Why Cyber Insurance Renewals Are Getting Harder for SMBs

Cyber insurance prices are falling. Renewals are still getting harder. Both things are true, and the reason catches most business owners off guard.

Why Cyber Insurance Renewals Are Getting Harder for SMBs (Even in a Soft Market)

For many small and mid-sized businesses, cyber insurance renewal used to be a routine administrative task. Fill out the application, sign, pay the invoice, and move on. Now it often feels like a security audit, because insurers are asking for proof of controls such as multi-factor authentication (MFA), endpoint detection and response (EDR), tested backups, and a documented incident response plan.

Here is the part that confuses most business owners: the cyber insurance market is actually getting cheaper. Marsh’s Global Insurance Market Index reported that cyber rates fell 4% globally and 2% in the United States in the second quarter of 2026, the twelfth consecutive quarter of declines. Capacity is abundant. Competition is real.

So if prices are falling, why does renewal feel harder?

Because the competition is not for every business. It is for well-documented businesses. Soft pricing has not made underwriters less demanding; it has made them more selective about who gets the good pricing. The friction has moved off the premium line and onto the evidence line. Carriers are still writing the business, but they are shifting the burden of proof onto the applicant, and businesses that cannot provide that proof are seeing higher retentions, narrower sublimits, added exclusions, delayed binding, or declinations.

Renewal is now a test, not a form

Renewal applications now go far beyond basic yes-or-no questions. Insurers increasingly want evidence that security controls are implemented, current, and consistently applied across the business.

That shift matters because many SMBs assume they are covered simply because they bought a policy last year. The policy may not renew on the same terms if the business cannot demonstrate current controls with documented evidence. One reinsurance broker’s 2026 market commentary described the change as a move toward control verification rather than declarations, and that phrasing matches what business owners are experiencing on renewal calls.

The distinction is subtle and expensive. Declaring that you have MFA is a sentence on a form. Verifying it is an admin console export showing enrollment coverage across every user and every access path.

What the claims data is telling underwriters

Underwriters are not asking these questions because they enjoy paperwork. They are asking because their loss data points at a small set of failures that repeat over and over.

Email is still the front door. Coalition’s 2026 Cyber Claims Report found that business email compromise (BEC) and funds transfer fraud (FTF) together accounted for 58% of all cyber claims. BEC claim frequency rose 15% year over year. The FBI’s 2025 Internet Crime Report logged 24,768 BEC complaints totaling $3.046 billion in reported losses, part of a record $20.877 billion in total reported cybercrime losses for the year.

Ransomware is less frequent but far more expensive. Coalition reported average ransomware losses of $269,000, making it the costliest claim type in its book, against an overall average claim severity of $116,000. Initial ransom demands surged 47% year-over-year and now average more than $1 million. Dual extortion (encrypting the data and steal it) appeared in 70% of ransomware claims and averaged $302,000, roughly twice the cost of encryption-only incidents.

Recovery costs money whether or not you pay. Sophos’ State of Ransomware 2026 study of 2,158 IT and security leaders found that the average recovery cost, excluding any ransom paid, reached $1.7 million per incident, up 11% year over year. The median ransom payment fell to $769,000 over the same period. Recovery is a separate bill from the ransom, and it arrives even for organizations that refuse to pay.

Small businesses absorb this disproportionately. Verizon’s 2025 Data Breach Investigations Report found ransomware present in 88% of small-business breaches, compared with 39% at large organizations. Sophos found that only 34% of organizations with 100 to 250 employees stopped an attack before encryption or extortion, versus 46% at organizations with 3,001 to 5,000 employees. Smaller companies get hit by the same playbook with fewer people watching the alerts.

The entry points have shifted. The 2026 Verizon DBIR, covering more than 31,000 incidents and 22,000 confirmed breaches across 145 countries, found that software vulnerability exploitation is now the leading initial access vector at 31%, overtaking credential abuse, which fell to 13% as an entry point. Credentials have not stopped mattering; they simply moved later in the attack: credential abuse still appears in roughly 39% of incidents overall. Ransomware was involved in 48% of breaches, up from 44%. The human element featured in 62%. Third-party involvement rose 60% year-over-year and now accounts for 48% of breaches.

Put those together and you have the underwriter’s mental model: an attacker gets in through an unpatched device or a phished credential, moves to email or endpoints, and either wires out money or encrypts the environment. Every control on the renewal application maps to one link in that chain.

The controls insurers want, and the evidence they want with them

1. MFA on every access path

MFA is the single most common friction point and has the strongest measurable case. Microsoft’s published research on Azure Active Directory accounts measured a 99.22% reduction in the risk of account compromise for MFA-enabled accounts, and a 98.56% reduction even among accounts whose passwords were already known to have leaked.

Underwriters increasingly expect MFA on email, VPN, remote access, cloud platforms, and administrative accounts, not just on email. Many now distinguish between phishing-resistant methods (authenticator apps, hardware keys, number matching) and basic SMS codes.

Evidence to have ready: an enrollment report showing the percentage of users covered, conditional access or policy export, and a specific answer for every exception account.

2. EDR on all endpoints and servers

Traditional signature-based antivirus is increasingly viewed as insufficient. Underwriters want tooling that detects suspicious behavior, isolates a compromised host, and preserves the telemetry a forensics team will need. That last point is often overlooked: EDR shortens the investigation, and investigation hours are a direct claim cost.

Evidence to have ready: a deployment coverage report by device, confirmation of server and endpoint coverage, and whether the tool is monitored 24/7 or only during business hours. That single distinction moves terms.

3. Immutable, tested backups

Backups matter, but not just any backups. Carriers want ransomware-resistant, immutable, offline or logically air-gapped copies, and they want proof of restoration testing. The reason is visible in the data: Sophos found backup-based recovery jumped to 66% of encrypted-data cases in 2026, up 12 percentage points year over year. Over the same window, a record 86% of businesses in Coalition’s book refused to pay a ransom in 2025. Neither report claims one caused the other, but a business that can restore has options a business that cannot restore does not have, and underwriters price options.

Untested backups fail exactly when they matter. An underwriter who sees “yes, we back up nightly” with no restore test date reads it as an unquantified recovery risk.

Evidence to have ready: the date of your last full restore test, recovery time and recovery point objectives, immutability settings, and a documented retention schedule.

4. A written incident response plan

Underwriters want assigned roles, escalation paths, notification obligations, and a recovery sequence, not a vague promise to call somebody. A plan that has been tabletop-tested carries more weight than a plan that has only been written.

Evidence to have ready: the plan document with a revision date, the tabletop exercise date and attendee list, and your carrier’s incident hotline saved somewhere your team can find it at 2 a.m.

5. Vulnerability and patch management

Given that vulnerability exploitation is now the top initial access vector at 31%, expect questions about patch cadence, edge device firmware, and end-of-life systems.

Evidence to have ready: a recent vulnerability scan summary, patch compliance percentages, and a remediation timeline for any outstanding items.

6. Security awareness training

With the human element in 62% of breaches, training records are becoming standard application material.

Evidence to have ready: completion rates, phishing simulation click rates and trends, and the training cadence.

Why missing controls create friction, in dollars

Insurers treat undocumented controls as evidence of higher loss potential because that is exactly what their claims data supports. If a business cannot prove MFA coverage, backup testing, or endpoint protection, the carrier responds with the tools it has: higher retentions, coverage sublimits on ransomware and funds transfer fraud, remediation requirements before binding, or a decision to walk away.

This is especially frustrating for SMBs because the gaps are often basic and fixable, but simply undocumented. A business may already have MFA in place, but if nobody can produce a console export, a policy record, or an admin report, the underwriter treats it as a gap. In underwriting, undocumented and absent look identical.

Now consider the economics from the business owner’s side.

Premiums are modest relative to losses, and that is the entire argument for protecting your terms. Insureon, drawing on roughly 100,000 small business policies, reports an average cyber liability premium of $129 per month, about $1,552 per year, with limits typically between $1 million and $5 million and deductibles of $1,000 to $2,500. That figure skews toward very small firms, so a 50-person professional services business should expect to pay more, often several thousand dollars a year depending on revenue, industry, and limits. Ask your broker for your own number rather than relying on an industry average.

Now put any of those premiums next to the loss side. The average ransomware claim in Coalition’s book is $269,000. A dual-extortion event averages $302,000. Sophos puts average recovery costs, excluding ransom, at $1.7 million. IBM’s 2025 Cost of a Data Breach Report puts the average United States breach at $10.22 million. Notably, IBM’s global average actually fell 9% to $4.4 million that year, so the pressure is not that every number is rising. It is that the United States remains the most expensive place in the world to have a breach, and the tail losses are large enough to end a small company.

Here is a simplified, illustrative way to frame the renewal decision. The numbers depend on your own policy, so treat this as a structure for the conversation with your broker rather than a quote:

Scenario What you pay What you keep on your own balance sheet
Renew with controls fully documented Premium plus a managed security stack Your deductible
Renew with a ransomware sublimit or higher retention imposed Similar or lower premium The gap between the sublimit and the actual loss, which averaged $269,000 in Coalition’s 2025 claims
Non-renewal or declination No premium The entire loss, plus legal, forensics, notification, and downtime

 

That third row is the one worth reading twice. A declination does not reduce your risk. It transfers it all back to you.

How SMBs can reduce renewal friction

Treat renewal as a 60- to 90-day project, not a last-minute paperwork scramble. The sequence that works:

Days 90 to 60: Inventory. Pull last year’s application. List every control the insurer asked about. For each one, mark it as in place with evidence, in place without evidence, or missing. Most SMBs are surprised by how much falls in the middle bucket.

Days 60 to 30: Remediate and document. Close the genuine gaps first, prioritizing MFA coverage on every access path, EDR on servers and workstations, and a verified restore test. Then produce the evidence pack for everything else.

Days 30 to renewal: Package and brief. Assemble a single evidence folder with dated artifacts. Give your broker a short narrative of what changed since last year. Underwriters price uncertainty, and a clear improvement story reduces uncertainty.

Your evidence folder should contain, at a minimum:

  • MFA enrollment report with coverage percentage and exception list
  • EDR deployment report covering endpoints and servers, with monitoring hours stated
  • Backup configuration showing immutability, plus the date and result of the last restore test
  • Written incident response plan with revision date and tabletop exercise record
  • Most recent vulnerability scan and patch compliance summary
  • Security awareness training completion rates and phishing simulation trend
  • Email security configuration, including DMARC, SPF, and DKIM status
  • Wire transfer verification procedure, given that funds transfer fraud represented 27% of claims, with an average loss of $141,000

If a control exists but no one can prove it, document it now before the carrier asks.

What does this mean for MSPs

For managed service providers, this trend is an invitation to move from break-fix support to risk advisory. Helping a client pass renewal is not a compliance chore. It is the difference between a client who can buy and keep coverage and one who cannot.

Practically, that means mapping technical services directly to insurance application questions, collecting continuous evidence rather than annually, and closing gaps in the quarter before renewal season rather than the week of. The MSPs who do this become part of their clients’ financial risk conversation, not just their help desk.

Where we can help

If your business is facing cyber insurance renewal pressure, our managed services team at CMIT Solutions of Edison-Piscataway can help you close the gaps before the underwriter finds them. We help SMBs across Central New Jersey implement the controls insurers expect, document the evidence they ask for, and build a security posture that supports both renewal and real-world resilience.

We will review your current environment against your carrier’s application, identify any missing controls and documentation, and build a practical remediation plan that fits your budget and operations. If you want fewer surprises at renewal and a stronger security baseline year-round, that is exactly the work we do.

Closing thought

Cyber insurance renewal is no longer about whether a business owns some security tools. It is about whether the business can demonstrate a security posture that an underwriter is willing to trust with capital.

For SMBs, that makes renewal friction a useful early warning system. Rates are falling for companies that can prove their controls. If your underwriter is asking hard questions and you are struggling to answer them, that is the clearest signal you will get, and it is a far cheaper signal than the one an attacker delivers.

Contact CMIT Solutions of Edison-Piscataway today.

##CyberInsurance #SmallBusiness #RiskManagement #cmitsolutions #ManagedIT #Cybersecurity #NewJerseyBusiness

Back to Blog

Share:

Related Posts

From Fort Knox to Fragile Walls: Why SMB Data Security Needs an Upgrade

  From Fort Knox to Fragile Walls: Why SMB Data Security Needs…

Read More

Ransomware Attacks in New Jersey: A Six-Month Review

Ransomware Attacks in New Jersey: A Six-Month Review Introduction In the digital…

Read More

Why Cyber Insurance Companies Hesitate to Insure Small and Medium-Sized Businesses: A Risk-Averse Market

Why Cyber Insurance Companies Hesitate to Insure Small and Medium-Sized Businesses: A…

Read More