A single magenta-lit form page among dim stacked documents on black, the cyber insurance renewal application
Cyber Insurance • 7 min read

What a Cyber Insurance Renewal Application Asks Now

Marsh recorded cyber rates down 4% globally in Q2 2026, the twelfth straight quarterly decline, while underwriting evidence standards tightened. What a cyber insurance renewal application asks now, and the folder to have ready.

A cyber insurance renewal application now asks for evidence, not attestation. Where a 2022 form accepted a checkbox saying multi-factor authentication was enabled, a 2026 form asks which accounts, which method, and increasingly for an export that shows the policy is enforced. The change matters because the answers become part of the contract.

I am Amelia S. Gagne, CEO of Kief Studio. This page is about preparing for the application itself. The companion pieces are the exclusions that decide whether a claim pays and why cyber insurance claims get denied. The broader coverage conversation is cyber insurance questions for a small business.

A single magenta-lit form page among dim stacked documents on black, the cyber insurance renewal application
The application is underwriting input first and contract language second. Both roles matter after a loss.

Why does the cyber insurance renewal application carry so much weight?

Two reasons, and only the first one is obvious.

The obvious one is pricing. Controls drive the quote, and underwriters segment harder than they used to. Howden's 1.1.26 market report describes carriers rewarding verifiable controls and clean claims histories while pricing other exposures more cautiously.

The less obvious one is that the application is a set of representations. If what you wrote does not match what forensics finds later, the insurer has grounds to revisit the policy. That is a different failure mode from a coverage dispute, and a worse one.

This is why the application deserves the same care as a contract review rather than being handed to whoever has time. The same logic applies to the paperwork in technology vendor due diligence: the file you build is the file someone reads back to you.

What is the market actually doing in 2026?

Two credible sources point in different directions, and the honest answer is that both are describing something real.

Marsh's Global Insurance Market Index recorded cyber rates down 4% globally in the second quarter of 2026 and down 2% in the US, the twelfth consecutive quarterly decline. Howden Re puts the cumulative fall at 27% from the mid-2022 peak.

S&P Global Ratings, meanwhile, has forecast premium increases of 15% to 20% in 2026, citing claim severity and the cost of AI-assisted attacks.

The reconciliation is segmentation. Average rate is falling while the spread widens. A buyer with documented controls sits on one side of that spread and a buyer without them sits on the other, which is roughly what Howden means by sharper risk selection. Price softness is not the same as underwriting softness.

Which questions changed the most?

Four areas account for most of the new specificity.

Multi-factor authentication. The question moved from whether MFA exists to where it applies. Email, remote access, administrative accounts, and cloud consoles are asked about separately because they fail separately. A deployment that covers the VPN but not the administrative console is a partial answer, and partial answers are where later disputes live.

Backups. The modern question is the date of the last successful restore test, not whether backups run. Those are different facts. Coalition's 2026 Cyber Claims Report found a record 86% of businesses refused to pay a ransom in 2025, and attributes that to viable backups and rehearsed incident response. Restore testing is the thing that converts a backup into leverage. The longer version is how to back up a business against ransomware.

Endpoint coverage. Not whether you run endpoint detection, but on what percentage of endpoints. Coverage gaps cluster on the machines nobody owns: the kiosk, the contractor laptop, the server everyone forgot.

Generative AI use. Newer forms include a block on AI tooling, which is a disclosure question rather than a controls question. If your team uses AI tools the application does not know about, the disclosure is wrong. That is the practical case for governing shadow AI by enabling it and for having an AI policy written before you need one.

Four hardware security tokens on a dark desk with one lit magenta, the MFA control coverage a cyber insurance renewal application asks about
Controls are now scored by coverage rather than presence. Partial deployment is a distinct answer from full deployment.

What does proof look like?

The general shape is that a screenshot shows a setting exists and an export shows a setting is enforced. Underwriters have learned the difference.

Practical artifacts worth having in one folder before the application lands:

  • Conditional access or MFA policy export, showing scope and exclusions. The exclusions list is the part that matters.
  • The last restore test: date, what was restored, how long it took, who signed off.
  • Endpoint agent coverage as a count against your asset inventory, not as a percentage with no denominator.
  • Privileged account list, with the service accounts included. Machine identities are the ones that get missed, which is the subject of non-human identity.
  • Your vendor and sub-processor list, because a question about third parties is now standard. See the sub-processor problem.

Assembling this once and maintaining it is less work than assembling it annually under deadline. It is the same asset inventory that an internal audit needs, so the marginal cost is low.

Who should answer the questions?

Whoever can be wrong about the answer should not be the only person who reviews it.

In the Travelers v. International Control Services matter, the application was signed by both the CEO and the employee responsible for network security. Two signatures did not prevent the mismatch between what was represented and what was deployed. More signatures are not the control. A reviewer who checks answers against exports is the control.

For a small team, the workable pattern is one person assembling evidence, a second person reading the answers against that evidence, and the broker seeing both. Brokers are generally willing to flag an answer that will not survive a claim, because a rescinded policy is not a win for them either.

One magenta document lit above dim duplicates on black, evidence supporting a cyber insurance renewal application
An exported policy shows enforcement. A screenshot shows that a setting exists somewhere in the console.

What happens between renewals?

This is the quiet part. The representations describe a state, and states drift. A control disabled in March for a migration and never re-enabled is a real exposure at the November claim, even though the application was accurate in January.

Systems drift toward mess without maintenance, and security controls drift the same way everything else does. A short quarterly check against the application answers closes most of that gap, and it is the same discipline described in automation maintenance is the job.

If a control genuinely changes, the answer is to tell the carrier rather than to hope. Mid-term notification is unglamorous and it preserves the coverage you paid for.

A magenta line slowly separating from a dim parallel line on black, control drift between cyber insurance renewal application cycles
Answers describe a state. States drift, and the drift is invisible until a claim asks about it.

Where this connects to how you build

Most of what an application asks about is architecture, not product. Identity boundaries, backup isolation, and least privilege are design decisions, which is why security architecture first makes the paperwork easier rather than harder.

Brian Gagne handles security architecture at Kief Studio and has for the fourteen years we have worked together. When the question is control design rather than underwriting paperwork, briansgagne.com is the deeper read. For cloud posture review specifically, JDR Security Solutions does cloud health checks and IAM audits. The model for running the stack day to day is at ltfi.ai.

Related reading

Frequently Asked Questions

What does a cyber insurance renewal application ask about MFA?

Current forms ask where multi-factor authentication applies rather than whether it exists. Expect separate questions for email, remote access, administrative accounts, and cloud consoles, and expect to be asked which method is used. Many carriers now request an export of the enforcing policy rather than an attestation.

Are cyber insurance rates going up or down in 2026?

Both, depending on the buyer. Marsh recorded cyber rates down 4% globally in Q2 2026, the twelfth consecutive quarterly decline, while S&P Global Ratings has forecast increases of 15% to 20% for 2026. The average is falling while the spread between well-documented and poorly documented risks widens.

What evidence should I gather before the application?

An MFA or conditional access policy export including its exclusions, the date and result of the last backup restore test, endpoint agent coverage counted against an asset inventory, a privileged and service account list, and a current vendor list. Keep them in one folder and refresh it quarterly.

What happens if a control changes mid-policy?

Tell the carrier. Representations describe a state, and a control disabled during a migration and never restored is a real gap at claim time even if the original answers were accurate. Mid-term notification preserves the coverage you already bought.

Who should sign the application?

Signature count is not the safeguard. The useful control is a second reviewer who checks each answer against an exported artifact before anyone signs, plus a broker who sees both the answers and the evidence.

Cybersecurity Oct 1, 2026 • 8 min

Why Cyber Insurance Claims Get Denied

Coalition found 64% of closed cyber claims in 2025 resolved with no out-of-pocket cost. Most claims pay. Here is what separates the ones that do not, and the five habits that close the gap.

Cybersecurity Sep 19, 2026 • 8 min

Cyber Resilience Tools Cost vs Breach Recovery and Fines

Cyber resilience tools cost versus breach recovery and fines is a recurring number you choose against a one-time number you do not. IBM's 2026 average breach is $4.99 million globally and $11.5 million in the US. The fine is rarely the largest line.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe