A few years ago, buying cyber insurance for a small business took about fifteen minutes. You confirmed your revenue, checked a box saying you had antivirus and backups, and the policy showed up in your inbox. Nobody looked closely, because nobody had to.
That is over. The renewal packet that lands on your desk now is closer to a security audit than an insurance form. It asks whether multi-factor authentication is enforced on remote access and email and administrative accounts. It asks what endpoint detection product you run and whether anyone watches its alerts. It asks whether a copy of your backup is immutable or offline, when you last restored from it, and how long that restore took. Then it asks you to sign at the bottom.
Most business owners I talk with are surprised by this and a little annoyed by it. I understand the reaction, but I would encourage a different one. Carriers wrote these questions because they paid claims, studied how the incidents started, and worked backwards to the handful of controls that showed up over and over on the losing side. The questionnaire is, whether you like the messenger or not, one of the better small business security checklists in circulation — and it comes with a financial incentive attached.
Why the Questionnaire Got Harder
The pattern behind almost every claim is unglamorous. The most common entry points are stolen credentials, exposed remote access, and phishing email. None of those require a sophisticated attacker. They require a password that worked, a remote desktop port that was still open from a project three years ago, or an invoice attachment that looked normal.
Underwriters figured out that a small set of controls interrupts those paths, and they now price against them. If you want to understand what your renewal will look like, read the questions as “here is how our claims actually happen” rather than as bureaucracy.
The Controls They Ask About
Multi-factor authentication, everywhere. This is the single most weighted question on most applications, and it is rarely a simple yes. Carriers now break it out: email, VPN and remote access, administrative accounts, and any remote access to backup systems. Turning MFA on for the leadership team and calling it done is exactly the gap they are probing for. Microsoft’s research has consistently found that multi-factor authentication blocks more than 99% of automated account-compromise attempts, which is why the question carries so much weight. It is also not a force field — adversary-in-the-middle phishing kits steal the session token after you approve the prompt, which defeats app codes and push approvals alike. For finance, email admin, and anything touching money, use phishing-resistant MFA such as passkeys or a hardware security key. Our MFA guide for business owners walks through the rollout order.
EDR, not antivirus. Applications increasingly name the category outright: endpoint detection and response, ideally monitored by someone. Traditional signature-based antivirus is treated as a partial answer. The distinction matters to a carrier because EDR records behavior, which is what lets an incident responder answer the question every claim turns on — what did the attacker actually touch? If you are not sure which one you have, the difference between EDR and antivirus is worth ten minutes of your time before you answer.
Backups that survive the attacker. The modern question is not “do you back up?” It is whether at least one copy is offline, immutable, or otherwise outside the reach of a domain administrator account, because ransomware crews delete backups first. Expect follow-ups on retention length, whether backups are encrypted, whether the backup console itself requires MFA, and when you last performed a test restore. Test a restore quarterly, and do one full restore test a year.
Email filtering and authentication. Advanced filtering beyond the default spam engine, attachment and link scanning, and external sender warnings all appear. So do SPF, DKIM, and DMARC records, which make it far harder for someone to send mail that appears to come from your exact domain. They do not stop lookalike domains or display-name impersonation, so the rule about verifying payment and banking changes by phone still matters.
Security awareness training. Carriers want to see a recurring program with phishing simulations, not a one-time onboarding video. Some ask for completion rates and click rates. If you have never run one, a practical look at security awareness training covers what a real program involves.
A written, tested incident response plan. The plan needs to exist as a document, name who decides what, include the carrier’s own claims hotline, and show evidence that you have walked through it. A tabletop exercise once a year satisfies most versions of this question and is genuinely useful the first time you discover nobody knows who can authorize taking the file server offline.
Privileged access hygiene. How many domain administrators do you have, do those people use separate accounts for daily work, and does anyone review the list? Small offices routinely discover they have six admins and two of them left the company.
Patching and end-of-life systems. Expect a question about your patch cadence and a specific one about unsupported operating systems. Our standard is critical and actively exploited vulnerabilities within 72 hours and everything else on a weekly cycle. Unsupported systems increasingly draw an exclusion rather than just a higher rate.
What a “No” Actually Costs
It is tempting to assume the penalty for a weak answer is simply a higher premium. Sometimes it is. More often it shows up in ways that are easier to miss when you are skimming a renewal:
- Fewer quotes. Brokers shop your submission to multiple carriers. Weak controls thin the field, and less competition moves every other term against you.
- Sublimits and coinsurance. Your policy may show a healthy overall limit while ransomware or funds transfer fraud sits at a fraction of it, or requires you to carry a percentage of the loss.
- Exclusions. Unsupported operating systems, unencrypted laptops, and unpatched internet-facing systems are all common targets for carve-outs.
- Higher retention. The deductible you pay before coverage responds can move substantially.
- Declination. Some carriers simply will not quote without MFA on remote access and email.
The Application Is Not a Survey
This is the part I most want small business owners to hear. The answers you give generally become part of the policy. If a claim happens and the investigation shows that a control you attested to was not actually in place — MFA enforced for everyone except the four people who found it annoying, an immutable backup copy that was configured but never worked — a material misstatement can give the carrier grounds to reduce, deny, or rescind. Confirm with your broker or counsel how your policy treats it.
That argument arrives at the worst possible moment: your systems are down, you are paying an incident response firm by the hour, and the coverage you were counting on is suddenly a legal question. An honest “no” costs you money at renewal. An optimistic “yes” can cost you the claim.
Practical rule: do not answer any control question from memory. Have whoever administers the system confirm the current configuration, in the console, before you sign.
What to Fix Before Your Renewal
Work backwards from the renewal date. Ninety days is enough time to change your answers honestly.
Ninety days out. Get last year’s questionnaire and go through it line by line with your IT provider, marking each answer as confirmed, partly true, or no. That list is your project plan. Start the slow items now: EDR deployment, backup redesign, the first full restore test, and getting staff through initial training.
Sixty days out. Close the fast gaps. Enforce MFA across all users rather than a subset. Audit the firewall for remote access rules nobody remembers creating. Reduce the administrator list. Turn on advanced email filtering and publish DMARC. Inventory anything running an unsupported operating system and decide what happens to it.
Thirty days out. Write or refresh the incident response plan and run a tabletop against it. Collect the evidence pack — MFA policy screenshot, EDR coverage report, backup and restore test report, patch compliance report, training completion and phishing simulation results, and the plan itself. Then complete the questionnaire against that evidence rather than against anyone’s recollection.
The Part Nobody Puts in the Brochure
Insurance is a backstop, not a security strategy. It reimburses some of your costs; it does not restore your data, unwind a fraudulent wire, or give your staff back the two weeks they spent working on paper. For a small business, recovering from a serious incident routinely runs into the tens of thousands of dollars once you count forensics, rebuild time, and lost work — before any ransom, fine, or lost customer, and before the portion your policy declines to pay.
The genuinely useful thing about the modern questionnaire is that it converts a vague ambition into a dated, prioritized list with a business consequence attached. Most of our clients who worked their renewal seriously ended up with better security and an easier renewal in the same motion. That is a rare combination, and it is worth taking.
Related Questions
Can I be denied cyber insurance coverage for not having MFA?
Yes, and it happens in two different ways. Some carriers will decline to quote at all if multi-factor authentication is not enforced on email, remote access, and administrative accounts, because those are the doors we most often see incidents come through. Other carriers will still write the policy but attach a sublimit or a coinsurance percentage to ransomware and funds transfer losses, which means you carry more of the loss yourself. The more serious risk is answering yes on the application when the control is only partly deployed. The answers you give generally become part of the policy. A material misstatement can give the carrier grounds to reduce, deny, or rescind — confirm with your broker or counsel how your policy treats it.
How far before my renewal should I start working on the questionnaire?
Ninety days is a realistic runway. Some items are fast: turning on multi-factor authentication for the whole company, enabling advanced email filtering, or removing a stale remote desktop rule from the firewall can all happen in days. Others are not. Replacing antivirus with a monitored EDR platform, rebuilding backups so a copy is immutable or offline, running a full restore test, writing an incident response plan, and getting staff through a first round of security awareness training take weeks of scheduling. If you start the week the questionnaire arrives, your only options are to answer no or to answer optimistically, and one of those is much worse than the other.
What evidence do underwriters ask for beyond the questionnaire?
Increasingly they want proof rather than checkboxes. Common requests include a screenshot of the conditional access or MFA enforcement policy showing it applies to all users, a report from the EDR console showing agent coverage across the device count you declared, a backup job report with a successful restore test noted, a patch compliance report showing the percentage of devices current, phishing simulation results, and the incident response plan itself with a date on it. Some carriers also run an external scan of your public IP addresses and domains before they quote, and will ask about anything exposed. Ask your IT provider to keep these artifacts in one folder so renewal is a retrieval exercise instead of a scramble.
Does a good security posture actually lower my premium?
It affects more than the premium number. Strong controls influence whether you get a quote at all, how many carriers compete for your business, what your deductible looks like, whether ransomware and social engineering are covered at the full limit or at a reduced sublimit, and whether the policy carries exclusions for unsupported operating systems or unencrypted devices. In our experience the spread between a well controlled applicant and a poorly controlled one shows up across all of those terms at once. Treat the questionnaire as the security roadmap it effectively is, and the insurance outcome tends to follow.
Renewal Coming Up?
Send us last year’s questionnaire and we will walk it line by line with you — what you can honestly answer yes to today, what is partly true, and what it would take to fix the gaps before your renewal date. No jargon, no scare tactics, just a clear list.
Review My Renewal Questionnaire (888) 735-7701