Cybersecurity

Your Cyber Insurance Renewal Just Doubled. Here’s How to Fight Back Before December.

48 Technologies Team ·

The three-year cyber insurance rate reprieve is ending. If your renewal lands in Q4, this is not the year to autopilot it.

From late 2023 through Q2 2026, cyber insurance rates fell for twelve straight quarters. International rates dropped about 43% off their 2022 peak (Insurance Business America). Reinsurance rates fell 32% in the same window. Underwriters got competitive. Renewals got easy.

That’s over. Reinsurance capacity is tightening, ransomware claims are spiking again, and industry analysts are now openly modeling 15–20% rate increases for 2026 renewals as the market repricies risk (Amitabh Palit Roy, LinkedIn). Your last renewal was the floor. The next one won’t be.

But the premium hike isn’t the real story. The real story is what happens if you file a claim.

The 82% Number Every Dallas Business Owner Should Know

Coalition’s 2024 Cyber Claims Report buried a finding that most business owners never saw: 82% of denied cyber insurance claims involved organizations that had multi-factor authentication (MFA) — but not properly implemented across their environment (BASG Corp analysis).

Read that again. Not “no MFA.” Not “lied on the application.” The applicant said yes to MFA, deployed MFA, believed they had MFA — and still got their claim denied because when the forensic investigator arrived, the coverage had gaps.

The gaps are almost always in the same places: service accounts, legacy VPNs, backup consoles, third-party admin portals, and privileged accounts held by IT contractors. Places the business owner doesn’t look. Places the underwriter didn’t ask about specifically. Places the forensic investigator absolutely will.

This is the pivot: cyber underwriting has stopped being a questionnaire and started being a technical audit with financial consequences (SecureBin). Carriers now run their own external attack surface scans against your firewall, DNS, and exposed services before they quote. Some ask for exportable evidence — screenshots, config exports, EDR console reports — instead of a signed attestation. If what they see doesn’t match what you told them, your renewal gets surcharged or denied. If it matches at renewal but doesn’t match at claim time, coverage evaporates.

What Actually Changed in Late 2026 Underwriting

Three specific things are different in a Q4 2026 renewal versus the one you did last year.

1. The questionnaire got longer and the questions got more specific

Carriers added roughly six controls to the standard SMB questionnaire in 2026 and expanded existing questions. The 2026 SMB questionnaire now scores 22 controls across six categories, up from the ~15-item questionnaires most SMBs saw in 2024 (Obsidian Ridge). The MFA question alone now typically has 5–7 sub-questions: MFA on email, on remote access, on privileged accounts, on cloud admin consoles, on backup consoles, on service accounts, and on any customer-facing portal. “Yes” is no longer a valid answer to any of them individually.

2. Carriers are actively scanning you before quoting

External attack surface scanning is now standard across major carriers. They point their tooling at your public IPs, your MX records, your DNS, your published services, and they compare what they find against what you claimed. If you said you don’t expose RDP to the internet and they see port 3389 open on a firewall, that’s a surcharge or a decline. This is happening whether or not your broker mentions it.

3. Coverage exclusions have gotten sharper

Post-2022, most SMB cyber policies now contain “widespread event” exclusions, ransomware sub-limits (typically 25–50% of the aggregate limit), and material misrepresentation clauses that let the carrier void the entire policy retroactively if the application misstated a control. The clauses aren’t new. What’s new is that carriers are actually invoking them.

The 2026 Q4 Renewal Checklist

Here’s what you should have documented and verifiable before you submit a 2026 cyber renewal application. If your answer to any of these is “I think so,” treat it as “no” until you’ve verified.

MFA (the one that matters most)

  • Enforced on every email account, including shared mailboxes and service accounts that receive mail
  • Enforced on every remote access path — VPN, RDP, SSH, any third-party remote support tool
  • Enforced on every privileged/admin account — Global Admin, Domain Admin, database admin, firewall admin, cloud console admin
  • Enforced on your backup console (this is the one people miss)
  • Enforced on any customer-facing portal that stores sensitive data
  • Documented with an exportable report showing coverage by user and by system

Endpoint protection

  • EDR or MDR on 100% of endpoints — desktops, laptops, servers, virtual desktops
  • The console shows coverage and the last check-in date for every device
  • Traditional antivirus (Symantec, McAfee legacy, built-in Defender without EDR features) will fail this question with most carriers now

Backups

  • 3-2-1-1 pattern: 3 copies, 2 media types, 1 offsite, 1 immutable or air-gapped
  • The immutable copy is the piece most carriers now require explicitly
  • Restore testing performed and documented in the last 12 months
  • Backup console protected with MFA (see above)

Incident response

  • Written incident response plan, updated in the last 12 months
  • Tabletop exercise run in the last 12 months (roughly 79% of carriers now require documented evidence)
  • Named incident coordinator and carrier notification path

Privileged access & identity

  • Admin accounts separated from daily-use accounts
  • Some form of PAM or admin account monitoring in place
  • Conditional access rules on your Microsoft 365 or Google Workspace tenant
  • Offboarding process that removes access within 24 hours

Patching & email

  • Documented patching cadence with evidence of compliance
  • Advanced email filtering with click-time link scanning and attachment sandboxing
  • DMARC published and enforced at p=quarantine or p=reject
  • Employee security awareness training with documented phishing simulation results

Three Renewal Landmines Specific to Dallas SMBs

Most Dallas businesses I audit trip on the same three things. These aren’t obscure. They’re just easy to miss when you’re staring at a 40-question form.

Landmine #1: Attesting to MFA on service accounts

Service accounts (the accounts your backup software uses, the account that runs a scheduled export, the account your line-of-business app authenticates as) frequently have MFA excluded because MFA breaks non-interactive login. This is a real technical problem with real workarounds — certificate-based authentication, workload identities, managed identities. But if the application asks “is MFA enforced on all accounts” and you say yes without excluding service accounts, that’s a misrepresentation.

The correct answer is usually: “MFA enforced on all interactive accounts; service accounts protected via [certificate auth / conditional access / managed identity / IP allow-listing].” The carrier is fine with that. They’re not fine with “yes” when the answer is “yes except.”

Landmine #2: Claiming EDR when you’re running AV

The line between EDR (endpoint detection and response) and traditional AV (antivirus) is not always obvious to a business owner. If your endpoint tool has “antivirus” in the marketing but no behavioral detection, no rollback capability, and no cloud console showing per-device telemetry, it’s AV. Modern EDR products — SentinelOne, CrowdStrike Falcon, Microsoft Defender for Endpoint (with the Plan 2 EDR features enabled), Huntress, Sophos Intercept X — behave differently. If you can’t log into a console and see the last 90 days of endpoint activity, you don’t have EDR.

Landmine #3: Attesting to backup testing you haven’t done

“Do you regularly test backup restoration?” is on nearly every 2026 application. The honest answer for most SMBs is “our provider runs automated test-restore jobs monthly.” That’s usually fine — if it’s true and you can produce the log. It’s not fine to click yes on the assumption that someone must be doing that somewhere. Ask your backup provider for the last 12 months of restore verification logs. If they can’t produce them, the answer to that question is no.

The 30-Day Pre-Flight

If your renewal is in the next 30–90 days, here’s the sequence:

  • Day 1–3: Pull last year’s application. Read every yes/no answer. For each “yes,” ask: can I prove this was true then, and is it still true now?
  • Day 3–10: MFA audit. Enumerate every system that should have MFA. Verify enforcement per user and per system. Document the exceptions and how they’re compensated for.
  • Day 10–20: Backup and EDR verification. Confirm immutable copies exist. Confirm EDR is on every endpoint. Pull the reports.
  • Day 20–25: IR plan and tabletop. If you don’t have a written IR plan, write one. Run a 90-minute tabletop with your leadership team.
  • Day 25–30: Broker call before the questionnaire hits. A good cyber broker will walk you through what the carriers are asking for in 2026 and help you position your answers accurately. If your broker doesn’t volunteer that call, you have a broker problem, not just a renewal problem.

The Texas SB 2610 Angle

One Texas-specific angle worth mentioning: SB 2610, the Texas cybersecurity safe harbor, doesn’t reduce your premium directly. But alignment to a recognized cybersecurity framework (NIST CSF, CIS Controls, ISO 27001, HIPAA, PCI DSS) is now a positive underwriting signal because it evidences a written and maintained cybersecurity program. Carriers scoring 22 controls prefer applicants who can point to a framework.

If you’re already investing in the SB 2610 safe harbor for the liability defense — and you should be — use it in your renewal narrative too. Free upside.

The Bottom Line

Cyber insurance in Q4 2026 is a different product than it was six months ago. Rates are turning back up after twelve quarters of decline. Underwriting is now a technical audit. And the claim-time enforcement of what you attested to on the application is the sharpest it has ever been.

The 82% number is what should stay with you: most denied claims aren’t denied because the business didn’t have security — they’re denied because the security the business had didn’t exactly match what the application said. That gap is where you lose the policy value you’ve been paying for.

The fix isn’t buying more security. It’s honestly auditing what you have, closing the gaps that matter, and answering the questionnaire in a way you can defend at claim time.

Free Cyber Insurance Application Audit for Dallas–Fort Worth SMBs

If your cyber insurance renewal is coming up in the next 90 days, the single most valuable thing you can do is have a security professional read your last application before you sign the next one.

48 Technologies offers a free 30-minute Cyber Insurance Application Audit for DFW small and mid-sized businesses. Here’s what you get:

  • A line-by-line review of your most recent cyber insurance application against 2026 underwriting standards
  • A 1–2 page written risk memo flagging any answers that look like misrepresentation risk (the kind that get claims denied after a breach)
  • A gap list prioritized by what a Q4 2026 underwriter is most likely to catch on their external scan
  • A direct conversation with Tom Cloud — no sales engineer, no junior tech, no script

No cost. No obligation. No sales pitch — if you’re already in good shape, I’ll tell you that and we’ll part ways.

Book your free Cyber Insurance Application Audit →

Tom Cloud is the founder of 48 Technologies, a Dallas-based managed IT and cybersecurity firm serving small and mid-sized businesses across DFW.

Get started

Want IT That Prevents These Problems?

Book a 30-minute call or send an email. Straight talk, no sales pitch.