What your cyber insurance renewal will ask this year
The renewal questionnaire got longer again. Here is what carriers are really asking, in plain English, and how to answer yes with evidence instead of hope.
If your cyber insurance renewal landed on your desk and the questionnaire looks longer than last year, you are not imagining it. Carriers paid out heavily over the past few years, and the questions are how they decide whether your business is a good bet.
The good news: the list is predictable. Most renewals for a small business come down to the same handful of questions, and none of them require an IT department to answer well.
The questions that decide your premium
Do you use multi-factor authentication? This is the big one. Carriers want a second step at sign-in, the code or the app prompt, on email, on remote access, and on anything an administrator uses. Most carriers now treat this as a requirement rather than a bonus, and answering no can mean a declined renewal, not just a higher price.
Do you have backups, and have you tested them? Two different questions. Plenty of businesses back up faithfully and have never once tried to restore. A backup you have never restored is a hope, not a plan. Carriers increasingly ask for the date of your last restore test.
What is running on your computers? They are asking whether machines get security updates, whether anything in the office has aged out of support, and whether some form of endpoint protection is watching for trouble.
Who can get into what? Shared logins, former employees whose accounts still work, and everyone-is-an-admin setups all show up in claims data. Expect a question about how access is granted and, more importantly, how it is removed.
What happens to a suspicious email? Filtering, a way for staff to report the ones that get through, and a habit of never wiring money on the strength of an email alone.
Answering yes with evidence
There is a difference between checking yes and being able to show it. If a claim ever gets filed, the carrier compares what happened to what you attested. A yes you cannot back up is the expensive kind.
Evidence does not need to be fancy. A screenshot of MFA enforced on the mail system. A note with the date of the last restore test and what came back. A one-page list of who holds admin access and why. An hour of collecting this before the renewal beats a week of arguing after a claim.
If the renewal is due and the answers are not ready
That is the situation we built our Cyber-Insurance Renewal Rescue for: a short, fixed-fee engagement that closes the gaps the questionnaire cares about and hands you the evidence file. If the renewal is not urgent, start smaller. Pick the MFA question and make it true this week.
Either way, do not guess on the form. If you want a second set of eyes on the questionnaire before you sign it, the first conversation is free.