Catch Advisors
Cybersecurity

Cybersecurity Insurance: What IT Leaders Need to Know Before Renewal

Cyber insurance used to feel like a finance task.

A broker sent a form. Someone in IT answered a few security questions. The company paid the premium and moved on.

That is not how it works anymore.

Cyber insurance carriers now ask deeper questions. They want proof that your company has strong security controls. They may ask about MFA, endpoint detection, backups, email security, patching, remote access, vendor risk, incident response, and employee training.

For IT Directors and CIOs, this creates a new problem. Cyber insurance renewal is no longer just a policy review. It is a security readiness test.

If your answers are weak, your company may face higher premiums, lower limits, more exclusions, or even a declined renewal. If your answers are wrong, you may create coverage problems later when you need the policy most.

The good news is that renewal does not have to be a panic project. If you know what carriers care about, you can prepare early and avoid surprises.

Why Cyber Insurance Renewals Are Getting Harder

Cyber insurance carriers are reacting to real loss.

Ransomware, business email compromise, data theft, wire fraud, and vendor-related incidents have created expensive claims. Carriers have learned that companies with weak controls are more likely to suffer major losses.

So they are asking better questions.

They are also looking for evidence. A simple “yes” on a form may not be enough if a claim happens later. Some carriers may ask for screenshots, policy documents, tool reports, or written procedures.

This shift matters because many mid-market companies have grown their security stack over time. They may have some strong controls, some gaps, and some old assumptions.

For example:

  • MFA may be turned on for Microsoft 365, but not for VPN or remote admin tools.
  • Backups may exist, but restore testing may not happen often.
  • Endpoint tools may be installed, but alerts may not be reviewed after hours.
  • Security training may be assigned, but not tracked well.
  • A written incident response plan may exist, but the team may never have practiced it.

Those details can affect renewal.

Start 90 Days Before Renewal

The biggest mistake is waiting until the broker sends the application.

By then, you may have only a few weeks to answer questions, gather proof, fix gaps, and explain risk to leadership. That creates stress and rushed decisions.

A better approach is to start at least 90 days before renewal.

Use that time to:

  • Review last year’s application
  • Compare last year’s answers to the current environment
  • Identify weak or unclear controls
  • Gather evidence for key security controls
  • Ask your broker what carriers are focused on this year
  • Build a short remediation plan for gaps
  • Brief finance and executive leadership early

This does not mean every issue must be fixed before renewal. But it does mean you should know your risk position before the carrier asks.

Know Who Owns the Answers

Cyber insurance applications often create confusion because several teams are involved.

Finance may own the policy. Legal may review terms. The broker may manage carrier communication. IT may answer technical questions. Security may own controls if there is a security team.

If no one owns the full process, the company can submit answers that are incomplete, outdated, or too broad.

Before renewal starts, define the roles.

At minimum, decide:

  • Who gathers the technical answers?
  • Who validates that the answers are accurate?
  • Who reviews policy language and exclusions?
  • Who approves business risk if a control is missing?
  • Who keeps a copy of the final application?

This is important because the application can become part of the insurance record. If there is a claim, the carrier may review what the company said during renewal.

Do not guess. If the answer is “partially implemented,” say that internally and work with your broker on how to explain it correctly.

Controls Carriers Care About Most

Every carrier is different, but most focus on a common set of controls.

Multifactor Authentication

MFA is one of the first things carriers ask about.

But they are not just asking, “Do you have MFA?” They want to know where it is enforced.

Review MFA for:

  • Email and productivity platforms
  • VPN and remote access
  • Privileged admin accounts
  • Cloud management consoles
  • Remote monitoring and management tools
  • Financial systems
  • Backup systems

The gaps often hide in admin tools, legacy systems, and third-party portals.

If MFA is only active for some users or some apps, document that clearly. Then build a plan to close the gaps.

Endpoint Detection and Response

Traditional antivirus may not satisfy every carrier. Many now expect endpoint detection and response, often called EDR, or a managed detection and response service, called MDR.

They may ask whether endpoints are monitored, whether alerts are reviewed, and whether devices can be isolated during an incident.

For IT leaders, the key question is simple: if a laptop or server shows signs of compromise at 2 a.m., who sees it and what happens next?

If the answer is “we will find out in the morning,” that may be a gap.

Backups and Recovery

Backups are central to ransomware recovery.

Carriers may ask whether backups are encrypted, immutable, offline, segmented, and tested. They may also ask how often restores are tested and how long recovery would take.

Do not only confirm that backups run. Confirm that recovery works.

Review:

  • Critical systems covered by backup
  • Backup retention periods
  • Access controls for backup platforms
  • Separation from production credentials
  • Restore test results
  • Recovery time expectations

A backup that has never been restored is an assumption, not a recovery plan.

Email Security

Business email compromise is one of the most common cyber claims.

Carriers may look for secure email gateways, phishing protection, domain controls, and user training. They may also ask about processes for wire transfer changes and payment approvals.

For IT, this means email security is not only a tool issue. It is also a business process issue.

Make sure your company has controls for:

  • Phishing detection
  • Suspicious link and attachment protection
  • External sender warnings
  • DMARC, SPF, and DKIM
  • Mailbox forwarding rules
  • Payment change verification

Finance and IT should review this together.

Patch Management

Carriers know that many breaches start with unpatched systems.

They may ask how quickly critical patches are applied, how assets are tracked, and whether internet-facing systems are scanned.

If your patch process is informal, renewal season is a good time to clean it up.

You do not need a perfect process. You do need a clear one.

Define:

  • How assets are tracked
  • How patches are prioritized
  • Who approves emergency patches
  • How exceptions are documented
  • How patch status is reported

Incident Response Plan

A written incident response plan is now a basic expectation.

The plan should explain who does what when an incident happens. It should include internal contacts, external partners, legal contacts, insurance contacts, communication steps, and decision paths.

A useful plan answers questions like:

  • Who can declare an incident?
  • Who contacts the broker or carrier?
  • Who approves outside incident response help?
  • Who communicates with employees, customers, and vendors?
  • Who decides whether systems are taken offline?

The plan should be short enough that people can use it under stress.

If your plan is a 40-page document no one has read, it may not help much.

Watch the Exclusions

Cyber insurance is not just about the premium and coverage limit.

Exclusions matter.

A policy may limit or exclude coverage for certain events, regions, technologies, vendors, or control failures. Some policies may have conditions tied to MFA, backups, or known vulnerabilities.

IT leaders should not be expected to read insurance language alone, but they should be part of the review.

Ask your broker and legal team:

  • Are there exclusions tied to missing controls?
  • Are ransomware payments covered, limited, or excluded?
  • Are social engineering and wire fraud covered?
  • Are incidents from vendors or cloud providers covered?
  • Are prior known issues excluded?
  • Are legal, forensic, notification, and recovery costs covered?

These questions help leadership understand what the policy really does and does not protect.

Be Careful With Application Language

Cyber insurance applications often use broad terms.

For example, a question may ask, “Do you require MFA for remote access?”

That sounds simple, but the real answer may depend on how remote access is defined. Does it include VPN only? Remote desktop? Cloud admin portals? SaaS apps? Vendor support tools?

Another question may ask whether backups are immutable. Some systems may be immutable. Others may not.

Avoid one-word answers until you understand the scope.

A good internal rule is this: answer based on what is true across the environment, not what is true in the best-case system.

If a control is partial, treat it as partial. Then work with your broker on the right wording.

Accuracy protects the company.

Build a Renewal Evidence Folder

One practical step can make renewal much easier: create an evidence folder.

This does not need to be complex. It can be a secure folder with current documents and screenshots.

Include:

  • MFA policy or screenshots
  • Endpoint security coverage reports
  • Backup and restore test records
  • Security awareness training reports
  • Incident response plan
  • Vulnerability scan summaries
  • Patch management policy
  • Email security settings
  • Network diagrams for critical systems
  • Vendor contact list for incident support

Update it quarterly. Then renewal becomes a review, not a scramble.

Turn Renewal Into a Security Roadmap

Cyber insurance should not drive your entire security strategy. But it can help reveal gaps.

If the renewal process shows weak MFA, untested backups, unclear incident response, or poor asset tracking, use that information to build a roadmap.

Group findings into three buckets:

  1. Fix before renewal
  2. Fix in the next 90 days
  3. Plan for the next budget cycle

This makes the conversation with leadership easier. Instead of saying, “We have security problems,” you can say, “Here are the controls affecting risk, insurance, and recovery. Here is the plan.”

That is a stronger business conversation.

What IT Leaders Should Do Next

Before your next cyber insurance renewal, take these steps:

  • Start 90 days early
  • Review last year’s application
  • Validate MFA coverage across all key systems
  • Confirm endpoint monitoring and response coverage
  • Test restores for critical backups
  • Review email security and payment change controls
  • Update your incident response plan
  • Ask about exclusions before you renew
  • Keep evidence for every major answer

Cyber insurance is not a replacement for security. It is a financial backstop for when security fails.

The goal is not just to get approved. The goal is to know your real risk, improve your controls, and avoid finding gaps during a claim.

If you want a vendor-neutral review of your security stack, cyber insurance readiness, or renewal gaps, Catch Advisors can help you make sense of the options before you spend more. Learn more at catchadvisors.com.