The Renewal Form Has Changed
A few years ago, buying cyber insurance was a short conversation with your broker. Today the proposal form can run to several pages of technical questions: Do you enforce MFA on all remote access? Are your backups segregated from your network? Do you run endpoint detection and response?
Insurers have paid out heavily on ransomware and fraud claims, and they’ve responded by pricing risk far more carefully. For businesses, that means two things: security controls now directly affect your premium, and the answers you give on that form matter more than ever.
What Insurers Typically Ask For
Every insurer’s wording differs, but the same core controls come up again and again:
- Multi-factor authentication on email, remote access and admin accounts. This is often a hard requirement, not a nice-to-have.
- Backups kept separate from your main network, ideally offline or immutable, and tested.
- Endpoint detection and response (EDR) rather than basic antivirus alone.
- Regular patching, especially of internet-facing systems like firewalls and VPNs.
- Security awareness training so staff can spot phishing and invoice fraud.
- Limited admin rights, so everyday accounts can’t install software or change settings.
- An incident response plan: who does what in the first hours of an attack.
The Real Risk: A Refused Claim
The most painful scenario isn’t a higher premium. It’s a claim being reduced or declined because the business said “yes” to a control that wasn’t actually in place.
This happens more easily than you’d think. The person filling in the form ticks “MFA on all accounts” in good faith, not knowing that two older mailboxes and the accounts software were never included. After an incident, the insurer’s forensic investigators will check. If the gap contributed to the breach, you may have a difficult conversation ahead.
Answer the form with your IT provider, not from memory. If the honest answer is “partly”, say so. Then fix the gap before renewal.
What Cyber Insurance Does and Doesn’t Do
A good policy can cover incident response specialists, legal advice, data breach notification costs, business interruption and, depending on the policy, some fraud losses. That support in the first 48 hours after an attack can be invaluable.
What it doesn’t do is prevent the incident. Downtime, disruption, and the loss of trust from customers and staff aren’t fully insurable. Insurance works best as the last layer, on top of solid controls, not as a substitute for them.
Before Your Next Renewal
- Get the proposal form early, a few weeks before renewal, not the day before
- Go through each question with whoever manages your IT and confirm the true answer
- Close the quick wins first: MFA gaps and backup segregation are usually the fastest to fix
- Keep evidence: screenshots or reports showing controls are in place
- Read the exclusions, especially around social engineering and payment fraud
If your renewal questionnaire is sitting in an inbox, send it over. We’ll go through it with you line by line and tell you honestly which answers are “yes”, which are “not yet”, and what it would take to close the gaps.