The carrier’s checklist is the product specification.
This is the most reliable purchase trigger in small and midsize healthcare, because it is dated and dollar-denominated. It is also the clearest specification anyone will ever hand you: the controls below are what a 2026 carrier will ask about, and three of them decline applications outright.
The three that decline applications
Miss any one of these in 2026 and applications are declined rather than surcharged. Missing MFA on remote access is the single most common cause of declination.
Phishing-resistant MFA on every account touching business data
Email, VPN, remote desktop, cloud administration, banking, and the practice management system. Not just Microsoft 365.
EDR on every endpoint and every server, with 24/7 monitoring
Antivirus is not EDR, and workstation-only coverage is the gap carriers now specifically ask about. The server is where the database lives.
Immutable, offsite, regularly tested backups
Immutable means an attacker holding domain administrator cannot delete or encrypt them. Tested means a documented, timed restore, not a backup job reporting success.
Asked on every application
These will not usually decline an application on their own, but each one prices the policy and several of them are verified rather than taken on trust.
A written incident response plan that has been tested
Tested means a tabletop with minutes and after-action items inside the last twelve months.
Security awareness training with phishing simulation
With completion records. Carriers increasingly ask for the click-rate trend, not just whether the programme exists.
Email filtering beyond the platform default
An API-layer or gateway inspection tier that catches business email compromise Microsoft alone lets through.
Privileged access management
Named administrator accounts, no shared credentials, and a documented break-glass procedure.
Network segmentation
Particularly separation of clinical devices, imaging, and guest Wi-Fi from administrative systems.
Patch cadence with reporting
Critical patches inside 14 days, with a compliance report you can produce rather than a policy that says you do.
End-of-life systems inventory
Unsupported operating systems, with compensating controls documented for the ones you cannot replace.
Vendor and business associate inventory
Who holds your data. Carriers ask because third-party incidents are now a large share of claims.
Funds transfer controls
Out-of-band verification for any payment instruction change. This is the control behind most social engineering claims.
Prior incident history, honestly disclosed
Non-disclosure is the fastest way to have a future claim denied for material misrepresentation.
Verified rather than attested, increasingly
Underwriting has moved from attestation to evidence. Carriers now run external attack-surface scans during underwriting and conduct mid-cycle audits.
External attack surface
Exposed remote access, unpatched edge appliances, and — for imaging-heavy specialties — internet-reachable DICOM services on ports 104, 11112, and 8042.
Domain and email authentication
SPF, DKIM, and DMARC at enforcement rather than monitoring.
Credential exposure
Whether your domain appears in known breach corpora. Carriers check; most applicants have not.
MFA coverage as implemented, not as described
In Travelers v. International Control Services a court permitted rescission of a cyber policy because an executive attested to MFA on privileged access that was not actually in place.
Score it honestly, ninety days out.
Renewals fail at the last minute because nobody looked at the application until the last minute. Ninety days is enough time to deploy EDR to servers, enforce MFA on the remaining paths, and run a documented restore test. Two weeks is not.
Go down the list and mark each control as in place, partial, or absent — and be strict about the difference between in place and described in a policy. Underwriting has moved from attestation to evidence. Carriers now run external attack-surface scans during underwriting and conduct mid-cycle audits, so a control that exists on paper and not in the tenant will be found.
The three that matter most
If you only fix three things before renewal: multi-factor authentication on every remote access path, endpoint detection and response on servers as well as workstations, and immutable backups with a timed restore test. Miss one of those three and the application is declined rather than surcharged, and missing MFA on remote access is the single most common cause of declination in 2026.
One thing not to do
Do not attest to a control you have not verified. It feels like a formality at signing and it is not. A misstatement on the application gives the carrier grounds to rescind the policy at exactly the moment you need it, which converts an insured event into an uninsured one.
This is why we complete the technical sections with clients and attest only to what we can evidence. If we cannot produce the report, we do not tick the box, and we tell you which box we did not tick.