Why Your Cyber Insurance Renewal Form Got Longer
If your cyber insurance renewal is coming up, you’ve probably noticed the application is longer and more specific than last time. That’s not accidental. Insurers reshaped their questions after paying out on a string of significant 2023 and 2024 claims — and every new section maps to a control that, when missing, let an incident escalate into a major loss.
Three events drove most of the changes:
- The MOVEit supply-chain breach (May 2023) affected more than 2,650 organisations and 66 million individuals, reshaping how underwriters ask about third-party software risk.
- The Change Healthcare ransomware attack (February 2024) froze healthcare claims processing across the US for weeks. The initial intrusion was made possible by missing MFA on a key entry point — a detail that’s now front and centre on every renewal form.
- The Arup deepfake wire fraud (early 2024) saw a finance employee transfer $25.6 million USD after a video call with AI-generated versions of company executives. Out-of-band callback verification for wire transfers is now standard on every underwriter’s checklist.
If your business handles cardholder data, health information, client funds, or escrow, expect the longest version of the form. These are the loss categories insurers got burned on.
The Controls Insurers Are Actually Testing
Immutable Backups
The backup question has tightened considerably. It’s no longer a simple yes/no — insurers now want to know whether your backups are immutable or air-gapped, when they were last tested, and whether they can be deleted using your domain administrator credentials.
Native Microsoft 365 retention is not a backup in the sense the insurer means. A backup that shares the same identity perimeter as your production tenant can be wiped by a compromised global admin. The ACSC’s guidance on ransomware aligns with what insurers now expect: immutable, tested backups with credentials separated from your production environment, and an immutability window of at least 14 to 30 days.
If you can’t answer this section clearly, fix it before you submit.
Multi-Factor Authentication
MFA used to be a single checkbox. Now insurers ask whether it’s enforced across email, VPN, remote desktop, all administrator accounts, and privileged service accounts. SMS-based MFA is treated as a weaker control — SIM-swap attacks have seen to that. If your admins are still authenticating by text message, expect a follow-up question or a premium adjustment.
Privileged Access Management (PAM) is the question most businesses haven’t seen before. A PAM solution vaults administrator credentials, rotates them after each use, and logs every session. Without it, a stolen admin password can sit in an attacker’s hands for weeks undetected. Microsoft Entra ID offers privileged identity management capabilities that directly support this requirement.
Wire Transfer and Deepfake Verification
Post-Arup, insurers now ask whether your organisation requires out-of-band callback verification — using a previously known phone number, not the number on the request email — for funds transfers above a defined threshold. Several applications also ask specifically whether staff have been trained on AI voice cloning and deepfake risks.
A written wire transfer policy with dual approval and documented callback procedures is a strong answer. Email-only authorisation is the configuration insurers are increasingly declining to cover.
Endpoint Detection and Managed Response
Traditional antivirus is no longer a passing answer. Insurers want to know whether you have EDR (Endpoint Detection and Response) deployed across all endpoints and servers, and whether a 24/7 team is monitoring and responding to alerts — that’s MDR. If you’re mid-deployment, say so with a timeline. Vague answers about future plans don’t help your application.
Vendor Risk
After MOVEit, supply chain questions expanded into a full section. Insurers want to know your top software vendors with access to sensitive data and whether each provides a SOC 2 Type II report or equivalent. If you haven’t asked your key vendors for that documentation, now is the time.
The One Mistake That Voids Everything
Cyber insurance applications are warranty documents. If a forensic investigation after a claim finds your environment didn’t match what you declared, the insurer can rescind the policy — treating it as if it never existed, denying the claim, and potentially clawing back prior payouts.
Under Australian insurance law and consistent with how the Privacy Act and Notifiable Data Breaches scheme interact with post-incident scrutiny, misrepresentation carries serious consequences. Some courts have found that insurers don’t need to prove a direct link between the misrepresentation and the loss — the misrepresentation itself is enough.
If you have a genuine gap, declare it with a remediation date. Insurers handle honest gaps with a plan far better than polished answers that don’t survive forensic review.
A 30-Day Pre-Renewal Checklist
- Week 1: Confirm MFA is enforced on email, VPN, RDP, and all administrator and service accounts. Move admin MFA off SMS to an authenticator app or hardware token — Microsoft Entra ID supports this natively.
- Weeks 1”“2: Verify backups are immutable or air-gapped. Run a test restore and document it with a date and screenshots.
- Week 2: Write a one-page wire transfer policy requiring callback verification for any transfer above your chosen threshold. Get it signed by anyone who can authorise payments.
- Weeks 2”“3: Confirm EDR is deployed on every endpoint and server. If you’re still on traditional antivirus, get quotes and a deployment timeline ready.
- Week 3: Identify your top five software vendors and request SOC 2 reports or equivalent attestations.
- Weeks 3”“4: Update your incident response plan and run a short tabletop exercise with your leadership team. Keep the notes — that’s your evidence of a tested plan.
- Week 4: Complete the application honestly. Flag anything you couldn’t fix, with a specific remediation date.
Get the Right Answers Before You Submit
If the gap between where your controls sit and where the form wants them to be feels wider than 30 days, you need a clear-eyed conversation before you submit — not after a claim.
The IT TechNinjas work with Brisbane businesses to close those gaps using Microsoft Defender, Entra ID, Intune, and Purview, alongside the broader Essential Eight controls the ACSC recommends. We can walk through your renewal application with you, identify what’s fixable in the time you have, and help you answer every question accurately.