Cyber insurance used to be a form you filled in once a year and largely forgot about. That is no longer true, and the change has been quick enough that a lot of businesses are meeting it for the first time at renewal.
The short version: the controls that used to earn you a discount are now the controls that decide whether you are offered a policy at all.
Insurers paid out heavily on ransomware and business email compromise, and they responded the way insurers do, by underwriting the risk properly instead of pricing it loosely. The questionnaire got longer, the questions got more specific, and the answers started carrying consequences.
The practical effect is that your renewal application is now a security audit with a policy attached. It is worth treating it as one.
The specifics vary by carrier, but the same themes come up almost everywhere.
Not "do you have MFA" but where. Email, remote access, VPN, administrative accounts, and increasingly any remote access to systems holding sensitive data. Partial coverage is a common failure point. A business enables MFA on Microsoft 365, answers yes, and has not covered the VPN or the legacy remote desktop connection that is actually the exposed route.
Traditional antivirus and EDR are not the same product and insurers know the difference. Expect to be asked which you run, on what percentage of machines, and whether anyone is watching the alerts it produces. That last part matters. An EDR nobody monitors is a subscription, not a control.
The questions here have become notably sharper: are backups isolated from the network they protect, are they immutable, and when did you last restore from one. A backup that has never been restored is a hypothesis.
How quickly critical patches get applied, and whether you are running operating systems that still receive security updates. This is where a room full of Windows 10 machines becomes an insurance question rather than an IT one.
Filtering, protections against spoofing your own domain, and whether staff receive security awareness training on a schedule.
An application is a set of representations. If you state that MFA is enforced on all remote access, and a claim later shows an account without it was the way in, you have a coverage dispute at the worst possible moment: after an incident, while you are trying to recover.
This is not a hypothetical risk and it is not the carrier being unreasonable. It is how the contract works.
The right instinct on a renewal form is the opposite of the sales instinct. Answer precisely, note the exceptions, and where something is partially in place, say so. A carrier can price a known gap. It cannot forgive one you told them was covered.
The useful move is to work the questionnaire sixty to ninety days early rather than the week it is due.
Cyber insurance is worth carrying, and the underwriting pressure has quietly done the industry a favor by making basic controls non-optional. But a policy is a way to survive the financial consequences of an incident. It is not a way to avoid one, and it does not restore your data, your clients' confidence, or the two weeks you spend recovering.
The controls are the point. The policy is what covers you when they are not enough.
We are not insurance brokers and we do not advise on policies or limits. That is your broker's job. What we do is make the answers on the form true, and give you a clear picture of what is actually in place before you sign anything.
If a renewal is coming up and you are not confident in the answers, book a discovery call and we will go through the questionnaire with you.