloud administrator accounts, and every privileged access path. 88% require endpoint detection and response (EDR) or managed detection and response (MDR) on every endpoint. 73% of SMBs currently fail their 2026 cyber-insurance assessments, resulting in outright denial or premium increases exceeding 300%. Written attestations no longer pass. Carriers now demand exported sign-in logs, Conditional Access screenshots, or a signed IT-vendor letter as evidence. For NC SMBs whose policies renew between July and December 2026, the window to build the evidence packet before the renewal quote lands is closing in weeks.
Key takeaway: Cyber insurance is no longer a checkbox at policy binding. It is a continuous evidence problem. If your Q4 renewal quote is going to be materially worse than last year's, the reason is almost never "your industry got risker." It is "your carrier now requires proof, and you have not built the proof yet."
Is your cyber insurance policy up for renewal between July and December 2026? Contact Preferred Data Corporation for a same-month cyber-insurance readiness assessment and evidence-packet build. BBB A+ rated. On-site within 200 miles of High Point. Call (336) 886-3282.
What Actually Changed in 2026 Cyber-Insurance Underwriting?
Cyber-insurance carriers underwent a wholesale re-underwriting of the SMB book of business between late 2024 and mid-2026 in response to a five-year run of ransomware, business-email-compromise, and SaaS-account-takeover claims that exceeded loss-ratio projections by two- to threefold. The 2026 renewal cycle is the first year in which the tightened questionnaires and control mandates fully bind for the SMB tier.
Three concrete facts every NC SMB should treat as confirmed:
- 96% of cyber insurers now mandate enforced MFA. The coverage scope is broad: email, VPN, RDP, cloud administrator accounts, and every privileged access path. "We have MFA enabled but not enforced" or "MFA on the CEO but not the accounting team" no longer passes. The 96% figure comes from consolidated 2026 broker-panel data published by cyber-insurance-focused technology firms across the Southeast and mid-Atlantic.
- 88% require EDR or MDR on all endpoints. Traditional antivirus (signature-based Symantec, McAfee, Windows Defender in default configuration) no longer satisfies the endpoint control. Named products in questionnaire responses: SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint (Plan 2), Sophos Intercept X, ESET Inspect, Huntress.
- 73% of SMBs fail their 2026 assessment. Failure means one of three outcomes: outright coverage denial, exclusion carve-outs for ransomware or extortion coverage, or premium increases in the 200-500% range with the mid-point around 300%.
The underwriting shift is not a rumor circulating in broker offices. It is the reality of every SMB questionnaire being circulated by Chubb, Travelers, AXA XL, Beazley, Hiscox, Coalition, At-Bay, and Corvus in the first half of 2026. The questionnaires are longer, the questions are more specific, and the evidence requirements have moved from "attest" to "prove."
Key takeaway: The 96%/88%/73% triad is the summary of a market that has finished consolidating around a common minimum. NC SMBs that treat their cyber-insurance renewal as an isolated event once a year will discover that "we passed last year" is no longer predictive.
Why Do Written Attestations No Longer Pass in 2026?
The specific evolution NC SMBs need to understand is the shift from "we attest that we have MFA" to "please attach a sign-in log export or Conditional Access screenshot showing MFA enforcement across the last 90 days." Carriers moved to the evidence-required posture because the attestation-based posture yielded too many claims where the attested control turned out to be missing at the moment of the incident.
Three concrete failure modes NC SMBs face on the 2026 questionnaire:
- The MFA gap on privileged accounts. MFA is enabled for the general user population but not for the domain administrator account, the SQL admin, the Cisco firewall admin, or the SaaS billing admin. Every one of those exclusions is a documented failure at questionnaire time.
- The EDR gap on servers. EDR is deployed on user workstations but not on file servers, print servers, domain controllers, or Hyper-V hosts. Because ransomware detonates most catastrophically on servers, carriers now specifically ask for the EDR coverage percentage on the server population.
- The backup-immutability gap. 3-2-1 backup is present, but the third copy is on the same NAS with a mapped drive letter reachable from the file server. Ransomware encrypts it in the same pass. Carriers now specifically ask for evidence of immutable, offline, or air-gapped backup with a documented restore test.
For a typical NC SMB with 60 users, 4 file servers, a domain controller pair, and a Hyper-V or VMware host, the "documented restore test in the last 90 days from immutable backup" line item alone will fail 40-60% of SMBs on the current questionnaire.
What Should NC SMBs Do Before Their Q4 2026 Renewal?
The response is a coordinated four-track program to close the questionnaire gap and build the evidence packet. All four tracks run in parallel over 60-90 days.
Track 1: Identity plane hardening (Weeks 1-4).
- Enforce MFA on every user, every admin, every service where a service account cannot be constrained by IP or certificate. Microsoft Entra ID Conditional Access, Duo, Okta, Google Workspace 2SV enforcement.
- Export MFA enforcement evidence. Entra sign-in log CSV export or Conditional Access policy screenshot showing "Require multi-factor authentication" applied to all users. Duo authentication log export by user population.
- Eliminate legacy authentication protocols. Basic Auth, POP3, IMAP, SMTP AUTH without OAuth. Every one is a bypass for the MFA control.
Track 2: Endpoint plane hardening (Weeks 2-6).
- Deploy EDR on 100% of workstations and 100% of servers. SentinelOne, CrowdStrike, Microsoft Defender for Endpoint Plan 2, Sophos Intercept X, or an equivalent modern platform. Traditional AV does not satisfy the mandate.
- Confirm coverage via the EDR console. Export the deployed-agent count. Compare to the Active Directory computer object count. Any delta is a finding that will surface at questionnaire time.
- Establish a documented EDR alert triage and response procedure. MDR partnership (24/7 SOC) or written internal escalation. Carriers now ask whether alerts route to a monitored inbox or a 24/7 responder.
Track 3: Backup and recovery hardening (Weeks 3-8).
- Deploy immutable backup on the third copy. Wasabi, Backblaze B2, Azure immutable blob, AWS S3 Object Lock, Veeam Hardened Repository, Datto Immutable Cloud Series, or an equivalent. A NAS with a mapped drive letter does not satisfy the mandate.
- Perform a documented restore test. Full-system restore of at least one production server to a test environment. Written record of the restore date, the source backup, and the successful application boot.
- Document the recovery time objective (RTO) and recovery point objective (RPO) per system class. File servers, email, ERP, CRM, line-of-business applications.
Track 4: Evidence packet assembly (Weeks 8-12).
- Compile the identity, endpoint, and backup evidence into a single dated packet. Cover page with the assessment date, followed by MFA enforcement screenshots, EDR coverage exports, backup immutability confirmation, restore-test record, and any other supporting artifacts.
- Route the packet to your broker two weeks before the questionnaire is due. Brokers who see the packet in advance can pre-negotiate with the underwriter on questionnaire ambiguities.
- Update the packet quarterly. The packet is a living artifact. Any month you renew it is a month you have current-state evidence for the renewal.
How Should NC SMBs Think About Ransomware Sublimits and Exclusions?
The 2026 questionnaire tightening is matched by a policy-language tightening. Even when coverage is bound, the ransomware and extortion sublimits inside the policy have moved from "full policy limit" toward "smaller sublimit or exclusion."
Three concrete policy-language patterns NC SMBs should ask their broker to flag:
- Ransomware sublimit language. Many 2026 policies impose a sublimit of 25-50% of the total policy limit on ransomware-specific first-party costs (ransom payment, negotiator, recovery). If your total limit is $1M, your ransomware coverage may be $250K-$500K, not $1M.
- Widespread event exclusion. Language that excludes coverage when a covered event is part of an industry-wide campaign (Kaseya-style, MOVEit-style, ChangeHealthcare-style). NC SMBs affected as downstream victims of a vendor breach can find themselves outside coverage if this language is not specifically negotiated.
- KEV-list-related exclusion. New 2026 language in some policies excludes coverage when the breach vector is a vulnerability that was on the CISA KEV catalog for more than a defined window (commonly 30-90 days) before the incident. This is the direct policy translation of the SonicWall, MOVEit, and Fortinet events that drove the 2024-2025 loss ratios.
How Does 2026 Cyber Insurance Compare to 2020 Cyber Insurance?
The 2020 SMB cyber-insurance market and the 2026 SMB cyber-insurance market are two different products.
Comparison: 2020 vs 2026 SMB cyber-insurance underwriting posture.
| Element | 2020 Standard | 2026 Standard |
|---|---|---|
| MFA requirement | Recommended | Mandatory, enforced across all users and admins |
| EDR requirement | Traditional AV acceptable | EDR/MDR required on all workstations AND servers |
| Backup requirement | 3-2-1 acceptable | 3-2-1-1-0 with immutable + documented restore test |
| Evidence standard | Written attestation | Exported logs, screenshots, or signed vendor letter |
| Questionnaire length | 20-30 questions | 60-120 questions |
| SMB approval rate | 85-90% | 27-40% (via the 73% failure rate figure) |
| Ransomware coverage | Full policy limit typical | 25-50% sublimit common |
| Premium range (typical SMB) | $2,000-$8,000/year | $8,000-$30,000/year |
| Broker-negotiable posture | Broad | Narrow, evidence-gated |
The market is not going to un-tighten. Carrier loss ratios remain elevated, and the 2024-2026 wave of catastrophic events (MOVEit downstream, ChangeHealthcare, CDK Global) reinforced the underwriting shift. NC SMBs should plan for a durable evidence-required, mandatory-controls posture through at least the 2028 renewal cycle.
Explore Preferred Data's cybersecurity services
How Does Preferred Data Handle Cyber-Insurance Readiness for NC SMBs?
Preferred Data has integrated the cyber-insurance readiness deliverable into every managed cybersecurity retainer since 2024. The offering is a four-layer package aligned to the questionnaire.
PDC's four-layer cyber-insurance readiness program for NC SMBs:
- Baseline assessment against the 2026 questionnaire. We walk your environment against the current Chubb, Travelers, Coalition, and At-Bay questionnaires and produce a gap report against the 96%/88%/immutable-backup triad.
- Remediation execution. MFA enforcement rollout, EDR deployment to workstation and server populations, immutable-backup provisioning, restore-test execution, legacy-auth elimination. Progress reported to your broker on a weekly cadence.
- Evidence packet assembly. Screenshots, log exports, policy documents, and vendor confirmations compiled into a single dated packet ready for questionnaire attachment. Refreshed quarterly.
- Renewal support. We attend the underwriter call with your broker and speak to the technical controls in place. Underwriters are more willing to bind coverage when a named MSP with sector expertise is on the line.
Cost for a typical 40-100 person NC SMB: $12,000-$25,000 for the initial readiness build, plus ongoing evidence-packet maintenance included in a managed cybersecurity retainer. The alternative, a 300% premium increase on a $12,000 policy, is $36,000 in year-one premium alone, plus the significantly reduced coverage terms.
Frequently Asked Questions
What percentage of SMBs actually pass the 2026 cyber-insurance assessment?
Consolidated 2026 broker data indicates that 73% of SMBs fail their cyber-insurance assessment. Failure means outright denial, exclusion carve-outs on ransomware or extortion coverage, or premium increases in the 200-500% range. The 27% who pass generally have (a) enforced MFA everywhere, (b) EDR on both workstations and servers, (c) documented immutable backup with a recent restore test, and (d) a written incident-response plan tested inside the last 12 months.
Is Windows Defender enough EDR for cyber insurance?
Windows Defender in its default free configuration is not sufficient. Microsoft Defender for Endpoint (Plan 2), which is the paid enterprise SKU with EDR capabilities, is accepted by every major 2026 carrier when properly deployed and monitored. The distinction between "free Windows Defender AV" and "Defender for Endpoint Plan 2 EDR" is not obvious from the product naming, and it is a common questionnaire failure point.
What if we cannot deploy MFA on our ERP system because the vendor does not support it?
This is a common NC SMB pattern with legacy Actian Zen, Pervasive SQL, or vendor-specific ERP systems. The 2026 carrier expectation is a compensating control: restrict access to the ERP system to a defined jump-host or Privileged Access Workstation that itself requires MFA at logon, and document the compensating architecture in the evidence packet. Some carriers will accept this; some will require the ERP to be behind Entra Private Access or a similar ZTNA layer.
How much time do we need to build the evidence packet before renewal?
For an SMB starting from a "we have MFA on some things, EDR on workstations only, and a NAS backup" baseline, plan for 60-90 days to close the gaps and build a defensible evidence packet. For SMBs at a stronger baseline, 30-45 days is achievable. Do not start the build the week the questionnaire arrives; the timeline does not work.
What is "immutable backup" and why do carriers care?
Immutable backup is a backup copy that cannot be modified or deleted for a defined retention period, even by an administrator with full credentials. Object Lock in S3-compatible storage, Veeam Hardened Repository, Datto Immutable Cloud Series, and Wasabi Bucket Lock are examples. Carriers care because the ransomware playbook now specifically targets and encrypts writable backups as a first step; an immutable copy is the one thing an attacker cannot delete.
Does using an MSP help our cyber-insurance renewal?
Underwriters have moved from indifferent to affirmatively positive on the presence of a named MSP with sector experience. The specific value is: (a) the MSP has the tooling to produce evidence packets that a broker can attach to a questionnaire, (b) the MSP is on the underwriter call to speak to controls, and (c) the MSP is contractually accountable for maintaining the controls between renewals. NC SMBs on a self-managed IT model face a materially harder renewal in 2026.
Can we skip cyber insurance and self-insure?
Self-insurance is a legitimate strategy for organizations with the balance sheet to absorb a $500K-$2M incident cost. For a typical NC SMB with $2-20M in annual revenue, the ransomware-payment plus incident-response plus business-interruption cost of a moderate event is 6-18 months of net income. Self-insurance without that balance-sheet backing is not a strategy; it is a bet.
Related Resources
- Cybersecurity Services for NC Small Businesses
- Managed IT Services
- Backup Services
- Contact PDC — request a same-month cyber-insurance readiness assessment and evidence-packet build