Renewal checklist
The questions cyber insurers ask professional firms at renewal
The pattern across carrier questionnaires is consistent. These are the twelve questions we see most, and what usable evidence looks like for each.
Before the list
Accuracy matters more than a perfect score.
Cyber-insurance applications used to be a page of checkboxes. Renewal questionnaires for small and mid-size firms now run 12 to 20 pages and ask line-by-line control questions, with proof expected.
Carriers review application answers when a claim is filed, and answers that did not match reality at the time of the incident can put the claim at risk. An honest “no, and here is our plan” is safer than an optimistic “yes.”
-
Is MFA enforced on all email accounts?
The trap word is “all.” Insurers mean every account, not most accounts.
Usable evidence: An enforcement export from Microsoft 365, plus a short list of exceptions and the compensating control for each.
-
Is MFA required for remote access and admin accounts?
VPN, remote desktop, remote support tools, and every privileged account.
Usable evidence: A conditional-access policy export and a list of admin accounts showing MFA status.
-
Is MFA required on the backup environment?
The question firms least expect. Attackers target backups first, so insurers ask whether the backup console has its own credentials and MFA.
Usable evidence: The backup-console access list and MFA setting.
-
Do all devices run EDR, not just antivirus?
Endpoint detection and response on every workstation and server, ideally monitored. Legacy antivirus alone no longer satisfies most questionnaires.
Usable evidence: A coverage report showing enrolled devices against the device inventory. The gap between those two lists is the finding.
-
What is your patching cadence, and who owns it?
Expect questions about critical patches on internet-facing systems and a defined timeline.
Usable evidence: A one-page patch policy with an SLA and a compliance report. “Our provider handles it” is not evidence; a report from the provider is.
-
Are any systems past end-of-support?
Old servers, legacy practice software, and unsupported operating systems.
Usable evidence: An inventory with OS versions, plus a plan or isolation note for anything unsupported.
-
Are backups separated from your main environment?
Sync tools such as OneDrive are not backup. Insurers ask whether backup copies are offline, offsite, or immutable, with separate credentials.
Usable evidence: The backup architecture in two sentences, plus recent job reports.
-
When did you last test a restore?
Backups that run are not the same as backups that restore. Questionnaires increasingly ask for the last tested restore date and recovery-time expectations for critical systems.
Usable evidence: A dated restore-test record showing what was restored, how long it took, and the result.
-
Do you have a written incident response plan?
Written, owned by someone, and ideally exercised. Insurers ask who you would call and in what order.
Usable evidence: The plan itself plus a dated tabletop or walkthrough note, even a short one.
-
Do staff receive security training and phishing simulation?
Cadence matters: annual at minimum, with completion tracking.
Usable evidence: A completion report and the last simulation summary.
-
Are access rights reviewed, and are leavers removed promptly?
Admin lists, shared logins, service accounts, and how fast departing staff lose access.
Usable evidence: A current admin-account list, a dated access-review note, and the offboarding checklist actually in use.
-
How do you verify payment-detail changes?
Wire-fraud questions now appear on most applications: does any bank-detail change get verified out of band, and is the finance team trained?
Usable evidence: The written verification step and a training note.
The real question behind all twelve
Can your firm produce evidence that matches what leadership believes?
In most firms the controls partly exist, but the proof is scattered across an IT provider, an office manager, and someone’s memory.
That is the gap the Technology Operations Review closes. We collect the evidence across your environment, mark anything unprovable as Not Verified rather than assumed, and hand your leadership an ownership map and a 90-day plan. Fixed CAD $2,500, 100% credited toward remediation or Managed Technology Operations. The findings belong to you either way.
Book a 20-minute fit callThis page is general information drawn from patterns in carrier applications and broker guidance. It is not insurance, legal, or compliance advice; your broker and carrier define your actual requirements.
Start with the review
Start with a 20-minute fit call.
Enter your details, choose a platform, then pick a time. Prefer email? Write to info@pineit.ca or use the contact form.