Cyber insurance used to be a checkbox. In 2026 it is a verification exercise. Brokers still send a PDF. Underwriters now want to know whether you could prove the answers with a screenshot — MFA enrolled, EDR actually installed, a restore you ran in the last 90 days — not whether someone on staff is willing to type “yes.”
This article walks the same 12 controls as our free insurability self-check. It is readiness support for Lincoln and Omaha businesses, clinics, and professional offices. It is not a promise that a carrier will bind coverage, not a substitute for your broker, and not a claim that SAINT is a licensed insurance advisor.
Primary next step: run the 3-minute insurability check, then book a free assessment so the gaps become a written plan. Or call 531-625-2111.
What do cyber insurance carriers actually check in 2026?
They check whether you can evidence a short list of load-bearing controls. The wording on applications varies by carrier and year. The substance does not. If you cannot show it, you do not have it — and an unmatched attestation is how claims get ugly after an incident.
SAINT’s tool weights the twelve items the way most SMB questionnaires weight them: identity and EDR heaviest, then backups you can restore, then monitoring, training, and the rest. You can score yourself in about three minutes. Below is what “yes” has to mean in an office that does not have a full-time CISO.
Why isn’t antivirus enough anymore?
Because ransomware and business email compromise do not look like 2012 malware. A signature-based tool that only blocks known files will happily watch a phished session create a forwarding rule. Carriers now ask for endpoint detection and response (EDR) — behavior, identity, and a human looking at alerts — not a consumer antivirus logo on a renewal form.
On SAINT-managed environments that stack is Huntress or Guardz. Huntress is SOC-led and modular (EDR, ITDR, SIEM, SAT). Guardz is the all-in-one alternative for a smaller shop that wants one console. We pick one core design. Stacking both without a reason is not “more insurable.”
How do carriers verify MFA — and which logins actually count?
Three separate questions, because attackers use three doors:
- MFA on email and cloud apps. Microsoft 365 or Google Workspace, plus the SaaS tools that hold client files or PHI. A single shared mailbox without MFA is a finding.
- MFA on remote access / VPN. Every path into the network from outside. An old SSL VPN with a password-only admin account is still a favorite ransomware door.
- MFA on privileged / admin accounts. Global admins, domain admins, and the service accounts nobody wanted to enroll. “Users have MFA” while break-glass admins do not is a partial.
Verification looks like Entra or Google admin exports, conditional-access screenshots, and VPN configuration — not a policy PDF that says “we use MFA.” If you need the email side hardened first, start at email security.
What backup evidence do underwriters actually want?
Three more controls, because “we have backups” is the most common untrue sentence on SMB applications:
- Immutable — ransomware cannot encrypt or delete the copies. A USB disk in the same closet as the server is not this.
- Offsite / separated — kept apart from the systems they protect. Same-VLAN NAS with the same domain admin is not this.
- Tested in the last 90 days — a restore you actually ran, with a date and a person, not a green checkbox in a backup console.
Carriers ask because claims after ransomware often fail on the restore, not the invoice. SAINT’s backup work is backup & disaster recovery: image-based copies, offsite replication, and recovery testing sized to your RTO — vendor-neutral, storage billed separately in the catalog.
Do you need a 24/7 SOC, or is “we look at alerts on Monday” enough?
The questionnaire usually asks whether someone is watching around the clock, not whether you purchased a dashboard. After-hours encryption does not wait for your internal IT person’s commute.
Huntress SOC investigates endpoints 24/7 on SAINT-managed Huntress environments; SAINT coordinates with you. Guardz packages monitoring inside its all-in-one plans. Either way, “EDR installed, nobody triaging” is a partial — and partials are where renewals get repriced.
This is also why a cybersecurity assessment maps installed agents, not slideware. If you already have a person on staff, co-managed IT is the overlay so you keep strategy and we take the night watch.
What else do they ask besides MFA, EDR, and backup?
Four more items round out the twelve:
Security-awareness training + phishing simulations. Recurring, documented, with completion tracking. A once-a-year video in a shared drive is a partial. Huntress SAT (catalog: $4 per learner per month, SAINT retail estimate) exists for this; Guardz includes awareness in its seat plans.
Documented incident-response plan. Written, and rehearsed at least once. A binder nobody has opened since 2019 is not a plan. You do not need a federal playbook. You need who to call, how to isolate, and when finance uses a known phone number instead of the email thread. Our public playbooks for phishing, BEC, and ransomware are starting points — they are not a substitute for your names and vendors.
Email filtering / anti-phishing gateway. Advanced filtering beyond the default spam folder. External sender tags, safe-links where licensed, forwarding-rule audits, DMARC moving toward enforcement. Default Microsoft or Google spam is a start, not the control. Program: email security.
Timely patching (critical patches in under 30 days). A tracked cadence, not “we click Windows Update when someone complains.” Unsupported operating systems on an imaging PC or a shop-floor box are findings even if the front desk is current.
How should a Nebraska SMB prepare for renewal without a 60-page PDF?
Work backwards from the questionnaire on your desk:
- Run /tools/insurability honestly — attest to what you could prove with a screenshot.
- Export the evidence you already have (MFA coverage, EDR console, last restore, SAT completions).
- Close the load-bearing gaps first: admin MFA, EDR on every device that can reach files, a restore test with a date.
- Put the rest on a written plan with owners. That is vCISO / risk advisory when you need someone to own the narrative for a broker or board — fractional, typically 4–16 hours a month after an assessment phase, catalog from $2,500/mo. It is not a compliance certificate.
Lincoln is a primary market from Hickman (city-level HQ only, no storefront). Omaha-metro is scheduled on-site. Same 12 controls. Different logistics. We do not invent a “cyber insurance certified” badge.
Clinics and professional offices should not treat this as a generic SMB quiz. A therapy practice still needs a BAA conversation and privacy-aware cameras; an independent insurance agency still needs BEC defenses on premium disbursements. The twelve controls stay the same. The evidence pack changes. Healthcare vertical: HIPAA IT checklist. Agencies: IT requirements for independent insurance agencies.
If a renewal is already on the calendar, skip the self-quiz theater and book the free assessment. Bring the questionnaire. We will tell you what you can evidence this week versus what needs a project.
Get the gap list in writing. Free insurability check · Free Security & IT Assessment · 531-625-2111.


