Employee Owned Since 2022  |  Serving Chicagoland since 1996Support: 630-523-0220Sales: 630-526-8030Remote support

WEBIT Learning Hub

Cyber Insurance Renewal Checklist for Small Businesses

Most businesses treat cyber insurance renewal as paperwork that lands on the office manager’s desk two weeks before the policy expires. That timing is the problem, because the application now asks technical questions that someone must answer truthfully and may have to prove later. In my experience running service delivery, the renewals that go smoothly start about 90 days out and treat the form as an evidence project.

Why cyber insurance renewal got harder

A few years ago, the renewal form was a page of yes or no boxes. Today, carriers ask how you enforce multifactor authentication, which devices run endpoint detection, and how often you test backups. Some also want screenshots or a signed statement from your IT provider.

The reason is simple, since claims got expensive. The FBI’s 2023 Internet Crime Report counted 880,418 complaints and $12.5 billion in reported losses, and business email compromise alone accounted for $2.9 billion.

So underwriters now want proof that basic controls exist before they write or renew a policy.

The real risk is answers that do not match reality

Here is where I see IT providers fall short most often. Someone fills out the application from memory, checks “yes” on MFA for all remote access, and moves on. However, nobody confirmed that the old VPN account or the shared scanner mailbox follows that rule.

That gap matters after an incident. The carrier’s forensic team will look closely at how the attacker got in. If the entry point contradicts an answer on your application, you could face a coverage dispute at the worst possible moment.

The fix is not complicated. Instead of answering from memory, answer from reports. Every “yes” should have a report, screenshot, or written policy behind it.

Who should own the renewal

Renewals fail when ownership is fuzzy. Finance owns the premium, the broker owns the carrier relationship, and IT owns the technical answers. As a result, each group assumes another group checked the details.

Pick one internal owner, usually the operations lead or office manager. That person runs the timeline, collects the evidence, and gets final sign-off from an executive. Your IT provider should support the owner with reports and plain answers, not just a quick signature.

Also decide who signs the application. The signer is attesting to the facts, so that person should see the evidence before signing. A five-minute review now is far cheaper than a denied claim later.

A 90-day timeline that works

90 days out: get the current form

First, pull a copy of last year’s application and ask your broker for this year’s version. Carriers change their questions often, so do not assume the form looks the same. Then share both with your IT provider and book a working session.

60 days out: verify and close gaps

Next, walk through every technical question with the person who manages your systems. Mark each answer as confirmed, partly true, or not true. Anything partly true becomes a small project with an owner and a due date.

30 days out: build the evidence packet

Finally, collect the proof in one shared folder. That way, the answers you submit match documents you can hand over later. It also makes next year’s renewal much faster.

Your cyber insurance renewal checklist

Use this list to test each answer before anyone signs. Each item names the evidence to collect, not just the control.

  • MFA where it counts: an export showing MFA enforced for email, remote access, and every admin account, including service and shared accounts.
  • Endpoint detection coverage: a device report from your EDR tool compared against your real device inventory, so you can show there are no gaps.
  • Backups that restore: the date and result of your last test restore, plus proof that one copy is offline or immutable.
  • Patching cadence: a compliance report showing how quickly critical updates reach workstations and servers.
  • Admin account control: a list of everyone with administrator rights and the reason each person needs them.
  • Email protections: your SPF, DKIM, and DMARC records plus your email filtering settings.
  • Training records: dates of security awareness training and phishing simulations for all staff.
  • Incident response plan: a current written plan that lists the carrier’s breach hotline and approved vendors.
  • Unsupported systems: a list of any end-of-life operating systems or servers and the plan to retire them.

Questions that trip up small businesses

A few questions cause most of the trouble. For example, “Do you require MFA for all remote access?” sounds simple. In practice, it covers remote desktop tools, vendor portals, and cloud admin consoles, not just the VPN.

Another common question asks whether backups are segmented or offline. A backup that sits on the same network with the same credentials does not count. Ransomware operators look for those backups first, because deleting them raises the pressure to pay.

Also watch the questions about vendors. Carriers increasingly ask who has remote access to your environment. That includes your IT provider, your line-of-business software vendor, and anyone else with a login.

Talk to your broker before you sign

Your broker is a partner in this, so use them. Ask what changed in the carrier’s requirements this year. Then ask which sublimits apply to social engineering and funds transfer fraud, because those losses are common and often capped low.

If you know about a gap, tell the broker. It is far better to disclose a control in progress, with a completion date, than to check “yes” and hope. In many cases, a documented plan keeps the conversation productive.

How WEBIT approaches this

We treat the renewal as part of ongoing cybersecurity work, not a once-a-year scramble. Our team reviews the application with the client, answers from live reports, and flags anything that is not fully true yet.

We also keep the evidence current through the year, so the next renewal starts from a finished packet. Because we take no commissions or kickbacks from insurers or security vendors, our advice stays focused on closing real gaps. You can see how this fits into our broader managed IT services.

Key takeaways

  • Start your cyber insurance renewal about 90 days before the policy expires.
  • Answer every technical question from a report or document, not from memory.
  • Name one internal owner and make sure the signer sees the evidence.
  • Disclose known gaps with a remediation date instead of guessing.
  • Ask your broker about sublimits for social engineering and funds transfer fraud.

Want a second opinion on your renewal answers before you sign? Talk to an owner.

Talk to an owner

Want help applying this to your business? A 30-minute discovery call gets you honest advice.

Schedule a discovery call

Industry whitepapers

In-depth guides for 13 industries, from medical to manufacturing.

Browse whitepapers →

Estimate your IT cost

Real per-unit pricing, updated as you go.

Open the calculator →

Keep reading

Two new clients per month. Maximum.

Ready to talk to an owner?

Every conversation starts with an honest look at where you are today. No pressure, no pitch deck, and no obligation.