Business Continuity
How To Answer Cyber Insurance Renewal Questions Without Voiding Your Policy
If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled in last time. It is also more specific. Incidents from 2023 and 2024 have left lasting effects on insurance carriers, causing new questions to map directly to preventative controls.
The most expensive mistake on these forms is misrepresentation, an answer that overstates the controls you actually have in place. If a forensic investigation after a claim finds your environment did not match what you declared, the carrier can rescind the policy and void coverage retroactively, including any prior payouts under the same policy term.
Misrepresentation does not just void a claim. It can void the entire policy term, including payouts already made.
Why the Application Got Longer
Three specific events shaped the current generation of applications, and each drove new sections onto renewal forms.
MOVEit supply-chain breach
Ultimately affected more than 2,650 organizations and 66 million individuals, pushing carriers to add a dedicated vendor-risk section to the application.
Change Healthcare ransomware incident
Froze US healthcare claims processing for weeks. The absence of MFA on a key entry point made the initial intrusion possible, with an estimated insurance loss exceeding $250 million.
Arup deepfake wire fraud
An employee transferred $25.6 million after a video call with AI-generated executives, prompting carriers to add callback verification requirements.
The Backup Question
What used to be a single yes or no question now asks whether your backups are immutable or air gapped, when they were last tested, and whether they can be deleted using your domain administrator credentials. “We use Microsoft 365, so we’re backed up” no longer holds up its own. The stronger answer is object lock enabled, an immutability window of at least 14 days, credentials separated from production admin accounts, and a documented restore test within the past 12 months. Most carriers now ask for that restore test data specifically. A backup nobody has tried to restore in the past year is not something you can rely on when it matters.
MFA Questions Go Deeper Than One Checkbox
Current applications ask whether MFA is enforced on email, VPN, remote desktop, all administrator accounts, and privileged service accounts, and the answer needs to be yes across the board for a clean pass. SMS is now treated as a weaker control, with carriers asking specifically whether you use an authenticator app, hardware token, or push with number matching instead. If you don’t have a privileged access management tool in place, declare it with a remediation timeline. A vague “MFA is enabled” invited more questions than it answers.
Wire Transfer and Deepfake Verification
After the Arup case, carriers added the callback verification requirements to applications, asking whether your organization requires out-of-band verification, calling the requestor at a number already on file rather than the one in the email, for any wire transfer above a defined threshold. A strong answer references a written policy, a defined threshold, dual approval, and annual training that includes deepfake awareness. Wire transfers authorized by email alone are now the configurations carriers are declining to cover.
“We always call to verify” is not the same as a written wire transfer policy with a defined threshold and dual approval.
Endpoint Detection and the End of 'We Have Antivirus'
Traditional antivirus checks files against a list of known threats. Endpoint Detection and Response watches behavior instead, a process trying to encrypt files, an account escalating its own privileges, a new service installed at 2am. Applications now ask whether EDR covers 100% of endpoints including servers, and whether a 24/7 SOC monitors and responds to alerts. Planning to add MDR? Say so with a timeline. Underwriters can work with a deployment schedule, but “we have antivirus” no longer answers the question being asked.
The Vendor Risk Section
Post-MOVEit, carriers now ask you to identify your top software vendors with access to sensitive data and confirm whether each provides a SOC 2 Type II report. You aren’t expected to audit every vendor in detail. An honest partial answer, five vendors identified with three reports received and two outstanding, reads better than a confident yes that can’t be sustained if documentation is requested.
The 30-Day Pre-Renewal Checklist
Weeks 1-2
- Confirm MFA everywhere, move admin off SMS
- Run and document a test restore
- Draft a signed wire transfer policy
Weeks 3-4
- Confirm EDR coverage or get MDR quotes
- Request SOC 2 reports from top vendors
- Run a 60-minute tabletop, keep the notes
If your current setup isn’t perfect, don’t fret. Managing a deployment plan and keeping an updated roadmap lets you check “in progress” for items you can’t yet resolve but are working toward.
A known gap with a plan is manageable. A misrepresentation discovered after a claim is not.
Cleartech Group helps businesses in Leominster, Worcester, and Greater Boston verify their security posture before they submit cyber insurance paperwork. If your renewal is coming up in Q3 or Q4, let’s talk before you sign.
Article adapted from The Technology Press.