|7 min read|Yvann Lièvre

Cyber Insurance in 2026: What Insurers Now Require

Hardened market, premiums up 50%, cyber war and ransomware exclusions without MFA. Minimum requirements: EDR, MFA, 3-2-1 backup, and LOPMI Art.5 law.

AssuranceCompliance

The cyber insurance market has hardened considerably since 2022. Insurers have learned from major claims (Colonial Pipeline, French hospitals, paralyzed municipalities) and now impose strict technical prerequisites before agreeing to cover cyber risk. In 2026, paying a premium is no longer enough to be covered.

A market in full transformation

The numbers speak for themselves:

  • Premiums up 50% on average over the past two years, according to the AMRAE 2025 barometer (LUCY report)

  • Loss ratio exceeding 100% in 2020-2021, triggering a brutal tightening of conditions

  • The French cyber insurance market represents approximately 328 million euros in premiums in 2025

  • Coverage rate: only 10% of mid-market companies and 3% of French SMBs have cyber insurance (CESIN 2025)

Exclusions becoming standard

Before looking at what is covered, you need to understand what is no longer covered:

  • Cyber warfare: since the NotPetya incident (2017) and the Russia-Ukraine conflict, most policies exclude cyber "acts of war". Lloyd's of London mandated cyber war exclusion clauses starting in 2023

  • Ransomware without MFA: if you suffer a ransomware attack and the investigation reveals no MFA on your remote access, most insurers will deny the claim

  • Untested backups: no functional, tested backup = no coverage for data loss

  • Gross negligence: unpatched systems for over 90 days, default passwords, no antivirus

Minimum insurer requirements in 2026

Here is the checklist most cyber insurers now demand:

  • MFA everywhere: on all remote access (VPN, RDP, webmail), privileged accounts, and critical SaaS applications

  • EDR deployed: antivirus is no longer enough. Active EDR on 100% of endpoints is required. CrowdStrike, SentinelOne, HarfangLab, or Defender are accepted

  • 3-2-1 backup: 3 copies, 2 different media, 1 offsite disconnected copy. Documented restoration tests

  • 24/7 monitoring: continuous detection capability via internal SOC, MDR, or autonomous agent like ThreatClaw

  • Incident response plan: documented, tested through an exercise within the past 12 months

  • Patch management: patching policy with SLAs (critical <72h, high <30 days)

  • Network segmentation: critical system isolation, no flat network

  • User training: phishing awareness at least annually, with simulation tests

LOPMI Law Article 5: file a complaint within 72 hours

Since April 2023, the LOPMI law (France's Interior Ministry Orientation and Programming Law) requires filing a police complaint within 72 hours of becoming aware of a cyberattack in order to receive insurance compensation. This Article 5 provision applies to all businesses and professionals.

In practice: if you do not file a complaint within the deadline, your insurer can refuse all compensation. This makes an automated incident response process essential, one that immediately triggers legal procedures in parallel with technical remediation.

How ThreatClaw helps meet requirements

ThreatClaw directly addresses several insurer requirements:

  • 24/7 monitoring: continuous surveillance by autonomous AI agent, with detection and response without human intervention

  • EDR-augmented detection: correlation of your existing EDR alerts with 26 CTI sources

  • Continuous compliance audit: automatic verification of technical criteria (active MFA, current patches, functional backup)

  • Documentation: complete logs of every incident for insurance claims and police reports

FAQ

How much does cyber insurance cost in 2026?

For an SMB with 50 employees and 10M euros revenue, expect 5,000 to 15,000 euros annual premium for 1M euros coverage. For mid-market companies, premiums can reach 50,000 to 200,000 euros depending on sector and cyber maturity level. Companies demonstrating strong security posture get better rates.

Is ransom payment covered?

This is debated. In France, ransom payment is not illegal but strongly discouraged by ANSSI. Some insurers cover payment (under strict conditions), others exclude it. The trend is toward progressive exclusion. The LOPMI law conditions compensation on filing a police report.

What happens if I do not meet the prerequisites?

Two scenarios: either the insurer flatly refuses to cover you, or they accept with major exclusions and a significantly higher premium. In all cases, in the event of a claim, the forensic investigation will verify actual compliance. Misrepresentation on the questionnaire can void the contract entirely.

Does ThreatClaw provide reports for insurers?

Yes. ThreatClaw generates security posture reports documenting the state of your controls (MFA, patching, EDR, backup) and the history of detected and handled incidents. These reports are directly usable for policy renewals and insurance audits.

Related articles