top of page
CETech 20 year logo.png
CETech 20 year logo.png

Renewing This Fall? Here's What That Questionnaire Is Really Asking

Sep 11
4 min read




The email usually shows up in September. Your broker forwards a renewal packet, and somewhere in it is a cyber insurance questionnaire that runs several pages and asks questions your office manager cannot answer from memory. Multi-factor authentication on remote access? Immutable backups? Endpoint detection and response? Privileged account separation? A few years ago that form was half a page and mostly a formality. It is not a formality anymore.


If you are staring at a cyber insurance renewal questionnaire right now and hoping somebody in the building knows the answers, you are in good company. We hear from Rochester-area business owners every fall who are in exactly that spot. The good news is the form is not a trick. Carriers are asking about a fairly predictable set of controls, and most of them are things you would want in place regardless of what an underwriter thinks.



Why the cyber insurance renewal questionnaire got so long



Insurers write these questions because they pay claims. When enough ransomware claims come out of businesses that had no multi-factor authentication on their VPN, the next round of applications asks about multi-factor authentication on the VPN. The questionnaire is essentially a list of the controls that showed up as missing when things went wrong.


That is why the tone has shifted from "do you have antivirus" to very specific, verifiable questions. Underwriters want to know what is deployed, where it is deployed, and whether there are exceptions. "Mostly" is not an answer they love.


It also means the questionnaire doubles as a decent security checklist. If you cannot answer a question with confidence, that gap is worth fixing whether or not the policy renews smoothly.






The questions that trip businesses up



A few areas cause the most trouble in our experience:



  • Multi-factor authentication scope. Not just email. Carriers usually ask about remote access, administrative accounts, and any cloud platform holding company data. Businesses often have it on Microsoft 365 and nowhere else.

  • Backups that survive an attack. The question is rarely "do you back up." It is whether backups are separated from the production network, whether they can be deleted by someone with domain admin rights, and when you last restored from them on purpose.

  • Endpoint detection and response. Traditional antivirus and EDR are not the same product category, and the form usually names the difference. Answering yes because you have the free tool that shipped with Windows may not hold up.

  • Privileged access. Do everyday users have local admin rights? Do IT staff use separate accounts for administrative work? Both questions show up regularly now.

  • Security awareness training. Carriers want to know it happens on a schedule and that it is documented, not that you sent one warning email after a scare.

  • End-of-life systems. Any server or workstation running an operating system that no longer receives security updates is a red flag, and there is usually a direct question about it.



None of that is exotic. It is the baseline most managed IT providers work toward anyway. The problem is usually that nobody has assembled the evidence in one place.







Answer honestly, then fix the gaps



This is the part worth being blunt about. Do not guess on the form, and do not let anyone check a box because it seems close enough. A cyber insurance application is a document you sign. If a claim ever lands and the carrier finds that the controls described on the application were not actually in place, the conversation about coverage gets very uncomfortable, very fast.


A more useful approach: answer what is true today, mark the gaps, and put dates on fixing them. Underwriters deal with businesses in progress all the time. What they cannot work with is a form that turns out to be fiction.


In practice, most of the common gaps are not expensive. Turning on multi-factor authentication across remote access and admin accounts is configuration work. Pulling local admin rights off everyday user accounts takes planning but not much money. Getting a real backup test on the calendar costs an afternoon. The genuinely bigger line items are usually replacing end-of-life hardware and moving from consumer-grade antivirus to a managed detection product.






Give yourself more than a week



The single most common mistake is starting the questionnaire two days before it is due. That leaves no room to close anything. If your renewal lands in November, September is the right time to open the form and see what you cannot answer.


The timing works out well in Rochester. Late summer into early fall is when most businesses here are back to a full schedule but not yet buried in year-end. Once Thanksgiving hits, half your staff is out and nobody wants to touch a server. Doing this work in September also lines it up with budget season, so if the questionnaire turns up something that needs real dollars, you can put it in next year's plan instead of scrambling for an emergency purchase.



What we do with clients at renewal time



For the businesses we support, the renewal questionnaire is a normal part of the year. Send us the form and we fill in the technical sections with what is actually deployed, flag anything that is a no, and give you a short list of what it would take to turn each no into a yes. You get an accurate application and a punch list, not a mystery.


If we are not your IT provider, the same idea still works. Whoever manages your systems should be able to answer these questions with specifics. If they cannot, or if the answers keep coming back as "I think so," that itself is worth paying attention to.


One more thing worth saying out loud: insurance is not a security strategy. A policy pays out after a bad week. It does not un-encrypt your files, un-wire the money, or explain the downtime to your customers. Treat the questionnaire as a prompt to get the controls right, and the coverage becomes what it is supposed to be, which is a backstop.






Get your answers in order before the deadline



CETech has been handling managed IT and cybersecurity for Rochester and Buffalo businesses for more than two decades, across manufacturing, engineering, construction, healthcare, professional services and more. If you have a renewal packet sitting in your inbox and no clean way to answer it, we are happy to walk through it with you.


Call us at 585-441-0055, email [email protected], or book a time through cetechno.com. Bring the questionnaire. We will tell you where you stand.


Comments


bottom of page