Skip to content
GalleonVirtual Services
Cybersecurity

What Cyber Insurance Now Requires (and How to Qualify)

August 2, 2026

A few years ago, buying cyber insurance meant filling out a short form and paying a premium. Those days are over. Carriers have been paying out on healthcare ransomware claims, and they have responded by tightening what they require before they will write or renew a policy. If your practice has ever been surprised by a denied renewal or a long security questionnaire, this is why. The good news: the controls carriers now demand are the same ones that actually protect you, so meeting them is not wasted effort.

The controls carriers now require

Across the market, a consistent baseline has emerged. To write or renew a healthcare policy, carriers now typically require:

  • Multi-factor authentication, increasingly phishing-resistant MFA, on email, remote access, and privileged accounts. This is the single most-cited requirement, and for good reason. Microsoft research shows MFA blocks more than 99.2 percent of account compromise attacks.
  • Endpoint detection and response, with active monitoring. EDR has moved from recommended to required.
  • Encrypted, offline or immutable backups, so ransomware cannot destroy your recovery path.
  • A documented, tested incident response plan.
  • Email security and phishing-awareness training.

For larger policies, carriers increasingly add annual penetration testing and evidence of third-party risk oversight. Healthcare practices are often steered toward two to five million dollars in coverage given HIPAA exposure.

The questionnaire is the real underwriting

The application is no longer a formality. It is a detailed security questionnaire, and the answers you attest to become part of the policy. Answer "yes, we have MFA everywhere" when you actually have gaps, and you have not just risked a denied claim, you have potentially created a coverage dispute at the worst possible moment. The safe path is to make the answers true first, document the evidence, and then attest. That is a very different exercise than checking boxes hopefully.

Where practices get caught

The gaps we see most often when helping clients through underwriting are the same three every time: MFA enabled for most accounts but with convenience exceptions, backups that exist but have never been tested end to end, and EDR alerts that are generated but not monitored after hours. Carriers ask about all three specifically, because attackers exploit all three specifically.

Prevention and coverage are the same project

The reason this is not a burden is that every control on the carrier's list is a control that reduces your actual risk. Meeting the insurance requirements and hardening the practice are the same work. You end up both more insurable and more secure, and the documentation you build for underwriting is the same documentation that helps in a HIPAA review.

How Galleon helps

We help clients meet the cyber insurance requirements and document the posture for the underwriting process. We deploy MFA, run managed EDR with a 24/7 Security Operations Center monitored by real human analysts, configure tested and isolated backups, and maintain the documented incident response plan and evidence that carriers ask to see. Base-level cybersecurity is included in our managed IT pricing, with tiered packages for organizations that need more robust protection.

If your renewal is coming up, or a carrier just sent you a questionnaire you are not sure how to answer honestly, start there. Explore our Cybersecurity and Backup and Disaster Recovery services, take the free IT Risk Assessment, or schedule a discovery call.

Get Started

Ready for a straight answer about your IT?

Schedule a 20-minute discovery call. We will tell you what is working, what is not, and what the gaps would cost.