Your Cyber Insurance Renewal Is Asking Questions You Can't Answer. That's Fixable.
The renewal packet arrives, and somewhere past the premium page is a questionnaire that didn't used to be there, or used to be shorter. Do you enforce multi-factor authentication on all email accounts? On remote access? Are your backups encrypted, tested, and kept separate from your network? Do you have endpoint detection and response deployed? Is there a written incident response plan?
And you're staring at it thinking: I genuinely don't know, and the person who set up our computers doesn't work with us anymore.
You're not alone in that. Insurers tightened these questionnaires after years of paying ransomware claims, and small businesses that renewed on autopilot for a decade are suddenly being asked for specifics. Here's what's actually at stake and how to get through it honestly.
Why guessing is the one wrong answer
The temptation is to check "yes" down the column and move on. Understand what that signature does: your answers become part of the insurance application, and a claim investigation will check them against reality. Insurers have denied claims and rescinded policies after breaches revealed that the MFA a business attested to didn't exist. When that happens, you don't just lose the claim. You absorbed the breach costs and paid premiums for coverage that evaporated exactly when it mattered.
An honest "no" costs you a higher premium or a required fix. A false "yes" costs you the coverage itself, discovered at the worst moment of your business's life. Answer what's true, and if the truth is embarrassing, fix the truth.
What the questions actually mean
The questionnaire is written in security vocabulary, but the underlying questions are plain:
- MFA on email and remote access. When someone logs in, is a password alone enough? If yes, that's a "no" on the form. This is the single most common gap, and often the one insurers care most about.
- Endpoint detection and response. Not "do you have antivirus," but is something actively watching every computer and is someone alerted when it fires? Free antivirus that nobody monitors doesn't qualify.
- Backups: separate, encrypted, tested. Separate means ransomware that hits your network can't also encrypt the backup. Tested means someone has actually restored from it, not assumed it works. A backup that's never been restored is a hope, not a backup.
- Incident response plan. A written document saying who does what when something happens. For a small business this is a few pages, not a binder.
- Patching and updates. Are computers and software kept current on a schedule, or whenever someone gets around to it?
None of these exist to annoy you. Each one maps to a way insurers have actually lost money.
The renewal-window playbook
You typically have weeks, not days, between receiving the questionnaire and the renewal date. Used well, that's enough.
- Answer nothing yet. First find out what's true. For each question, identify who can actually verify it: log into the email admin panel and look at whether MFA is enforced, don't ask around and accept "I think so."
- Triage the gaps. Some fixes are fast. Enforcing MFA on a small Microsoft 365 tenant is typically a short project, not a long one. Deploying monitored endpoint protection is days, not months. A basic written incident response plan is an afternoon with the right template and honest inputs. Tested backups take longer to prove, but a first test restore can happen this week.
- Fix what's fixable before the deadline, then answer truthfully. "Yes, as of this month" is a perfectly good answer, and a materially better one than it would've been.
- For what you can't fix in time, tell your broker. Brokers deal with this daily, and a documented remediation plan with dates often keeps you insurable at a reasonable rate. Silence or false confidence does not.
The part nobody mentions
Everything on that questionnaire is something your business should have had anyway. The insurer didn't invent new burdens. They wrote down the basics and attached a price to skipping them. Which means the renewal, annoying as it is, is a decent forcing function: it hands you a prioritized list of your most important gaps, with a deadline, once a year.
Getting a small business from "I don't know" to a questionnaire you can sign without flinching is work we take on regularly: verifying what's actually in place, closing the standard gaps, and putting the documentation behind each answer. If your renewal is sitting on your desk right now, book a 15-minute review and bring the questionnaire. We'll go through it together.
Tech 360 Solutions provides managed IT and cybersecurity for small businesses in the Kansas City metro. Built for HIPAA, FTC Safeguards, and other regulated environments.