CTS - Computer Technology Specialists

Cyber Insurance Renewal Checklist

Cyber insurance renewal is increasingly technical — underwriters now require documented evidence of security controls before offering coverage at last year's terms, and businesses that cannot produce that evidence face reduced limits, higher premiums, or declined renewal.

Melbourne IT support with visible local credentials

CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.

Certifications, affiliations and technology partners

Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.

What underwriters review at renewal

The renewal process now typically includes a technical questionnaire covering specific security controls. Common questions cover: whether MFA is enforced on all remote access and cloud email, whether managed EDR is deployed on all endpoints, whether backups are immutable and have been tested in the last 12 months, what the patch management cycle is and how compliance is measured, whether privileged admin accounts are separate from daily-use accounts, and whether staff receive security awareness training. Self-declaration is insufficient — underwriters increasingly request supporting documentation or run their own external scans.

MFA and access control evidence

For the MFA requirement, the evidence package should include: a Microsoft Entra ID conditional access policy report showing MFA enforced for all users and all applications, a user report confirming no accounts are exempt from MFA policies, and MFA registration status for all licensed accounts. CTS can export these reports from the Microsoft 365 admin portal and package them for the renewal submission.

Backup and recovery documentation

For the backup requirement, documentation should include: a backup policy showing backup schedules, retention periods, and immutability settings, the most recent restore test result with date and the time taken to complete the restore, confirmation that Microsoft 365 data (Exchange, SharePoint, OneDrive, Teams) is backed up separately from the Microsoft platform, and offsite or cloud backup confirmation. Many underwriters specifically ask whether backups are disconnected from the production environment — immutable cloud backups satisfy this requirement.

Endpoint protection and EDR evidence

Underwriters are moving away from accepting traditional antivirus as sufficient endpoint protection. Managed EDR — with behavioural detection, automated response, and central management — is increasingly the minimum required. For Microsoft 365 Business Premium clients, Microsoft Defender for Business provides managed EDR. CTS can produce a Defender for Business device coverage report showing all managed endpoints enrolled and active.

Patching compliance evidence

Patch management documentation should show the patching policy (monthly cycle, critical patches within 48-72 hours of release) and a current compliance report showing OS and application patch status across all managed devices. Devices that are significantly behind on patching are a red flag for underwriters and may trigger additional questions or exclusions. CTS maintains patch compliance reports for all managed IT clients as part of the standard service.

How CTS prepares the renewal evidence pack

CTS compiles the cyber insurance evidence pack for managed IT clients as part of the annual renewal process. The pack includes MFA coverage reports, conditional access policy exports, Defender for Business device reports, patch compliance summaries, backup policy documentation, restore test results, and an Essential Eight maturity summary. This documentation is assembled from the monitoring and management platforms CTS already uses for the managed service, so there is no additional audit burden.

Frequently asked questions

What happens if we can't evidence our security controls at renewal?

If controls cannot be evidenced, underwriters may offer renewal with reduced limits, higher premiums, additional exclusions, or they may decline to renew. In some cases underwriters run their own external scans before renewal — if these identify exposed services or obvious vulnerabilities, the renewal offer may be conditional on remediation before coverage starts.

How far in advance should we prepare for cyber insurance renewal?

Start at least 60-90 days before the renewal date. Reviewing current controls, identifying gaps, implementing remediations, and assembling the evidence pack takes time. CTS compiles the renewal evidence pack for managed IT clients as part of the standard annual renewal process — including MFA reports, Defender device coverage, patch compliance summaries, backup test results, and an Essential Eight maturity summary.

Related case studies

Related CTS services

Share this page