Skip to content
0800 374 775

Your cyber insurance renewal is now a security audit

The proposal form used to be three questions. It is now a controls checklist, the answers are warranties, and the price is set by what you can evidence.

Cyber cover used to be straightforward to obtain and largely uninterrogated. That has changed. Insurers paid out enough claims to work out which controls actually correlate with loss, and they now underwrite on them.

Which means the renewal form is no longer administrative. It is a security assessment with pricing attached, and in some cases with cover attached.

What they ask about, and why

The questions cluster tightly, because a handful of controls do most of the work in preventing the claims insurers actually see.

Multi-factor authentication, specifically on remote access, email and privileged accounts. This is the one most likely to be a condition rather than a question.

Backup arrangements, with emphasis on whether a copy is offline or immutable and whether restores are tested. They are pricing your recovery time because that is what drives business interruption cost.

Endpoint detection, and whether it is monitored by anyone or simply installed.

Privileged access, how many administrators you have and whether their rights are standing or granted when needed.

Patching cadence, particularly on anything internet-facing.

Email filtering and payment verification process, because business email compromise is a very large share of claims and the control for it is procedural.

Staff awareness training, on a schedule rather than once at induction.

None of that is exotic. It is close to the same list a customer security questionnaire asks about, which is convenient: work done for one satisfies the other.

The part that carries real risk

Answers on a proposal form are representations, and depending on the wording they can be warranties. Overstating a control to get a better premium is a bad trade, because the moment it matters is the moment it will be examined.

The claim scenario is exactly the scenario in which an insurer checks whether MFA was actually enforced on all remote access, or whether it was enabled for most people with four exceptions nobody mentioned. Discovering a coverage argument during an incident, on top of the incident, is the worst position available.

Say what is true. “Not currently, planned by June” is an answer underwriters handle every day. A misrepresentation is not.

Using the renewal as leverage

There is an upside here, and it is worth taking.

The proposal form is a free, externally validated prioritisation of your security spend, produced by people with actuarial data on what goes wrong. Very few internal risk assessments are that well grounded.

Better still, it comes with a number attached. Improvements to the controls above usually move the premium or the excess, which means the security work has a quantifiable return in a language the board already speaks. That is a much easier business case than an abstract risk reduction argument.

So the sequence we would suggest: get the form early rather than at the deadline, answer it honestly, and treat every no as a candidate project. Then take the gaps, the premium impact and a remediation plan to the same meeting.

What we do with it

Readiness work for insurance is the same work as readiness for a customer questionnaire and largely the same as framework alignment. We would rather do it once, keep the evidence, and use it for all three.

If your renewal is in the next quarter and you are not confident the answers would survive scrutiny, that is a better problem to look at now than in the fortnight before it is due.

Next step

Recognise any of this? Let's talk.

We respond within one business day.