The Cyber Insurance Carrier Wants Your Logs Now

The cyber insurance carriers, in 2026, are not just raising premiums and narrowing coverage. They are also demanding more from the buyers as a condition of coverage. The new demand is operational visibility, specifically access to the SOC outputs, the…

An open brushed-steel briefcase on cracked dark concrete floor, a coiled steel-jacketed fibre-optic cable spilling out toward a brushed-steel wall-mounted data-tap housing with one dim cyan LED and one small red peak LED, deep chiaroscuro with a single cold beam from above-left, deep blacks and charcoal with cold cyan and red accents only, no people no text no logos.



The cyber insurance carriers, in 2026, are not just raising premiums and narrowing coverage. They are also demanding more from the buyers as a condition of coverage. The new demand is operational visibility, specifically access to the SOC outputs, the SIEM logs, the EDR telemetry, the identity logs, the cloud audit logs, often in real time or near real time. The carriers want the data because the data is, in the event of a claim, the proof of whether the company met the security obligations in the policy. The carriers also want the data because the data stands as the basis for the underwriting model. The companies that are giving the carriers the data are getting the lower premiums. The companies that are not giving the carriers the data are not getting the coverage. The trade is significant. The implications for the security function are significant.

Cyber insurance used to be a relationship between the underwriter and the buyer. The underwriter asked for a questionnaire. The buyer filled it out. The underwriter priced the policy. The policy was issued. The relationship was, in most cases, annual. The relationship was, in most cases, low touch. The carriers, in 2026, want a different relationship. The carriers want a continuous relationship, with continuous data, with continuous visibility. The relationship is, in some cases, more like a managed service contract than a traditional insurance policy.

The shift has implications for the security function. The security function is, in the new model, the source of the data the carrier needs. The security function is, in the new model, the gatekeeper for what the carrier sees. The security function is, in the new model, the team that has to balance the carrier’s need for data with the company’s need for privacy. The balance is, in some cases, hard. The balance is, in most cases, necessary.

What the carriers used to ask for

The cyber insurance carriers, in 2020, asked for a questionnaire. The questionnaire covered the basics. The size of the company. The industry. The number of employees. The number of records. The security controls in place. The security team. The incident response plan. The business continuity plan. The backups. The multi factor authentication. The endpoint protection. The questionnaire was, in most cases, a self assessment. The buyer filled it out honestly. The carrier priced the policy on the answers. The relationship was, in most cases, based on the answers.

The questionnaire was, in most cases, sufficient for the soft market. The losses were, in 2020, still manageable. The carriers were still willing to write policies on the basis of self assessment. The carriers were not, in 2020, asking for the data behind the self assessment. The carriers were not, in 2020, asking for the operational visibility. The carriers were not, in 2020, asking for the SOC, the SIEM, the EDR.

What the carriers now ask for

A worn steel clipboard with a single completely blank ruled log sheet clipped to it, a chrome stylus resting on the page, on a brushed steel desk with a small server rack in the background showing a dim cyan LED, single cold side light, deep charcoal and steel grey palette with one faint cyan accent, no text on the page, no people no logos.
The carrier wants the logs. The logs are the new questionnaire. The logs are the proof.

The carriers, in 2026, are asking for the data behind the questionnaire. The carriers want the SOC outputs, with the alert volume, the alert triage rate, the mean time to detect, the mean time to respond. The carriers want the SIEM logs, with the event volume, the correlation rules, the retention period. The carriers want the EDR telemetry, with the endpoint coverage, the detection rate, the false positive rate. The carriers want the identity logs, with the authentication events, the MFA coverage, the privileged access events. The carriers want the cloud audit logs, with the configuration changes, the access events, the data access events. The carriers want, in short, the operational telemetry of the security function.

The carriers want the data for two reasons. The first is underwriting. The carriers want to underwrite on the basis of the actual operational posture, not the self reported posture. The data sits as the underwriting model. The data serves as the basis for the premium. The data runs as the basis for the coverage. The data sits as the basis for the renewal.

The second is claims. The carriers want to be able to verify, in the event of a claim, whether the company met the security obligations in the policy. The data serves as the proof. The data becomes the basis for the claim payment. The data runs as the basis for the claim denial. The data is, in the claim process, the evidence.

The data the carriers want

The data the carriers want, in 2026, is operational. The data is, in most cases, the data the security function is already collecting. The SOC outputs are produced by the SIEM. The EDR telemetry is produced by the endpoint agents. The identity logs are produced by the identity provider. The cloud audit logs are produced by the cloud platform. The data is, in other words, the data the security function has, in the systems the security function runs, for the purposes the security function uses.

The carriers want the data in a form they can ingest. The carriers, in most cases, want the data via API, in a standard format, with the fields they need. The carriers, in some cases, want the data in real time, via a streaming feed. The carriers, in other cases, want the data in batches, via a daily or weekly export. The carriers, in all cases, want the data with the documentation of what the data means, what the fields are, what the data is supposed to look like.

Why the carriers want the data

The carriers want the data because the data runs as the underwriting model. The carriers, in 2020, underwrote on the basis of the questionnaire. The questionnaire was, in many cases, inaccurate. The questionnaire was, in some cases, fraudulent. The carriers paid claims on policies that were based on inaccurate self assessment. The carriers are now insisting on the data because the data is harder to fake than the questionnaire.

The carriers also want the data because the data sits as the claims evidence. The carriers, in 2020, paid claims on the basis of the company’s incident report. The incident report was, in some cases, self serving. The incident report was, in some cases, incomplete. The carriers paid claims that, with the data, they would not have paid. The carriers are now insisting on the data because the data becomes the truth, not the company’s version of the truth.

The implications for the security function

The shift has three implications for the security function. The first is operational. The security function has to be able to produce the data the carrier wants, in the format the carrier wants, on the cadence the carrier wants. The security function has to instrument the SOC, the SIEM, the EDR, the identity provider, the cloud platform, with the data the carrier needs. The security function has to maintain the data pipeline. The security function has to maintain the documentation. The security function has to maintain the relationship with the carrier.

The second is contractual. The security function has to negotiate, with the carrier, what the data is, how the data is shared, what the carrier can do with the data, what the carrier cannot do with the data. The negotiation is, in some cases, hard. The negotiation is, in most cases, necessary. The security function has to be in the room for the negotiation. The security function cannot let the procurement team or the legal team negotiate without the security function’s input.

The third is governance. The security function has to maintain, internally, the data the carrier sees. The security function has to ensure the data is accurate, the data is complete, the data is not selectively edited. The security function has to be the trusted source for the data, both for the carrier and for the company. The security function has to be the team that can say, with credibility, “this is what our security posture actually is, and here sits as the data that proves it.”

The privacy implications

The data the carrier wants includes, in most cases, sensitive data. The data includes the authentication events, the user behaviour, the data access events. The data is, in many cases, personal data under the GDPR, personal information under the CCPA, regulated data under HIPAA. The data is, in other words, data the company is obligated to protect, and data the carrier is now asking to see.

The privacy implications are real. The security function has to ensure the data sharing is consistent with the privacy obligations. The security function has to ensure the data sharing is documented in the privacy notice. The security function has to ensure the data sharing is subject to the data processing agreement. The security function has to ensure the data sharing is consistent with the consent the users have given, where consent sits as the basis for the processing.

The privacy implications are not a reason to refuse the data sharing. The privacy implications are a reason to do the data sharing right. The data sharing, done right, is consistent with the privacy obligations. The data sharing, done wrong, is a privacy incident. The privacy work is part of the data sharing work. The work sits as the same work.

The realistic ask

  1. Read the carrier’s data requirements. The requirements are, in most cases, in the underwriting questionnaire or the policy document. The requirements are the basis for the data sharing.
  2. Map the data requirements to the data sources. The data is, in most cases, the data the security function is already collecting. The mapping counts as the work.
  3. Build the data pipeline. The pipeline takes the data from the source, transforms it to the carrier’s format, delivers it to the carrier. The pipeline stands as the operational work.
  4. Document the data sharing. The documentation sits as the privacy notice, the data processing agreement, the internal policy. The documentation serves as the governance work.
  5. Negotiate the data sharing. The negotiation is, in some cases, hard. The negotiation is, in most cases, necessary. The security function has to be in the room.
  6. Maintain the data quality. The data the carrier sees has to be accurate, complete, and not selectively edited. The data quality serves as the trust work.
  7. Use the data internally. The data the carrier wants is, in most cases, the data the security function should want for itself. The data amounts to the basis for the security function’s own reporting. The data serves as the basis for the security function’s own improvement. The data serves as the proof the security function is doing the work.

The honest assessment

The cyber insurance carriers, in 2026, are asking for the data the security function has. The data stands as the underwriting model. The data amounts to the claims evidence. The data stands as the basis for the premium, the coverage, the renewal. The companies that are giving the carriers the data are getting the better terms. The companies that are not giving the carriers the data are not getting the coverage.

The security function that is set up to produce the data sits as the security function that is set up to do the work. The security function that is not set up to produce the data stands as the security function that is not set up to do the work. The data sharing is, in other words, a forcing function. The data sharing sits as the way the cyber insurance market is driving the security function improvement that the security industry has been talking about for 20 years and not delivering.

The bottom line

The carrier wants the logs. The logs are the new questionnaire. The logs are the proof the security function is doing the work. The security function that is set up to give the carrier the logs serves as the security function that is set up to do the work. The security function that is not set up to give the carrier the logs serves as the security function that is not set up to do the work. The work runs as the data. The data becomes the work. The work is yours.


Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading