Most firms treat cyber insurance renewal as a paperwork exercise. The form arrives, someone fills in the answers as best they can, and the policy rolls over for another year. The problem is that most of the answers are guesses.
Insurers have changed. They ask harder questions now, and they use the answers to determine whether a claim is valid. A policy completed with good intentions but inaccurate information can be declined at exactly the moment the firm needs it most.
The gap between what firms declare and what is actually in place is almost always the same thing: nobody has asked the IT provider the right questions before the form is completed. Here are five that are worth asking.
Which Security Controls Are Actually Active Right Now?
Most firms believe they have protections in place because they were discussed at some point, added in part, or included in a proposal. That is not the same as having them live, tested, and applied across every user and device — and insurers now know the difference.
Before the renewal, ask your provider to confirm in plain English exactly what is active. Multi-factor authentication, endpoint protection, email filtering, backups, device encryption, access controls — not what is on the roadmap, and not what was configured for some users. What is running, right now, for everyone.
A strong answer is specific. It names the controls, explains where they apply, and flags where gaps remain. A weak answer is broad and reassuring. If your provider cannot separate what is in place from what is planned or assumed, your renewal answers are already unreliable.
Who Owns Each Security Control?
Cyber insurance forms look simple. What they expose is more complicated. In most firms, nobody has written down who owns what — the provider assumes the firm handles policy decisions, the firm assumes the provider handles security end-to-end, and cloud vendors sit somewhere in the middle. Nobody has joined the dots.
When an insurer asks whether multi-factor authentication is enforced, or whether access is reviewed regularly, the answer depends on who owns that control. If the boundary has never been defined, the answer on the form is a best guess.
Before renewal, ask your provider to map ownership clearly. Which controls do they manage directly? Which require approval or input from the firm? Which depend on a third-party platform? That conversation, however uncomfortable, is far less uncomfortable than a disputed claim.
Can You Evidence Your Answers to Insurers?
Saying a control exists is one thing. Being able to show that it existed and was active at the time of an incident is another. Insurers do not only read renewal forms — after a claim, they ask for proof.
Insurers do not only read renewal forms. After a claim, they ask for proof that the controls named on the form were active and maintained. That evidence might be audit logs, backup reports, patch records, access review history, or MFA enrolment reports. It does not need to be presented to the managing partner in full. It does need to exist and be retrievable quickly.
If your provider’s answer to this question is “we would need to pull that together,” you have found a gap — not just in your insurance position, but in your IT governance more broadly.
What’s Changed in Your Environment Since Last Year?
Most renewals are completed as if nothing has changed. In reality, quite a lot has. New staff, new devices, contractors with access, additional cloud tools, hybrid working arrangements that were meant to be temporary but became permanent — each of those changes can alter your firm’s exposure.
Each of those changes can alter the firm’s exposure. Each can make last year’s answers inaccurate. A good provider reviews what has changed across users, devices, systems, and remote access before the renewal — not as an add-on, but as a standard part of the process.
If your provider has no structured way to track change across the year, the renewal process becomes little more than an annual guess.
If You Had a Claim Tomorrow, Where Would It Fail?
This is the most direct question and the most useful. It asks your provider to stop selling reassurance and name the actual risk.
Every firm has a weak point. Old devices, patching exceptions, incomplete MFA rollout, poor offboarding, untested backups. The question is not whether a gap exists — it is whether your provider can identify it clearly and explain what it means for your insurance position.
A provider who can answer this question honestly understands the difference between keeping systems running and helping the firm manage risk. That is the difference between a renewal completed with confidence and one completed with hope.
If you are not confident your IT provider could answer all five of these questions clearly, that is worth knowing before you sign the renewal form.
The IT Ownership Scorecard takes five minutes and tells you exactly where the gaps are.