Cyber Insurance Now Starts at Onboarding, Not Renewal
Rodney Hall, COO

Cyber insurance underwriting now happens at the moment a client signs, not at renewal. Insurers in 2026 require documented proof that controls like MFA, EDR, and tested backups are already running before coverage binds, which means onboarding is no longer just account setup. It is the point where a new client becomes insurable or does not.
Why is cyber insurance now an onboarding problem instead of a renewal problem?
Because underwriters stopped accepting attestation and started requiring evidence. In 2026, most MSP cyber insurance questionnaires focus on five control areas: MFA on email, remote access, and admin accounts, EDR or MDR on every endpoint, tested offline or immutable backups, a written incident response plan, and proof that users complete security awareness training. The underwriter wants exports, screenshots, and reports showing each control was actually deployed and enforced, not a checkbox saying it exists.
That shift moved the pressure point earlier in the client lifecycle. A prospect who signs with an MSP today expects to be insurable within days, not after a 90-day security hardening project runs its course. If your onboarding process treats security baseline deployment as a phase two initiative, you are handing every new client weeks of uninsured exposure and handing yourself a support ticket queue full of insurance-renewal panic six months later.
What happens when a client fails their cyber insurance assessment?
Coverage gets denied, or the premium jumps hard enough to change the client's whole budget conversation. Roughly 73 percent of small and midsize businesses currently fail their 2026 cyber insurance assessments outright, and 96 percent of insurers now list MFA as a non-negotiable condition of coverage, with 82 percent of claim denials citing missing MFA as the primary reason. Businesses that do get renewed after a gap in controls are seeing premium increases of 40 to 100 percent, and some are pushed into surplus lines markets where premiums run triple the standard rate.
Endpoint protection carries the same weight. Roughly 88 percent of underwriters now mandate EDR on every managed device, and legacy antivirus alone does not clear that bar anymore. When a client fails on either front, the phone call that follows is rarely calm, and it always lands on the MSP, whether or not the MSP was the one who set the original policy terms.
The data on what happens when controls are actually in place makes the stakes concrete. Coalition's 2026 cyber claims research found that 64 percent of closed claims at organizations with functioning controls and backups resulted in no out-of-pocket loss at all, even as average ransom demands climbed 47 percent year over year to more than $1 million. The gap between an insured client with working controls and an uninsured client without them is not a paperwork difference. It is the difference between an incident that costs a deductible and one that costs the business.
Building insurability into day one of onboarding
Provisioning a new client's environment and proving that client is insurable are now the same task, and treating them as separate workstreams is where most onboarding timelines quietly slip. A baseline that gets deployed and documented at handoff, rather than audited after the fact, removes the scramble entirely.
- Deploy MFA across email, remote access, and every administrator account as a blocking step before a client environment goes live, not a follow-up ticket.
- Stand up EDR on every endpoint during initial provisioning and capture the deployment report the same day, so evidence exists from day one instead of getting reconstructed under deadline pressure later.
- Configure and test backup immutability during onboarding, and save the test result. A backup that has never been tested is not evidence of anything to an underwriter.
None of this needs to add days to onboarding if it is built into the provisioning workflow itself rather than bolted on as a separate security engagement. The MSPs closing this fastest are the ones who stopped treating insurance readiness as a client-request item and started treating it as a default output of standing up a new environment.
| Control area | What underwriters check | Evidence to capture at onboarding |
|---|---|---|
| MFA | Email, remote access, admin accounts | Enforcement policy export, coverage report |
| EDR or MDR | Every endpoint and server | Deployment confirmation, agent coverage list |
| Backups | Offline or immutable, tested | Test restore result and date |
| Incident response | Written plan on file | Signed plan document |
| Security awareness training | User completion | Completion log by user |
Mapping each row to a specific onboarding step, rather than treating security as a general goal, is what turns this from an audit scramble into a repeatable checklist item.
What about clients who signed on before these standards existed?
They are the harder problem, and most MSPs are carrying more of this exposure than they realize. A client onboarded two or three years ago under a lighter security baseline is now facing the same 2026 underwriting standard at renewal, without ever having gone through a provisioning process built for it.
Treating this as a retroactive project, client by client, is where operations teams lose the most time. A better approach borrows the same standardized checklist built for new onboarding and runs it as a scheduled remediation pass across the existing base, prioritized by renewal date. Clients whose cyber policy renews in the next 90 days move to the front of the queue, since a denied renewal or a 100 percent premium increase is a business problem for them well before it becomes a support ticket for you.
Why documentation now matters as much as deployment
A control that exists but was never documented is functionally invisible to an underwriter, and rebuilding that documentation after the fact costs far more staff time than capturing it once during setup. Every MSP that has scrambled to produce six months of MFA enforcement logs during a renewal audit already knows this. The fix is procedural: generate and file the evidence artifact the same day the control goes live, tied to the client record, so it exists before anyone asks for it.
That discipline also protects the MSP directly. Most clients now expect their MSP to carry its own technology E&O and cyber liability coverage, and an MSP that cannot show consistent control deployment across its own client base is answering harder questions in its own renewal conversations too.
There is a contract layer worth tightening here as well. Master service agreements should state plainly which controls the MSP deploys and monitors, which controls depend on the client's own behavior such as approving MFA prompts or completing training, and who is responsible for producing evidence at renewal time. Ambiguity in that language is exactly what turns a routine insurance renewal into a dispute between MSP and client about who dropped which control.
Where this fits in a provisioning workflow
Standardizing this is an operations problem before it is a security problem. A repeatable provisioning checklist that bakes in control deployment and evidence capture removes the judgment calls that cause inconsistency between technicians and between clients. Catalyst is built around exactly that kind of standardized provisioning, so insurability evidence is a byproduct of onboarding done correctly rather than a separate project chasing yesterday's client signups.
Getting a clear view of where your current stack already covers these control areas, and where it does not, is the first step before you rebuild the checklist. Stack Builder maps that gap against what underwriters are actually asking for in 2026, and the broader Actiforge product line covers the rest of what a modern onboarding motion needs beyond the security baseline.
See the full stack to build an onboarding process that makes every new client insurable from day one instead of eventually.
Sources: MSSP Alert cyber insurance readiness coverage | ChannelInsider best cyber insurance companies for MSPs 2026 | Coalition 2026 cyber claims research.