If you’ve got a cyber insurance renewal coming up, you’ve probably already noticed it: the application is longer than the one you filled out last year. A lot longer, in some cases. What used to be a page of yes/no boxes is now several pages of specific, technical questions about MFA configurations, backup immutability windows, wire transfer verification, and vendor risk.
It’s tempting to speed through it and check the boxes that make you look good. That instinct is exactly what gets small businesses across Michiana into serious trouble, because these applications function as legal warranty documents, not as a formality. Answer optimistically in a few spots, and you can end up with a policy that looks solid on paper and evaporates the moment you actually need it.
Here at Ma3SP, renewal season is one of the times business owners in South Bend, Goshen, and Elkhart lean on us most, because the form has gotten specific enough that most owners genuinely don’t know how to answer half of it without help. We wrote this to walk you through why the application got longer, what each new section is actually asking, how to answer honestly without overstating your controls, and what to fix in the 30 days before you submit.
Why the renewal application got longer
The current generation of cyber insurance applications was shaped by three specific claim events from 2023 and 2024, and understanding them explains almost every new question you’ll see on your form.
The MOVEit supply-chain breach surfaced on May 28, 2023, when Progress Software received the first reports of unusual activity from customers. The Cl0p ransomware group had been exploiting a previously unknown vulnerability in Progress Software’s MOVEit Transfer file-sharing tool, with activity detected by some researchers as early as February of that year. By late 2023, more than 2,650 organizations and over 66 million individuals had been affected, with totals climbing further into 2024. Carriers paid claims across that entire footprint, and the experience reshaped how underwriters ask about third-party software risk on every application since.
Then the Change Healthcare ransomware incident in February 2024 froze U.S. healthcare claims processing for weeks. The attacker gained network access on February 12, 2024, and deployed ransomware on February 21, with downstream impact on pharmacies, providers, and patients across the country. Coverage from HIPAA Journal noted that the absence of multifactor authentication on a key entry point made the initial intrusion possible in the first place. Industry analysts have estimated the cyber insurance loss from this single event at over $250 million, and the response was tighter questions about backup immutability and incident response readiness on nearly every carrier’s form.
The Arup deepfake wire fraud, also from early 2024, reframed how underwriters approach social engineering entirely. A finance employee at the engineering firm’s Hong Kong office transferred $25.6 million across 15 wires after a video call with what appeared to be the company’s CFO and other executives — all of whom turned out to be AI-generated deepfakes. The fraud went undiscovered for about a week, until the employee happened to contact Arup headquarters about a “secret transaction.” Out-of-band callback verification for wire transfers is now on every underwriter’s checklist because of this single case.
If you run an e-commerce store handling cardholder data, a healthcare practice with protected health information, an accounting or law firm moving client funds, or a real estate brokerage handling escrow, your application is the longest of all. You sit squarely in the loss categories carriers got burned on, and the underwriters know it.
The backup question changed
The backup question on cyber insurance applications has tightened materially since 2023. What used to be a single yes/no question now asks whether backups are immutable or air-gapped, when they were last tested, and whether they can be deleted using domain administrator credentials.
Expect wording along the lines of: “Are backups stored in an immutable or air-gapped state, tested for restoration within the past 12 months, and inaccessible to domain administrator credentials?” “Microsoft 365 backup” is no longer a passing answer on its own, and third-party backups that share the same identity perimeter as your production tenant can be wiped by a compromised global admin just as easily as native retention can. We cover this specific question in detail in our companion article on what immutable backup actually means, if you want the full breakdown.
MFA questions go deeper than one checkbox
MFA was once captured as a single yes/no question on most applications. The current generation asks whether MFA is enforced on email, VPN, remote desktop, all administrator accounts, and privileged service accounts — and the answer needs to be yes on all five for a clean pass.
SMS-based MFA is now treated as a weaker control. SIM-swap attacks and SS7 vulnerabilities have made text codes the weakest authentication factor available, and several carriers now ask specifically whether your MFA uses an authenticator app, hardware token, or push with number matching, rather than SMS. If you’re still on SMS for admin accounts, expect a follow-up question or a premium adjustment.
The privileged access management (PAM) question is the one most owners haven’t seen before. PAM is a category of tool that keeps administrator credentials out of regular password managers, vaulting privileged credentials, rotating them on use, and logging every session. That last part matters: it means a stolen admin password can’t be used unnoticed for weeks before someone catches it. A strong answer describes exactly that setup. Weaker answers — admin passwords stored in a shared password manager with annual rotation — will usually trigger follow-up underwriting. Shared admin accounts that never rotate and produce no audit log at all are the configuration most likely to result in sub-limits or non-renewal.
Will your cyber insurance be denied outright if you don’t have MFA everywhere? Not always. Expect significant premium increases, sub-limits on ransomware coverage, or exclusions for any incident that traces back to the unprotected entry point instead.
The wire transfer and deepfake verification questions
After the Arup case and a string of business email compromise losses, carriers added callback verification questions to their applications. Callback verification means that before sending any wire above a defined threshold — commonly $10,000 or $25,000 — the person authorizing the transfer calls the recipient at a phone number previously verified and stored, not the number sitting on the request email.
Expect wording like: “Does your organization require out-of-band verification using a previously known phone number for all funds transfer requests above [threshold], including requests appearing to come from executives?” Several current applications now ask separately whether staff have been trained on AI voice cloning and deepfake video risks specifically. The Arup case made that question relevant for every carrier writing coverage in professional services.
Accounting firms, law firms with escrow or trust accounts, and real estate brokers see this section scrutinized most carefully, and for good reason. Anyone moving other people’s money is a soft target and an expensive claim when wire fraud lands. A strong answer references a written wire transfer policy requiring callback verification to a verified number above a stated threshold, dual approval, and annual social engineering training that includes deepfake awareness. Informal verification practice without a written policy usually gets flagged for follow-up. Wire transfers authorized by email approval alone are the configuration carriers are now declining to cover at all.
EDR, MDR, and the end of the “we have antivirus” answer
Traditional antivirus scans files against a list of known threats. Endpoint Detection and Response (EDR) watches behavior on each device and flags suspicious activity — a process trying to encrypt files or escalate privileges, for example. Managed Detection and Response (MDR) is EDR plus a 24/7 team watching the alerts and responding when something fires at 2am on a Sunday, which is exactly when most attackers move.
Current applications ask whether you have EDR deployed, whether it covers 100% of endpoints including servers, and whether a 24/7 security operations center monitors and responds to alerts. The MDR question is increasingly yes or no, and the no answer has real pricing consequences.
If you don’t have MDR yet but plan to add it, say so plainly with a timeline. Underwriters can work with “MDR deployment scheduled for Q2 with vendor selected.” They cannot work with vague answers about future plans that never turn into an actual date.
The vendor risk questions
Supply chain questions used to be a single yes/no item. After MOVEit and Change Healthcare, carriers now want a full section on the software vendors holding your data.
Expect questions like: “List your top five software vendors with access to sensitive data and confirm whether each provides a SOC 2 Type II report or equivalent.” If you’ve never asked your practice management software vendor for a SOC 2 report, that conversation is overdue, and it’s a quick email to send.
You’re not expected to audit every vendor’s security program in exhaustive detail. The carrier wants to see that you know who your top vendors are, what data they hold, and that you’ve asked the basic questions. An honest “we’ve identified our top five vendors and requested SOC 2 reports from three, with two outstanding” reads far better to an underwriter than a confident answer that falls apart the moment it’s checked.
The mistake to avoid: misrepresentation and rescission
The most expensive answer on a cyber insurance application is the one that overstates the security controls you actually have in place. These applications are warranty documents. If a forensic investigation after a claim finds your environment didn’t match what you declared, the carrier can rescind the policy entirely.
Rescission means the policy is treated as if it never existed, your claim is denied, and any prior payouts under the same policy term can be clawed back after the fact. Some courts have found that the carrier doesn’t even need to prove a direct link between the misrepresentation and the loss — the misrepresentation itself is enough to void the policy.
The cleanup approach is direct and, frankly, a relief once you commit to it. If a question asks about MFA on all admin accounts and you have a gap, declare the gap and include a remediation date. Carriers reward honest gaps with a plan more than they reward polished answers that don’t survive forensic review after a real incident.
Checking “no” or “in progress” on the form may raise your premium or tighten your coverage terms somewhat. That cost is predictable and you can plan around it. Misrepresentation discovered after a claim can void the policy entirely, and the timing means you absorb the full incident cost yourself, at the worst possible moment.
The 30-day pre-renewal checklist
Work through this in order. Most items are genuinely achievable in a month if you start now, and none of them require ripping out your existing IT stack.
Week 1. Confirm MFA on email, VPN, remote desktop, all administrator accounts, and any service accounts that support it. Move admin MFA off SMS to an authenticator app or hardware token.
Weeks 1 to 2. Verify your backups are immutable or air-gapped. Run a test restore, and document the result with a date and screenshots you can point to on the application.
Week 2. Write a one-page wire transfer policy requiring callback verification to a previously verified phone number for any transfer over your chosen threshold. Get it signed by anyone who can authorize payments.
Weeks 2 to 3. Confirm EDR is deployed on every endpoint and server. If you only have traditional antivirus, get quotes for EDR or MDR now so you can answer with a real deployment timeline instead of a vague intention.
Week 3. Identify your top five software vendors and request SOC 2 reports or equivalent attestations. Note who responded and who didn’t.
Weeks 3 to 4. Document or update your incident response plan, then run a 60-minute tabletop exercise with your leadership team. Keep the notes — that’s your “tested in the past 12 months” evidence.
Week 4. Sit down with the application and answer honestly. Flag anything you couldn’t fully fix, with a specific remediation date attached.
Frequently Asked Questions
What does rescission mean on a cyber insurance policy?
Rescission means the carrier voids the policy from inception after discovering material misrepresentation on the application. The policy is treated as if it never existed, the current claim is denied, and any prior payouts under the same policy term can be clawed back.
Will my cyber insurance be denied if I don’t have MFA on everything?
Not always denied outright. Expect a significant premium increase, sub-limits on ransomware coverage, or exclusions for incidents that trace back to the unprotected entry point. The most common gap is MFA on privileged or service accounts specifically.
What’s the difference between EDR and MDR on an insurance application?
EDR is the technology that watches device behavior and flags suspicious activity. MDR is the same technology plus a 24/7 team watching the alerts and responding. Carriers increasingly want both, and the application often asks about each one separately.
Why are cyber insurance renewal applications longer than they used to be?
Carriers added detailed sections in response to specific 2023 and 2024 losses, including the MOVEit supply-chain breach, the Change Healthcare ransomware incident, and the Arup deepfake wire fraud. Each event drove changes to backup, MFA, vendor risk, or wire transfer questions on subsequent applications.
Can my cyber insurance claim be denied if I answered the application incorrectly?
Yes. Material misrepresentation on a cyber insurance application can trigger rescission, which voids coverage retroactively. Many courts have found that the carrier does not need to prove a causal link between the misrepresentation and the specific loss.
Graham’s Take
Most of the businesses we work with in South Bend and Goshen aren’t trying to game their insurance application — they just genuinely don’t know how to translate “do you have PAM” or “is your MFA phishing-resistant” into a yes or no they can stand behind. That’s the exact gap we close. If your renewal is coming up in the next few months, run through the 30-day checklist above, and if you want a second set of eyes before you sign anything, that’s a conversation we’re happy to have with no strings attached.
