The Control Cyber Insurers Expect Is The One IT Teams Find Hardest To Run

Estimated reading time: 6 minutes

Kaseya’s 2026 Cybersecurity Report puts human error first. Two other findings speak directly to cyber insurance requirements. MFA tops the list of controls IT teams find hardest to run. And compliance or insurance rules prompt security spending as often as attacks do.

Multifactor authentication (MFA) is one of the first controls cyber insurers look for. IT teams also say it causes them the most friction.

Kaseya surveyed 1,132 managed service providers (MSPs) and in-house IT professionals. It asked which security practices create the most operational friction. Thirty-six percent named MFA. Privileged access management came second, at 18%.

Kaseya’s explanation applies to every control. Each one needs day-to-day management, the report says. Policies need maintaining, access exceptions need handling, and users need support.

MFA reaches every employee who signs in. End-user requests were the most common interruption to security work, named by 38%. Password resets drew 13%.

Marsh lists MFA first among its 12 key cyber controls. The broker says certain controls have become “a minimum requirement of insurers.”

Kaseya warns that hard-to-use controls generate support requests and cut productivity. They also “put pressure on teams to weaken them,” the report says. Its advice is to make secure behavior the easier path.

The survey ran in August 2026 across 63 countries and territories. MSPs made up 55% of respondents.

Bar chart of the security practices that create the most operational friction, with multifactor authentication highest at 36 percent, from Kaseya's 2026 Cybersecurity Report
Security practice creating the most operational friction, share of respondents. Source: Kaseya 2026 Cybersecurity Report.

Cyber Insurance Requirements Move Security Budgets

Insurers also shape when clients spend. Kaseya asked MSPs what mainly drives their clients to invest in cybersecurity.

Cost and available budget came first, at 39%. A recent incident or near miss drew 20%. Compliance or cyber insurance requirements also drew 20%. Clear evidence of business impact drew 11%, and demonstrated risk reduction 9%.

See also  Are Cyber Insurers and their Clients Putting Too Much Trust in MFA (Multifactor Authentication) to Stop Ransomware? 

Kaseya grouped compliance and cyber insurance into one answer, so the figure does not isolate insurance. Even so, outside requirements prompted spending nearly twice as often as evidence of business impact.

The report calls the pattern “a reactive cycle.” Clients spend once a trigger arrives, it says, rather than ahead of the risk.

Bar chart of what drives MSP clients to invest in security, with compliance or cyber insurance requirements and recent incidents each at 20 percent, from Kaseya's 2026 Cybersecurity Report
Main driver of client security investment, share of MSPs. Compliance and cyber insurance were a single answer choice. Source: Kaseya 2026 Cybersecurity Report.

MSPs see underinvestment across their client base. Sixty-five percent say clients are underinvested relative to their risk, including 21% significantly. Among IT departments, only 20% say their budget is growing in line with real risk.

Human Error Tops The Threat List

Kaseya’s headline finding is human error, including social engineering and distraction. Sixty-eight percent named it among the threat vectors that concern them most. Email followed at 55%.

Among organizations with an incident in the past three years, four of the top five contributing factors involved people. Poor user practices or gullibility led at 41%. Lack of end-user cybersecurity training followed at 40%. Outdated security patches drew 8%.

“People aren’t perfect, and everyone knows it,” said David Baggett, Kaseya’s SVP and general manager for Security Suite. “Expect mistakes, account for constraints and engineer around them.”

People also shaped recovery. Among organizations that recovered within two hours, 35% credited a well-trained internal IT or security team. Among those that recovered more slowly than expected, 19% blamed manual or complex recovery processes. Another 17% cited dependence on third-party vendors.

Compliance Audit Confidence Runs Ahead Of The Evidence

Sixty-five percent say they could pass a compliance audit today with no preparation. Asked what could cause problems, 49% named incomplete documentation or policies. Thirty-four percent cited security controls that are not fully implemented.

See also  Cowbell Launches Prime One With Affirmative AI Coverage And Quantum Risk Protection

Kaseya calls an audit “a point-in-time test.” Compliance means keeping controls, documentation, and employee practices current, the report says.

Underwriting faces the same limit. A proposal form only knows what the insured declares, on the day the applicant fills it in. Cyber Tzar’s Andrew Horkan explored that gap on the CINI podcast. The episode title sums it up: Compliant In May. Seventeen Thousand Open Ports In June.

Boards rely on audits as well. PwC found that CEOs and board members rank compliance audits and control effectiveness first among cyber metrics, at 50%.

Get The Cyber Insurance News Upload Delivered
Subscribe to our weekly newsletter!

MSP Cybersecurity: What High Performers Do Differently

Kaseya also released an MSP resilience assessment with the report. It separates high and low performers by whether they met revenue and growth goals over the last two quarters.

High performers treat compliance, cyber insurance, and AI adoption as competitive advantages, Kaseya said. The release did not include insurance figures from the assessment.

Fifteen percent of MSPs have no incident response plan, according to Kaseya. That share falls to 11% among high performers and rises to 25% among low performers. Almost 30% of high performers test clients’ incident response plans quarterly, compared with 18% of low performers.

FAQ – Cyber Insurance Requirements

What is Kaseya’s 2026 Cybersecurity Report?

A survey of 1,132 managed service providers and in-house IT professionals in 63 countries and territories, conducted in August 2026. MSPs made up 55 percent of respondents.

Which security control creates the most friction?

Multifactor authentication. 36 percent of respondents named MFA as the practice that creates the most operational friction. Privileged access management came second at 18 percent.

See also  CyberArk Report Reveals Employee Behaviors Pose Widespread Cybersecurity Risks That Can Sink Companies

Do cyber insurance requirements drive security spending?

About as often as attacks do. 20 percent of MSPs named compliance or cyber insurance requirements as the main driver of client investment. Another 20 percent named a recent incident or near miss. Kaseya grouped compliance and insurance into one answer.

What is the top threat concern?

Human error, including social engineering and distraction, named by 68 percent. Email followed at 55 percent.

Are organizations ready for compliance audits?

65 percent say they could pass an audit with no preparation. Yet 49 percent named incomplete documentation or policies as their biggest audit risk.

How many MSPs lack an incident response plan?

15 percent, according to Kaseya. The share is 11 percent among high-performing MSPs and 25 percent among low performers.

Leave a Comment

×