Why Your Cyber Insurance Application Is Twice as Long as Last Year
Cyber insurance applications for professional services firms are getting longer and more technical every renewal cycle. Here's what's driving the changes and what to do about it.
You open your cyber liability renewal application and it’s 15 pages instead of 8. There are questions about endpoint detection and response. Questions about privileged access management. Questions about whether you test your backups, how often, and whether you can document it. Questions about your vendor management program. A whole section on AI governance that didn’t exist last year.
If you’re wondering why the application keeps growing, the answer is straightforward: your carrier lost money, and now they want more information before they agree to cover you again.
The loss ratios drove the changes
Between 2020 and 2023, cyber insurance carriers paid out more in claims than they collected in premiums across multiple quarters. Ransomware attacks, business email compromise, and vendor-chain breaches hit professional services firms particularly hard. Law firms and CPA firms showed up in claim data at rates disproportionate to their size because the data they hold is unusually sensitive and the regulatory consequences of losing it are unusually severe.
Carriers responded the way insurance companies always respond to sustained losses: they raised premiums, tightened underwriting, and started asking harder questions. The 8-page application became 15 pages. The “do you have antivirus” question became “what EDR platform do you use, is it managed 24/7, and what is your mean time to respond to alerts.”
By 2025, loss ratios improved because the harder underwriting was working. Firms with weak security postures were either denied coverage, priced out, or forced to improve their controls before they could renew. The carriers that survived the rough years now have data showing exactly which controls correlate with lower claim frequency. That’s what they’re asking about.
What changed in the last 12 months
The 2026 renewal cycle has added a few new wrinkles that weren’t on most applications a year ago.
AI use and governance. Some carriers are now asking whether your firm uses AI tools for client-facing work, whether you have an AI use policy, and whether staff can input client data into consumer AI platforms. If your answer is “we don’t have a policy,” that’s not a disqualifier yet, but it’s being tracked. We wrote about what a practical AI use policy looks like for exactly this reason.
Vendor and supply chain risk. After the wave of supply-chain breaches this year (EY through a ticketing platform, RingCentral through social engineering, 3.6 million Azure records through compromised credentials), carriers are asking more granular questions about your third-party vendors. Do you maintain a vendor inventory? Do you evaluate vendor security before onboarding? Do you know which vendors have access to client data?
Identity and access management specifics. The old question was “do you use MFA.” The new question is “do you use MFA on all remote access, all cloud applications, all privileged accounts, and all email access, with no exceptions.” Some applications now ask what type of MFA you use and whether it’s phishing-resistant (hardware keys, number matching) versus standard push notifications.
Backup verification. It’s no longer enough to say backups exist. Carriers want to know whether backups are tested (when was the last successful restore?), whether they’re isolated from your production network (can ransomware reach them?), and whether they cover all critical systems or just some.
The attestation problem
Every question on your application is an attestation. You’re signing a document that says “yes, we have this control in place.” If you file a claim and the carrier’s forensic team discovers that what you attested to wasn’t accurate, the claim can be denied.
This isn’t hypothetical. In 2022, Travelers sought to rescind a policy after the insured misrepresented their MFA status on the application. The case settled, but it signaled a shift: carriers are investing more in post-breach forensics and comparing what happened to what you attested. We’ve covered specific examples of the kinds of gaps that create risk: firms that attested to MFA but had exceptions for VPN accounts, firms that checked “yes” on backup testing but hadn’t actually run a restore in over a year. When the breach happens and the forensic report comes back, the carrier compares your application to reality. Gaps create grounds for dispute, and potentially for denial.
The tricky part is that many of these attestations are made in good faith. The managing partner signs the application, assumes IT has it covered, and nobody verifies. The IT provider might have set up MFA two years ago but hasn’t audited whether every account is still enrolled. Backups might be running but nobody has confirmed a restore works. The gap is usually lack of verification, not dishonesty.
How to make renewal less painful
The best time to prepare for your insurance renewal is about 60 days before it comes due. That gives you enough time to identify gaps and fix them rather than rushing to check boxes.
Start with last year’s application. Pull it out and read your answers. Are they still accurate? If you answered “yes” to MFA enforcement, has anyone checked that every account, every application, and every remote access method still requires it? If you answered “yes” to backup testing, can you produce a test restore report from the last 90 days?
Ask your IT provider for a compliance snapshot. Any competent managed IT provider should be able to show you: which endpoints have EDR running, which devices are compliant with your security policies, when the last backup test was completed, who has administrative access, and what your patch compliance looks like across Windows and Mac.
Review your vendor list. If your carrier asks for a list of vendors with access to sensitive data and you don’t have one, build it now. Include your IT provider, your phone system, your practice management software, your cloud storage, your document management platform, and any AI tools in use. For each vendor, note what data they can access and whether they carry their own cyber insurance.
Document your incident response plan. If you don’t have one, create one. If you have one, confirm the contact information is current and the people named in it know they’re named in it. This is one of the easiest boxes to check and one of the most commonly skipped.
The firms that handle renewals well aren’t doing anything extraordinary. They’re verifying that their controls match their attestations, fixing the gaps before the application goes in, and keeping documentation that proves it. The application is long, but if your security posture is real, most of the answers are easy.
If your renewal is coming up and you’re not sure whether your controls match what you’ll be attesting to, we can run a pre-renewal assessment.

