Heights Consulting Group

Your cyber insurance renewal asks for controls you cannot evidence

The renewal application asks whether specific controls are in place everywhere, and the honest answer is not a clean yes. What the questions are for, and what to do before the form goes back.

What to do first

What it is
Your customer applying their vendor risk process to your organization.
What it needs
Answers that are accurate within a stated scope, and evidence behind them.
Who owns it
One accountable person, working from what the systems actually do.

The short answer

What you are holding

A cyber insurance application is an underwriting document, which means the answers are warranties rather than estimates. A control that is in place for most of the environment is not in place, and saying otherwise is the one mistake that can affect whether a claim is paid.

The document

What it is, plainly

The application asks about a short list of controls that underwriters have found to correlate with losses: multi-factor authentication, particularly for remote access and administrative accounts, endpoint detection, backups that are tested and held separately, privileged access management, email filtering and patching cadence.

The questions are usually absolute. They ask whether something is enabled for all users or all servers, not whether a rollout is underway. That phrasing is deliberate, because partial coverage is where the losses they are pricing actually occur.

Renewal is also where the requirements move. A control that was a discount last year is frequently a condition of cover this year, which is why an organization that changed nothing can still find its renewal harder than its original policy.

Consequence

What your answers commit you to

  • The answers are warranties

    They form part of the basis of the contract. An inaccurate answer can affect the response to a claim, which is a materially different exposure from failing an assessment.

  • Partial coverage reads as no

    Multi-factor authentication on most accounts, with an exception for a service account or a legacy system, is the exact gap the question exists to find. The exception is the answer.

  • The form is a controls roadmap

    Underwriters converge on the same list because it reflects observed loss data. Read as guidance rather than paperwork, the application is a reasonable statement of what to do first.

Before you reply

What to establish first

In this order. Each one narrows what the next has to decide.

  1. Get the questions early

    Ask the broker for the application well before renewal. Discovering a condition of cover a week out leaves no time to do anything except answer it uncomfortably.

  2. Test each answer against the exceptions

    For every control, ask what is excluded: which accounts, which servers, which locations, which legacy system nobody wants to touch. Those exclusions are the real answer to the question.

  3. Verify rather than ask around

    Confirm from the systems themselves that a control is enabled where it is believed to be. Configuration drift and rollouts recorded as finished are common, and neither is visible from a conversation.

  4. Close what can close quickly

    Some gaps are configuration changes achievable inside a renewal window. Doing those first changes the answer rather than qualifying it, which is a better position on the form.

  5. Document what cannot close yet

    Where a gap is real, a written plan with an owner and a date is what underwriters generally want to see. It also stops the same gap being rediscovered at the next renewal.

  6. Answer exactly what was asked

    Match the scope in the question. If it asks about all privileged accounts, answer about all of them, and state the exception plainly where one exists.

Failure modes

Where responses go wrong

Answering from intent
A project is underway, so the control is recorded as in place. Underwriting asks about the environment as it stands, and a rollout scheduled for next quarter is not a control.
The broker filling it in
A broker can explain what a question means and cannot know the state of your environment. The answers are the organization's, whoever transcribes them.
Forgetting the exceptions list
Service accounts, break-glass accounts, contractors and the one application that cannot support modern authentication get left out because they are exceptions. They are what the question is looking for.
Optimizing only for the discount
Controls are adopted to improve terms and then not maintained, so the answer is accurate on the day it is given and not twelve months later when it matters.
Keeping no record of what was submitted
The application, its answers and the evidence behind them should be retained. If a claim is ever examined, that record is the difference between a defensible answer and a recollection.

Referenced

What the questions usually cite

  • NIST CSF Any organization wanting a defensible, comparable baseline. Frequently requested by customers and insurers as a reference point.
  • PCI DSS Any organization handling payment card data, with validation effort scaled to transaction volume and method.
  • SOC 2 Technology and service companies whose enterprise customers require evidence of a controlled environment.

After

Where this leads

  • Organizations that treat the application as an annual controls review tend to find renewal gets easier rather than harder, because the same questions are already answered and evidenced.
  • The controls on the form are a floor rather than a program. They address the losses insurers see most, and they do not consider the obligations that are specific to your sector, your contracts or your data.
  • Where the exercise surfaces a genuine gap, the useful outcome is the same as anywhere else: a prioritized plan with an owner and dates, and a record of what leadership decided to accept.

Where Heights fits

If you would rather not work it out alone

Heights establishes what is actually true across the environment before the form is answered, separates what can be closed inside the renewal window from what needs a plan, and puts the answers and their evidence somewhere they can be found next year. The controls the application asks about then sit inside a program rather than being an annual scramble.

Schedule a Confidential Consultation Read about vCISO leadership

FAQ

Questions this raises

Broader questions about executive security leadership are answered on the vCISO page.

What happens if a control we attested to was not actually in place?

It depends on the policy wording and the jurisdiction, and it is a question for your broker and your counsel rather than for a security firm. What is consistent is that the answers form part of the basis of the contract, so an inaccuracy is capable of affecting how a claim is handled.

That is why the practical advice is always the same: answer what is true today, state the exceptions, and keep the evidence. A qualified answer is routine and a wrong one is not.

Do we need every control in place before we renew?

Not usually. Some controls have become conditions of cover rather than discounts, and those are worth identifying early, but the rest are priced rather than required.

A documented plan with an owner and a date is generally a workable position for a gap that cannot close in time. What is not workable is answering as though the gap were not there.

Why is the application harder than it was last year?

Underwriting requirements move with observed losses, so the bar tends to rise even for an organization that has not changed anything. Controls that were optional become expected, and questions that were broad become specific about scope.

Reading the current application against last year's answers is a quick way to see what shifted, and it is usually a short and informative list.

Is this the same work as preparing for an audit?

It overlaps and it is narrower. An insurance application asks about a specific set of technical controls; an audit or a framework assessment asks about governance, process and evidence across the whole program.

Work done properly for the application counts toward the broader picture. The reverse is more reliable: an organization with a real program answers these questions easily, because it already knows what is true.