Cyber Insurance Renewal: What Underwriters Ask in 2026

If your company carries cyber insurance, there is a questionnaire in your future. And if it has been a couple of years since you really read one, it is not the form you remember.

The early years of cyber coverage were loose. Policies were cheap, applications were short, and a business owner could tick a few boxes about antivirus software and get a quote back the same week. Then came a wave of ransomware claims that cost insurers far more than they had priced for, and the entire market tightened. Applications got longer. Questions got specific. And underwriters started asking for something they rarely asked for before, which is proof.

That shift matters more than the premium. A business can absorb a higher premium. What it cannot easily absorb is discovering, in the middle of an actual incident, that the coverage it thought it had is in dispute.

Here is what is on the form now, in plain language, and what to do about it if your renewal is coming up.

The Question Everything Else Hangs On

Multi-factor authentication. That is the second sign-in step, the code or the app prompt or the physical key, and it is the single control underwriters care about most.

The question used to be whether you had it. Now it is where you have it. Insurers want it on email, on remote access, on any cloud administration console, and on every administrator account, with no exceptions carved out for the owner or for the one employee who found it annoying. That last part is where businesses get into trouble, because the exceptions are usually made quietly and forgotten.

This is also where the honesty of your answer matters most. There is real legal precedent here. An insurer has gone to court to rescind a policy after determining the business had attested to multi-factor authentication that was not actually in place across the accounts in question. The policy existed. The premium had been paid. The coverage still ended up in litigation.

The takeaway is simple. Answer the questionnaire based on what is actually configured, not on what you intended to configure. If there are gaps, it is better to disclose them and pay a bit more than to attest to something that will not hold up when someone examines it after a breach.

Antivirus Is Not the Answer Anymore

The second question that stops applications is about endpoint protection.

Traditional antivirus looks for known bad files. Modern attacks often do not involve a file at all, or use tools already installed on the machine. So underwriters now ask about endpoint detection and response, usually shortened to EDR, and increasingly about whether someone is actually watching the alerts around the clock rather than letting them pile up in a dashboard nobody opens on a Saturday.

They also ask about coverage, meaning every laptop, every server, and yes, the machine in the back office that runs one old program and never gets touched. Unmanaged devices are a common reason an application gets kicked back.

They Will Ask About Backups. Then They Will Ask About Restores.

Almost every business says it has backups. Far fewer can say when they last successfully restored from one.

Underwriters have learned this distinction the hard way, because attackers learned it first. Modern ransomware operators go looking for backup systems before they encrypt anything, since a company that can restore is a company that will not pay. So the questions now cover whether backups are isolated from the main network, whether they can be altered or deleted once written, and whether you have actually tested a restore and documented the result.

If you take one thing from this article, make it this one. Test a restore. Put the date in writing. It is the single cheapest item on this list and it answers a question no promise can.

Patching, Training, and the Written Plan

Three more items appear on nearly every current application.

Patching, with a timeframe attached. “We update regularly” is not an answer anymore. Insurers want to know how quickly critical vulnerabilities get closed and how you know they did.

Security awareness training for staff, on a recurring basis rather than the one session everyone sat through in 2021. Phishing remains the way most incidents start, and the humans reading the email are the control being asked about.

A written incident response plan. Not a concept of a plan. A document that says who gets called, in what order, with which phone numbers, on a weekend. Some carriers now ask whether you have ever walked through it as a drill.

What Happens to Businesses That Cannot Answer

Three things, roughly, and only one of them is good.

Some applications get declined outright. Some come back with coverage but at a materially higher premium, or with lower limits, or with exclusions that quietly remove the part of the coverage the business most wanted. And some get approved on the strength of answers that will not survive scrutiny during a claim, which is the worst outcome of the three because it feels like success right up until it does not.

Businesses that can document their controls tend to see the opposite. Better pricing, cleaner terms, and a faster process, because the underwriter is not chasing them for evidence.

The Ninety Day Version

If your renewal is within a quarter, this is a reasonable order of operations.

Start by getting a copy of last year’s completed application. Read what your business attested to and check whether each answer is still true. Things drift. People leave, systems change, an exception gets made for a vendor and never gets removed.

Next, verify multi-factor authentication account by account rather than in principle. Ask specifically whether any accounts are excluded, and get the answer from a system report rather than from memory.

Then test a restore and write down what happened, including how long it took. Confirm every device has current endpoint protection, including the ones nobody thinks about. And if there is no written incident response plan, produce a one-page version this month. A single page with names and numbers beats an elaborate document that does not exist.

Finally, if something on the list cannot be fixed before renewal, tell your broker. A gap disclosed in advance is a pricing conversation. The same gap discovered after a claim is a coverage conversation, and those go very differently.

Where to Get Help

Most small businesses do not have someone in-house whose job is to answer these questions, which is why the questionnaire so often lands on the desk of an office manager or a finance lead at the worst possible moment. Many owners work through it with their IT provider, and a good one should be able to produce the underlying evidence rather than just an opinion.

Kenyatta Computer Services is a Denver-based managed IT and cybersecurity provider that works with small and mid-size businesses on exactly this kind of preparation, including the control documentation insurers now expect to see at renewal.

Whoever you work with, the goal is the same. Cyber insurance is worth having, and it is worth having in a form that pays out. The difference between those two things is usually a handful of controls and the paperwork proving they were switched on before anything went wrong.

- Advertisement -
- Advertisement -

Yonkers Rising August 14, 2026 PDF

https://yonkerstimes.com/yonkersaug14pq/

Westchester Rising August 7, 2026 PDF

https://yonkerstimes.com/westaug7pq/

Yonkers Rising August 7, 2026 PDF

https://yonkerstimes.com/yonkers-aug-7pq/

Level Up Casinos: Bonuses, Payments and the Curaçao Licensing Claim

This review of levelupcasinos.com cross-checks the headline claims against...

Hospice of Westchester Receives Donation from The Scarsdale Woman’s Club

L-R: Holly K. Benedict, Director of Development and Public Affairs,...
- Advertisement -
- Advertisement -

Related Articles