Estimated reading time: 6 minutes
Kaseya’s 2026 Cybersecurity Report puts human error first. Two other findings speak directly to cyber insurance requirements. MFA tops the list of controls IT teams find hardest to run. And compliance or insurance rules prompt security spending as often as attacks do.
Multifactor authentication (MFA) is one of the first controls cyber insurers look for. IT teams also say it causes them the most friction.
Kaseya surveyed 1,132 managed service providers (MSPs) and in-house IT professionals. It asked which security practices create the most operational friction. Thirty-six percent named MFA. Privileged access management came second, at 18%.
Kaseya’s explanation applies to every control. Each one needs day-to-day management, the report says. Policies need maintaining, access exceptions need handling, and users need support.
MFA reaches every employee who signs in. End-user requests were the most common interruption to security work, named by 38%. Password resets drew 13%.
Marsh lists MFA first among its 12 key cyber controls. The broker says certain controls have become “a minimum requirement of insurers.”
Kaseya warns that hard-to-use controls generate support requests and cut productivity. They also “put pressure on teams to weaken them,” the report says. Its advice is to make secure behavior the easier path.
The survey ran in August 2026 across 63 countries and territories. MSPs made up 55% of respondents.
Cyber Insurance Requirements Move Security Budgets
Insurers also shape when clients spend. Kaseya asked MSPs what mainly drives their clients to invest in cybersecurity.
Cost and available budget came first, at 39%. A recent incident or near miss drew 20%. Compliance or cyber insurance requirements also drew 20%. Clear evidence of business impact drew 11%, and demonstrated risk reduction 9%.
Kaseya grouped compliance and cyber insurance into one answer, so the figure does not isolate insurance. Even so, outside requirements prompted spending nearly twice as often as evidence of business impact.
The report calls the pattern “a reactive cycle.” Clients spend once a trigger arrives, it says, rather than ahead of the risk.
MSPs see underinvestment across their client base. Sixty-five percent say clients are underinvested relative to their risk, including 21% significantly. Among IT departments, only 20% say their budget is growing in line with real risk.
Human Error Tops The Threat List
Kaseya’s headline finding is human error, including social engineering and distraction. Sixty-eight percent named it among the threat vectors that concern them most. Email followed at 55%.
Among organizations with an incident in the past three years, four of the top five contributing factors involved people. Poor user practices or gullibility led at 41%. Lack of end-user cybersecurity training followed at 40%. Outdated security patches drew 8%.
“People aren’t perfect, and everyone knows it,” said David Baggett, Kaseya’s SVP and general manager for Security Suite. “Expect mistakes, account for constraints and engineer around them.”
People also shaped recovery. Among organizations that recovered within two hours, 35% credited a well-trained internal IT or security team. Among those that recovered more slowly than expected, 19% blamed manual or complex recovery processes. Another 17% cited dependence on third-party vendors.
Compliance Audit Confidence Runs Ahead Of The Evidence
Sixty-five percent say they could pass a compliance audit today with no preparation. Asked what could cause problems, 49% named incomplete documentation or policies. Thirty-four percent cited security controls that are not fully implemented.
Kaseya calls an audit “a point-in-time test.” Compliance means keeping controls, documentation, and employee practices current, the report says.
Underwriting faces the same limit. A proposal form only knows what the insured declares, on the day the applicant fills it in. Cyber Tzar’s Andrew Horkan explored that gap on the CINI podcast. The episode title sums it up: Compliant In May. Seventeen Thousand Open Ports In June.
Boards rely on audits as well. PwC found that CEOs and board members rank compliance audits and control effectiveness first among cyber metrics, at 50%.
Get The Cyber Insurance News Upload Delivered
Subscribe to our weekly newsletter!
MSP Cybersecurity: What High Performers Do Differently
Kaseya also released an MSP resilience assessment with the report. It separates high and low performers by whether they met revenue and growth goals over the last two quarters.
High performers treat compliance, cyber insurance, and AI adoption as competitive advantages, Kaseya said. The release did not include insurance figures from the assessment.
Fifteen percent of MSPs have no incident response plan, according to Kaseya. That share falls to 11% among high performers and rises to 25% among low performers. Almost 30% of high performers test clients’ incident response plans quarterly, compared with 18% of low performers.
FAQ – Cyber Insurance Requirements
What is Kaseya’s 2026 Cybersecurity Report?
A survey of 1,132 managed service providers and in-house IT professionals in 63 countries and territories, conducted in August 2026. MSPs made up 55 percent of respondents.
Which security control creates the most friction?
Multifactor authentication. 36 percent of respondents named MFA as the practice that creates the most operational friction. Privileged access management came second at 18 percent.
Do cyber insurance requirements drive security spending?
About as often as attacks do. 20 percent of MSPs named compliance or cyber insurance requirements as the main driver of client investment. Another 20 percent named a recent incident or near miss. Kaseya grouped compliance and insurance into one answer.
What is the top threat concern?
Human error, including social engineering and distraction, named by 68 percent. Email followed at 55 percent.
Are organizations ready for compliance audits?
65 percent say they could pass an audit with no preparation. Yet 49 percent named incomplete documentation or policies as their biggest audit risk.
How many MSPs lack an incident response plan?
15 percent, according to Kaseya. The share is 11 percent among high-performing MSPs and 25 percent among low performers.
Related Cyber Insurance Posts
- Recovery And Insurability: How Boards Judge Cyber Strategy, PwC Finds
- CISO: AI Risk Reshapes Cybersecurity Strategy In Retail And Hospitality(Opens in a new browser tab)
- Top Strategies for Identity Verification in the Age of Deepfakes, Remote Work, and AI Threats(Opens in a new browser tab)
- Move Fast Get Phished(Opens in a new browser tab)
- How Rising Cybersecurity Spending Powers Defense and Tech Stocks(Opens in a new browser tab)