The Cyber-Insurance Renewal Checklist

Your renewal application wants proof this year — not promises.

The questionnaire got longer. The questions got harder. Somewhere on the form is a control you either have or you do not. And the premium — or the renewal itself — turns on that answer. A cyber-insurance application is now a security exam with a price attached.

Twenty-seven percent of small businesses carry no cyber coverage at all. The ones that do now earn their premium with controls, not paperwork (Guardz, Dec 2025). This is prep, not fear. Walk in knowing what they will ask and where you stand.

Performance Connectivity is a managed IT and technology advisory firm in Purchase, NY. We help Westchester and Fairfield County businesses pass cyber-insurance underwriting. A modern renewal turns on four controls: enforced MFA, EDR on every device, tested backups, and a written incident-response plan. This page breaks down the ten questions insurers ask, so you know where you stand before you sign.

Before the checklist

Four controls sit under almost every question.

Underwriters have settled on the same short list. Get these four right and most of the form answers itself. Get one wrong and you will feel it in the premium, or in a denied claim later.

MFA everywhere that mattersMulti-factor on email, remote access, and every admin account. Insurers no longer ask whether you have MFA. They ask where you do not, and treat each gap as the risk.
Endpoint detection (EDR)Not the antivirus that came with the laptop. Underwriters want a tool that spots an attack in progress and can cut the machine off. On every device and server, not most of them.
Tested backups — not just running backupsA backup that has never been restored is a guess. The real questions: have you restored from it lately, are copies kept offline or locked, and how long does a real restore take?
A written incident-response planOnly 34% of firms have a plan built with a professional. And 80% of those avoided major damage in an attack (Guardz, Dec 2025). Insurers ask because the plan is the difference between a bad week and a closed business.
The full checklist

Ten questions your insurer will ask — decoded.

For each item you get three things. The question the way the application asks it. What a real “yes” takes. And the gap most firms find when they look honestly. Tell us where to send it, and it opens right here on this page.

Open the checklist

See all ten — and where the gaps usually hide.

The full checklist opens on this page the moment you submit. We will also send you a copy. Tim reads these himself. No rep, no queue.

A copy goes to Tim, who replies the same business day. 5.0 average across 15 Google reviews · Same three partners since 1997.

Straight answers

Straight answers to fair questions.

What does a cyber-insurance application actually ask for?

Modern applications focus on a short list of controls. Enforced multi-factor login. Endpoint detection and response (EDR). Tested, restorable backups. A written incident-response plan. Email filtering with staff training. Patching. Limited admin rights. Encryption. And controlled remote access. Underwriters settled on these because they predict claims. Get them right and most of the form answers itself.

Why did our cyber-insurance premium go up or renewal get harder?

Insurers now price on controls, not paperwork. The questionnaire got longer and the questions got harder. Carriers are underwriting the real security behind each answer. A gap on one required control shows up as a higher premium or a declined renewal. Think MFA that is not enforced everywhere, or backups that have never been test-restored.

Can a claim be denied if our application answers were not accurate?

Yes, and that is the real risk. When you bind or renew, you attest to specific controls. If a claim check shows the attestation was not true, the carrier can deny coverage at the moment you need it most. Maybe MFA was off on an account, or a backup was never restorable. That is why every "yes" should be backed by something you could show them.

What is EDR, and isn't antivirus enough?

EDR, or endpoint detection and response, watches for attacker behavior and can cut off a hacked machine. The antivirus bundled with a laptop cannot do that. Underwriters ask for EDR on every workstation and server, not most of them. Built-in antivirus counted as EDR is one of the most common gaps firms find.

How can PCI help before our renewal?

We review your setup against the exact controls the application asks for. We show you which answers are a real yes and which are a gap. Then we fix what is worth fixing before you submit. Bring the application, or just the questions that made you pause. Fifteen minutes with a partner is usually enough to know where you stand.

30 Years — coming in 2027