|
Getting your Trinity Audio player ready...
|

If your cyber insurance policy is up for renewal, don’t expect the application to look like it did a few years ago. Insurance carriers have significantly expanded their questionnaires, asking more detailed questions about your cybersecurity controls, backup strategy, vendor management, and employee security practices.
These changes aren’t just paperwork, they’re the result of millions of dollars in cyber insurance claims paid after major ransomware attacks, supply chain breaches, and AI-driven fraud incidents. Today, insurers want evidence that your organization has the safeguards in place to reduce cyber risk before they’ll offer the same level of coverage.
Just as important, your answers need to accurately reflect your current environment. Overstating your security controls or guessing your way through the application could create problems if you ever need to file a claim.
In this guide, we’ll explain why cyber insurance renewal questions have become more detailed, what insurers are really looking for, and how to prepare your business before submitting your renewal application.
Why Cyber Insurance Renewal Applications Are More Detailed
Cyber insurance applications have evolved because cyberattacks have become more sophisticated, and far more expensive.
Several high-profile incidents during 2023 and 2024 changed how insurers evaluate risk. Rather than simply asking whether basic security measures are in place, carriers now want to understand how well those controls actually protect your organization.
The MOVEit supply chain breach exposed thousands of organizations after attackers exploited a vulnerability in a widely used file transfer platform. The widespread impact forced insurers to take a much closer look at third-party software vendors and supply chain security.
Around the same time, the Change Healthcare ransomware attack disrupted healthcare providers across the United States, delaying claims processing for weeks and highlighting how a single compromised system can create massive financial losses.
Events like this prompted insurers to place greater emphasis on identity protection, immutable backups, and incident response planning.
Artificial intelligence has also changed the threat landscape. In one well-publicized case, criminals used AI-generated voice and video technology to impersonate company executives during a virtual meeting, convincing an employee to authorize millions of dollars in fraudulent wire transfers.
Incidents like these have led insurers to add new questions about wire transfer verification procedures, employee awareness training, and defenses against deepfake attacks.
Businesses operating in healthcare, legal services, accounting, financial services, real estate, and e-commerce can expect the most extensive questionnaires because these industries routinely handle sensitive information and remain attractive targets for cybercriminals.
Backup and Recovery Questions Carry More Weight Than Ever
One of the biggest changes you’ll notice during renewal is the increased focus on backups. Instead of simply asking whether backups exist, insurers now want to know how they’re protected, how often they’re tested, and whether they could survive a ransomware attack.
Many renewal applications now include questions such as:
- Are your backups immutable or air-gapped?
- Have you successfully tested a full restore within the last 12 months?
- Can privileged administrator accounts modify or delete your backups?
- Are backup administrator credentials separate from production credentials?
These questions help insurers determine whether your organization could recover quickly if critical systems were encrypted or compromised.
Immutable backups prevent data from being changed or deleted during a defined retention period, even if attackers obtain administrative credentials. Air-gapped backups go one step further by isolating backup data from the production environment, making them much harder for ransomware to reach.
The CISA #StopRansomware Guide also recommends maintaining offline, encrypted, and regularly tested backups as a foundational defense against ransomware.
It’s also important to understand that Microsoft 365’s built-in retention features aren’t considered a complete backup solution by most insurers. Carriers increasingly expect organizations to use dedicated backup platforms that provide immutable storage, separate administrative access, and documented recovery testing.
The strongest renewal applications typically demonstrate:
- Immutable storage using Object Lock or Write Once Read Many (WORM) technology
- An immutability period of at least 14 days, with 30 days becoming increasingly common
- Dedicated backup administrator accounts separate from production accounts
- Recent restore testing with documented results
Organizations relying on local network storage, untested backups, or shared administrator credentials should expect additional underwriting questions and, in some cases, higher premiums or reduced coverage.
Multi-Factor Authentication Requirements Continue to Expand
A few years ago, insurers simply asked whether your organization used multi-factor authentication (MFA). Today, that single question has evolved into several.
Most carriers now want confirmation that MFA is enabled for:
- Business email
- VPN connections
- Remote Desktop (RDP)
- All administrator accounts
- Privileged service accounts
They also want to know which authentication methods you’re using.
While SMS-based verification is still accepted by some providers, authenticator apps, hardware security keys, and push notifications with number matching are now viewed as much stronger security controls.
Many applications also ask whether your organization uses Privileged Access Management (PAM). PAM solutions secure administrator credentials, rotate privileged passwords automatically, and create detailed audit logs that help prevent unauthorized access from going unnoticed.
If gaps exist, answer honestly. Insurers are generally more receptive to organizations with documented improvement plans than businesses that overstate their cybersecurity controls. Need help preparing for your next cyber insurance renewal? Contact Twintel today.
Another
Twintel has grown into an expansive, full team of IT services professionals, acting as the outsourced IT department of non-profits, small to mid-size businesses, and enterprise-level corporations in Orange County, across California, and nationally.
Today, it’s the strength and deep expertise of the Twintel team that drives positive outcomes for clients. Each of the support staff, technicians, and engineers works diligently each day to make sure that the companies served have the seamless, secure, and stable IT environments needed to allow them to pursue their organizational objectives.