Cyber insurance stopped being a formality several renewals ago. Underwriters now send technical questionnaires, and the answers move your premium, your coverage exclusions — and, if you ever file a claim, whether it pays. Here are the questions that show up on nearly every mid-market renewal, what underwriters are actually probing for, and what a credible answer looks like.
The five questions that decide your premium
"Is multi-factor authentication enforced?" Not "available" — enforced, everywhere: email, remote access, admin accounts, and increasingly your line-of-business systems. Partial MFA reads as no MFA. The credible answer names the enforcement mechanism and the exceptions list (which should be short and justified).
"Do you run EDR on all endpoints?" Traditional antivirus no longer counts. Underwriters want endpoint detection and response, deployed to every device — including the forgotten ones. "All company laptops" is a weaker answer than "all endpoints, with a device inventory that proves it."
"Are backups tested, and are they isolated?" The word that matters is tested. Ransomware crews attack backups first; underwriters know it. A credible answer includes immutable or offline copies and a date on which restoration was last actually performed — not scheduled, performed.
"What is your patching cadence?" They're asking how long known vulnerabilities live in your environment. "As needed" is the wrong answer. A defined cadence with an exception process for critical patches is the right one.
"Describe your offboarding process." The quiet killer. Departed-employee accounts are a favorite entry point, and "the manager emails IT" is not a process. Same-day access revocation, documented, is.
Why "our IT person handles it" costs money
Underwriters don't price your intentions; they price your evidence. The same controls, documented and attestable, produce a different premium than the same controls existing informally — because in a claim dispute, evidence is what exists. This is where the structure of your IT operation shows up in dollars: a managed environment generates the documentation as a byproduct of doing the work. Reports, inventories, patch logs, and restoration tests exist because the system produces them, not because someone stayed late before the renewal.
Getting renewal-ready deliberately
If your renewal is one or two quarters out, the sequence is: get an honest gap read against the questionnaire, fix the failures in priority order (MFA and backups first — they carry the most premium weight), and assemble the evidence package before the broker asks. We run exactly this as a fixed-fee cyber insurance readiness project — a defined-scope engagement that stands on its own, whoever runs your IT. Keeping the answers true year-round is what Managed IT coverage is for; the renewal just makes the difference visible annually.
One more section of the questionnaire is growing fast: AI usage — what tools your people use and what governs them. That one gets its own treatment here, and the thirty-day fix is real.
