What Your Cyber Insurance Renewal Will Actually Ask You

Team Neuron·
A cluttered desk in a small manufacturing office, late afternoon light through venetian blinds, a thick stapled insurance questionnaire open next to a cold cup of coffee and a desk phone.

Your broker forwards the renewal questionnaire in August. Three years ago it was a single page. You ticked a few boxes, signed it, and the policy renewed at roughly last year's price.

This year it is fourteen pages. The questions are specific. Several of them ask for evidence, not answers. And somewhere around question nine you realize you genuinely do not know what the true answer is.

That is not a sign you have been careless. It is a sign the market changed underneath you.

Why the questionnaire got harder

Insurers spent several years paying out far more on cyber claims than they expected. They responded the way insurers always do. They did not stop writing policies. They got specific about what they would insure.

The result is that the questionnaire is no longer a formality attached to the invoice. It is now the underwriting. Your answers determine your premium, what gets excluded, and in some cases whether you get an offer at all.

There is a second, sharper consequence. The form is a legal document. If you attest that something is in place and it turns out not to be, that can become the reason a future claim is reduced or denied. The worst possible outcome is not a higher premium. It is paying premiums for two years and then finding out your coverage did not apply.

What they are actually asking about

The wording varies by carrier, but the subject matter has converged. Nearly every renewal packet now works through the same territory.

  • Sign-in protection on every account. Specifically MFA (the second code you enter after your password, usually from an app on your phone). Not just on email. On remote access, on your finance systems, and on the administrator accounts that can change everything else.
  • What is installed on your computers and servers to catch an attack in progress. And whether anyone is actually watching what it reports, including overnight and at weekends.
  • Backups, and whether you have restored from them. Not whether backups run. Whether somebody has taken a backup and successfully put the data back, and on what date.
  • Whether backups can be deleted by someone who breaks in. If your backup lives on the same network with the same passwords, an attacker gets both.
  • Who has administrator rights. Carriers have noticed that in smaller companies, quite often, everyone does.
  • How quickly security updates get installed, and who confirms they actually applied.
  • Whether staff get any training, and whether you have ever tested them with a fake phishing email.
  • Whether you have a written plan for the first twenty-four hours after something goes wrong, including who you call.

None of this is exotic. That is rather the point. The list is short and the items are ordinary, which is exactly why carriers feel comfortable making them conditions.

"Mostly" is the wrong answer

The single most expensive habit we see is answering from memory and rounding up.

Somebody asks whether sign-in protection is on for everyone. The honest internal answer is usually "it's on for email, and I think it's on for the remote access, and there are a couple of service accounts nobody wanted to touch because something broke last time." The answer that gets written on the form is "yes."

That gap is where claims get denied.

The same happens with backups. "We have backups" is true almost everywhere. "We restored a full server from backup on the 14th of last month and it took four hours" is a different statement, and it is the one the form is really asking for.

Carriers increasingly want the evidence alongside the answer. A screenshot of the setting. A report showing which machines are covered. A dated restore test. If you cannot produce those, the safe answer is the accurate one, even when it is worse.

What good looks like

A business that finds renewal season boring has four things.

Someone owns the form. One named person gathers the answers, and they start sixty days before the renewal date rather than four days before.

Every answer traces to a report, not a memory. When the form asks how many computers have protection installed, the answer comes from a list you can print, and the number matches the number of employees.

The gaps are known in advance. You are not discovering in August that two-thirds of your machines are running an operating system the carrier will ask about. You knew in March, and either fixed it or planned for the question.

Nothing on the form is aspirational. Every yes is a yes today. Where something is genuinely in progress, it is described as in progress, with a date.

That last one feels like it costs you money. It does, slightly, in premium. It is also the only version where the policy reliably pays.

What to do before your renewal date

Find the date first. Most people are vaguer about it than they expect. Then work backwards sixty days.

Get last year's completed questionnaire out and read your own answers. You will usually find one or two that were optimistic, and those are the ones to deal with first.

Then get an honest inventory in front of you: what computers and servers exist, what is running on them, who has administrative access, and when a restore was last tested successfully. If producing that takes more than a day, that is itself the finding.

Fix what is cheap and fast. Sign-in protection and administrator rights cleanup are usually days of work, not months, and they move the needle more than anything else on the form.

For the rest, decide deliberately. Some gaps are worth closing before renewal. Some are worth disclosing and living with for a year. Both are defensible. Guessing is not.

If you would rather not find out in August

We do this with clients as a matter of course, and we do it for companies that are not clients yet as part of a free IT assessment. You end up with the inventory, the honest answers, and a short list of what would actually change your position before the renewal date.

It takes about two weeks and under four hours of your time. Whether you hand the results to us, to your current provider, or to your broker is entirely up to you.