Your cyber insurance renewal asks for controls you cannot evidence
The renewal application asks whether specific controls are in place everywhere, and the honest answer is not a clean yes. What the questions are for, and what to do before the form goes back.
- What it is
- Your customer applying their vendor risk process to your organization.
- What it needs
- Answers that are accurate within a stated scope, and evidence behind them.
- Who owns it
- One accountable person, working from what the systems actually do.
The short answer
What you are holding
A cyber insurance application is an underwriting document, which means the answers are warranties rather than estimates. A control that is in place for most of the environment is not in place, and saying otherwise is the one mistake that can affect whether a claim is paid.
The document
What it is, plainly
The application asks about a short list of controls that underwriters have found to correlate with losses: multi-factor authentication, particularly for remote access and administrative accounts, endpoint detection, backups that are tested and held separately, privileged access management, email filtering and patching cadence.
The questions are usually absolute. They ask whether something is enabled for all users or all servers, not whether a rollout is underway. That phrasing is deliberate, because partial coverage is where the losses they are pricing actually occur.
Renewal is also where the requirements move. A control that was a discount last year is frequently a condition of cover this year, which is why an organization that changed nothing can still find its renewal harder than its original policy.
Consequence
What your answers commit you to
-
The answers are warranties
They form part of the basis of the contract. An inaccurate answer can affect the response to a claim, which is a materially different exposure from failing an assessment.
-
Partial coverage reads as no
Multi-factor authentication on most accounts, with an exception for a service account or a legacy system, is the exact gap the question exists to find. The exception is the answer.
-
The form is a controls roadmap
Underwriters converge on the same list because it reflects observed loss data. Read as guidance rather than paperwork, the application is a reasonable statement of what to do first.
Before you reply
What to establish first
In this order. Each one narrows what the next has to decide.
-
Get the questions early
Ask the broker for the application well before renewal. Discovering a condition of cover a week out leaves no time to do anything except answer it uncomfortably.
-
Test each answer against the exceptions
For every control, ask what is excluded: which accounts, which servers, which locations, which legacy system nobody wants to touch. Those exclusions are the real answer to the question.
-
Verify rather than ask around
Confirm from the systems themselves that a control is enabled where it is believed to be. Configuration drift and rollouts recorded as finished are common, and neither is visible from a conversation.
-
Close what can close quickly
Some gaps are configuration changes achievable inside a renewal window. Doing those first changes the answer rather than qualifying it, which is a better position on the form.
-
Document what cannot close yet
Where a gap is real, a written plan with an owner and a date is what underwriters generally want to see. It also stops the same gap being rediscovered at the next renewal.
-
Answer exactly what was asked
Match the scope in the question. If it asks about all privileged accounts, answer about all of them, and state the exception plainly where one exists.
Failure modes
Where responses go wrong
- Answering from intent
- A project is underway, so the control is recorded as in place. Underwriting asks about the environment as it stands, and a rollout scheduled for next quarter is not a control.
- The broker filling it in
- A broker can explain what a question means and cannot know the state of your environment. The answers are the organization's, whoever transcribes them.
- Forgetting the exceptions list
- Service accounts, break-glass accounts, contractors and the one application that cannot support modern authentication get left out because they are exceptions. They are what the question is looking for.
- Optimizing only for the discount
- Controls are adopted to improve terms and then not maintained, so the answer is accurate on the day it is given and not twelve months later when it matters.
- Keeping no record of what was submitted
- The application, its answers and the evidence behind them should be retained. If a claim is ever examined, that record is the difference between a defensible answer and a recollection.
Referenced
What the questions usually cite
- NIST CSF Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
- PCI DSS Any organization handling payment card data, with validation effort scaled to transaction volume and method.
- SOC 2 Technology and service companies whose enterprise customers require evidence of a controlled environment.
After
Where this leads
- Organizations that treat the application as an annual controls review tend to find renewal gets easier rather than harder, because the same questions are already answered and evidenced.
- The controls on the form are a floor rather than a program. They address the losses insurers see most, and they do not consider the obligations that are specific to your sector, your contracts or your data.
- Where the exercise surfaces a genuine gap, the useful outcome is the same as anywhere else: a prioritized plan with an owner and dates, and a record of what leadership decided to accept.
Where Heights fits
If you would rather not work it out alone
Heights establishes what is actually true across the environment before the form is answered, separates what can be closed inside the renewal window from what needs a plan, and puts the answers and their evidence somewhere they can be found next year. The controls the application asks about then sit inside a program rather than being an annual scramble.
Schedule a Confidential Consultation Read about vCISO leadership
FAQ
Questions this raises
Broader questions about executive security leadership are answered on the vCISO page.
What happens if a control we attested to was not actually in place?
It depends on the policy wording and the jurisdiction, and it is a question for your broker and your counsel rather than for a security firm. What is consistent is that the answers form part of the basis of the contract, so an inaccuracy is capable of affecting how a claim is handled.
That is why the practical advice is always the same: answer what is true today, state the exceptions, and keep the evidence. A qualified answer is routine and a wrong one is not.
Do we need every control in place before we renew?
Not usually. Some controls have become conditions of cover rather than discounts, and those are worth identifying early, but the rest are priced rather than required.
A documented plan with an owner and a date is generally a workable position for a gap that cannot close in time. What is not workable is answering as though the gap were not there.
Why is the application harder than it was last year?
Underwriting requirements move with observed losses, so the bar tends to rise even for an organization that has not changed anything. Controls that were optional become expected, and questions that were broad become specific about scope.
Reading the current application against last year's answers is a quick way to see what shifted, and it is usually a short and informative list.
Is this the same work as preparing for an audit?
It overlaps and it is narrower. An insurance application asks about a specific set of technical controls; an audit or a framework assessment asks about governance, process and evidence across the whole program.
Work done properly for the application counts toward the broader picture. The reverse is more reliable: an organization with a real program answers these questions easily, because it already knows what is true.