When your cyber-insurance renewal arrives, start with the application your agent sent and a small folder of current evidence. For each technical answer, record what is protected, who checked it, when they checked it and any exceptions. Your IT provider can verify the technology. Your insurance agent or broker should clarify the application and coverage questions.
That gives you something more useful than last year's checked boxes: a picture of what your business actually has in place today.
For an owner or operations manager with a 5–100-person team, this does not need to become a giant documentation project. I would start with the questions about sign-ins, devices and recovery, then work through the rest of your insurer's form with the people responsible for those systems.
Start with the actual renewal form
Ask your agent which application and supplements apply, when they are due and how supporting information should be shared. Keep that version with your working notes. A generic online checklist can help you prepare, but it cannot tell you how to answer a different insurer's question.
For example, the MFA supplement currently linked on Travelers' application page separates access to cloud email, remote networks and administrative systems. It includes third-party access in parts of that scope. One answer about staff email would not address every category on that form. This is an example of why wording matters, not a statement that every insurer uses the same requirements. Travelers' applications and MFA supplement.
Give your IT provider the exact questions. Ask them to flag anything they cannot verify, along with systems maintained by another vendor. Keep planned improvements separate from controls already operating.
MFA: check where it is required
Multifactor authentication adds another way to verify a sign-in. The important renewal question is where it is actually required and which accounts are included.
Ask your IT provider to identify the relevant email, remote-access and administrator accounts, review the enforcement settings, and explain any exclusions. Do not treat a screenshot showing that an authentication app is registered as proof that every relevant sign-in requires it.
Microsoft's Authentication Methods Activity documentation distinguishes registration from usage reporting. It also describes reporting delays and omissions, including third-party MFA in one of its sign-in reports. Those reports can help a qualified administrator check the setup, but one dashboard does not answer every scope question. Microsoft's reporting guidance.
A useful note identifies the system, account group, policy checked, evidence date and unresolved exceptions. Keep passwords, recovery codes and secret keys out of the evidence folder.
Device protection: reconcile the list
If the application asks about endpoint protection, ask your provider to compare the protection console with your current device inventory. Which business laptops, desktops and servers are included? Are any missing, no longer reporting or assigned to someone who has left?
If a question names endpoint detection and response, have your provider confirm that specific capability and its scope. Avoid answering from the product name alone.
Here is a made-up example: an office has 20 work laptops, but its protection report shows 18. The useful next step is to identify the other two and resolve or accurately describe the gap. Saving the report without reconciling it leaves the underlying question unanswered.
Also record who receives alerts and who handles them. A report is easier to act on when someone owns the exceptions.
Backups: include evidence of a recovery check
Ask for a list of protected systems and cloud data, backup dates, retention settings and who can change or delete the copies. Check whether anything important lives outside that scope.
CISA recommends offline, encrypted backups of critical data and regular testing of their availability and integrity. Your provider should explain how your actual backup design protects recovery copies and what was tested. CISA's ransomware guide.
For your evidence folder, keep a dated result from an agreed restore exercise: what was restored, where it was tested, whether an authorized person could use it and what still needs attention. A successful sample-file restore supports that specific result. It does not establish how quickly the entire business could recover.
Coordinate testing with your provider so it does not overwrite current work. Our business recovery planning guide covers a controlled exercise. If your question is about cloud files, start with Microsoft 365 backup versus retention.
Build a renewal evidence worksheet
Use this as an internal working sheet alongside your insurer's form. It is an IT MGMT preparation tool, not an insurer-approved application or certification.
| Area | What to record | What to resolve |
|---|---|---|
| Application scope | Form version, business entity, relevant systems and due date | Questions for the agent; systems owned by other vendors |
| MFA | Accounts and services covered, enforcement evidence and check date | Exclusions, unsupported systems and unverified access |
| Device protection | Inventory matched to protection status and recent reporting | Missing devices, stale records and alert ownership |
| Backups and recovery | Protected data, copy protection, retention and dated test result | Unprotected workloads, failed tests and recovery dependencies |
| Follow-up | Named owner, action, target date and verification result | Planned work still awaiting implementation or a recheck |
For each row, link to the supporting file and name the person who checked it. Use a clear status such as verified, gap found or not yet verified. Agree those working labels internally; they do not replace the answer choices on the application.
Review the answers together before submitting
Have the business owner and IT provider walk through the technical answers, then take unclear wording or coverage questions to the agent. The FTC recommends discussing a business's cyber-insurance needs with its insurance agent. FTC cyber-insurance guidance.
Share only the supporting information requested, through the agreed secure channel. Review screenshots for customer information, account details and secrets before sending them. Keep the final answers, supporting evidence and open actions in a restricted location your authorized team can find again.
This preparation can make the technical review clearer. It does not guarantee insurance eligibility, coverage, a premium reduction or payment of a claim.
If you want help checking what your business has in place, IT MGMT's cybersecurity services are a starting point. Book a conversation and bring the renewal questions, your device list and the latest backup report. We can discuss the technical work needed to support accurate answers and address the gaps.



