Cybersecurity · Last updated

Cyber Insurance Renewal: Presenting Your Firm Well

Rates are falling, but your own renewal turns on evidence. A month-by-month plan, and what each question on the proposal form is really testing.

Nerdster Team

Cyber insurance renewals have a habit of arriving as an admin task and turning into a technical project. The questionnaire asks about MFA coverage, restore testing and patch timings, and the honest answers turn out to live in four different places, none of which is the person filling in the form.

The good news is that the process rewards preparation more than it rewards spend, and the market itself is friendlier than it was. This is a companion to our cyber insurance readiness page, which covers what underwriters ask for and why. Here we go through the renewal itself: the timetable, the form, and how to build an evidence file once so that next year takes an afternoon.

Where the cyber insurance market actually is

In Rebooting growth: 2025 cyber insurance report, published on 24 September 2025, Howden describes cyber rates “continuing to fall in the low-double-digit range”, with competition among insurers increasing. That is the backdrop most firms are renewing into.

A softening market does not mean your renewal is automatically easier. It means capacity exists for firms that present well, and that a weak submission is now a more visible outlier than it used to be. The lever you control is not the market. It is the quality of what you put in front of it.

Working backwards from your renewal date

Ninety days out. Ask your broker for last year’s completed questionnaire and, if the insurer has released it, this year’s. Read your own answers from twelve months ago with fresh eyes. The useful question is not “is this still true?” but “could I produce the evidence for this today?” Those are different tests, and the gap between them is where most renewals get uncomfortable.

Sixty days out. Close what you can. Enrolling the handful of accounts that slipped out of MFA, running a full restore test and writing up the result, refreshing training completions and scheduling a tabletop exercise are all weeks of work rather than months. Anything requiring new spend or a migration needs to be a plan with a date rather than a promise.

Thirty days out. Gather the evidence into one place. One folder, one file per answer, each with the date it was produced and the system it came from. This is the artefact that makes next year straightforward.

Fourteen days out. Complete the form with whoever runs your IT sitting alongside whoever signs it. Most of the awkwardness at renewal comes from a technical question being answered by someone who cannot check it and a commercial question being answered by someone who cannot see the estate.

What each proposal question is really testing

These are the questions we are asked to help clients answer most often, and what sits behind each one.

“Do you enforce multi-factor authentication?” The question behind it is on what proportion of accounts, and on which systems. Email and VPN are assumed. What the underwriter is looking for is whether the answer covers administrative accounts, service accounts, and the secondary cloud platforms — the practice management system, the accounting package, the file-sharing tool. A tenant-wide enrolment report answers this in one page. It is also still a genuine differentiator: the government’s Cyber Security Breaches Survey 2025/26, fielded between August and December 2025 and published on 30 April 2026, found that only 47% of UK businesses have any two-factor authentication in place.

“What endpoint protection do you use?” The product name is the least interesting part of your answer. Give the coverage: how many endpoints you own, how many are enrolled, and how the difference is accounted for. Then say who reviews what it finds and during which hours.

“Do you take regular backups?” The underwriter already assumes yes. What they want is the date of your last full restore, the recovery time you achieved, and whether at least one copy is out of reach of anyone holding domain administrator credentials. Our backup and disaster recovery checklist covers what a restore test should actually prove.

“How quickly do you apply critical patches?” Give a measured figure from patch reporting, and give the exceptions honestly — the machine that cannot be rebooted during trading hours, the application that lags its vendor. A number with named exceptions reads as a firm that knows its estate.

“Do you run any unsupported software?” Answer this one carefully, because it is easy to get wrong by accident. If you still have Windows 10 machines, the position and the plan both need to be on the form; our note on the Windows 10 ESU deadline sets out the options and the dates.

“Do you have a documented incident response plan?” The date of the last exercise is what the question is reaching for. It is also a place where a well-run firm stands out sharply: the Breaches Survey found only 25% of UK businesses have a formal incident response plan at all, rising to 57% of medium-sized businesses and 76% of large ones.

“Do you provide security awareness training?” Completion rates and phishing simulation results, with dates. Here too the baseline is low — 19% of UK businesses ran staff training or awareness activity in the past year, unchanged from the year before.

“Have you experienced an incident in the last three to five years?” Answer it fully, including the ones you handled quietly. Partial disclosure is the single most avoidable problem in this whole process. It is worth noting that firms are getting better at spotting incidents themselves: M-Trends 2026, published by Mandiant and Google Cloud on 23 March 2026, found 52% of intrusions were detected internally, up from 43% the year before. An incident you found, contained and documented is a considerably better story than a clean sheet an underwriter has no way to verify.

Building the evidence file once

The reason renewals feel heavy is that the evidence is assembled from scratch every year. It does not need to be.

For each answer on the form, keep the report that supports it, the date it was produced, and the system it came from. MFA enrolment. Endpoint coverage reconciled against the asset list. The restore test write-up with its recovery time. Patch compliance. Training completions and simulation results. The incident response plan with the date of its last exercise. Six artefacts, refreshed on a schedule.

Once that file exists, the renewal stops being an investigation and becomes a transcription. It is also exactly what a client security questionnaire or a procurement due-diligence pack asks for, so the same folder does more than one job.

Written documents are worth keeping current for a related reason: they are getting rarer among smaller firms, which makes having them more visible than it used to be. Among UK small businesses the Breaches Survey recorded formal cyber security policies falling to 52% from 59%, business continuity plans that address cyber security falling to 44% from 53%, and risk assessments falling to 41% from 48% — all back to roughly where they were two years earlier.

Answer accurately, and keep a record of why

A commercial insurance proposal is a legal presentation of risk. Part 2 of the Insurance Act 2015 requires a fair presentation: disclosure of every material circumstance the insured knows or ought to know, presented in a manner “which would be reasonably clear and accessible to a prudent insurer”, with material representations of fact that are “substantially correct”.

There is nothing to be nervous about in that, and it is a useful discipline rather than a trap. It points at three habits:

  • Answer each technical question from a report rather than from memory.
  • Keep the report you relied on, with its date, alongside the submission.
  • Tell your broker during the year when something material changes, rather than saving it for the next renewal.

Firms that work this way tend to find the conversation with their underwriter gets shorter each year, because the answers are consistent and the supporting material is already in a recognisable shape.

Using your broker properly

A broker who writes cyber regularly is worth a great deal at this stage, because carriers weight the same controls differently and they know which appetite fits which security profile. Give them the technical detail rather than a summary, and give it early enough that they can market the risk rather than simply renew it.

It is also reasonable to ask what your submission is doing to your terms — not just to the premium, but to the retention, the sub-limits, and any conditions attached to specific perils. Those are often where an improved control set shows up first.

What to do with an honest “no”

Some answers will be no, and that is a normal position rather than a failure. What matters is what accompanies it.

A bare no invites the underwriter to assume the worst. A no with a scope, an owner and a date invites them to price a known quantity. “Multi-factor authentication is enforced across Microsoft 365 and remote access for all users; two legacy line-of-business applications do not support it and are scheduled for replacement in Q1” is a completely respectable sentence to put on a form, and a much better one than a yes you would struggle to stand behind.

Getting this into the routine

The firms that find renewals easy are not the ones that spend the most. They are the ones where the evidence is a by-product of how the estate is run, so nobody has to go looking for it.

That is the shape of what we do. Our managed IT and cyber security work is built so the reporting exists anyway: MFA enrolment, endpoint coverage, restore tests with recorded recovery times, patch compliance, training records and a rehearsed incident response plan. At renewal we complete the technical sections alongside your broker and put the evidence behind each answer.

If your renewal is coming up and you would like a second opinion on the submission, send us the questionnaire and your renewal date and we will go through it with you. Our cyber insurance readiness page explains what underwriters look for in more depth, and Cyber Essentials is often the most efficient way to put independent evidence behind several answers at once.

cyber insurancemanaged ITcompliancerenewal

FAQ

Cyber Insurance Renewal: your questions answered

When should we start preparing for a cyber insurance renewal?

Around ninety days out is comfortable. That is enough time to get last year's questionnaire in front of you, work out which answers you can still evidence, and close anything that has drifted — enrolling the accounts that slipped out of MFA, running a restore test, refreshing training records. Thirty days is enough to gather evidence for a position that is already good. It is not enough to change the position itself.

Our broker has sent a questionnaire we cannot fully answer. What should we do?

Answer what you can from evidence, and treat the gaps as a short work list rather than a problem with the form. Most questionnaires have three or four questions that turn out to be genuinely awkward, and they are usually the same ones: how widely MFA is actually enforced, when you last restored from a backup, how quickly critical patches reach every machine, and when your incident response plan was last exercised. Each of those is fixable inside a renewal window if you start early enough. If one is not fixable in time, say so plainly and describe the plan and the date — an underwriter can price a known gap with a remediation date attached far more comfortably than an unclear answer.

Will Cyber Essentials get us a cheaper premium?

It gives the underwriter something independent to rely on rather than your own description, which helps, and it carries cover of its own: the NCSC states that any UK organisation with a turnover under £20m certifying across its whole organisation is automatically entitled to Cyber Liability Insurance arranged by IASME. Whether it moves your specific premium is the underwriter's decision and nobody can promise it in advance. What it reliably does is shorten the conversation, because several of the questions on the form are the scheme's five controls restated.

Should we answer yes if a control is only partly in place?

No, and a qualified answer is usually better received than people expect. A proposal is a legal presentation of risk under Part 2 of the Insurance Act 2015, which asks for material representations of fact that are substantially correct and a presentation that is reasonably clear to a prudent insurer. In practice that means writing what is true: which systems are covered, which are not, and what is scheduled. An accurate partial answer with a date on it is a normal thing for an underwriter to read. An unqualified yes that turns out to have exceptions is the version that causes difficulty later.

Do we have to tell our insurer if something changes during the policy year?

Talk to your broker as soon as anything material shifts — a significant new system, a merger or acquisition, a change of IT provider, a control you described that you have since had to switch off. Your broker can tell you whether it needs to be notified under your particular policy. Keeping them informed during the year also makes the next renewal much easier, because the story is already on record rather than being reconstructed twelve months later.

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

0330 043 7414

Mon-Fri 8am-6pm

[email protected]

We reply within 2 hours

71-75 Shelton Street

Covent Garden, London WC2H 9JQ

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report