What Your Cyber Insurance Renewal Is Actually Asking For
The cyber insurance renewal questionnaire is the most consequential form most small businesses fill out all year. It usually gets completed in a hurry, by whoever has the login.
The questions are no longer a formality. Underwriters use them to decide whether to offer you a policy at all. The bigger issue is that your answers become part of your record. If you attest to a control you do not actually have, and a claim later turns on that control, you have handed the insurer a clean reason to reduce or deny it.
Here is what the 2026 questionnaires are really asking, and what “yes” has to mean before you write it.
“Do you enforce multi-factor authentication?”
This is the question that decides most applications. Enforced MFA has become a near-universal precondition for coverage. The vast majority of carriers will not write or renew a small business policy without it.
The load-bearing word is enforced. MFA that is available, encouraged, or turned on for most people does not satisfy an underwriter. They mean a user cannot authenticate without a second factor, because the system will not let them.
Coverage is typically expected across:
- Email, including Microsoft 365 and Google Workspace
- VPN and any remote access
- Every administrator and privileged account
- Cloud infrastructure consoles
The thing that usually breaks a clean answer is an exception somebody made. A leader who found MFA annoying, a service account nobody wanted to break, a legacy protocol left enabled “temporarily.” Each of those makes a truthful “yes” impossible, and each is exactly the account an attacker looks for.
Before you answer, have someone confirm there is a conditional access policy, or the equivalent, that requires MFA. Then ask for the list of exclusions. If that list is not empty, you either fix it or you answer honestly.
“Do you have endpoint detection and response deployed?”
Basic antivirus no longer counts. Underwriters draw a line between signature-based antivirus and EDR, which watches behavior, catches activity that has no known signature, and can isolate a machine on its own.
Answering “yes” because you have the antivirus that shipped with the operating system looks fine right up until someone examines it during a claim.
Underwriters expect EDR on every in-scope device, and 100% of servers. Where a machine genuinely cannot run an agent, it belongs on a written exception register, with a reason and a remediation date, rather than quietly rounded off the count. All of that assumes a current inventory of what you own. A surprising number of businesses cannot produce one, and “we think it is on everything” is not evidence.
“Are backups tested, encrypted, and isolated?”
Three separate claims in one question, and most businesses can honestly say yes to only one or two.
Tested means someone actually ran a restore and confirmed the data came back usable. A backup job reporting success is a different thing entirely. Backup software reports success on backups that cannot be restored.
Encrypted means at rest and in transit.
Isolated means an attacker who gains domain administrator rights cannot reach and delete them. This is the one that catches people. Backups sitting on a network share that a compromised admin account can reach are not isolated, and modern ransomware deliberately hunts them before it encrypts anything.
Insurers now commonly want the date of your most recent restore test, which systems were tested, and the recovery time achieved. If you cannot produce those, you have not really answered the question.
“Do you provide security awareness training?”
This one is straightforward, and usually cheap to fix. Underwriters want training that is regular and documented. A one-off onboarding video from three years ago does not clear the bar. Simulated phishing with tracked results satisfies most questionnaires.
The question underneath all the questions
The list of required controls is the familiar part. What has shifted in recent renewal cycles is that insurers increasingly want proof the control was actually operating at the moment of the loss, rather than proof it was purchased.
That changes what you are doing when you fill out the form. You are assembling evidence, and evidence gets generated over the course of the year rather than in the week before renewal.
In practice, that means keeping:
- A screenshot or export of your MFA enforcement policy, with the exception list
- An endpoint report showing EDR coverage against your device inventory
- Restore test records with dates, systems, and outcomes
- Training completion records
- Dated evidence rather than “we have always done this”
Do not answer optimistically
Overstating a control is the most expensive mistake available on this form.
Every answer you give is a written representation the insurer relied on when it priced your risk. If a claim turns on a control you claimed and did not have, you may find yourself uninsured at the exact moment you need coverage most, having paid premiums the whole time.
If the honest answer is no, the honest answer is no. A policy priced on accurate information is worth more than a better-looking application.
Give yourself 30 to 60 days
Most of these controls cannot be put in place the week the renewal is due. Enforcing MFA across an organization takes communication and a few genuinely annoying conversations. Deploying EDR takes scheduling. Running a real restore test takes planning.
Start 30 to 60 days out. Work the questionnaire in order, gather the evidence as you go, and treat any answer you cannot substantiate as a project rather than a wording problem.
Where this connects to the rest of your security work
Nearly everything on a cyber insurance questionnaire is something you would want in place even if you never bought a policy. MFA, EDR, tested backups, and trained staff are the short list of controls that actually prevent the incidents insurers are pricing.
The questionnaire is just the first time somebody with financial leverage asks you to prove it.
If you are staring at a renewal and are not sure which answers you can defend, our virtual CISO work is built for this kind of gap-and-evidence problem, and we are happy to look at the questionnaire with you. If we find you are already in good shape, that is a fine outcome too.
If you are an insurance agency yourself, rather than only a buyer of the cover, the same evidence does double duty. It answers your own renewal, and it speaks to the written information security program Ohio expects of a licensee. What we do for Ohio insurance agencies covers where those overlap.
On sources, and what this article is not
There are no percentages in this article, on purpose. Statistics about “what share of carriers require X” circulate widely in vendor marketing and are almost never traceable to a carrier’s own underwriting guidance. We would rather describe the direction of the market than quote a number we cannot stand behind.
For the controls themselves, these are the authorities worth reading:
- CISA guidance on multi-factor authentication
- NIST Cybersecurity Framework
- #StopRansomware Guide, which covers the backup and recovery expectations underwriters are effectively testing
This article describes general market practice and is not insurance advice. Underwriting requirements vary by carrier, by industry, and by year. Your policy and your broker are the authority on what your specific coverage requires. If a control on your application is ambiguous, ask them rather than guessing.