The cyber insurance questionnaire you receive at renewal is not paperwork to rush through. Carriers now treat it as a verification of specific security controls: multi-factor authentication, endpoint detection, tested backups, and incident response readiness. Answer inaccurately and you risk claim reduction, denial, or policy rescission when an incident exposes the gap.
This is distinct from the underwriting process for a new policy (for that, see what cyber insurers check before quoting). At renewal, the carrier already has a baseline on your business. The questionnaire asks what has changed, probes the same controls at greater depth, and expects you to produce evidence on request. If your security posture has drifted since last year, the questionnaire will surface it.
What security controls do cyber insurance questionnaires ask about?
Every major cyber insurance questionnaire now covers the same core controls. Major carriers ask about MFA, EDR, backups, and incident response in similar language. The Insurance Bureau of Canada's Cyber Savvy Canada assessment mirrors many of the same questions. This is what you should expect to answer:
- Multi-factor authentication (MFA): Is MFA enforced on email, VPN and other remote access, privileged and admin accounts, and the backup console? Carriers increasingly ask whether you use phishing-resistant methods (hardware keys, passkeys) rather than SMS.
- Endpoint detection and response (EDR): Do you run EDR on all workstations and servers, and is it monitored around the clock? Legacy antivirus no longer satisfies most carriers.
- Offsite and immutable backups: Is at least one backup copy stored offline or in immutable storage? Is the backup console protected with MFA? When did you last test a full restore?
- Patch management: How quickly do you apply critical security updates, especially to internet-facing systems? Unpatched VPN appliances and firewalls are a leading ransomware entry point.
- Security awareness training: Do employees receive regular phishing and social engineering training, and do you track completion?
- Incident response plan: Do you have a written plan that names who is called, who decides, and how the insurer's breach team is engaged? Has it been tested or rehearsed in the last 12 months?
If you answer yes to any of these but cannot produce evidence when asked, you have introduced risk into your policy. A yes that cannot be substantiated is worse than acknowledging a gap.
Why do inaccurate questionnaire answers put your coverage at risk?
Carriers underwrite risk based on what you attest to. If an incident reveals that a control was missing or not enforced, the carrier has grounds to dispute the claim. In severe cases, the policy can be rescinded entirely, leaving you with no coverage at all.
The most cited example is Travelers v. International Control Services (ICS) in 2022. ICS attested on its application that it used MFA. After a ransomware attack in May 2022, Travelers discovered that ICS had MFA only on its firewall, not on the server that was compromised or other digital assets. Travelers filed for rescission in July, and the parties jointly agreed to void the policy. On August 30, 2022, the federal court entered an order rescinding the policy and declaring it null and void from inception.
Misrepresentation does not require intent to deceive. If you genuinely believe a control is in place but it is not, or if it covers only part of your environment, the outcome can be the same. Carriers are not testing your honesty; they are testing whether the risk they priced matches the risk they are covering.
How often are cyber insurance claims denied or reduced?
Denial rates are not published consistently across the industry, so there is no single authoritative number. What is clear from broker experience and case law is that the most common path to a disputed claim is a control that was attested to on the application but not in place at the time of the incident. Partial MFA deployment, untested backups, and lapsed incident response plans are recurring themes in coverage disputes.
Coalition's 2026 Cyber Claims Report offers a useful counterpoint: 64% of closed claims resulted in no out-of-pocket loss for the policyholder. That success, however, depends on the controls being in place at the time of the incident. When a forensic investigation reveals a gap between what was attested and what was deployed, the claim conversation changes.
What evidence should you gather before renewal?
Answering the questionnaire accurately requires more than memory. Before your renewal meeting, assemble these artifacts so you can answer each question with confidence:
- MFA enrollment report: Export from Microsoft Entra ID, Google Workspace, Okta, or your identity provider showing which accounts have MFA enforced and which, if any, are exempt. Carriers want to see email, remote access, and admin accounts covered.
- EDR or MDR coverage report: A device list from your endpoint console confirming that agents are installed and healthy on every workstation and server. Note any gaps (unmanaged devices, legacy systems).
- Backup restore test record: Documentation of a successful restore test within the last 12 months, showing what was restored, when, and by whom. A backup job log is not a restore test.
- Incident response plan: The current version, with a date of last review or tabletop exercise. If you have not reviewed it in over a year, do so before renewal.
- Training completion report: Records showing security awareness training completion by employee, ideally including phishing simulation results.
- Patching and vulnerability summary: Evidence of how quickly critical patches are applied, especially on internet-facing systems.
If you cannot produce any of these, treat that as a gap to close before renewal rather than a question to hedge on the form.
How do Canadian and US requirements compare?
The core controls are the same on both sides of the border. Carriers operating in Canada and the United States ask about MFA, EDR, backups, and incident response in nearly identical language. The underlying risk is the same: ransomware, business email compromise, and funds transfer fraud do not respect borders.
In Canada, the Insurance Bureau of Canada (IBC) has published guidance through its Cyber Savvy Canada initiative. IBC's assessment asks about written information security plans, incident response procedures, disaster recovery, employee training, access controls, and regular audits. These questions map directly to what carriers ask on renewal questionnaires. An IBC survey from August 2025 found that only 22% of Canadian SMBs carry cyber insurance and only 47% say they are prepared for a cyber attack.
In the United States, CISA's guidance for small businesses emphasizes the same controls: MFA on all critical systems, regular patching, tested backups, and a culture of security starting at the CEO level. CISA specifically recommends phishing-resistant MFA (FIDO authentication) as the most effective protection against credential theft.
Whether you operate in Canada, the United States, or both, the controls that satisfy underwriters are the controls that reduce your actual risk.
How should you prepare before your cyber insurance renewal?
Start at least 60 days before your renewal date. This gives you time to close gaps rather than attest to controls that are partially in place. Work through these steps with your IT team or managed service provider:
- Audit MFA coverage. Export the enrollment report and confirm that MFA is enforced, not just available, on email, remote access, and all admin accounts. If SMS is your only factor, plan the move to app-based or phishing-resistant authentication.
- Verify EDR deployment. Pull the coverage report and confirm agents are installed on every device. Note any legacy systems or unmanaged devices that are not covered.
- Test a backup restore. Do not assume backups work because jobs complete. Run a restore test, document the date and outcome, and confirm at least one copy is offline or immutable.
- Review and date your incident response plan. If it has not been reviewed in over a year, update it. If it has never been tested, run a tabletop exercise with your leadership team.
- Compile evidence. Assemble the reports and documentation before the renewal meeting so you can answer questions with specifics, not estimates.
If you find gaps you cannot close before renewal, discuss them with your broker. An honest gap is better than an inaccurate attestation that surfaces during a claim.
What question should you ask your IT provider before renewal?
Before you sign the renewal questionnaire, ask your IT lead or managed service provider one question: "Can you produce the evidence an underwriter would ask for within a week?"
If the answer is yes, you are ready for renewal. If the answer is uncertain or involves checking with someone else, you have identified the gap that needs attention now, not after an incident. The controls that satisfy underwriters are the same controls that reduce your exposure. Preparing for the questionnaire and preparing for a breach are the same project.
If you are unsure where your organization stands against this checklist, our free quick security assessment is a fast way to surface the gaps underwriters look for before an underwriter finds them for you.
This article is intended for general informational purposes only and does not constitute professional security, legal, or insurance advice. Cyber insurance requirements vary by carrier, industry, and jurisdiction. Statistics and case references are based on public reporting, industry data, and guidance documents as of the date of publication and may change. Organizations should consult a licensed insurance broker and qualified cybersecurity professionals before making decisions about cyber insurance coverage or security controls.