← Back to blog

8 July 2026

How to Answer Cyber Insurance Renewal Questions Without Voiding Cover

Close-up of a businessman reviewing paperwork on a wooden desk

Photo by cottonbro studio via Pexels

If your cyber insurance renewal is due soon, you'll probably notice the application is longer than last year's. It's also asking much more pointed questions. Instead of a single "do you have backups?" tick box, you might see three or four follow-up questions about how those backups are configured, who can delete them, and when they were last tested.

That shift isn't random. Insurers rewrote their forms after a run of expensive claims in 2023 and 2024 exposed exactly which gaps let those incidents escalate. Every new question on your form traces back to a real loss a carrier had to pay out on.

This post covers why the form changed, what each new section is really asking, the honest way to answer without overstating your controls, and the one mistake that can cost you the entire claim later, not just a higher premium now.

Three claims that rewrote the application

A UK engineering firm lost $25.6 million to a deepfake video call. In early 2024, a finance employee at Arup, the London-headquartered engineering firm behind projects like the Sydney Opera House, joined a video call that appeared to include the company's CFO and several other senior colleagues. Every one of them was an AI-generated deepfake. Convinced by the call, the employee authorised 15 wire transfers totalling HK$200 million (around $25.6 million) before anyone realised something was wrong. It's one of the clearest examples yet of why insurers now ask specifically about how you verify a payment request, not just whether you have a finance team that's "careful."

A single missing MFA setting froze US healthcare payments for weeks. In February 2024, attackers used stolen credentials to log into a remote access portal at Change Healthcare, a system that had never been fitted with multifactor authentication because it sat on infrastructure absorbed through a prior acquisition and hadn't been brought fully into the company's security controls. Nine days after that first login, ransomware locked the platform down, and the fallout disrupted prescriptions, payments and insurance claims across the US for weeks. The lesson insurers took from it wasn't "add MFA everywhere in general." It was "ask specifically whether MFA covers every account, including the ones inherited from somewhere else."

One vulnerable file-transfer tool exposed data at thousands of organisations. Also in 2023, the Cl0p ransomware group exploited a previously unknown flaw in Progress Software's MOVEit file transfer product. By the time the dust settled, more than 2,500 organisations and upwards of 66 million people had data exposed through the tool, even though most of those organisations had never heard of MOVEit themselves, only their supplier used it. That's the incident behind the vendor-risk section now appearing on most renewal forms.

The backup question is no longer a yes or no

Where a form used to ask "do you back up your data?", you're now more likely to see something like: are backups immutable or air-gapped, tested for restoration within the last 12 months, and out of reach of your own domain administrator credentials?

That last part is the one that catches people out. An immutable backup can't be deleted or altered during a fixed retention window by anyone, including someone using a stolen admin login. A backup sitting on a NAS on the same network, or Microsoft 365's built-in retention settings, generally doesn't meet that bar, because both can be reached and wiped by whoever holds admin access at the time.

We've written a full breakdown of what "immutable" actually means and which common setups fail the question without the business realising it: what "immutable backup" means on your cyber insurance form. Worth reading in full if backups are the section you're least sure about.

MFA questions now cover five places, not one

A single "do you use MFA?" question used to be enough. Current forms typically ask whether MFA is enforced on email, VPN, remote desktop, every administrator account, and any privileged service accounts, five separate yes/no answers rather than one.

Text message codes are increasingly treated as the weak option rather than a safe default, since SIM-swap fraud and known weaknesses in the underlying mobile network signalling can let an attacker intercept them. An authenticator app, hardware key, or push notification with number matching is what most current applications are really asking about when they say "MFA."

The newer question, and the one most owners haven't seen before, is about privileged access management. This is a category of tool that keeps administrator passwords out of a shared spreadsheet or password manager, instead vaulting them, rotating them after each use, and logging every session. Without it, a stolen admin password can sit unnoticed and usable for weeks. If your business doesn't have this in place, an honest "not yet, here's our timeline" answer is a far safer position on the form than dressing up a shared admin login as something it isn't.

Callback verification for wire transfers is now expected

After Arup and a wave of similar business email compromise losses, insurers added a specific question about payment verification: does your organisation require a phone call, to a number you already have on file rather than the number on the request itself, before sending any transfer above a set threshold?

That single control would have stopped the Arup fraud outright. No callback, no transfer, regardless of how convincing the video call looked. A written policy, even a one-page one, that sets a threshold, requires that callback, and applies it even to requests that appear to come from a director, is what a strong answer to this section looks like. Some applications now also ask directly whether staff have had any awareness training on AI voice cloning and deepfake video, a question that simply didn't exist on forms before 2024.

Accountancy and law firms handling client money, and any business that regularly moves large sums by wire, should expect this section to get the closest scrutiny.

"We have antivirus" doesn't answer the EDR question

Traditional antivirus checks files against a list of known threats. Endpoint Detection and Response (EDR) instead watches what's happening on a device and flags behaviour that looks wrong, a process trying to encrypt hundreds of files in seconds, for example, even if that specific attack has never been seen before. Managed Detection and Response (MDR) adds a team that actually watches those alerts around the clock and responds when something fires outside office hours.

Applications increasingly ask for EDR across every endpoint and server, plus whether a monitored service responds to alerts 24/7. If you're not there yet, say so with a plan rather than stretching the truth: "MDR rollout scheduled for next quarter, vendor selected" is a workable answer. A vague assurance that falls apart under a forensic review after a claim is not.

Your software vendors are on the form too

Since MOVEit showed how one vendor's vulnerability can expose dozens of downstream businesses that never chose that vendor themselves, several applications now ask you to list your top software suppliers with access to sensitive data and confirm whether each can produce a SOC 2 report or an equivalent standard like ISO 27001.

You're not expected to audit every supplier's security programme yourself. What the question is really testing is whether you know who holds your data and have at least asked. "We've identified our top five vendors and requested evidence from three, with two still outstanding" is a credible, honest answer. A confident "yes, all our vendors are secure" with nothing behind it is the one likely to unravel later.

The real cost of overstating your controls

The most expensive mistake on a renewal form isn't a missing control. It's an answer that claims a control exists when it doesn't.

UK business insurance, including cyber cover, sits under the Insurance Act 2015's duty of fair presentation. How an inaccurate answer gets treated depends on how it happened. If a misrepresentation was deliberate or reckless, meaning you knew the honest answer was no and answered yes anyway, the insurer can treat the policy as if it never existed, refuse the claim entirely, and keep the premium you already paid. If the mistake was genuinely careless rather than deliberate, for example you believed a control was in place when it wasn't, the insurer instead gets a proportionate remedy, which might mean a reduced payout or different terms rather than losing cover outright.

Neither outcome is one you want to discover midway through an actual incident, which is exactly when a forensic investigator is most likely to find the gap between what the form said and what was really configured. Flagging a gap honestly, with a remediation date, protects your claim far better than a polished answer that doesn't survive that review.

Getting the form ready

Rather than working through the whole application in one sitting, it helps to split the prep into three buckets.

Fix this week, no external help needed. Move admin accounts off SMS-based MFA onto an authenticator app. Check whether MFA is actually enforced on every admin and service account, not just regular user logins. Draft a one-page wire transfer policy that sets a callback threshold and get it signed by whoever authorises payments.

Needs a conversation with your IT provider. Confirm whether your backups are genuinely immutable, and get that in writing along with the retention window, not just a verbal yes. Ask for a real test restore with a dated result you can point to on the form. If you don't have EDR or MDR yet, get a quote and a rough timeline so you can answer honestly rather than vaguely.

Needs sign-off before you submit. Run a short incident response tabletop exercise with your leadership team so you have a genuinely tested plan, not just a document nobody has opened. Reading through how a small business ransomware attack actually unfolds is a useful way to prime that conversation, since it shows how quickly gaps like these get exploited once an attacker is inside. Then go through the form itself line by line, and where the honest answer is "not yet," write the remediation date next to it rather than leaving it blank or rounding up.

This is exactly the kind of review our cyber security & compliance work is built around, checking what's actually configured against what a renewal form is asking, before a gap becomes a declined claim. If you'd like a second set of eyes on your application before you submit it, book a call with our team.

Frequently Asked Questions