What Your Cyber Insurance Renewal Is About to Ask You
- Asheville Computer Company
- 6 minutes ago
- 4 min read
The cyber insurance renewal packet arrives, someone opens it expecting a page of checkboxes, and instead finds three pages of technical questions. Do you enforce multi factor authentication on every account? Do you run endpoint detection and response? Are your backups offsite, and when did you last test a restore? Do you have a written incident response plan?
Most owners we talk to do not know the answers. That is not a failing. It does mean the questionnaire deserves more attention than it usually gets, because these forms have quietly become the most consequential technology document a small business signs all year.
Why the questions got harder
Insurers spent several years paying out on ransomware claims that were, in hindsight, preventable. The industry response was not to stop writing policies. It was to stop guessing. Carriers now underwrite on specific, verifiable controls, and businesses that have them get better coverage at better prices than businesses that do not.
The practical effect is that your insurance company has become a de facto security auditor. That is annoying if you are unprepared, and genuinely useful if you are, because it turns security from a vague good intention into a list you can actually work through.
What carriers are asking for now
The wording varies between carriers, but the same controls appear on nearly every application we see:
Multi factor authentication, actually enforced. Not available, not encouraged, enforced. Email, remote access, VPN, cloud applications, and especially administrator accounts. The distinction matters: an insurer asking whether MFA is required is asking a different question than whether MFA is possible, and the honest answers are often different.
Endpoint detection and response, not just antivirus. Traditional antivirus checks files against a list of known bad things. EDR and managed detection and response watch behavior, catch what the list misses, and let someone respond when something starts moving through your network at two in the morning. Many applications now name this explicitly.
Backups that are offsite, and tested. Two separate questions live inside this one. Do backups exist somewhere ransomware cannot reach, and has anyone confirmed they restore? Carriers ask because they have watched too many businesses discover the answer during an actual emergency.
Patching and supported systems. This is where a lot of otherwise healthy small businesses have a problem right now. Running critical work on an operating system that no longer receives security updates is exactly the condition underwriters ask about, and it connects directly to the Windows 10 deadline many offices are still working through.
Limited administrator rights. Do everyday users have the ability to install anything they want? Attackers love that answer to be yes.
Security awareness training and a written incident response plan. The training question is about your people. The plan question is simply whether anyone has written down who gets called, in what order, when something goes wrong at 4:45 on a Friday.
The part almost nobody thinks about
Unlike a survey, the application is a legal document, and your answers become part of the policy.
Claims get denied for reasons that are less exotic than people imagine. The most common ones are not clever coverage exclusions. They are gaps between what a business said on the form and what was actually true when the incident happened. MFA that was answered yes but had exceptions carved out for a few executives. Endpoint protection that was installed but had stopped reporting months earlier. Backups that existed and had never been restored. A system running software that had passed end of support before the claim was filed.
There is a version of this that is genuinely accidental, and it is the version we see most. Nobody lied. Someone answered the questionnaire in good faith, based on how things were set up two years ago, and the environment drifted. Then a claim gets investigated, and the investigation is thorough.
The lesson is not to be afraid of the form. It is that the application, your actual technology, and your documentation all need to tell the same story.

How to handle your next renewal
Ask for the questionnaire early. Weeks before the deadline, not the night before. It is very hard to fix a control while you are filling in the box that asks about it.
Answer it with whoever handles your IT in the room. Most of these questions are not business questions. If we manage your systems, we can answer them directly and tell you where you actually stand, which is more useful than a confident guess.
Fix the gaps before you sign, not after. Most of what carriers ask for is ordinary work. Turning on enforced MFA, moving from basic antivirus to managed detection, getting backups offsite and tested, retiring or upgrading unsupported machines. None of it is complicated, and doing it usually improves your premium as well as your odds.
Keep evidence. Screenshots of policy settings, backup test results, training completion records, and your written incident response plan. If you ever file a claim, that folder is what supports your answers.
Recheck annually. Environments drift. People leave, software changes, exceptions get made for convenience and never get removed. The renewal is a reasonable annual moment to confirm reality still matches the paperwork.
An honest note about what we can promise
We cannot promise a claim gets paid. Coverage questions belong to you, your agent, and your carrier, and the policy language is theirs, not ours. Anyone telling you their product guarantees a payout is overselling.
What we can do is make sure the answers on your application are true, and that they stay true. That is the part that lives in the technology, and it is squarely our job.
If your renewal is coming up and you are not sure how your business would answer these questions, we are glad to walk through the questionnaire with you and give you a straight assessment of where you stand. Asheville Computer Company helps businesses in Asheville, Arden, Fletcher, Hendersonville, and across Western North Carolina put these controls in place and keep them in place, so the form is a formality instead of a scramble.


