Live webinar · Free · 45 minutes
Cyber Insurance Renewal Requirements 2026 (SMB Webinar) soft pricing, harder questions
Renewal questionnaires increasingly ask for dated artifacts — MFA coverage percentages, EDR reach across every endpoint, immutable backup copies, and a documented restore test — rather than yes/no attestations. This session walks through the six artifacts an SMB can realistically produce, what each one should show, and how to reconcile the application answers with what your tooling actually covers before anyone signs.
- Answer in numbers, not adjectivessee the difference between "yes, we have MFA" and a coverage figure with an account count, a privileged-account count, a legacy-authentication status and an export date. Some MSP-published readiness guidance suggests targets in the 98–100% range for user-account MFA coverage, 100% on privileged accounts, and zero legacy authentication use or a justified exception list, alongside patch compliance %, EDR coverage % and RTO/RPO test results. Treat those as directional: the point is that the answer is a measured number with a date on it.
- Leave with the evidence binder listthe six artifacts SMBs can actually assemble: an MFA coverage export from the identity provider, an EDR agent-coverage report with unmanaged-device exceptions, a backup job report showing immutable retention and an offsite copy, a signed restore-test record with date, scope and measured RTO, a dated incident response plan with named contacts and carrier notification timelines, and training completion records.
- See what a defensible restore test looks likescope, date, who signed it, how long it took, what was validated. Industry commentary holds that backups which exist but have never been tested for restoration are not treated as a meaningful control, and that underwriters now ask for evidence of tested restores rather than the existence of a backup system.
- Understand why backups alone stopped answering the questionAllianz Commercial's 2025 cyber risk material is cited by secondary aggregators as showing ransomware still drives around 60% of large cyber claims by value, with incidents involving data exfiltration producing losses more than double those without. Restoring data does not undo a data theft, which is why identity and endpoint detection sit next to backup on the questionnaire.
- Reuse the work outside insurancemuch of the same documentation overlaps with what NIST 800-171 and CMMC assessors, HIPAA contingency-planning reviews and school board governance reviews ask for. Overlap, not equivalence: an assessor does not accept an insurance binder as evidence, and CUI-scoped or GCC High environments carry backup and data-residency constraints a generic approach may not satisfy.
Reserve your seat
Free · 45 minutes · 12 seats per session
No sales sequence. One reminder before the session, and the recording after.
What we actually cover
What people bring to this session.
Rates have been falling for years — so why does renewal feel harder?
Because price and terms move separately. Marsh's Global Insurance Market Index reports that global cyber rates declined 4%, the twelfth consecutive quarter of declines, supported by stable capacity and continuing high insurer competition. Separately, Marsh reported that US cyber rates fell 3% in Q4 2025 — the 11th consecutive quarter of US decreases, with US capacity described as stable. A soft market is when carriers compete on terms and conditions rather than price. One caveat that applies to every broker index in this session: they reflect those brokers' own client portfolios, which skew larger than SMB, so they are not a forecast of your premium.
Our backup jobs report success every night. Isn't that the proof?
A green job is evidence that a backup ran, not that a restore works. We walk through what a dated, successful test restore of a defined workload with a measured recovery time looks like on paper, and who in a small organization is realistically able to sign it.
Does EDR actually need to be on every endpoint?
Industry guidance for 2026 renewals lists MFA, EDR on every endpoint, immutable tested backups, a written incident response plan and security awareness training, with the significant shift being the burden of proof rather than the controls themselves. In practice that means a coverage percentage and a named exception list for the devices your agent does not reach.
We're small — are we really the segment under pressure?
Aon reported US cyber pricing declined 7% in Q1 2025, the 10th consecutive quarter of decreases, with the market remaining in buyers' favor despite rising attack frequency, and identified middle-market companies as facing the greatest vulnerability. Middle-market is a larger segment than most SMBs, and the same broker-portfolio caveat applies to Aon's index as to Marsh's — but the underwriting behavior described there is what shows up in SMB questionnaires next, which is the position this session is built for.
Before you register
Common questions
- Is this insurance advice?
- No. The session is educational and covers what underwriters commonly ask for and how to document it. Policy wording, coverage interpretation and anything about whether a specific control affects your premium belong with your broker or counsel.
- Is this an Acronis product demo?
- The subject is the process, not a SKU walkthrough. Acronis is a confirmed palmiq partner (palmiq is an Acronis Platinum partner, top 1% globally), and any product capability discussed is attributed to Acronis and checked against current Acronis documentation, including which edition or add-on it requires.
- Do we need to be a palmiq client to attend?
- No. The artifact checklist works with whatever identity, endpoint and backup tooling you already run.
- What do registrants get afterward?
- The evidence binder handout: the six-artifact list, what each artifact should show, and a 90-day renewal runway you can calendar against your own renewal date.
Rather talk it through first? Call 703-336-9700, or see the other sessions.