The email from your broker shows up about sixty days before your policy expires. Attached is the renewal application, and it is longer than it was last time. Questions about multi-factor authentication. Questions about endpoint detection. Questions about whether your backups are immutable and how fast you patch internet facing systems. Somewhere around question thirty one you realize you do not know the answer to most of these, and the form is due back Friday.
So you do what almost everybody does. You skim, you check the boxes that feel roughly true, you tell yourself your IT guy probably has all that handled, and you send it back. That is the moment the real risk gets created, and it has nothing to do with hackers. A cyber policy is a contract, and the answers on that form are part of it. If you check a box that turns out not to be accurate, you may find out at the worst possible time that the coverage you have been paying for is not there.
A note before we go further: this is general information from an IT company, not insurance or legal advice. Your broker and your attorney are the right people to interpret your specific policy.
Why the Questionnaire Keeps Getting Longer
Cyber insurance grew fast and then got expensive to write, because ransomware claims turned out to be larger and more frequent than early pricing assumed. Carriers responded by raising prices and then by underwriting on security controls instead of just revenue and industry. The National Association of Insurance Commissioners, the standards body for state insurance regulators, reported in its 2025 cyber insurance market study that United States cyber direct written premium came to roughly $9.14 billion, a slight decline after several years of steep growth.
What that means for a small business in Denton County is simple. The questionnaire is no longer a formality. It is the underwriting. Carriers figured out that a handful of controls account for most of the difference between a small claim and a catastrophic one, and they price and sometimes decline based on your answers.
The Controls Almost Every Application Now Asks About
- Multi-factor authentication, and specifically where. Multi-factor authentication, or MFA, means a second proof of identity beyond a password. Applications now ask separately about email, remote access, and administrator accounts, because those are three different answers at most companies.
- Endpoint detection and response. EDR is software on every computer that watches for suspicious behavior rather than just matching known virus signatures, and can isolate a machine from the network when something looks wrong. Traditional antivirus alone increasingly does not count as a yes.
- Backups that an attacker cannot reach. The words on the form are usually offline, immutable, or air gapped, all of which mean the same thing in practice: a copy of your data that cannot be deleted or encrypted by somebody who has taken over your network.
- How fast you patch. Patching means installing the security updates software makers publish. Applications ask for a timeframe on critical updates, and they usually ask separately about anything reachable from the internet.
- Remote access exposure. Expect a direct question about whether Remote Desktop Protocol, the Windows feature that lets you control a computer from somewhere else, is reachable from the open internet. The right answer is no, and it is a common cause of ransomware.
- A written funds transfer verification procedure. If you want coverage for the wire fraud and invoice scam side of things, carriers want to see a documented rule requiring voice verification on a known number before money or bank details change.
What an Honest Yes Actually Requires
This is where most small businesses get into trouble, and it is almost never dishonesty. The question just sounds simpler than it is. “Do you use MFA?” feels like a yes if you have it on email. But the form usually means everywhere, including the tools your IT provider uses to reach into your network, and those are the crown jewels.
- Yes to MFA means every account, not most of them. Before you check that box, get a report from your email platform showing the enrollment status of every user, including service accounts and the owner’s old address that still forwards somewhere.
- Yes to tested backups means a date. Not “the backup runs nightly.” Somebody restored a real file or a real server on a real day and wrote it down. If nobody can name the date, the honest answer is no.
- Yes to security awareness training means records. A roster of who took what training and when. A video everybody watched once two years ago is not a training program.
- Yes to an incident response plan means it exists on paper. A written document naming who calls the carrier, who calls the lawyer, and who decides to shut things down. If it lives only in your head, write it down before you check the box.
- Yes to endpoint protection means on every machine. Including the laptop the bookkeeper works from at home and the old computer running the machine in the back that nobody wants to touch.
The Answer That Can Void the Policy
A well known court case makes this concrete. Travelers sued an Illinois company called International Control Services seeking to rescind its cyber policy, alleging the company misrepresented its use of multi-factor authentication on the application. Travelers said its investigation after a ransomware attack found MFA protecting the firewall but not other systems. The parties agreed to let the court rescind the policy, which means it was treated as if it never existed. Insurance broker Lockton wrote it up as a warning about answering application questions carefully.
The lesson is not that carriers hunt for excuses. It is that the application is a legal representation, and a box checked optimistically by somebody who did not know the details can undo the whole reason you bought the policy. If you are unsure, say so, or answer no and describe what you actually have. A lower score costs you money. A wrong answer can cost you the coverage.
How to Handle Renewal Sixty Days Out
- Ask your broker for the questionnaire early. Not the week it is due. Two months of lead time is the difference between fixing a gap and reporting one.
- Have your IT provider answer the technical questions in writing. Whoever manages your systems should give you their answers, in an email you keep, with evidence attached. If they hedge, that is information too.
- Build an evidence folder. Screenshots of MFA enrollment, the last restore test with its date, the training roster, the written incident response plan, the funds transfer policy. You want this before a claim, not during one.
- Turn the gaps into a project list. Every no on the form is a to do item with a price attached. Most of them are cheaper than the premium increase they cause.
- Reread your existing policy while you are at it. Look at sublimits, the waiting period before business interruption coverage starts, and exclusions. Ask your broker to walk you through the parts you do not understand.
The Bottom Line
The renewal questionnaire is annoying, and it is also the most useful free security assessment your business gets all year. Somebody who does this for a living wrote down the controls that actually matter and handed you the list. Answer it honestly, gather the evidence behind each answer, and turn the gaps into a plan. The businesses that sail through renewal stopped treating the form as paperwork and started treating it as the checklist it is.
Again, this is general information and not insurance or legal advice. Your broker and your attorney should review your specific policy and your specific answers. What we can help with is the technical side: figuring out what is actually true about your environment so the answers you give are accurate. If your renewal is coming up, reach out at harrisonward.com/contact and we will go through the questionnaire with you.
Comments are closed