If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled in last time. It’s also more specific. Each new question maps to a control that, if missing, allowed a major 2023 or 2024 claim to escalate. How you answer the cyber insurance renewal form matters more than it used to — and the most expensive mistake is the answer that overstates the security controls you actually have in place.
This post covers why the cyber insurance renewal application got longer, what each new section is asking, how to answer honestly without overstating your controls, and what to fix in the 30 days before submission.
Why Your Cyber Insurance Renewal Application Got Longer
The current generation of cyber insurance renewal applications was shaped by three specific claim events from 2023 and 2024.
The MOVEit supply-chain breach surfaced on May 28, 2023, when Progress Software received the first reports of unusual activity. The Cl0p ransomware group had exploited a previously unknown vulnerability in MOVEit Transfer, a widely used file-sharing tool. By late 2023, more than 2,650 organizations and over 66 million individuals had been affected. Carriers paid claims across that footprint, and the experience reshaped how underwriters ask about third-party software risk.
The Change Healthcare ransomware incident in February 2024 froze US healthcare claims processing for weeks. The attacker gained network access on February 12, deployed ransomware on February 21, and the downstream impact reached pharmacies, providers, and patients across the country. The absence of multifactor authentication on a key entry point made the initial intrusion possible, and industry analysts estimated the cyber insurance loss from this single event at over $250 million. The response: tighter backup immutability questions and new incident response requirements.
The Arup deepfake wire fraud, also from early 2024, reframed how underwriters approach social engineering. A finance employee at the engineering firm’s Hong Kong office transferred $25.6 million across 15 wires after a video call with what appeared to be the company’s CFO and other executives — all of whom were AI-generated deepfakes. Out-of-band callback verification for wire transfers is now on every underwriter’s checklist.
If your Southeast Texas business handles cardholder data, protected health information, client funds, or escrow, your cyber insurance renewal application is the longest of all. You sit in the loss categories carriers got burned on.
The Backup Question on Your Cyber Insurance Renewal Changed
What used to be a single yes/no backup question now asks whether those backups are immutable or air-gapped, when they were last tested, and whether they can be deleted by your domain administrator credentials.
Expect wording like: “Are backups stored in an immutable or air-gapped state, tested for restoration within the past 12 months, and inaccessible to domain administrator credentials?”
An immutable backup is one that nobody can delete or alter during a fixed retention window — including someone using stolen administrator credentials. CISA’s Stop Ransomware guidance lists immutable, tested backups as a baseline control, which is the same standard most cyber insurance carriers now apply.
“Microsoft 365 backup” is no longer a passing answer on its own. Native Microsoft 365 retention isn’t a backup in the sense the carrier means — it can be bypassed by a compromised global admin. Third-party backups sharing the same identity perimeter as your production tenant carry the same risk.
For the immutable backup question on your cyber insurance renewal, the strongest answer references a backup platform with object lock or write-once-read-many storage enabled, an immutability window of at least 14 days (with 30 days now preferred), credentials separated from your production admin accounts, and a recent successful restore test. Answers that leave the immutability question unclear are the ones most likely to push a renewal toward sub-limits or non-renewal.
MFA Questions Go Deeper Than One Checkbox
MFA was once captured as a single yes/no on most cyber insurance renewal forms. The current generation asks whether MFA is enforced on email, VPN, remote desktop, all administrator accounts, and privileged service accounts. All five need to be yes for a clean pass.
SMS-based MFA is now treated as a weaker control. SIM-swap attacks and SS7 vulnerabilities have made text codes the weakest authentication factor available. Several carriers ask specifically whether your MFA uses an authenticator app, hardware token, or push with number matching rather than SMS. If you’re still on SMS for admin accounts, expect a follow-up question or a premium adjustment on your cyber insurance renewal.
The privileged access management (PAM) question is the one most Southeast Texas business owners haven’t seen before. PAM platforms vault administrator credentials, rotate them on use, and log every session — which means a stolen admin password can’t be used unnoticed for weeks. A strong PAM answer describes a vaulting tool with credentials rotated on use and session logging enabled. Shared admin accounts that never rotate and produce no audit log are the configuration most likely to result in sub-limits or non-renewal.
Wire Transfer and Deepfake Verification Questions
After the Arup case and a string of business email compromise losses, carriers added callback verification questions to their cyber insurance renewal forms. Callback verification means that before sending any wire above a defined threshold — commonly $10,000 or $25,000 — the person authorizing the transfer calls the recipient at a phone number previously verified and stored, not the number on the request email.
Expect wording like: “Does your organization require out-of-band verification using a previously known phone number for all funds transfer requests above [threshold], including requests appearing to come from executives?”
Several current applications now ask separately whether staff have been trained on AI voice cloning and deepfake video risks. Accounting firms, law firms with escrow or trust accounts, and real estate brokers will see this section scrutinized most carefully on their cyber insurance renewal.
A strong answer references a written wire transfer policy requiring callback verification to a verified number for transfers above a stated threshold, dual approval, and annual social engineering training that includes deepfake awareness. Wire transfers authorized by email approval alone are the configuration carriers are now declining to cover.
EDR, MDR, and the End of “We Have Antivirus”
Traditional antivirus scans files against a list of known threats. Endpoint Detection and Response (EDR) watches behavior on each device and flags suspicious activity — such as a process trying to encrypt files or escalate privileges. Managed Detection and Response (MDR) is EDR plus a 24/7 team watching the alerts and responding when something fires at 2am on a Sunday.
Current cyber insurance renewal applications ask whether you have EDR deployed, whether it covers 100% of endpoints including servers, and whether a 24/7 security operations center monitors and responds to alerts. The MDR question is increasingly yes or no, and the no answer has pricing consequences.
If you don’t have MDR yet but plan to add it, say so plainly with a timeline. Underwriters can work with “MDR deployment scheduled for Q3 with vendor selected.” They cannot work with vague answers about future plans.
Vendor Risk Questions
Supply chain questions used to be a single yes/no item on cyber insurance renewal forms. After MOVEit and Change Healthcare, carriers now want a full section on the software vendors holding your data.
Expect questions like: “List your top five software vendors with access to sensitive data and confirm whether each provides a SOC 2 Type II report or equivalent.”
You’re not expected to audit every vendor’s security program in detail. The carrier wants to see that you know who your top vendors are, what data they hold, and that you’ve asked the basic questions. An honest “we’ve identified our top five vendors and requested SOC 2 reports from three, with two outstanding” reads better than a confident answer that falls apart in discovery.
The Mistake to Avoid: Misrepresentation and Rescission
The most expensive answer on a cyber insurance renewal application is the one that overstates the security controls you have in place. Cyber insurance renewal applications are warranty documents. If a forensic investigation after a claim finds your environment didn’t match what you declared, the carrier can rescind the policy.
Rescission means the policy is treated as if it never existed, your claim is denied, and any prior payouts under the same policy term can be clawed back. Some courts have found that the carrier doesn’t need to prove a direct link between the misrepresentation and the loss — the misrepresentation itself is sufficient grounds.
The cleanup approach is direct: if a question asks about MFA on all admin accounts and you have a gap, declare the gap and include a remediation date. Carriers reward honest gaps with a plan more than they reward polished answers that don’t survive forensic review. Checking “no” or “in progress” may raise your premium. Misrepresentation discovered after a claim can void the policy entirely — and the timing means you absorb the full incident cost yourself.
The 30-Day Pre-Renewal Checklist
Work through this in order before your next cyber insurance renewal. Most items are achievable in a month if you start now.
- Week 1: Confirm MFA on email, VPN, remote desktop, all administrator accounts, and any service accounts that support it. Move admin MFA off SMS to an authenticator app or hardware token.
- Weeks 1–2: Verify your backups are immutable or air-gapped. Run a test restore and document the result with date and screenshots.
- Week 2: Write a one-page wire transfer policy requiring callback verification to a previously verified phone number for any transfer over your chosen threshold. Get it signed by anyone who can authorize payments.
- Weeks 2–3: Confirm EDR is deployed on every endpoint and server. If you only have traditional antivirus, get quotes for EDR or MDR now so you can answer with a deployment timeline.
- Week 3: Identify your top five software vendors and request SOC 2 reports or equivalent attestations. Note who responded.
- Weeks 3–4: Document or update your incident response plan, then run a 60-minute tabletop exercise with your leadership team. Keep the notes — that’s your “tested in the past 12 months” evidence.
- Week 4: Sit down with the cyber insurance renewal application and answer honestly. Flag anything you couldn’t fix, with a specific remediation date.
If you’d like help preparing your Southeast Texas business for your next cyber insurance renewal — reviewing controls, documenting your security posture, and making sure your answers are accurate — our managed IT services include pre-renewal security reviews. Schedule a free IT checkup to get started.
Frequently Asked Questions: Cyber Insurance Renewal
What does rescission mean on a cyber insurance policy? Rescission means the carrier voids the policy from inception after discovering material misrepresentation on the application. The policy is treated as if it never existed, the current claim is denied, and any prior payouts under the same policy term can be clawed back.
Will my cyber insurance renewal be denied if I don’t have MFA everywhere? Not always denied outright. Expect a significant premium increase, sub-limits on ransomware coverage, or exclusions for incidents tracing back to the unprotected entry point. The most common gap is MFA on privileged or service accounts.
What is the difference between EDR and MDR on a cyber insurance renewal application? EDR (Endpoint Detection and Response) is the technology that watches device behavior and flags suspicious activity. MDR (Managed Detection and Response) is the same technology plus a 24/7 team watching alerts and responding. Carriers increasingly want both, and the application often asks about each separately.
Why are cyber insurance renewal applications longer than they used to be? Carriers added detailed sections in response to specific 2023 and 2024 losses, including the MOVEit supply-chain breach, the Change Healthcare ransomware incident, and the Arup deepfake wire fraud. Each event drove changes to backup, MFA, vendor risk, or wire transfer questions on subsequent applications.
What does immutable backup mean on a cyber insurance renewal application? A backup that cannot be modified or deleted for a defined retention period, even by someone using stolen administrator credentials. Cloud object lock and write-once-read-many storage are common implementations. Most carriers want a window of at least 14 days, with 30 days now preferred.
Article used with permission from The Technology Press.
