How to Answer Cyber Insurance Renewal Questions Without Risking Your Policy

cyber-checklist

If your cyber insurance renewal is coming up, the application may look different this year. It is likely longer. It is also more specific.

That is not random. Each new question usually points to a control that was missing in a recent claim. When that control was missing, the loss got worse. Carriers paid for those losses. Then they changed how they ask about risk.

The result is a renewal form that asks sharper questions about backups, MFA, wire transfers, endpoint security, vendors, and incident response.

How you answer matters. A wrong answer can do more than raise your premium. If you say a control is in place and it is not, a future claim may be denied. This is called rescission. It means the carrier treats the policy as if it never existed.

The safer path is simple. Answer honestly. Fix what you can before you submit. For anything you cannot fix in time, explain the gap and give a clear date for remediation.

Why Cyber Insurance Applications Got Longer

Cyber insurance applications changed because claim patterns changed.

Three major events from 2023 and 2024 shaped many of the questions businesses now see on renewal forms.

The MOVEit supply-chain breach changed how carriers look at software vendor risk. According to Cybersecurity Dive’s MOVEit breach timeline, unusual activity was first reported in May 2023. The Cl0p ransomware group had exploited a previously unknown vulnerability in Progress Software’s MOVEit Transfer tool. By late 2023, more than 2,650 organizations and more than 66 million people had been affected. The impact kept growing into 2024.

The Change Healthcare ransomware incident in February 2024 pushed carriers to ask harder questions about MFA, backups, and incident response. HIPAA Journal’s coverage of major 2024 healthcare breaches noted that the incident disrupted healthcare claims processing and affected pharmacies, providers, and patients. The attacker gained access on February 12 and deployed ransomware on February 21. Coverage of the incident also noted that a key access point did not have multifactor authentication.

The Arup deepfake wire fraud case changed how carriers look at social engineering. Fortune reported on the Arup deepfake fraud, where a finance employee in the company’s Hong Kong office transferred $25.6 million across 15 wires after a video call with people who appeared to be company executives. They were AI-generated deepfakes. The fraud was not found for about a week.

After events like these, carriers want proof that common controls are in place. They also want cleaner answers.

If your business handles cardholder data, protected health information, client funds, escrow, or sensitive client records, expect the renewal form to be even more detailed. E-commerce, healthcare, accounting, law, and real estate all sit in areas where carriers have seen expensive losses.

The Backup Question Is More Specific Now

The old backup question was often simple. It asked whether you had backups.

That is no longer enough.

Many applications now ask whether your backups are immutable or air-gapped. They may ask when you last tested a restore. They may also ask whether domain administrator credentials can delete the backups.

You may see wording like this:

Are backups stored in an immutable or air-gapped state, tested for restoration within the past 12 months, and inaccessible to domain administrator credentials?

An immutable backup cannot be changed or deleted during a set retention period. That includes deletion by someone using stolen administrator credentials.

An air-gapped backup sits outside the reach of your production network. If ransomware spreads across your main environment, the backup is still separate.

This matches the direction of federal ransomware guidance. The CISA Stop Ransomware Guide lists tested backups as a key ransomware control, and carriers now look for similar proof during underwriting.

Carriers also expect more than “we have Microsoft 365 backup.” Native Microsoft 365 retention is not the same as a backup in the way most carriers mean it. A third-party backup can also fall short if it uses the same identity system as your production tenant. If a compromised global admin can delete it, the carrier may not treat it as strong protection.

A stronger answer names the backup platform, confirms object lock or write-once-read-many storage, lists an immutability window of at least 14 days, and notes a recent successful restore test. A 30-day immutability window is now preferred.

A weaker answer is daily backups to a NAS on the same network with no recent restore test. That may lead to follow-up questions, higher premiums, sub-limits, or non-renewal.

MFA Questions Now Go Beyond One Checkbox

MFA used to be one yes-or-no question. Current applications go deeper.

Carriers may ask whether MFA is enforced on email, VPN, remote desktop, all administrator accounts, and privileged service accounts. For a clean answer, the control needs to apply across all of those areas.

SMS-based MFA is also treated as weaker protection. Text codes can be exposed through SIM-swap attacks and other telecom risks. Many applications now ask whether you use an authenticator app, hardware token, or push notification with number matching.

If admin accounts still use SMS, expect follow-up questions or a price impact.

You may also see a question about privileged access management, often called PAM. This is new for many owners.

PAM tools protect administrator credentials. They keep privileged passwords out of regular password managers. They can vault credentials, rotate them after use, and log sessions. That makes it harder for a stolen admin password to be used for weeks without being noticed.

A strong answer says privileged credentials are vaulted, rotated on use, and logged. A weaker answer says admin passwords are stored in a shared password manager and rotated once a year. Shared admin accounts with no rotation and no audit log are the highest-risk answer.

Will cyber insurance always be denied without MFA everywhere? Not always. But you should expect higher premiums, ransomware sub-limits, or exclusions for incidents tied to an unprotected entry point.

Wire Transfer and Deepfake Questions Are Now Common

Business email compromise and deepfake fraud have changed the wire transfer section of many applications.

Carriers now want to know if you require out-of-band verification before sending money. That means the person approving a transfer must confirm the request through a separate channel.

For example, before sending a wire above a set amount, the employee calls the recipient using a phone number that was already verified and stored. They do not use the phone number in the request email.

You may see wording like this:

Does your organization require out-of-band verification using a previously known phone number for all funds transfer requests above a stated threshold, including requests that appear to come from executives?

Some applications now ask whether staff have been trained on AI voice cloning and deepfake video risks. The Arup deepfake wire fraud case made that question more important for professional services firms and any business that moves money.

Accounting firms, law firms with escrow or trust accounts, and real estate brokers should expect this section to get close review.

A strong answer includes a written wire transfer policy. It should require callback verification to a verified number for transfers above your chosen threshold. It should also require dual approval and annual social engineering training that includes deepfake awareness.

An informal practice is weaker. Email-only approval for wire transfers is the type of process carriers may decline to cover.

Antivirus Is No Longer Enough

Many applications no longer accept “we have antivirus” as a strong answer.

Traditional antivirus checks files against known threats. Endpoint Detection and Response, or EDR, watches behavior on each device. It can flag activity such as file encryption, privilege escalation, or suspicious processes.

Managed Detection and Response, or MDR, adds a 24/7 team. That team watches alerts and responds when something happens, even at 2 a.m. on a Sunday.

Current applications may ask whether EDR is deployed across all endpoints, including servers. They may also ask whether a 24/7 security operations center monitors and responds to alerts.

The MDR question is becoming more important. A “no” answer can affect pricing.

If you do not have MDR yet, do not pretend you do. State the truth and include a timeline if you are adding it. “MDR deployment scheduled for Q2 with vendor selected” is much stronger than a vague promise to improve security later.

Vendor Risk Questions Are More Detailed

Supply-chain risk is now a larger part of cyber insurance underwriting.

After events like MOVEit and Change Healthcare, carriers want to know which vendors hold your sensitive data. They also want to know whether those vendors can show basic security assurance.

You may be asked to list your top five software vendors with access to sensitive data. You may also be asked whether each vendor provides a SOC 2 Type II report or something similar.

You are not expected to audit every vendor in depth. But you should know who your top vendors are, what data they hold, and whether you have asked basic security questions.

An honest answer is better than an overconfident one. For example, you might say that you identified your top five vendors, requested SOC 2 reports from three, and are waiting on two responses.

That kind of answer shows progress. It is better than claiming everything is complete when you cannot prove it later.

The Mistake to Avoid: Misrepresentation

The most expensive mistake on a cyber insurance application is overstating your controls.

A cyber insurance application is not casual paperwork. It is a warranty document. If a forensic review after a claim finds that your environment did not match your answers, the carrier may rescind the policy.

Rescission means the policy is treated as if it never existed. Your claim can be denied. Prior payouts under the same policy term may also be clawed back.

In some cases, courts have found that the carrier does not need to prove the incorrect answer caused the loss. The misrepresentation itself may be enough.

This is why honest answers matter.

If the form asks whether MFA protects all admin accounts and one admin account is missing MFA, do not answer yes. State the gap. Add a date when it will be fixed.

A “no” or “in progress” answer may raise your premium or reduce coverage. That cost is known before the policy starts. A false “yes” can leave you without coverage when you need it most.

A 30-Day Cyber Insurance Renewal Checklist

If your renewal is due soon, start with the controls carriers are most likely to ask about.

Week 1: Confirm MFA Coverage

Check MFA on email, VPN, remote desktop, all administrator accounts, and any service accounts that support it. Move admin MFA away from SMS. Use an authenticator app, hardware token, or push with number matching where possible.

Weeks 1 and 2: Verify Backups

Confirm that backups are immutable or air-gapped. Run a test restore. Document the result with the date and screenshots. Make sure production administrator credentials cannot delete the backup.

Week 2: Write a Wire Transfer Policy

Create a one-page policy for wire transfers. Require callback verification to a previously verified phone number for any transfer above your chosen threshold. Require signatures from anyone who can authorize payments.

Weeks 2 and 3: Review Endpoint Protection

Confirm that EDR covers every endpoint and server. If you only have traditional antivirus, get quotes for EDR or MDR now. That allows you to answer with a real deployment timeline.

Week 3: Review Key Vendors

List your top five software vendors with access to sensitive data. Request SOC 2 reports or similar security attestations. Track who responded and who has not.

Weeks 3 and 4: Test Incident Response

Update your incident response plan. Then run a 60-minute tabletop exercise with your leadership team. Keep the notes. This gives you evidence that the plan was tested in the past 12 months.

Week 4: Answer the Application Carefully

Review the application with your IT provider. Answer honestly. For any control you could not fix, explain the gap and include a specific remediation date.

Frequently Asked Questions

What Does Rescission Mean on a Cyber Insurance Policy?

Rescission means the carrier voids the policy from the start after finding a material misrepresentation on the application. The policy is treated as if it never existed. The claim can be denied, and prior payouts under the same policy term may be clawed back.

Will My Cyber Insurance Be Denied if I Do Not Have MFA on Everything?

Not always. But you may see a significant premium increase, ransomware sub-limits, or exclusions for incidents that trace back to the unprotected access point. Common gaps include privileged accounts and service accounts.

What Is the Difference Between EDR and MDR?

EDR is the technology that watches device behavior and flags suspicious activity. MDR includes EDR plus a 24/7 team that monitors alerts and responds. Many applications now ask about both.

Why Are Cyber Insurance Applications Longer Than They Used to Be?

Carriers added detailed questions after major losses in 2023 and 2024, including MOVEit, Change Healthcare, and Arup. Those events drove more detailed questions about backups, MFA, vendor risk, wire transfers, and incident response.

Can My Claim Be Denied if I Answer the Application Incorrectly?

Yes. A material misrepresentation can trigger rescission. That can void coverage retroactively. In some cases, the carrier may not need to prove that the incorrect answer caused the specific loss.

What Does Immutable Backup Mean?

An immutable backup cannot be changed or deleted for a defined retention period, even by someone using stolen administrator credentials. Cloud object lock and write-once-read-many storage are common ways to do this. Many carriers want at least 14 days, with 30 days preferred.

Final Takeaway

Cyber insurance renewal forms are more detailed because claims have become more expensive and more specific. Carriers want proof that the controls tied to recent losses are in place.

Do not guess. Do not overstate. Do not answer “yes” because a control is planned.

Use the renewal process as a short security project. Confirm MFA. Test backups. Write the wire transfer policy. Review EDR or MDR. List key vendors. Test incident response. Then answer the application with care.

If the gap between your current controls and the application feels wider than 30 days, your IT provider should help you sort what can be fixed now and what needs a clear plan. Caldera Cybersecurity can help you review the application, close key gaps, and avoid answers that put coverage at risk.

Related articles

You may also be interested in

Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.

Headline

Never Miss A Story

Get our Weekly recap with the latest news, articles and resources.
Cookie policy
We use our own and third party cookies to allow us to understand how the site is used and to support our marketing campaigns.

Hot daily news right into your inbox.