Cyber insurance renewal arrives on a schedule, but too many firms treat it as a surprise. The broker emails a long application, the administrator scrambles, and the partners learn about a premium change or new exclusion only when the invoice comes. A little planning changes the experience, and often the outcome.
Use this checklist, starting around ninety days before your policy expires.
90 Days Out: Take Stock
- Pull your current policy and declarations page. Note limits, retentions (deductibles), sublimits, exclusions and conditions.
- Gather incident history. List any security events since the last renewal, even minor ones, including any claims or near misses.
- Review changes in your firm. Headcount, revenue, new offices, new practice areas, new vendors and new systems can all affect the application.
- Talk to your broker. Ask what underwriters are focusing on this year and what controls are expected.
75 Days Out: Verify Your Controls
Underwriters commonly ask about these controls, so confirm where each stands:
- MFA for email, remote access, administrative accounts and cloud applications
- Endpoint detection and response with active monitoring
- Email security including filtering and DMARC
- Backups: frequency, encryption, offline or immutable copies, tested restores
- Patch management timelines
- Removal of unsupported systems
- Security awareness training and phishing simulations
- Incident response plan, tested or reviewed
- Privileged access management
- Vendor oversight
For each, collect evidence: a report, a screenshot, a policy or a ticket. If a gap exists, decide whether you can fix it before the application is due.
60 Days Out: Close Cheap Gaps
Some fixes are quick and meaningfully change your risk and your answers:
- Enforce MFA on the last handful of accounts that lack it
- Retire or isolate old servers and unsupported software
- Run a restore test and record the result
- Update the incident response plan with current names and numbers
- Complete overdue training
- Turn on external email banners and impersonation protection
45 Days Out: Complete the Application Carefully
- Have the person who knows the environment, usually your IT provider, answer technical questions.
- Describe partial controls honestly rather than ticking a box that overstates reality.
- Have a partner review before signing, since the signer attests to accuracy.
- Save a copy of exactly what you submitted.
- Answer follow-up questions in writing and keep the thread.
Misstatements can complicate a claim later, so precision beats optimism.
30 Days Out: Review the Quote
Do not compare premiums alone. Compare:
- Limits and retentions. Are they appropriate for your size and the data you hold?
- Sublimits, especially for funds transfer fraud, social engineering and ransomware-related costs
- Waiting periods for business interruption coverage
- Conditions, such as requirements to verify payment changes by callback or maintain MFA
- Exclusions for unpatched systems, war or infrastructure events, or failure to maintain controls
- Breach response panel, including forensic firms, breach counsel and notification services
- Coverage for regulatory defense and client claims
Ask the broker to explain anything unclear in plain language, and get the answers in writing.
Before Binding
- Confirm the effective date has no gap with your current policy.
- Confirm the retroactive date, if applicable.
- Make sure contacts for reporting a claim are current and shared with the people who would need them.
After Renewal
- Store the policy and claims reporting instructions where people can reach them offline.
- Put the incident hotline number into your incident response plan.
- Calendar next year's review.
- Schedule a quarterly check that controls promised on the application are still in place.
If an Incident Happens Mid-Term
Read the policy's notice requirements today, not after something happens. Many policies require prompt notification and may restrict you to approved vendors, so calling the carrier early is generally safer.
We Can Help
Counsel Cyber helps law firms prepare renewal documentation, verify controls and fix gaps ahead of underwriting. If your renewal is coming up, ask us for a pre-renewal review.