TL;DR: Your next cyber insurance renewal application is longer and more specific than last year’s, because carriers rewrote it after big 2023 and 2024 losses. Each question maps to a control that, if missing, let a real claim spiral. Answer honestly, declare any gaps with a fix date, and never overstate your controls. A false answer discovered after a claim can void your entire policy.
If you have a cyber insurance renewal coming up, the application is probably longer than the one you filled out last time, and far more specific. Each new question maps to a security control that, when missing, let a major claim in 2023 or 2024 turn into a payout the carrier never wants to make again.
That means how you answer the form now matters more than it used to. The costly mistake is not a higher premium. It is rescission, where a future claim gets denied because the carrier finds the controls you declared were not actually in place.
This post covers why the application grew, what the new backup, MFA, wire transfer, and antivirus sections are really asking, and how to answer honestly without overstating what you have. It closes with a 30-day checklist to run before you submit.
Why did the cyber insurance application get so long?
The current wave of cyber insurance applications was shaped by three specific losses that carriers paid for in 2023 and 2024. Each one exposed a control gap, and each gap became a new question on your renewal form. Once you know the events behind the questions, the form makes a lot more sense.
The MOVEit supply-chain breach surfaced in late May 2023, when the Cl0p ransomware group exploited an unknown flaw in a widely used file-transfer tool. More than 2,550 organizations and over 66 million people were affected. Carriers paid claims across that whole footprint, and it reshaped how they ask about third-party software risk.
Then the Change Healthcare ransomware attack froze US healthcare claims processing for weeks in early 2024. Attackers got in through a remote access portal that had no multi-factor authentication, then moved through the network for nine days before launching the ransomware. That single missing control drove tighter questions about MFA and backups. Around the same time, a finance worker at engineering firm Arup was tricked into wiring millions after a video call with deepfakes of his own executives, which put wire transfer verification on every underwriter’s checklist. Strong cybersecurity protection is what these questions are really testing for.
What does the backup question ask now?
The backup question is no longer a simple yes or no. It now asks whether your backups are immutable or air-gapped, when they were last tested, and whether your domain administrator account could delete them. An immutable backup cannot be changed or erased for a set period, even by someone using stolen admin credentials. Air-gapped means the backup sits on infrastructure your production network cannot reach.
“We back up Microsoft 365” is no longer a passing answer. Native Microsoft 365 retention is not a backup in the sense the carrier means, and a third-party backup that shares the same login perimeter as your production tenant can be wiped by one compromised global admin.
The strong answer points to a backup platform with object lock or write-once storage turned on, an immutability window of at least 14 days (30 is now preferred), backup credentials kept separate from your production admin accounts, and a recent successful restore test. Daily backups to a network drive with no recent test is the answer most likely to trigger follow-up questions or a premium bump. This is exactly why data backup and recovery has become a front-page item on the application.
How deep do the MFA questions go now?
Far deeper than one checkbox. The current application asks whether MFA is enforced on email, VPN, remote desktop, all administrator accounts, and privileged service accounts. You need a yes on all five for a clean pass, since a single unprotected entry point is exactly how the Change Healthcare attackers got in.
Text-message MFA is now treated as a weak control, because SIM-swap and other attacks have made codes sent by text the easiest factor to steal. Several carriers ask specifically whether you use an authenticator app, a hardware key, or push with number matching instead of text codes. If your admin accounts still rely on text messages, expect a follow-up question or a higher premium.
The newer question most owners have not seen is about privileged access management, or PAM. PAM is a type of tool that keeps admin passwords out of regular password managers, stores them in a vault, rotates them after each use, and logs every session. It means a stolen admin password cannot be used quietly for weeks. If you lack MFA everywhere, coverage is not always denied outright, but expect higher premiums, lower ransomware limits, or exclusions for any incident that traces back to the gap.
The new wire transfer and deepfake questions
After the Arup deepfake fraud, where an employee sent about $25.6 million across 15 transfers on the strength of a faked video call, carriers added wire verification questions to the form. Expect a question about whether you require out-of-band verification for transfers above a set threshold, commonly $10,000 or $25,000, including requests that appear to come from an executive.
Out-of-band verification simply means the person approving a wire calls the recipient back at a phone number you already have on file, not the number on the request email. Many applications now also ask whether staff have been trained on AI voice cloning and deepfake video, which is where security awareness training earns its keep. Accounting firms, law firms with trust accounts, and real estate brokers handling escrow will see this section read most closely, since they move other people’s money.
The strong answer describes a written wire policy requiring callback verification to a known number, dual approval, and annual training that covers deepfakes. Wire transfers approved by email alone are the setup some carriers now decline to cover at all.
The end of the “we have antivirus” answer
Antivirus by itself no longer passes. Traditional antivirus checks files against a list of known threats. Endpoint Detection and Response, or EDR, watches how each device behaves and flags suspicious activity, like a program trying to encrypt your files. Managed Detection and Response, or MDR, is EDR plus a 24/7 team that responds when an alert fires at 2am on a Sunday.
Current applications ask whether you have EDR, whether it covers every endpoint including servers, and whether a round-the-clock team monitors the alerts. The MDR question increasingly comes down to yes or no, and no has a price. If you do not have it yet but plan to, say so plainly with a timeline. Underwriters can work with “MDR scheduled for next quarter, vendor selected.” They cannot work with vague plans.
What is rescission, and why does it matter most?
Rescission is when a carrier voids your policy from day one after finding you overstated your controls on the application, and it is the most expensive mistake you can make. Cyber insurance applications are warranty documents. If a forensic review after a claim shows your environment did not match what you declared, the carrier can treat the policy as if it never existed, deny the claim, and claw back earlier payouts.
Some courts have found the carrier does not even need to prove the misrepresentation caused the loss. The false statement alone can be enough. So the honest approach wins. If a question asks about MFA on all admin accounts and you have a gap, declare the gap and add a fix date. Carriers reward an honest gap with a plan more than a polished answer that falls apart under investigation.
Checking “no” or “in progress” might raise your premium or tighten your terms, and that cost is predictable. Misrepresentation found after a claim leaves you paying the full incident yourself. Working with an experienced IT partner to review the form before you sign is the cheapest insurance of all.
Your 30-day pre-renewal checklist
Most of this is doable in a month if you start now. In week one, confirm MFA on email, VPN, remote desktop, all admin accounts, and service accounts, and move admin MFA off text codes. In weeks one and two, verify your backups are immutable or air-gapped, run a test restore, and save the result with a date and screenshots.
In week two, write a one-page wire transfer policy requiring callback verification for any transfer over your chosen threshold, and have it signed by anyone who can approve payments. In weeks two and three, confirm EDR is on every device and server, and get quotes for EDR or MDR if you only have antivirus. In week three, list your top five software vendors and request their SOC 2 reports or equivalent, noting who responds. In weeks three and four, update your incident response plan and run a 60-minute tabletop exercise, since that is your “tested in the past year” evidence. In week four, sit down with the application and answer honestly, flagging anything you could not fix with a specific date.
Answer the form straight, fix what you can, and declare the rest with a plan. If the gap between where your controls are and where the form wants them feels wider than 30 days, that is worth sorting out now. Want help walking through your renewal application before you sign it? Reach out to our team and we will go through it with you.
Not sure your controls match your application?
The worst time to learn your environment does not match your insurance form is after a claim, when the carrier is reviewing every answer. Z-JAK Technologies can review your current controls against the questions your carrier is asking, close the gaps that are fixable, and help you answer the rest honestly. Schedule a renewal readiness review and protect the coverage you are paying for.
Frequently Asked Questions
What does rescission mean on a cyber insurance policy?
Rescission means the carrier voids your policy from the start after finding a material misstatement on your application. The policy is treated as if it never existed, your current claim is denied, and any earlier payouts under the same policy term can be clawed back. It is the most expensive outcome of an inaccurate application.
Will my cyber insurance be denied if I don’t have MFA on everything?
Not always denied outright. Expect a significant premium increase, lower limits on ransomware coverage, or exclusions for any incident that traces back to the unprotected entry point. The most common gap carriers find is missing MFA on privileged or service accounts.
What is the difference between EDR and MDR on an application?
EDR, or Endpoint Detection and Response, is the technology that watches device behavior and flags suspicious activity. MDR, or Managed Detection and Response, is that same technology plus a 24/7 team watching the alerts and responding. Carriers increasingly want both, and the form often asks about each one separately.
Why are cyber insurance renewal applications longer than before?
Carriers added detailed sections in response to specific 2023 and 2024 losses, including the MOVEit supply-chain breach, the Change Healthcare ransomware attack, and the Arup deepfake wire fraud. Each event drove new questions about backups, MFA, vendor risk, or wire transfer verification.
Can my claim be denied if I answered the application incorrectly?
Yes. A material misstatement on a cyber insurance application can trigger rescission, which voids coverage retroactively. Many courts have found the carrier does not need to prove a direct link between the misstatement and the specific loss, so accuracy on every answer protects you.
