A cyber insurance policy looks like a financial product. More and more, it works like a contract whose terms are your client’s security controls.
That’s the core of a September 2026 client alert from Mark Lehman of Shumaker, published in the National Law Review. It describes a market that has become “an evidence-driven discipline.” Carriers that once underwrote from a short annual questionnaire now tie both binding coverage and paying claims to specific, verifiable controls, documented procedures, and compliance throughout the policy period. The alert’s conclusion is blunt: the tightening is “structural, not cyclical.”
For MSPs, that changes what renewal season means. The application isn’t paperwork you help a client fill out once a year. It’s a set of promises about the environment you run, and those promises have to stay true every day the policy is in force.
What the market is signaling
The alert cites NAIC data showing roughly 38,500 closed cyber claims in 2024, about three-quarters of which closed without a payout. That figure needs context: claims close without payment for many reasons, including losses that fall below the retention. But the alert says carriers attribute a substantial share of non-payment outcomes to three causes: inadequate security controls, inaccurate applications, and late notice.
All three are operational problems, and all three sit squarely inside the work MSPs already do.
The alert also notes the upside. Strong, documented controls can reduce premiums, while material gaps can bring rate increases, higher retentions, exclusions, or declination. Requirements vary by carrier, industry, and policy form. Some carriers still accept a simple attestation, while surplus lines markets and high-limit towers increasingly ask for independent evidence such as external scans, penetration tests, and SOC 2 reports.
The controls carriers keep naming
The Shumaker alert lists the controls “the overwhelming majority of cyber insurers” condition coverage on. Notice how many describe operation, not just deployment:
MFA on remote access, email, and privileged accounts, with text-message codes increasingly seen as inadequate and contractor pathways under review
EDR on every managed endpoint, plus clarity on who watches telemetry and how threats are contained and escalated
Immutable and offline backups, with recurring restore tests and dated records that recovery worked
A current incident response plan that assigns escalation and notification steps, rehearsed through tabletop exercises
External vulnerability scanning, with exposures closed and corrective steps recorded
Privileged access management, patch deadlines for critical vulnerabilities, network segmentation, DMARC enforcement, and security awareness training with completion records
Each one implies an owner, a cadence, and a record. That’s a program, not a checklist.
Three ways covered clients drift out of coverage
The application overstated reality. The alert warns that a single unimplemented control can support a denial, a limitation, or, where a representation was materially inaccurate, rescission. Its advice: treat each answer as a statement about the present state of a specific system, have the person who manages that system verify it, and disclose a remediation plan rather than presenting a partial rollout as complete.
The environment changed mid-policy. New hires, acquisitions, migrations, and new remote-access tools all change the environment the carrier underwrote. The alert recommends revalidating controls whenever those changes happen, and setting systems to flag disabled MFA, unprotected endpoints, failed backups, and material configuration drift.
Notice came too late. Because delayed notice can threaten coverage, the alert recommends giving the response team decision rules, a reporting timetable, and current contacts, with named responsibility for notifying the carrier, preserving evidence, retaining counsel, and coordinating the broker and breach-response vendors.
The MSP playbook: treat the policy as a review cycle
1. Map the application to a control register
For each client, link every application answer to a control, an owner, and the evidence that supports it. When the renewal form arrives, you’re updating a living record rather than starting from memory.
2. Put the system owner’s name on each answer
The person who signs the application often isn’t the person who knows the configuration. Close that gap in writing: the technician or engineer who manages the system confirms the answer, its scope, and any exceptions before it goes to the client for signature.
3. Set drift alerts that match the policy
Configure alerts around the controls the carrier named: MFA disabled for an account, an endpoint without EDR, a backup job that failed, an exposed service found by an external scan. Retain the records those checks produce. The alert specifically recommends keeping dated versions of policies, control inventories, configuration reports, logs, test results, training records, and approvals.
4. Write the notice clause into the incident response plan
Pull the client’s notice requirements from the policy and put them in the IR plan: who calls the carrier, who calls the broker, who preserves evidence, and on what timeline. Rehearse that sequence in the next tabletop exercise so the first call isn’t improvised.
5. Hold a mid-term review
Don’t wait for renewal. A quarterly check of the control register against the live environment catches drift while it’s still a ticket rather than a coverage dispute, and it gives you a natural QBR agenda item.
Where certification fits
Some MSPs are going further and validating their own service delivery. SPECTRA’s Business Advantage Program, now supported inside Blacksmith InfoSec, evaluates the people, processes, technologies, and service delivery practices behind an MSP’s security offering. SPECTRA says certified providers “may help their clients qualify for preferred coverage programs and more favorable cyber-insurance terms, subject to carrier underwriting and program eligibility.” Inside Blacksmith InfoSec, those requirements become mapped controls, collected evidence, and ongoing tasks, the same review-cycle discipline the carriers are asking for.
The client conversation
Clients don’t need a lecture on conditions precedent. They need a simple framing: your policy pays when your controls match what we told the carrier, so we keep those controls running, check them on a schedule, and keep the records. That’s a security program outcome a business owner understands, and it positions the MSP as the party protecting the client’s coverage, not just its endpoints.
Frequently asked questions
Q: Why do cyber insurers care about security controls after the policy is issued?
A: Carriers increasingly tie claim payment, not just binding, to controls that operate throughout the policy period. According to a Shumaker client alert in the National Law Review, a gap between the environment described in the application and the one in place at the time of an incident may give a carrier grounds to deny a claim or seek rescission.
Q: What security controls do cyber insurers commonly require?
A: Commonly named controls include MFA on remote access, email, and privileged accounts; EDR on every managed endpoint; immutable and offline backups with restore testing; a current incident response plan; external vulnerability scanning; privileged access management; patch management; network segmentation; DMARC enforcement; and security awareness training. Requirements vary by carrier, industry, and policy form.
Q: Can late incident notice affect cyber insurance coverage?
A: Yes. Carriers cite untimely notice as one of the main reasons claims go unpaid. Incident response plans should include the policy’s notice requirements, a reporting timetable, and named responsibility for contacting the carrier, broker, counsel, and breach-response vendors.
Q: How can MSPs help clients stay insurable between renewals?
A: MSPs can link each application answer to a control, owner, and evidence record; have system owners verify answers; alert on drift such as disabled MFA or failed backups; revalidate controls after major environment changes; and hold periodic reviews instead of waiting for renewal.
Q: Does certification guarantee better cyber insurance terms?
A: No. Certification can strengthen the evidence an underwriter reviews, but terms remain subject to carrier underwriting and program eligibility. SPECTRA, for example, says its certified providers may help clients qualify for preferred coverage programs, subject to those conditions.