Cyber Insurance Readiness Assessments: Why MFA and EDR Gaps Are Costing California Businesses Their Coverage

For a decade, buying cyber insurance meant filling out a short attestation questionnaire and writing a check. That era is closing. The National Association of Insurance Commissioners' 2025 Report on the Cybersecurity Insurance Market found that total U.S. cyber insurance direct written premium fell 7.11% in 2024, to $9.14 billion -- the first decline in the market's history -- even as the number of claims reported rose almost 40% year-over-year to nearly 50,000. The same report notes that U.S. cyber insurance rates fell an average of 5% in the fourth quarter of 2024 alone, the first quarterly rate decrease after seven straight years of increases. Read at face value, that looks like good news for buyers. Read correctly, it's a market that got far more selective about who qualifies for the discount: insurers aren't pricing more cheaply because cyber risk went down, they're pricing more cheaply for the narrowing subset of applicants who can prove -- not just attest to -- a specific set of technical controls, and quietly routing everyone else toward higher retentions, narrower terms, or a declined quote.

The shift is from attestation to evidence. Five years ago, a cyber insurance application asked whether a business had multi-factor authentication, and a business could check the box if MFA existed anywhere in the environment. Marsh's cyber risk practice now describes underwriters who 'continue to scrutinize organizations' cybersecurity practices to confirm they have effective controls in place' before extending the favorable terms that make headlines. In practice that means MFA enforced -- not optional, not partially rolled out -- on every email account, VPN and remote-desktop connection, and privileged or administrative login; endpoint detection and response (EDR) deployed and actively monitored across every workstation and server, not a legacy antivirus product installed years ago and forgotten; encrypted, immutable, tested backups; a written incident response plan; and a documented patch management cadence. Underwriters increasingly verify these claims with external attack-surface scans, requested screenshots of admin consoles and MFA enforcement settings, and exported sign-in logs, rather than taking a broker's word for it.

That verification shift matters even after a policy is bound, because a control gap discovered during a claim can be as damaging as one discovered during underwriting. Insurance policies have always allowed a carrier to deny or rescind coverage over material misrepresentation, and cyber carriers are now applying that doctrine aggressively: a business that attested to enforced MFA at renewal, then suffers a breach through an account that turns out to have been exempted from it, risks a denied claim on exactly the incident the policy was bought to cover -- not because the policy excludes ransomware or business email compromise, but because the attested control wasn't actually in place when the loss occurred. That risk is exactly why brokers now push clients toward a documented, evidence-based readiness assessment before renewal rather than a quick internal self-certification: the goal isn't just qualifying for better pricing, it's making sure the policy that gets bound will actually pay out when something happens.

The claims data explains why insurers tightened the screws heading into 2026. Coalition's 2026 Cyber Claims Report, drawn from more than 100,000 policyholders globally over calendar year 2025, found that initial ransomware demands surged 47% year-over-year to an average of just over $1 million, and that 70% of ransomware incidents now involve both encryption and data theft -- the double-extortion pattern that makes a clean backup restore insufficient on its own to close out a claim. Business email compromise and funds-transfer fraud, not exotic malware, drove 58% of all claims Coalition processed in 2025, and more than half of funds-transfer-fraud losses -- averaging $112,000 each -- traced back to a compromised inbox. The FBI's Internet Crime Complaint Center found a similar pattern nationally: business email compromise alone generated $3.046 billion in reported U.S. losses in 2025, with an average loss per complaint above $122,000, contributing to $20.877 billion in total reported cyber-enabled crime losses, a 26% jump from the year before. None of that is exotic nation-state tradecraft. It's mailbox compromise and social engineering -- precisely what enforced MFA and modern email security are built to stop, and precisely why insurers now grade applicants on whether those specific controls are actually enforced rather than merely available.

IT security analyst monitoring multiple screens in a security operations center, representing 24/7 EDR monitoring for cyber insurance readiness

Small and midsize businesses carry a disproportionate share of this exposure even though their individual claims run smaller than a large enterprise's. NetDiligence's fifteenth annual Cyber Claims Study, drawn from more than 10,000 claims filed for incidents between 2020 and 2024, found that large companies made up just 2% of the claims dataset but accounted for over half of total incident costs -- meaning small and midsize enterprises represent the overwhelming majority of claim frequency, exactly the metric insurers price against when setting SMB terms. Hiscox's 2026 Cyber Readiness Report, surveying 1,000 U.S. small businesses, found 56% had experienced at least one cyberattack in the prior twelve months, averaging 2.38 attack attempts per business. Paying a ransom is not a reliable fix: among businesses in that survey that paid, only half recovered all of their data, 27% were attacked again, and victims who paid ended up doing so an average of 2.24 times before actually getting their data back. For an underwriter deciding whether to bind a policy, that combination -- high frequency, unreliable recovery even after payment, and a rising rate of double extortion -- is exactly what turns MFA, EDR, and immutable backups from a nice-to-have into a hard underwriting gate.

The clearest evidence that weaker-controlled accounts are being pushed out of the standard insurance market is where the premium dollars are actually landing. NAIC's 2025 market report shows that U.S. domestic surplus lines carriers -- the non-admitted market that specializes in harder-to-place, higher-risk business -- wrote 57% of total U.S. cyber insurance premium in 2024, up 12 percentage points from 2023, with alien (offshore) surplus lines carriers writing another 18%. Combined, 75 cents of every cyber insurance premium dollar in the United States now flows through the non-admitted surplus lines channel rather than the admitted, standard-rate market regulated directly by state insurance commissioners. Surplus lines policies typically carry higher retentions, narrower coverage grants, and fewer negotiated concessions than an admitted-market policy. A business that can't demonstrate the control set underwriters now expect isn't usually told in plain language that its security posture caused the outcome -- more often it's simply re-quoted into that non-admitted segment at a materially worse price, or the renewal quote doesn't come back at all.

California businesses carry a second, compounding layer of exposure that makes insurability planning inseparable from compliance planning. Senate Bill 446 tightened Civil Code Section 1798.82 effective January 1, 2026, replacing California's old 'most expedient time possible' breach notification standard with a hard 30-calendar-day deadline to notify affected residents, plus a 15-day Attorney General notice requirement for breaches touching 500 or more residents. The California Privacy Protection Agency's cybersecurity audit regulations, finalized in 2025 and phasing in from 2028 through 2030 depending on revenue, name 18 specific control categories -- including MFA, encryption, access controls, network monitoring, and incident response planning -- as the working definition of 'reasonable security' under Civil Code Section 1798.81.5. That list overlaps almost exactly with what cyber insurance underwriters now ask for on a bind application. A California business that builds toward the CPPA's audit framework is, in practice, assembling the same evidence package an insurance underwriter wants to see -- and a business that ignores both is exposed on two fronts at once: a denied claim if the carrier finds a misrepresented control, and separate statutory liability under CCPA/CPRA regardless of what the policy does or doesn't pay.

A genuine cyber insurance readiness assessment doesn't start with a generic security checklist -- it starts by mapping current controls against the specific questions on the applications of the carriers a business is actually likely to approach, cross-referenced against a recognized baseline like the CIS Critical Security Controls Implementation Group 1 or NIST Cybersecurity Framework 2.0, both of which brokers and underwriters increasingly cite as shorthand for 'reasonable' SMB security. That means testing whether MFA is actually enforced, not merely enabled, across every login path including legacy systems and shared accounts; confirming EDR coverage extends to servers and remote endpoints, not just office desktops; verifying that backups are both encrypted and immutable and have actually been test-restored rather than just scheduled; and producing a written, exercised incident response plan instead of a template nobody on staff has read. It also means documenting patch cadence, third-party and vendor remote access, and employee phishing-awareness training, since underwriters increasingly ask about supply-chain and vendor exposure with the same specificity they apply to a company's own network.

The financial case for doing this work before renewal, not after a denied claim, is straightforward once the numbers sit side by side. NetDiligence's fifteenth annual study puts the five-year average incident cost for small-to-midsize enterprise claims (organizations under $2 billion in annual revenue) at $246,000 for claims filed 2020 through 2024, and separately finds that when an incident triggers business interruption, average costs run more than 650% higher than incidents without it. A denied claim doesn't just mean an uncovered breach -- under most policy language it means the legal, forensic, notification, and business-interruption costs a cyber policy was specifically purchased to absorb now land directly on the business's balance sheet, on top of whatever CCPA/CPRA statutory exposure follows separately. Set against that downside, the cost of a professionally conducted readiness assessment and the remediation work it identifies is a rounding error -- and it's the same work that, done right, also qualifies a business for the better pricing the softening headline rates are actually describing.

This is exactly the gap Mytek Pros' compliance-audit practice is built to close. As a licensed California low-voltage contractor and managed service provider (License #1116987) with DIR public-works registration (PW-LR-1001158430), BICSI certification, and DBE/DVBE/MBE certification, based in Carlsbad and serving San Diego County and businesses throughout California, Mytek Pros conducts cyber insurance readiness assessments that map your actual environment against the MFA, EDR, backup, and incident-response criteria carriers are underwriting to in 2026 -- and against the same 18-point CPPA audit framework California regulators are phasing in through 2030 -- producing the documentation package a broker or underwriter actually wants to see, not a generic checklist. Where gaps exist, our managed IT and managed security services (typically $125-$250 per user per month) implement and maintain enforced MFA, monitored EDR, immutable backup, and tested incident response, so your business gets insurable and stays insurable through the next renewal cycle, not just the next application. If your last cyber insurance renewal came back with a rate increase, a new exclusion, or a list of security requirements you couldn't fully answer, contact Mytek Pros at (619) 353-5702 or inquire@mytekpros.com to scope a readiness assessment before your next renewal date does it for you.

Questions about audits? Get in touch or explore our Audits services.