DMARC & Cyber Insurance: 2026 Underwriting Trends
Ecosystem NewsSecurity InsightsContents
Cyber insurance has become a risk management standard for organisations, and insurers have grown increasingly sophisticated in assessing an organisation’s security posture.
Five years ago, cyber insurers were tightening terms and raising premiums fast, and email authentication was just one line on a growing list of underwriting questions. That list hasn’t gotten shorter; if anything, it’s gotten more specific.
Today, those questions are far more detailed, with organisations expected to demonstrate implementation of SPF, DKIM, and DMARC alongside other key security controls. In Europe, a second track has opened up alongside it: questions that used to live only on an insurance application are now questions regulators ask directly, backed by law rather than underwriting alone. Here’s where both tracks stand in 2026.
Why Cyber Insurance Continues to Drive DMARC Adoption
Business email compromise (BEC) and ransomware remain the two incident types insurers pay closest attention to because they continue to cause significant financial losses worldwide.
The FBI’s Internet Crime Complaint Centre attributed over $3.04 billion in U.S. losses to BEC in 2025 alone; these staggering losses are part of why email authentication now appears on cyber insurance applications.
Today, a typical cyber insurance application asks a version of the same questions we outlined in 2021, with a few additions:
- Have you implemented SPF, DKIM, and DMARC? What is your DMARC enforcement policy?
- Do you use phishing-resistant Multi-Factor Authentication (MFA) for email and cloud services?
- Do you maintain offline or immutable backups, and have you tested their restoration?
- Do you use Endpoint Detection and Response (EDR) tools?
- Do you have a documented, tested Incident Response Plan?
- Do you run regular security awareness training, including simulated phishing?
- Do you assess the security posture of third-party vendors?
- Have you documented your organization’s use of artificial intelligence?
Chubb’s current Irish proposal form is a good example of this in practice. The questionnaire asks applicants to confirm whether “SPF is enforced” as part of their email security controls.
Likewise, Aviva’s UK cyber insurance application form explicitly references DMARC alongside SPF and DKIM, encompassing all aspects of email authentication.
Organisations that already have DMARC in place, especially at the enforcement level, tend to move through these questions quickly and with confidence. This translates to a clearer underwriting process and positions your organization proactively ahead of market demands, rather than meeting basic requirements.
How Cyber Insurance Requirements Have Changed Since 2021
In 2021, we cited the U.S. Government Accountability Office (GAO) data showing cyber insurance take-up had risen from 26% (2016) to 47% (2020). Five years on, the market has moved through a full pricing cycle and looks different again:
- U.S. direct written premiums dipped slightly in 2024, even as the number of claims rose nearly 40% (National Association of Insurance Commissioners, 2025).
- Pricing has kept softening for longer than many expected: AM Best recorded eight consecutive quarters of rate declines in the U.S. market through the first quarter of 2026, even as rising claim severity puts pressure on insurers to eventually reverse course.
- Ransomware still accounts for the majority of large-claim value, even as faster detection has helped bring down average claim severity (Allianz Commercial).
- Insurers increasingly favour controls-based underwriting, where pricing and coverage are shaped by provable security practices over blanket rate changes.
The takeaway: the more clearly an organisation can show proof of its controls, including DMARC and its enforcement level, the easier the underwriting conversation tends to be.
How Cyber Insurance Is Addressing the Rise of AI
Organisations are facing increased pressure from the cyber insurance marketplace and underwriters to fully disclose all AI usage to ensure that any related incidents are covered.
For years, AI risk was often assumed to be covered under both cyber and technology errors and omissions (Tech E&O) policies, even when AI was never named in the policy. Like shadow IT, shadow AI can now leave organisations exposed to risks that are neither clearly defined nor explicitly addressed in their coverage.
As exclusions and narrower terms emerge, AI-related claims may fall between Tech E&O, directors and officers (D&O), and employment practices liability (EPL) policies, creating coverage gaps.
Choosing a technology vendor that utilises AI is no longer just an IT decision. Depending upon the organisation, it may involve legal, privacy, security, procurement, compliance, and insurance teams. Organisations need to assess data handling, vendor terms, and potential coverage impacts then update relevant AI use, data governance, and vendor risk policies.
On the receiving end of abuse, AI can enable more convincing phishing, business email compromise, and impersonation attacks through polished lures, cloned voices, and deepfake video. But it does not change the core question behind email authentication: Is the sender authorized to use the domain?
How NIS2, DORA, and DMARC Are Changing Cyber Insurance in Europe
Cyber insurance has matured. Five years ago, organisations mainly completed questionnaires; today, insurers increasingly expect organisations to demonstrate mature security controls. At the same time, European regulation is pushing organisations toward many of the same controls.
Email authentication and DMARC sit at the intersection of both trends. In the EU, two regulations now sit alongside the insurance conversation:
- NIS2 (in force since October 2024) sets baseline cybersecurity risk-management expectations for organisations across 18 sectors, including incident notification requirements. For example, the German Federal Office for Information Security names email authentication explicitly as an expected control.
- DORA (in force since January 2025) applies to banks, insurers, and their information and communications technology (ICT) providers across the EU, formalising ICT risk management, third-party risk oversight, resilience testing, and incident reporting.
For EU organisations, this means the cyber insurance questionnaire and the regulatory checklist are converging. It’s reasonable that NIS2 or DORA compliance status will become a standard question on EU applications before long, as the two processes increasingly ask the same organisations about the same underlying controls.
Cyber insurance uptake in Europe is still catching up to the risk, though. Howden’s 2025 Cyber Report found just 22% of Italian businesses and 39% of UK businesses carry coverage, even though cyber ranks as the top business risk in Europe for two years running (Allianz Risk Barometer).
Meanwhile, ENISA’s 2025 Threat Landscape report found phishing responsible for 60% of observed intrusions across the EU. That combination points to a real opportunity: organisations that get ahead of DMARC now are well positioned for both the insurance conversation and the regulatory one.
We’re here to help
Effective DMARC deployment and maintenance is crucial in meeting cyber insurance requirements. At dmarcian, we offer the resources and expertise you need to get it right the first time.
We help organisations of all sizes:
- Deploy DMARC the right way—no guesswork, no disruptions
- Gain full visibility into your email ecosystem
- Meet compliance requirements and stay ahead of evolving email security mandates
Want to continue the conversation? Head over to the dmarcian Forum.
Did you like this article?