Cyber insurance renewals rarely go well when they begin two weeks before expiration. Underwriters may ask for new documentation, request proof of controls that were previously self-reported or change terms based on current conditions. Starting early gives you time to fix gaps, compare options and negotiate from a position of knowledge.
Below is a 90-day timeline you can adapt. Policy terms and underwriting practices vary by carrier, so use your broker as a guide and read your actual policy.
Day 90 to 75: Review and plan
- Pull the current policy and read the declarations, exclusions, retentions and sublimits. Note anything you did not understand last time.
- Gather last year's application. Review each answer. Which have changed?
- Record changes in the firm: new offices, headcount, practice areas, software, vendors and revenue. Material changes often matter at renewal.
- Review claims and incidents. Any security event, even one that did not lead to a claim, should be discussed with your broker. Check policy notice conditions.
- Meet with your broker to ask what the market is looking for and whether the carrier has changed its requirements.
Day 75 to 60: Assess your controls
Walk through the controls insurers commonly ask about and note the status of each.
- MFA on email, remote access, administrator accounts and other key systems.
- Endpoint detection and response or managed monitoring.
- Backup design, immutability and recent restore tests.
- Email security and impersonation protection.
- Patch timelines and unsupported software.
- Security awareness training and phishing simulation records.
- Incident response plan and when it was last tested.
- Wire transfer verification procedures.
- Privileged access management and vendor access controls.
For each, ask: can we show proof today? If not, put it on the fix list.
Day 60 to 45: Close the gaps you can
Prioritize quick wins that insurers value and that improve security regardless.
- Close MFA exceptions.
- Remove or isolate unsupported systems.
- Run a restore test and save the results.
- Complete overdue staff training.
- Update and rehearse the incident response plan.
- Document the wire callback procedure and have staff sign it.
For items that cannot be finished before renewal, write a remediation plan with owners and dates. Underwriters generally respond better to a concrete plan than to silence.
Day 45 to 30: Collect evidence
Assemble a folder with:
- MFA enforcement reports.
- Endpoint protection coverage reports.
- Backup logs and a restore test record.
- Training completion data.
- Policy documents, including incident response and acceptable use.
- Vendor lists and agreements for providers with access to firm data.
- Network and system inventory summary.
Clear, organized evidence speeds underwriting and reduces back-and-forth.
Day 30 to 20: Complete the application carefully
Fill out the application with owners for each section, a second reviewer and evidence on hand. Answer accurately, not optimistically. Avoid absolutes unless you can prove them. The person who signs should understand what is being attested to. If an answer is unclear, ask your broker how to respond.
Day 20 to 10: Review quotes and coverage
When quotes arrive, compare more than price.
- Limits and retentions: are they appropriate for your size and exposure?
- Social engineering and funds transfer fraud coverage: is it included, sublimited or conditioned on verification procedures?
- Business interruption: how is it triggered and measured?
- Incident response services: are vendors pre-approved, and what is the notice requirement?
- Regulatory and notification costs: what is covered?
- Exclusions and conditions: especially ones linked to maintaining specific controls.
- Panel counsel and vendor requirements.
Ask your broker to explain any provision you do not understand and to put answers in writing.
Day 10 to 0: Decide and document
Choose the policy, bind coverage and confirm in writing. File the final application, evidence and policy together. Update your incident response plan with the claims hotline and notice requirements, and distribute them to those who need them, including offline copies.
After renewal
- Calendar the next renewal and a mid-year control review.
- Track the remediation items you promised.
- Brief partners on what the policy does and does not cover.
- Treat any material change, such as a vendor switch, as a trigger to check the policy conditions.
Common mistakes
- Starting too late to fix problems.
- Answering from memory.
- Assuming last year's answers are still true.
- Focusing only on premium and ignoring exclusions.
- Not telling partners what the policy requires them to do after an incident.
Where we help
Counsel Cyber helps law firms prepare for renewal by verifying controls, producing evidence and closing gaps before the application goes out. If your renewal is approaching, we can build a plan around your date.