Quick summary: Cyber insurance underwriting changed a lot over the last couple of years. Carriers used to hand out policies based on a short questionnaire. Now they want proof — enforced multi-factor authentication, endpoint protection on every device, backups that actually restore, and a written incident response plan. Dallas businesses face an extra wrinkle: Texas has one of the more actively enforced data breach notification laws in the country, so the cost of not having coverage (or not qualifying for good coverage) is higher here than in a lot of other states. This guide walks through exactly what underwriters look for in 2026, what that looks like for different kinds of Dallas businesses, and what you can actually do to bring your premium down.
Why Cyber Insurance Applications Feel Different Now
If you applied for cyber insurance three or four years ago, you probably remember it being pretty painless. A few checkboxes, a signature, done.
That’s not how it works anymore.
Insurers got burned. Ransomware claims spiked, payouts got bigger, and carriers realized a lot of the businesses they’d been covering didn’t actually have the security controls they’d claimed on their applications. So the application itself changed. It now reads a lot more like a security audit than a form — and increasingly, carriers ask for evidence, not just answers.
For a small office in Uptown Dallas or a manufacturer out in Carrollton, that means the old “just fill out the form and get a quote” approach doesn’t really work anymore. You need to actually know what’s being asked and, ideally, have most of it already in place before you apply.
That’s what this guide is for.
What Cyber Insurance Actually Covers (and Why General Liability Doesn’t)
A lot of business owners assume their general liability policy already handles this. It doesn’t, and it’s worth understanding why.
General liability insurance is built for bodily injury and property damage — someone slips in your store, a delivery truck damages a client’s fence, that kind of thing. A data breach isn’t bodily injury or property damage in the traditional sense, so most GL policies simply exclude it, or only offer a small, bolted-on endorsement that falls far short of what a real incident costs.
Cyber liability insurance is a separate, purpose-built policy. Most carriers now sell it as a standalone policy rather than an add-on, because the standalone version gives you higher limits and broader coverage than an endorsement tacked onto a business owner’s policy.
Here’s what a solid standalone cyber policy typically covers:
| Coverage area | What it actually pays for |
| Incident response | Forensic investigators, breach coaches/legal counsel, PR support, customer notification costs |
| Business interruption | Lost income and extra expenses while you’re down after a ransomware attack or system outage |
| Cybercrime / social engineering | Wire fraud, fraudulent instruction scams, funds transfer fraud, extortion payments |
| Privacy liability | Legal fees, settlements, and regulatory defense tied to a breach of customer or employee data |
| Data restoration | Cost to rebuild or recover systems and data after an attack |
| Regulatory fines & penalties | Defense costs and, where insurable, fines from regulators (rules vary by state) |
Notice that this is a mix of first-party coverage (things that happen to you directly — your systems, your downtime) and third-party coverage (claims other people bring against you because their data was exposed through your business). A good policy needs both. A lot of the cheap, bare-bones policies you’ll see marketed only cover one side.
Why This Matters More in Texas Than in a Lot of Other States
Every state has some version of a data breach notification law. Texas’s is stricter than most, and it’s actively enforced — not just sitting on the books.
Under the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code, Chapter 521), if your business experiences a breach involving Texans’ sensitive personal information, you’re required to notify affected individuals without unreasonable delay, and no later than 60 days after you discover the breach. If the breach affects 250 or more Texas residents, you also have to report it to the Texas Attorney General’s office — the AG’s site lays out the exact reporting process.
Miss those deadlines, or handle the notification badly, and you’re looking at civil penalties that can run well into five figures per violation, on top of whatever the breach itself already cost you.
This is the part a lot of Dallas businesses miss: cyber insurance isn’t just about covering the cost of the breach. It’s about covering the cost of responding to it correctly, on a legally mandated timeline, in a state that doesn’t go easy on businesses that get it wrong.
A quick, real-world way to think about it:
- A small professional office (say, a five-person accounting or law practice) handling client Social Security numbers and financial records is squarely inside the scope of the Texas law the moment they store that data digitally.
- A medical office in Dallas is dealing with both the Texas breach law and HIPAA at the same time — two overlapping notification obligations if patient records are exposed.
- A retail store taking card payments has PCI obligations layered on top of the state law.
- A warehouse or distribution business might not think of itself as a “data” business at all, right up until its shipping and customer database gets hit with ransomware.
- A corporate office running its own servers or a hybrid cloud setup has the broadest exposure of the group, simply because there’s more infrastructure to secure.
Different businesses, same underlying question: if it’s exposed, do you have the coverage — and the security posture — to respond the way Texas law requires?
The 2026 Cyber Insurance Qualification Checklist
This is the part that’s changed the most. Underwriters aren’t asking “do you have security measures in place?” anymore. They’re asking for specifics, and in a growing number of cases, evidence.
Here’s what shows up on almost every serious carrier’s application in 2026:
| Control | What underwriters are actually checking | Why it matters |
| Multi-factor authentication (MFA) | Enforced — not optional — on email, VPN/remote access, admin accounts, and cloud apps | The single biggest factor. Most breach claims trace back to an account that didn’t have MFA turned on |
| Endpoint Detection & Response (EDR) | Deployed on every workstation and server, not just “some antivirus somewhere” | Traditional antivirus alone often no longer satisfies underwriting |
| Backups | Encrypted, stored offsite or immutable, and tested — meaning you’ve actually restored from them, not just scheduled them | Ransomware recovery lives or dies here |
| Patch management | A documented process for updating operating systems, firewalls, and critical software | Unpatched systems are still one of the most common entry points |
| Email security | Spam/phishing filtering plus domain authentication (SPF, DKIM, DMARC) | Email is still the #1 delivery method for attacks |
| Security awareness training | Documented, recurring training for staff — bonus points for phishing simulation results | Insurers increasingly treat your people as part of your attack surface |
| Written incident response plan | An actual document, reviewed and ideally tested, not just “we’d figure it out” | Determines how fast — and how well — you respond when something goes wrong |
| Access control | Limited admin rights, regular access reviews | Reduces how far an attacker can move once they’re in |
A stat worth knowing: industry claims data shows a large majority of cyber insurance claims involve businesses that either didn’t have MFA at all, or had it available but not enforced everywhere it should have been. That “available but optional” gap is one of the most common reasons applications get flagged or premiums spike at renewal.
What’s different about a small office versus a corporate office here isn’t really the list — it’s the scale. A five-person shop can usually get MFA and EDR rolled out across the whole company in an afternoon. A 150-person corporate office with legacy systems and multiple locations needs a real rollout plan, and underwriters know the difference. Be honest about where you actually are, not where you think you should be.
How to Actually Get Audit-Ready Before You Apply
Once you know what’s on the checklist, the next question is timing. Don’t wait until the week your renewal is due.
Here’s a realistic prep timeline:
60 days out: Pull together the basics — a list of every system, cloud app, and device your business uses, plus who has admin access to each. This alone is eye-opening for a lot of businesses. A corporate office that’s grown through a couple of acquisitions often finds old accounts and forgotten admin logins nobody’s touched in years.
45 days out: Start collecting evidence, not just answers. Screenshots of MFA enforcement settings, EDR deployment reports showing coverage across every endpoint, and logs from your last backup restore test. If you’ve never actually tested a backup restore, this is the moment to do it — “we have backups” and “we’ve confirmed we can restore from backups” are very different answers to an underwriter.
30 days out: Run an internal risk review, even an informal one. Look at your vendors too — if a payroll processor or a scheduling app has access to your data, their security posture becomes part of your risk profile.
2 weeks out: Fill out the application with consistent, accurate answers. This sounds obvious, but it’s where a lot of businesses trip up. If one section says MFA is enforced everywhere and another lists a remote access tool that doesn’t require it, that inconsistency can slow down underwriting or come back to bite you at claim time.
For a small office, this whole process can usually be compressed into a couple of weeks, since there’s less infrastructure to document. A medical office or corporate office with more systems and more people should realistically start closer to the 60-day mark.
If your current setup doesn’t check most of these boxes yet, MFA and endpoint security setup for Dallas businesses is usually the fastest way to close the gap — most of the core controls (enforced MFA, EDR rollout, backup testing) can be in place well inside that 60-day window.
How to Actually Lower Your Premium (Not Just Get Approved)
Getting approved and getting a good rate aren’t the same thing. A lot of businesses meet the bare minimum, get a policy, and then wonder why their premium is still high or climbs at renewal.
A few things actually move the needle on price:
Full MFA coverage, not partial. Enforced on email, remote access, admin accounts, and cloud apps — not just “the important stuff.” Underwriters treat MFA as close to pass/fail, and partial coverage is treated closer to a fail than most business owners expect.
A tested, documented incident response plan. Not a mental plan the owner has in their head — an actual written document that’s been reviewed, and ideally walked through in a tabletop exercise. Carriers can tell the difference between a plan that exists on paper and one that’s genuinely ready to use.
Security awareness training with completion tracking. If your staff have gone through phishing simulation training and you can show completion rates, that’s a concrete data point underwriters can price against — far more useful to them than “we talk about phishing sometimes.”
A recent, documented risk assessment. Some carriers, including tech-forward insurers like Coalition, bundle in ongoing risk monitoring as part of the policy itself — worth asking your broker whether your carrier offers something similar, since it can give you an evidence trail for free.
A clean claims history and accurate, specific application answers. Vague “yes to everything” answers can actually work against you — if a claim happens later and the carrier finds a gap between what you claimed and what was actually in place, that’s a coverage dispute waiting to happen. Specific, honest answers price better and hold up better.
On the flip side, these are the things that quietly push premiums up or trigger a decline:
| Red flag | Why it hurts |
| MFA that’s “available” but not enforced everywhere | Treated as equivalent to no MFA by most underwriters |
| Backups that have never been test-restored | No proof recovery will actually work when it matters |
| Security documentation that’s more than a year old | Signals your controls may not reflect current reality |
| Assuming your cloud provider handles all the security | Microsoft 365 and Google Workspace secure their infrastructure — you’re still responsible for how you configure MFA, permissions, and data access on top of it |
| Inconsistent answers across the application | Raises questions during underwriting and can create disputes at claim time |
That last point trips up more Dallas businesses than you’d think, especially retail stores and warehouses running point-of-sale or inventory systems through a mix of cloud and on-premise tools. It’s worth having someone technical — not just whoever fills out insurance paperwork — review the application before it’s submitted.
If you want a clear picture of where your business actually stands against this checklist before you talk to a broker, that’s exactly the kind of gap managed IT support in Dallas is built to catch — not just once, but on an ongoing basis, since carriers reassess most of this at every renewal.
Thinking about your renewal or a new policy in the next few months? The businesses that get the best rates are the ones that started preparing before the application landed in their inbox. If you want a straightforward read on where your current setup stands, reach out to Ighty Support and we’ll walk through it with you.
Common Mistakes That Get Applications Declined
A few patterns show up again and again:
- Claiming MFA is “in place” when it’s really optional. An underwriter who asks a follow-up question or requests a screenshot will find this fast.
- No tested backup restores. Plenty of businesses schedule backups and never actually check whether they work. The first real test shouldn’t be during a ransomware attack.
- Outdated security documentation. A policy written two years ago, before half your current software stack existed, doesn’t reflect your real risk.
- Misunderstanding the shared responsibility model. Your cloud provider secures the platform. You’re responsible for configuring it correctly — turning on MFA, managing permissions, and monitoring for misuse.
- Inconsistent answers across the application. This is the quiet one. It doesn’t look like a red flag when you’re filling out the form, but it’s one of the most common reasons underwriting slows down or gets denied.
A useful way to think about it: a small consulting firm with five employees, solid MFA, EDR, and clean backups can often qualify without much friction. A medical office handling patient records, or a corporate office running its own servers, is going to get a closer look — more systems, more data, more places for something to have slipped through the cracks. Neither one is disqualifying on its own. What matters is whether what you claim on the application matches what’s actually running.
FAQs
Is cyber insurance required by law in Texas?
No. Texas doesn’t mandate cyber insurance itself. What Texas does mandate is data breach notification — under Chapter 521 of the Texas Business & Commerce Code, businesses have to notify affected individuals within 60 days of discovering a breach, and notify the Texas Attorney General if 250 or more Texans are affected. Insurance isn’t required, but it’s what typically pays for meeting that obligation.
What’s the difference between cyber insurance and general liability insurance?
General liability covers bodily injury and property damage. It generally excludes data breaches and cyber incidents, or only offers a thin add-on. Cyber liability is a separate policy built specifically for breach response, business interruption from an attack, cybercrime, and privacy liability.
Do I need MFA to qualify for cyber insurance?
In almost all cases, yes — and it needs to be enforced, not just available. Most carriers in 2026 treat enforced MFA as close to a pass/fail requirement across email, remote access, and admin accounts.
How long does it take to get approved for cyber insurance?
It varies by carrier and how ready your documentation is, but businesses that show up with evidence already gathered (MFA screenshots, EDR reports, tested backup logs) typically move through underwriting faster than those still scrambling to pull that information together mid-application.
What happens if I don’t have cyber insurance and experience a breach in Texas?
You’re still legally on the hook for notification under Texas’s breach law — the insurance doesn’t create that obligation, it just typically pays for it. Without coverage, you’d be paying out of pocket for forensic investigation, notification costs, legal fees, and potentially regulatory penalties, on top of any business interruption from the incident itself.
Does a small business really need this, or is it just for larger companies?
Smaller businesses are actually targeted more often, not less — attackers assume smaller offices have weaker security. A five-person office handling client financial data or patient records has real exposure regardless of headcount.
The Bottom Line
Qualifying for cyber insurance in Dallas in 2026 isn’t really an insurance exercise anymore — it’s a security exercise with an insurance policy attached at the end of it. Enforced MFA, real endpoint protection, tested backups, and a written response plan aren’t just what gets you approved. They’re what actually keeps a bad day from becoming a business-ending one, especially with Texas’s notification deadlines running on the clock the moment a breach is discovered.
If you’re not sure where your business stands against this checklist, that’s a conversation worth having before your next renewal notice shows up. Talk to Ighty Support and we’ll help you figure out exactly what’s missing — and get it handled.