What Your Cyber Insurance Renewal Is Actually Asking For
The cyber insurance renewal questionnaire is the most consequential form most small businesses fill out each year, and it is usually completed in a hurry by whoever has the login.
That is a problem, because the questions are no longer a formality. Underwriters use them to decide whether to offer you a policy at all, and — more importantly — the answers become part of your record. If you attest to a control you do not actually have, and a claim later depends on that control, you have handed the insurer a clean reason to reduce or deny it.
Here is what the 2026 questionnaires are really asking, and what “yes” needs to mean before you write it.
“Do you enforce multi-factor authentication?”
This is the question that decides most applications. Enforced MFA is now a near-universal precondition for coverage — the vast majority of carriers will not write or renew a small business policy without it.
The load-bearing word is enforced. MFA that is available, encouraged, or enabled for most people does not satisfy an underwriter. They mean: it is technically impossible for a user to authenticate without a second factor.
Coverage is typically expected across:
- Email, including Microsoft 365 and Google Workspace
- VPN and any remote access
- Every administrator and privileged account
- Cloud infrastructure consoles
The common failure is the exception. A leader who found MFA annoying, a service account nobody wanted to break, a legacy protocol left enabled “temporarily.” Each of those makes a truthful “yes” impossible, and each is exactly the account an attacker looks for.
Before you answer: have someone confirm there is a conditional access or equivalent policy that requires MFA, and get the list of exclusions. If the list is not empty, you either fix it or you answer honestly.
“Do you have endpoint detection and response deployed?”
Basic antivirus no longer counts. Underwriters distinguish between signature-based antivirus and EDR, which monitors behavior, detects activity that has no known signature, and can isolate a machine automatically.
Answering “yes” because you have the antivirus that shipped with the operating system is the kind of answer that looks fine until it is examined during a claim.
Underwriters expect EDR on every in-scope device, and 100% of servers. Where a machine genuinely cannot run an agent, it belongs on a written exception register with a reason and a remediation date — not quietly rounded away. That means you need a current inventory of what you own. A surprising number of businesses cannot produce one, and “we think it is on everything” is not evidence.
“Are backups tested, encrypted, and isolated?”
Three separate claims in one question, and most businesses can honestly say yes to only one or two.
Tested means someone has actually performed a restore and confirmed the data came back usable. Not that the backup job reported success. Backup software reports success on backups that cannot be restored.
Encrypted means at rest and in transit.
Isolated means an attacker who gains domain administrator rights cannot reach and delete them. This is the one that catches people. Backups sitting on a network share that a compromised admin account can reach are not isolated, and modern ransomware deliberately hunts them before encrypting anything.
Insurers now commonly want the date of your most recent restore test, which systems were tested, and the recovery time achieved. If you cannot produce those, you have not really answered the question.
“Do you provide security awareness training?”
Straightforward, and usually cheap to fix. What underwriters want is regular, documented training rather than a one-off onboarding video from three years ago. Simulated phishing with tracked results is the version that satisfies most questionnaires.
The question underneath all the questions
The significant shift in recent renewal cycles is not which controls are required. It is that insurers increasingly want proof the control was actually operating at the moment of the loss, not proof it was purchased.
That reframes the whole exercise. You are not assembling a shopping list. You are assembling evidence, and evidence has to be generated continuously rather than the week before renewal.
Practically, that means keeping:
- A screenshot or export of your MFA enforcement policy, with the exception list
- An endpoint report showing EDR coverage against your device inventory
- Restore test records with dates, systems, and outcomes
- Training completion records
- Dated evidence rather than “we have always done this”
Do not answer optimistically
This is worth saying plainly, because it is the most expensive mistake available on this form.
Overstating a control on an application is not a harmless rounding-up. It is a written representation the insurer relied on when pricing your risk. If a claim turns on a control you claimed and did not have, you may find yourself uninsured at the exact moment you need coverage most — and you will have paid premiums for the privilege.
If the honest answer is no, the honest answer is no. A policy priced on accurate information is worth more than a better-looking application.
Give yourself 30 to 60 days
Most of these controls cannot be implemented the week the renewal is due. Enforcing MFA across an organization requires communication and a few genuinely annoying conversations. Deploying EDR takes scheduling. Running a real restore test takes planning.
Start 30 to 60 days out. Work the questionnaire in order, gather the evidence as you go, and treat any answer you cannot substantiate as a project rather than a wording problem.
Where this connects to the rest of your security work
Nearly everything on a cyber insurance questionnaire is something you would want regardless of whether you were buying insurance. MFA, EDR, tested backups, and trained staff are not an insurance checklist. They are the short list of controls that actually prevent the incidents insurers are pricing.
The questionnaire is just the first time somebody with financial leverage asks you to prove it.
If you are staring at a renewal and are not certain which answers you can defend, our virtual CISO work exists for exactly this kind of gap-and-evidence problem, and we are happy to look at the questionnaire with you. If the honest finding is that you are in good shape, that is a fine outcome too.
On sources, and what this article is not
Deliberately, there are no percentages in this article. Statistics about “what share of carriers require X” circulate widely in vendor marketing and are almost never traceable to a carrier’s own underwriting guidance, so we have described the direction of the market rather than quote a number we cannot stand behind.
For the controls themselves, these are the authorities worth reading:
- CISA — multi-factor authentication
- NIST Cybersecurity Framework
- #StopRansomware Guide — for the backup and recovery expectations underwriters are effectively testing
This article describes general market practice and is not insurance advice. Underwriting requirements vary by carrier, by industry, and by year. Your policy and your broker are the authority on what your specific coverage requires — and if a control on your application is ambiguous, ask them rather than guessing.