If you’ve renewed a cybersecurity insurance policy in the last year, you’ve probably noticed the application got a lot longer. Carriers are tightening requirements because claims are way up. Here’s what they’re actually asking for in 2026, and how Mesa small businesses can meet it without breaking the bank.
The non-negotiables
Almost every carrier now requires:
- Multi-factor authentication (MFA) on all email accounts. No exceptions. If even one user doesn’t have it, you can be denied a claim.
- MFA on remote access. Any VPN, RDP, or remote desktop tool needs MFA in front of it.
- Endpoint Detection and Response (EDR). Traditional antivirus isn’t enough anymore. Carriers want a real EDR product like SentinelOne, CrowdStrike, or Microsoft Defender for Business.
- Offsite, immutable backups. Backups that can’t be deleted by ransomware. Tested at least quarterly.
- Security awareness training. Documented, recurring training for all staff.
The “nice to haves” that are quickly becoming required
- Email filtering beyond what’s built into Microsoft 365 / Google Workspace
- DNS filtering or web filtering at the network level
- Privileged access management (separate admin accounts)
- Patch management with documented timelines
- An incident response plan you can actually produce on request
What this costs in real money
For a typical 10-person Mesa office, meeting all of the above runs roughly $30–$60 per user per month, depending on which products you choose. That’s less than most carriers will charge you in increased premiums if you can’t check the boxes.
Common gotchas we see
- “We have MFA” — but it’s only on the owner’s account
- “We have backups” — but they’re on a USB drive sitting next to the server
- “We have antivirus” — but it’s the free version and hasn’t updated in 6 months
- “We trained the staff” — in 2022, once
Need help getting compliant?
We help Mesa and East Valley businesses meet cyber insurance requirements every week. See our cybersecurity services or call 480-434-4222.
