Every year a document lands in my inbox that most people treat as paperwork and I treat as the second-hardest exam my program sits. It is the cyber-insurance renewal application. Two hundred-odd questions about MFA coverage, backup immutability, privileged access, email filtering, endpoint detection, patch cadence, and incident-response testing. Procurement calls it a form. I call it an audit — and unlike the SOC 2, this one is run by a party with its own money on the line, which makes it the more honest of the two.
Here is the reframe. The underwriter is not asking to be thorough. They are asking because a loss-actuarial model has priced each control against real claims data, and your answers move a number that ends up on a binder. Read it that way and it stops being a compliance chore. It becomes the best-prioritized controls roadmap you will get all year — written by the one party that has paid, repeatedly, for the consequences of the gaps.
And the output is not just a premium. It is a set of numbers — premium, retention, sub-limits, exclusions — that an independent, financially motivated third party assigned to your risk posture. That is a board-grade metric, and most security leaders bury it in the finance folder. This post is about treating the renewal like the second audit it is.
The questionnaire is a controls roadmap, not a form to survive
The market has converged. In the ransomware years the carriers got burned, tightened, and standardized, and the questions are now remarkably consistent from carrier to carrier — because they are the controls that separate the accounts that file catastrophic claims from the ones that do not. That consistency is a gift: the application is effectively a market consensus on what actually prevents loss. So before I answer a single question, I diff it against what we actually have. Here is what the recurring questions are really testing.
- MFA everywhere, including the ugly corners. The question is never "do you have MFA." It is whether MFA covers remote access, webmail, privileged accounts, and the VPN — and whether any legacy protocol or service account still slips past it. The gaps are always in the corners: the ERP with a shared login, the mail protocol that predates modern auth.
- EDR coverage as a percentage, not a product name. The underwriter wants the fraction of endpoints and servers under managed detection with real response capability. The coverage number is the answer, and the honest one is usually lower than the dashboard implies.
- Backups that are tested, immutable, and out of reach. The question tests whether a ransomware actor who owns your domain can also reach and encrypt your recovery path. Untested backups are an assertion. A dated restore test is a control.
- Privileged access and its blast radius. How many standing domain admins, whether privileged access is time-bound and just-in-time, whether tiering exists at all. This is the question that quietly prices your worst-day scenario.
- Email security and the BEC surface. Filtering and DMARC, yes, but also out-of-band verification for payment and banking-detail changes — because business email compromise is where the frequent, unglamorous claims come from.
- A patch SLA and an incident-response plan you have actually run. A tabletop in the last twelve months, named owners, a tested plan. A response plan you have never exercised is a document, and the underwriter knows the difference between a document and a control.
Diff that list against reality and you have a remediation backlog pre-prioritized by the one entity that pays if you are wrong. The gaps it surfaces are almost always cheaper to close than the premium increase they would otherwise buy you.
The renewal is a board-grade metric, not a procurement line item
Most self-reported security metrics have a credibility problem: the person reporting them chose them. Coverage percentages, closed-finding counts, phishing click rates — all useful, all selected by the party being measured. The renewal is different. Premium, retention, sub-limits, and the exclusions the carrier added or removed are set by someone betting real capital on being right, with no incentive to flatter you. That is exactly the property a board wants in a metric and rarely gets.
So report it. Year over year: did the premium move, and in which direction relative to the market? Did the carrier raise your retention — the loss you eat before coverage attaches — because they now read you as riskier? Did a sub-limit shrink? Did a new exclusion appear? Each of those is the market repricing your risk, and each maps to a control decision you can narrate.
The strongest version of that update has a shape: the premium held flat in a market that rose, because you closed the privileged-access gap the underwriter flagged last year, and the ransomware sub-limit returned to full policy limits after a control you shipped. That is a security update in the language a board already speaks — money, trend, and a decision that produced the trend. It beats a slide of green checkmarks, because the party grading it wasn't you.
Coverage gaps are where claims die, not where they get filed
The failure mode that should keep a security leader up at night is not "we had no policy." It is "we had a policy, we filed a claim, and it was denied." Cyber policies are dense with the language that produces that outcome, and most of the traps are knowable in advance.
Start with the application itself, because it is the sharpest trap and the one security creates. In many policies your answers are warranties, not casual disclosures. If you attested that MFA covers all remote and privileged access, and the breach walks in through the one legacy service account that bypassed it, the carrier can argue material misrepresentation and rescind the coverage you paid for. The person who signed that questionnaire — often me — is the person the whole policy rests on. I answer as if every "yes" is a representation I will defend under oath, because functionally it is.
Then read the coverage terms for the carve-outs the market has quietly hardened.
- Ransomware sub-limits. The extortion coverage that used to sit at full limit is now often carved down to a fraction of the policy. Know that number cold before the incident, not while the negotiation clock is running.
- Social-engineering and BEC sub-limits. Business email compromise frequently lives under a separate, much smaller sub-limit, and payment is sometimes conditioned on out-of-band verification you must prove you performed. The condition is the trap.
- War and nation-state exclusions. Carriers tightened attribution-based exclusions after 2022, and a state-attributed attack can fall outside coverage on an attribution you have no standing to contest.
- Widespread-event and systemic exclusions. These cap the carrier's exposure when one vendor compromise cascades across many insureds — the exact shape of a modern supply-chain event, the kind you are most likely to actually suffer.
- Failure-to-maintain and betterment. Coverage can be voided if you failed to maintain the controls you attested to, and betterment clauses decline to pay for improving your posture beyond its pre-loss state. Together they mean the policy pays to restore, not to fix the thing that let the attacker in.
- Dependent business interruption. Whether an outage at a critical vendor — your cloud region, your core processor, your identity provider — is covered, and up to what limit. For a fintech serving more than 1,500 financial institutions, the dependency map is not hypothetical, and neither is this gap.
Two more sit at the intersection of the policy and the law. Paying a ransom can violate OFAC sanctions if the actor is on a designated list, and no policy indemnifies an illegal payment — Treasury's advisory is explicit, and your carrier's negotiation panel operates inside it. And if you are a public company, the SEC's four-business-day materiality clock under Item 1.05 runs on its own schedule regardless of where your claim stands. The insurance timeline and the disclosure timeline are not the same clock. Map both before an incident, not during one.
Transfer the risk you can't price down, retain the rest
Insurance is risk transfer, and the only intelligent transfer decision starts with knowing what you are transferring. This is where the FAIR model earns its place: express your loss scenarios in dollars — frequency times magnitude — and you can see, in the same units the policy uses, which risks are worth a premium to move off the balance sheet and which are cheaper to retain and self-fund. A high-frequency, low-severity exposure you often keep and control; a multi-week ransomware outage is exactly what the transfer exists for.
Where the retention line finally sits — the loss you absorb before coverage attaches — is a finance and treasury call, not mine to make, and I don't pretend the capital-allocation decision is my seat. But it is priced almost entirely on the input I own: the strength and provability of the controls. So I hand finance a defensible dollar view of residual risk, and the retain-versus-transfer conversation gets grounded in something better than the carrier's opening quote. A CFO negotiating a retention with a real loss curve in hand negotiates from strength; one working from the broker's spreadsheet negotiates from the carrier's framing. That input is my job. The check is theirs.
The roadmap and the transfer decision are the same conversation from two directions: every control the questionnaire prices either lowers the premium or lets you safely raise the retention. Spend on the ones that do both — real loss reduction and real premium signal — before the ones that only look good on a certificate. The certificate proves you passed a point-in-time test. The premium proves someone will bet money on your posture. I trust the bet more than the badge.
Run the renewal like an audit
Here is the sequence I run, starting roughly ninety days before the policy binds.
- Pull last year's signed application and verify every answer is still true. Controls drift. The MFA exception granted for one team in October, the EDR agent that fell off a fleet of servers during a migration — each one silently turns a prior "yes" into a current misrepresentation. Reconcile before you re-attest.
- Gap-assess against this year's questionnaire. Carriers add questions where the market just took losses, so new questions are a preview of next year's expectations. Treat them as the roadmap even for the controls you don't have yet.
- Remediate the cheap, high-signal gaps first. Closing an MFA corner or hardening backup immutability usually costs less than the premium delta it prevents. Do those before you market the account.
- Assemble evidence, not assertions. Coverage percentages, restore-test dates, tabletop reports, the actual configuration. Underwriters want proof now, and evidence prices better than checked boxes.
- Put security in front of the underwriter, through the broker. The narrative of what you closed since last year is worth real premium, and it gets lost if it stays inside a form. I get on the call.
- Reconcile the bound policy against reality one last time. Before it binds, confirm every representation still holds and every sub-limit and exclusion is one you can live with. This is the last cheap moment to catch a coverage gap; the next one is a claim.
- Report the outcome to the board as a priced risk signal. Premium, retention, limits, exclusions, and the control decisions that moved them. That closes the loop from roadmap to metric, and grounds next year's remediation budget.
Treat the renewal like the second audit it is
Mine the questionnaire for the roadmap it is. Read the coverage terms for the traps that kill claims. Answer every question as a warranty you will defend, not a box you will check. And put the renewal in front of your board as the priced, independent signal it is — because it is the one risk number in your program that you did not get to choose.
I am curious how other security and risk leaders split this work. Where does the questionnaire live in your shop — with security, with finance, with a broker who owns the relationship — and who actually owns the accuracy of the answers when a claim is on the line? Tell me how you've drawn that line, and whether your board sees the renewal at all.
