Skip to content
  1. Home
  2. Insights
  3. Your insurer is now your auditor

Your insurer is now your auditor

Cyber insurance renewals have quietly become the most demanding security audit most mid-sized organisations face - and the questionnaire is not a formality.

For years cyber insurance was underwritten on revenue, sector and a short declaration. That has changed. Renewal questionnaires now ask for specific technical controls, and the answers are treated as warranties rather than aspirations.

What is actually being asked

The questions have converged across carriers, and they are consistently the same handful:

  • Multi-factor authentication on email, remote access and privileged accounts - with coverage percentages, not a yes.
  • Endpoint detection and response deployed across the estate, including servers.
  • Backups that are immutable or offline, and separated from production credentials.
  • Patch currency for critical vulnerabilities, with a stated window.
  • An incident response plan that has been tested within the last twelve months.
  • Email filtering, and disabled legacy protocols that bypass MFA.

Why optimistic answers are dangerous

If you answer that MFA is enforced everywhere and an incident later traces to an account that was excepted, the carrier has grounds to reduce or decline the claim. The questionnaire has become a contractual representation, and organisations sign it without the technical detail to know whether it is true.

The exceptions list is the single most important document in a renewal, and most organisations do not have one.

The gap that catches people

Nearly every environment has exceptions: a service account that cannot do MFA, a legacy application requiring basic authentication, a server the detection agent will not install on. These are usually well-known internally and completely undocumented.

Before renewal, produce a written exceptions register - what is excepted, why, what compensating control exists, and when it will close. It turns an inaccurate yes into an accurate yes-with-qualification, which is both defensible and materially safer.

Treat it as free scoping

The questionnaire is a reasonable security baseline assembled by people with financial exposure to getting it wrong. Even if you never file a claim, working through it honestly gives you a prioritised list of what to fix - and the premium difference often funds most of the work.

Ready to find out what your IT is really costing you?

A 45-minute working session gets you an honest read on estate health, security posture, and the two or three changes that would pay for themselves first.