
Cyber insurance renewal questionnaires have quietly turned into security audits. Five years ago you attested to a few basics. Now carriers ask control-by-control questions, and increasingly they validate the answers with external scans before they quote.
Two things matter here: getting coverage at a sane premium, and — far more important — not having a claim denied because an attestation didn't match reality.
The controls carriers ask about
- MFA everywhere, not just email. Email, VPN and remote access, privileged/admin accounts, and your RMM or management tooling. "MFA on Microsoft 365" is no longer a sufficient answer.
- EDR, not antivirus. Carriers want managed detection and response with human monitoring, not a signature scanner on a schedule.
- Immutable, tested backups. Offline or immutable copies that ransomware can't encrypt, plus evidence of an actual restore test. Untested backups are the single most common gap we find.
- Privileged access separation. No daily-driver accounts with domain admin rights.
- Email filtering and phishing training. With records of completion, not just a subscription.
- Patch cadence with evidence. Critical patches inside a defined window, reportable from your RMM.
- A written incident response plan. Named contacts, escalation path, breach notification obligations — and a tabletop exercise on record.
- End-of-life systems. Expect a direct question about unsupported operating systems.
Why "yes" on a form you can't prove is dangerous
An application is a representation. If you attest to MFA on all remote access and a claim investigation finds a VPN account without it — and that's how the attacker got in — you are in a coverage dispute at the worst possible moment. Under-attesting and paying slightly more is a much better trade than a denied claim.
How to prepare in the 90 days before renewal
- Get last year's application. Read what you actually claimed. Verify each line.
- Run the gaps down. MFA coverage audit, restore test with a documented result, EDR deployment coverage report, patch compliance report.
- Write the IR plan if you don't have one, then run a 60-minute tabletop and keep the notes.
- Check your own external attack surface — open RDP, expired certificates, forgotten subdomains. Carriers scan this.
- Assemble an evidence pack. Screenshots and reports, dated. It shortens underwriting and often improves terms.
What good answers are worth
Clients who walk into renewal with documented controls consistently see better outcomes than those who don't — and more importantly, they're measurably harder to breach. The questionnaire is annoying, but it's a reasonable baseline.
We do this with clients every year
BITS regularly fills out these questionnaires alongside our clients and produces the supporting evidence. If your renewal is coming up and you're not sure how you'd answer, let's talk before the deadline pressure starts.


