Chant's IT
Back to Insights
Security7 min read

Cyber insurance is getting harder to get — here's what your carrier actually wants to see

Cyber-insurance renewal questionnaires are getting longer, premiums are climbing, and coverage is getting narrower. Here's what carriers actually check for and how to prepare.

Every renewal cycle, more of our clients hand us their cyber-insurance questionnaire and ask for help filling it out. The questionnaires used to be two pages. Now they're eight, sometimes twelve, and the questions are specific enough that a lot of businesses realize halfway through that they don't actually have the controls they thought they had.

Here's what changed, what carriers actually check, and what to have in place before your renewal date to avoid non-renewal or a giant premium hike.

Why the market got tight

Cyber-insurance carriers spent the mid-2020s writing a lot of policies at generous terms, then paid out a lot of ransomware claims. Loss ratios went upside down. The market corrected in stages: first by raising premiums, then by narrowing coverage, and now by requiring specific security controls as a condition of coverage.

The new normal: carriers won't insure you if you can't demonstrate baseline controls. And if you claim you have controls that a post-incident forensic investigation shows you didn't actually have, they can deny the claim. Misrepresentation on the questionnaire is not a small deal.

The controls carriers now expect

These aren't all universal — different carriers weight things differently — but this is the composite of what we see across the questionnaires for Cape Breton small and mid-sized businesses.

1. MFA everywhere, no exceptions

Multi-factor authentication on email, VPN, remote desktop, admin accounts, and privileged applications. The "no exceptions" part is the tricky one. We often see MFA rolled out for most users but exempted for "the owner because it's inconvenient." That single exemption is often the entry point for the compromise, and carriers know it.

2. EDR / managed threat response

Basic antivirus doesn't cut it anymore. Carriers want endpoint detection and response (EDR) — the modern generation of endpoint security that detects behaviour, not just signatures. Bonus points for managed detection and response (MDR / MTR) with 24/7 human monitoring on top.

Our Managed Threat Response add-on is designed exactly for this — Bitdefender GravityZone (already standard on our managed IT tiers) plus 24/7 human analysts. That combination satisfies the EDR + MDR line item on essentially every cyber-insurance questionnaire we've seen.

3. Backup that's tested and off-network

Carriers ask specifically: are backups isolated from the primary network (so ransomware can't encrypt them), are they tested regularly, and can you recover within a defined RTO? "We back up to a NAS in the office" is not a good answer anymore.

4. Patching cadence

Documented patching for critical vulnerabilities within 14 days, sometimes 7. Managed IT plans handle this automatically. Businesses without a managed plan tend to fail this one.

5. Security awareness training

Documented ongoing training for staff on phishing and social engineering. A once-a-year video isn't enough anymore. Carriers want to see ongoing simulated phishing tests with tracked click-through rates and improvement over time. Our phishing-simulation service is built for this specifically.

6. Access control and privilege management

Least-privilege access (users don't have admin rights on their own machines unless they need to), separate admin accounts for admin work, documented departing-employee procedures. Many small businesses fail the departing- employee question — either accounts stay active for weeks after departure, or someone keeps using them.

7. Incident response plan

Written down. Not "we'll figure it out." Who calls whom, in what order, with what phone numbers. Where's the backup stored, who has access, who contacts the insurance carrier.

How to prepare — the 60-day pre-renewal drill

If your renewal is 60 days out, this is what we'd do with you:

  1. Get last year's questionnaire. If it's a new carrier, get a blank current one from your broker. See what they're asking.
  2. Do an honest gap analysis. Every question — do you actually have this control, or does it sound like you should? "Yes" answers you can't defend under investigation are worse than "no" answers you can improve on.
  3. Close the biggest gaps first. MFA everywhere, EDR deployed, backup tested. Those three carry most of the weight.
  4. Document what you have. Screenshots of the policy in Microsoft 365. Reports from the EDR platform. Backup restore test results with dates. This becomes the evidence file for renewal AND for a claim later.
  5. Consider a formal security assessment. If the questionnaire has questions you can't confidently answer, our Comprehensive Security Assessment will produce a formal document that answers most of them and identifies remediation for the rest.

What to do if you get non-renewed

It happens more than it used to. If your carrier declines to renew, don't panic — but do act fast:

  • Your broker can shop the risk to other carriers. Some will still write, especially if you have documented improvements underway.
  • Coverage typically stays in force through the current policy period, so you have runway to fix things and shop.
  • Use the non-renewal as leverage to fund security improvements internally. Nothing loosens an IT budget like "our insurance carrier said we can't be insured until we fix these things."

The bottom line

Cyber insurance in 2026 is a security-controls audit with a policy attached. The businesses that renew smoothly are the ones that would probably be fine without the insurance too, because they've done the work. The businesses that struggle are the ones that were coasting on "we've never been hit" — which stops being a defence the moment carriers start asking questions.

If your renewal is coming up and you'd rather not do this alone, that's exactly what we help clients with. Free 15-minute call to talk through your questionnaire and figure out the fastest path.


Cyber insurance renewal coming up?

Free walkthrough — we'll look at your questionnaire together and identify the gaps before your carrier does.