Blog

Your Cyber Insurance Renewal Is a Security Audit Now

Written by Axcede | Jul 14, 2026, 4:15:00 PM

Cyber insurance used to be a form you filled in once a year and largely forgot about. That is no longer true, and the change has been quick enough that a lot of businesses are meeting it for the first time at renewal.

The short version: the controls that used to earn you a discount are now the controls that decide whether you are offered a policy at all.

What changed

Insurers paid out heavily on ransomware and business email compromise, and they responded the way insurers do, by underwriting the risk properly instead of pricing it loosely. The questionnaire got longer, the questions got more specific, and the answers started carrying consequences.

The practical effect is that your renewal application is now a security audit with a policy attached. It is worth treating it as one.

What they ask about

The specifics vary by carrier, but the same themes come up almost everywhere.

Multi-factor authentication

Not "do you have MFA" but where. Email, remote access, VPN, administrative accounts, and increasingly any remote access to systems holding sensitive data. Partial coverage is a common failure point. A business enables MFA on Microsoft 365, answers yes, and has not covered the VPN or the legacy remote desktop connection that is actually the exposed route.

Endpoint detection and response

Traditional antivirus and EDR are not the same product and insurers know the difference. Expect to be asked which you run, on what percentage of machines, and whether anyone is watching the alerts it produces. That last part matters. An EDR nobody monitors is a subscription, not a control.

Backups, and whether you have tested them

The questions here have become notably sharper: are backups isolated from the network they protect, are they immutable, and when did you last restore from one. A backup that has never been restored is a hypothesis.

Patching and supported software

How quickly critical patches get applied, and whether you are running operating systems that still receive security updates. This is where a room full of Windows 10 machines becomes an insurance question rather than an IT one.

Email security and user training

Filtering, protections against spoofing your own domain, and whether staff receive security awareness training on a schedule.

The part that gets businesses into trouble

An application is a set of representations. If you state that MFA is enforced on all remote access, and a claim later shows an account without it was the way in, you have a coverage dispute at the worst possible moment: after an incident, while you are trying to recover.

This is not a hypothetical risk and it is not the carrier being unreasonable. It is how the contract works.

The right instinct on a renewal form is the opposite of the sales instinct. Answer precisely, note the exceptions, and where something is partially in place, say so. A carrier can price a known gap. It cannot forgive one you told them was covered.

Getting ahead of the renewal

The useful move is to work the questionnaire sixty to ninety days early rather than the week it is due.

  • Get last year's completed application. It tells you what you already claimed, which is the baseline you have to either meet or correct.
  • Verify each answer against the systems, not against memory. Where is MFA actually enforced? Which machines actually have EDR installed and reporting?
  • Close whatever closes cheaply. MFA on a remaining application, an unmonitored endpoint, a backup that has never been test-restored. Several of these cost effort rather than money.
  • Document what you cannot close, and why, and what compensates for it. A segmented legacy machine with no internet access is a defensible answer. An unsegmented one is not.
  • Answer the form honestly and let your broker work with accurate information.

A note on what insurance is for

Cyber insurance is worth carrying, and the underwriting pressure has quietly done the industry a favor by making basic controls non-optional. But a policy is a way to survive the financial consequences of an incident. It is not a way to avoid one, and it does not restore your data, your clients' confidence, or the two weeks you spend recovering.

The controls are the point. The policy is what covers you when they are not enough.

Where we come in

We are not insurance brokers and we do not advise on policies or limits. That is your broker's job. What we do is make the answers on the form true, and give you a clear picture of what is actually in place before you sign anything.

If a renewal is coming up and you are not confident in the answers, book a discovery call and we will go through the questionnaire with you.