Insurance

Cyber Insurance Renewal: What IT Admins Must Check

Cyber Insurance Renewal: What IT Admins Must Check

Know what attackers see before they do. See a sample Radar scan report →

There's a story circulating in MSP communities that should make every IT admin and small business owner uncomfortable: a managed service provider lost their cyber insurance policy after 11 years — not because of a breach, not because they filed too many claims, but because of a minor service scope discrepancy the insurer decided violated policy terms at renewal. Eleven years of premiums. Gone.

If you think your long-standing relationship with your insurer protects you, think again. The cyber insurance market has fundamentally changed, and the consequences of getting caught without coverage during an incident are severe.

The Threat Landscape Is Forcing Insurers to Tighten Controls

Insurers aren't tightening requirements arbitrarily. They're responding to a measurable increase in claim frequency and severity driven by increasingly professional threat actors.

According to The Hacker News, the DevMan Ransomware-as-a-Service portal now centralizes payload builds, victim management, and affiliate payouts — essentially a turnkey ransomware business that lowers the barrier to entry for attackers and dramatically increases the volume of incidents hitting small businesses. When more businesses file claims, insurers respond by scrutinizing what controls were in place before they pay out.

The operational damage is real. A ransomware attack recently disrupted a Japanese frozen-food chain, halting logistics and production — exactly the kind of business continuity catastrophe cyber insurance is designed to cover. But coverage only pays when the policy requirements were met before the incident occurred.

And the threat vectors keep expanding. According to The Hacker News, Cl0p affiliates are actively targeting internet-exposed PTC Windchill and FlexPLM installations with unauthenticated remote code execution. If your policy requires you to maintain patched, non-internet-exposed systems and you haven't done that, you may be handing your insurer a reason to deny your claim.

Even the act of filing a claim has become dangerous. The Hacker News reports that CTM360 research has uncovered how insurance-sector phishing has evolved into real-time account hijacking operations — attackers are now intercepting insurance interactions to steal credentials and redirect claim payments. The entire insurance process, from application to claim, is now an attack surface.

What Insurers Are Actually Checking at Renewal

Most small business owners signed their cyber policy during a 20-minute application process and haven't looked at it since. That was fine in 2019. It's not fine now.

Here's what modern cyber liability policies increasingly require — and what underwriters are verifying:

Multi-Factor Authentication (MFA) — Not just on email, but on remote access tools, VPNs, and privileged accounts. Policies that previously accepted SMS-based MFA are now specifying app-based or phishing-resistant MFA. If you haven't addressed this yet, our post on SMS MFA deprecation and what small businesses need to do before Microsoft's September 2026 deadline is required reading before your next renewal.

Endpoint Detection and Response (EDR) — Basic antivirus is no longer sufficient. Many policies now explicitly require EDR on all endpoints. "We have Windows Defender" may not satisfy this requirement depending on how your policy defines EDR.

Patching and Vulnerability Management — Policies increasingly include language requiring timely patching of critical vulnerabilities. If Cl0p is exploiting unpatched business software and your insurer finds out you were running a vulnerable version at the time of your incident, expect a coverage dispute.

Backup and Recovery Controls — Offline or immutable backups are frequently specified. A backup that ransomware can reach and encrypt won't satisfy this requirement.

Incident Response Plan — Some policies now require a documented IR plan. "We'd call our IT guy" is not a plan.

Access Controls and Privilege Management — Least-privilege access, separation of duties, and offboarding procedures. If a former employee's credentials were used in a breach, insurers will ask whether you had proper offboarding controls. Our employee offboarding security checklist walks through exactly what needs to happen when someone leaves.

The Renewal Trap: Attestation Without Verification

Here's where small businesses get hurt. Most renewal applications ask you to attest that controls are in place. You check the boxes based on your best understanding. But if you haven't actually verified your environment recently, you may be attesting to controls that have drifted, been misconfigured, or were never fully implemented.

This is called a material misrepresentation, and it gives insurers grounds to deny claims even after you've paid premiums for years.

The fix is to verify before you attest — not after an incident. That means running an actual scan of your external attack surface, auditing your MFA enrollment, confirming your EDR is deployed and reporting, and testing your backup restores. As we covered in our guide to vulnerability scanning vs penetration testing, a vulnerability scan is often the right starting point for exactly this kind of pre-renewal verification.

A Pre-Renewal Checklist for IT Admins

Before you sign your next renewal application, work through this list:

  1. Pull your current policy and read the security controls section — not the summary, the actual policy language.
  2. Inventory your MFA coverage — every user, every application, every remote access point.
  3. Run a vulnerability scan on your internet-facing systems and review open findings against your policy's patching requirements.
  4. Audit EDR deployment — confirm every endpoint has a reporting agent and that alerts are being reviewed.
  5. Test a backup restore — not just confirm backups are running, but actually restore a file or system.
  6. Review your offboarding log — confirm all departed employees and contractors have had access revoked.
  7. Document your IR plan — even a one-page procedure satisfies most policy requirements.
  8. Talk to your broker — ask specifically what the underwriter will verify this year that they didn't verify last year.

Don't wait until the renewal form arrives. By then you have days, not weeks, to remediate findings.

Take Action

Cyber insurers are now enforcing the controls they've been listing in policies for years. The businesses that get caught are the ones that assumed nothing had changed.

Before your next renewal, run a scan. Know what your external attack surface looks like. Know what a motivated attacker — or a motivated underwriter — would find.

Oscar Six Security's Radar gives small businesses and IT admins an affordable, straightforward way to verify their security posture before renewal season. At $99 per scan, it's a fraction of what a denied claim or a lapsed policy will cost you.

Focus Forward. We've Got Your Six.

Frequently Asked Questions

What security controls do cyber insurance companies require?

Most modern cyber liability policies require MFA on all remote access and email, endpoint detection and response (EDR) on all devices, timely patching of critical vulnerabilities, offline or immutable backups, and a documented incident response plan. Requirements vary by insurer and policy tier, so always read your specific policy language rather than relying on the application summary.

Can a cyber insurance claim be denied if I didn't have the right security controls?

Yes. If you attested to having security controls in place at renewal and an investigation reveals those controls were absent or misconfigured, insurers can deny your claim on grounds of material misrepresentation. Running a vulnerability scan before renewal — like Oscar Six Security's Radar ($99) — helps you verify your actual posture before you sign anything.

How much does a pre-renewal vulnerability scan cost for a small business?

A professional vulnerability scan for a small business typically ranges from $99 to several hundred dollars depending on scope. Oscar Six Security's Radar is available at $99 per scan and is specifically designed for small businesses and IT admins who need to verify their external attack surface before insurance renewals or compliance audits.

Does cyber insurance cover ransomware attacks?

Most cyber liability policies do include ransomware coverage, but payouts depend on whether your policy's required security controls were in place at the time of the incident. If your policy required EDR or MFA and you didn't have them fully deployed, your insurer may dispute or deny the claim even if ransomware coverage is listed in your policy.

How do I know if my cyber insurance policy requirements have changed at renewal?

Ask your broker directly what the underwriter will verify this year that wasn't verified in prior years — insurers have been quietly adding attestation requirements without making them obvious in renewal forms. Review the security controls addendum in your full policy document, not just the declarations page, and compare it line by line against last year's version.

Step-by-Step Guide

  1. Pull and Read Your Policy

    Retrieve your current cyber liability policy and read the security controls or warranty section in full — not just the summary or declarations page. Note every specific control requirement listed.

  2. Audit MFA Coverage

    Inventory every user account, application, VPN, and remote access tool in your environment and confirm MFA is enrolled and active on each. Flag any gaps, especially on privileged or admin accounts.

  3. Run a Vulnerability Scan

    Scan your internet-facing systems and internal network to identify unpatched vulnerabilities or exposed services. Compare findings against your policy's patching and exposure management requirements before attesting to compliance.

  4. Verify EDR Deployment

    Confirm that endpoint detection and response software is installed and actively reporting on every endpoint in scope. 'Installed' is not the same as 'configured and monitored.'

  5. Test Backup Restores

    Don't just confirm backups are running — actually restore a file or system from backup and document the test. Many policies require tested, restorable backups, not just backup jobs that complete without errors.

  6. Review Access and Offboarding Records

    Audit your access logs to confirm all former employees and contractors have had credentials revoked. Document this review so you can demonstrate it was performed if a claim is ever disputed.

  7. Document Your Incident Response Plan

    Create or update a written incident response plan that defines roles, escalation paths, and notification procedures. Even a one-page document satisfies most policy requirements and demonstrates due diligence.

  8. Brief Your Broker

    Before signing the renewal application, ask your broker what the underwriter will specifically verify this year and whether any new control requirements have been added. Adjust your attestations to reflect your verified, actual posture.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →