For years the cyber insurance renewal was a form. Somebody in finance forwarded it to somebody in IT, the boxes got ticked, and the policy renewed. That has changed, and the change is not that the questions got harder. It is that the answers now have to be proved.
Three answers decide whether you are covered
Carriers have converged on the same short list. Miss one of these and you are not looking at a higher premium, you are looking at a declined renewal:
Multi-factor authentication on everything that touches business data. Not just email. Remote access, VPN, cloud admin consoles, banking, your line-of-business system. Underwriters increasingly want phishing-resistant methods instead of codes over SMS.
Endpoint detection and response on every endpoint and every server. Legacy antivirus does not satisfy this, and a growing number of carriers want to know that somebody is watching the alerts around the clock instead of reading them on Monday.
Immutable, isolated backups that have been restored from. The important word is restored. A backup job with a green tick is not evidence that the data comes back.
None of that is unreasonable. It is roughly the list of things that decide whether a ransomware incident is a bad week or a closure.
The part that catches people out
The shift for this renewal season is evidentiary. Carriers are asking for the reports behind the answers: a console export showing MFA coverage, an EDR deployment report showing every machine, a log from a restore test with the date on it, a written incident response plan, and a note of when you last walked through it.
This creates a trap that did not exist when the form was self-reported. If you tick yes to a control you cannot evidence, and you later have a claim, the carrier has grounds to argue the policy was written on a misrepresentation. A no on the form costs you money at renewal. A yes you cannot back up can cost you the claim, which is the entire reason you bought the policy.
If you are not certain about an answer, that uncertainty is the finding. It is worth more attention than the premium.
What “tested backups” means
This is the one we see fail most often, because it looks done.
A tested backup means somebody picked a real file and a real server, restored them somewhere isolated, confirmed the data was intact and usable, wrote down the date, and can produce that note. Monthly is a reasonable rhythm for most organizations. Quarterly is defensible. Never, which is the honest answer in a lot of buildings, is not.
The failure mode is quiet. Backups run for two years, the job reports success every night, and nobody discovers that a database was being backed up in a state it cannot be recovered from until the morning they need it.
What to do before the form arrives
Start the paperwork ninety days out, because assembling evidence takes longer than answering questions and some of it needs a change first.
Pull your MFA report and look for the accounts that are exempt, because there are always some. Pull the endpoint list and compare it to the asset list, since the gap is usually servers and the machines of people who left. Run a restore test and write the date down. Find your incident response plan, and if you cannot find it, that is your answer.
Districts, agencies and nonprofits are in this too. Cyber cover is increasingly a condition of grants, of contracts and of board policy, and the underwriting does not get gentler because you are not a business.
If you would like a hand working out what your current setup can evidence, we will go through the questionnaire with you. We would rather you found the gaps now than at a claim, and that is true whether or not we end up closing them for you.
Sources: carrier underwriting requirements for 2026 renewals, as reported across the cyber insurance market.