Cyber insurance renewals rarely go badly because a firm lacks controls. They go badly because the firm cannot show it has them, or because the application was filled out in a hurry by someone guessing. A managing partner who signs an application attesting to multifactor authentication everywhere, when two legacy systems still use passwords alone, has created a problem that surfaces at the worst possible time: after a claim.
Starting about 60 days before your renewal date gives you room to fix gaps, gather evidence, and talk to your broker without pressure. This plan breaks that window into manageable stages.
Days 60 to 45: Take inventory
Begin by pulling last year's application and policy. Read the application as if you were an underwriter. Every yes/no answer is a statement the firm made, and you need to confirm each is still true.
- List every control the application asked about: MFA, endpoint detection, backups, email filtering, training, incident response planning, and vendor management.
- Note any answers that were qualified or marked "in progress" last year and check whether they were completed.
- Ask your IT provider for a current inventory of users, devices, servers, and cloud applications. New hires, new offices, and new software since last renewal often change the answers.
Check the policy itself
Look at limits, retentions, sublimits, and exclusions. Many policies treat funds-transfer fraud, ransomware, and business interruption differently, with separate sublimits. Ask your broker plainly whether a wire fraud loss that begins with a spoofed email would be covered, and under what conditions. Some policies require a call-back verification procedure to have been followed.
Days 45 to 30: Close gaps you can close
Insurers commonly ask about a small set of controls, and these are also the ones that most reduce real risk.
- Multifactor authentication on email, remote access, administrator accounts, and cloud practice-management tools. Confirm there are no exceptions for "just this one partner."
- Endpoint detection and response on every laptop and server, with someone actually watching alerts.
- Backups that are separated from the main network, protected from deletion, and tested by restoring files, not just by checking that a job reported success.
- Email security beyond the default filters, including protection against spoofed domains and impersonation.
- Security awareness training with a record of who completed it and when.
- A written incident response plan that names who calls whom, including your carrier's breach hotline.
If a control cannot be finished in time, do not overstate its status. Document it as in progress with a target date. Underwriters generally respond better to candor and a plan than to answers that later prove wrong.
Days 30 to 15: Gather evidence
Assemble a folder you can hand to your broker or underwriter if they ask for proof:
- MFA enforcement settings or screenshots from your Microsoft 365 or identity provider admin console
- A report showing endpoint protection coverage
- Your last backup restore test, with date and result
- Training completion records
- The incident response plan and the date it was last reviewed
- A list of vendors with access to client data and the security questions you asked them
Having this ready also helps when a corporate client sends its own security questionnaire, because many of the questions overlap.
Days 15 to 0: Complete the application carefully
Assign one person to own the application, and have your IT provider review the technical answers before a partner signs. Read every question literally. If a question asks whether MFA is enforced for all remote access, the answer is only yes if it is all.
Keep a copy of the final submitted application. If a claim occurs, the carrier will compare what happened against what you said.
Questions worth asking your broker
- Does the policy cover regulatory defense and notification costs in the states where our clients live?
- Are we required to use the carrier's panel vendors for forensics and breach counsel?
- What happens to coverage if we fall out of compliance with a control we attested to mid-term?
- How are social engineering and funds-transfer losses defined?
What to do after you bind
Calendar the next review. Controls drift: a new application gets deployed without MFA, a laptop skips encryption, a departed employee's account lingers. A quarterly check against the same list keeps next year's renewal from becoming another scramble.
Getting help
Counsel Cyber works with law firms in Texas, Arkansas, Louisiana, Oklahoma, and Kansas on exactly this kind of preparation. If you would like a second set of eyes on your application answers or a gap review before renewal, we are glad to walk through it with you. Nothing here is insurance or legal advice, so confirm coverage specifics with your broker.