Most business owners glance at a renewal, note the premium, and sign. Cyber insurance does not reward that habit. It is one of the few lines where the coverage form, the sublimits, the security questionnaire, and the price can all change in a single year — sometimes in your favor, sometimes not.
General liability and commercial property are built on decades of loss data and largely standardized forms. Cyber is not. The threat landscape shifts every year, the policy wording is proprietary to each carrier, and insurers are still calibrating how much risk they want to hold. When ransomware losses spiked, cyber premiums rose sharply and capacity tightened. When claims moderated and security standards improved across the market, pricing softened again. Few other lines swing that hard in either direction.
There is a second reason renewals move: your own risk profile changes faster than it does on other policies. A building's square footage does not change much year to year. Your headcount, revenue, cloud vendors, remote-access setup, payment workflows, and the volume of records you store almost certainly did. Underwriters re-price against the business you are today, not the one you described twelve months ago.
The practical result is that a cyber renewal deserves the same attention you would give a first-time purchase. Treat it as a fresh underwriting exercise, because that is exactly how the carrier is treating it.
Renewal applications are shorter than new-business submissions, but they focus on the items most predictive of loss. Expect questions about revenue, industry, the number of sensitive records you hold, and whether you have had any incident — claim or not — since the last application.
Underwriters also compare your answers to last year's. Inconsistencies get flagged. If you said you had multifactor authentication on email in year one and now say you are "in the process of implementing it," that is a red flag that can affect pricing or trigger a request for more detail. If a control lapsed, say so plainly and explain the plan. Misrepresentation on a cyber application is one of the fastest ways to have a claim contested later.
Many carriers now supplement your answers with outside scanning. They look at your public-facing footprint — open ports, exposed remote desktop, expired certificates, email authentication records, credentials showing up in breach dumps. You may never see that report, but it shapes the offer you receive.
A short list of security controls carries disproportionate weight in cyber underwriting. Having them in place is often the difference between a competitive quote and a declination.
If you added any of these during the year, document it and put it in front of the underwriter. Improvements are not automatically credited — someone has to tell the carrier they happened.
The premium is the number everyone checks. The form is where the real movement often happens. Because cyber wording is not standardized, carriers revise their forms regularly, and a renewal can arrive on a newer edition with meaningful differences from the policy you bought.
Watch for sublimits. Full-limit coverage for social engineering or funds transfer fraud may quietly become a $100,000 sublimit. Ransomware and extortion coverage sometimes carries its own retention or a coinsurance requirement, meaning you share a percentage of the loss. Business interruption may pick up a longer waiting period — twelve hours instead of eight — which can eliminate smaller outages from coverage entirely. Dependent or contingent business interruption, which responds when a vendor's outage stops your operations, is frequently added or removed at renewal.
New exclusions appear as well. Widespread-event and infrastructure exclusions, war and state-sponsored attack wording, and conditions requiring specific controls to remain in place are all common. A policy checkup that compares last year's form to this year's is the only reliable way to catch these before they matter.
Cyber underwriters ask about incidents, not just claims. A phishing email that led to an unauthorized login you caught and reset is an incident, even if you never filed anything. Some applications ask whether you are aware of any circumstance that could give rise to a claim. Answer honestly — a known issue that goes undisclosed can create a prior-knowledge dispute later.
A paid claim will affect your renewal, but not always as much as owners fear. Underwriters care most about what changed afterward. A business that suffered a ransomware event, rebuilt with segmented backups, deployed EDR, and mandated MFA everywhere can sometimes renew on better terms than a claim-free business with weak controls. Remediation is a selling point. Put it in writing.
Cyber submissions take longer to market than most commercial lines, especially if a carrier requires a security questionnaire or a call with your IT provider. Start early.
Sixty to ninety days out, pull your current declarations page and list every limit, sublimit, retention, and waiting period. Ask your IT provider or managed service provider to confirm, in writing, the status of MFA, backups, EDR, patching, and email security. Update your revenue and record counts. Note any new locations, acquisitions, or systems that store customer data. If you handle payments, document your verification procedure and confirm staff actually follow it.
Then decide what you want to fix. Renewal is the natural moment to raise a limit that has not kept pace with revenue, add dependent business interruption if you rely on a critical vendor, or increase a social engineering sublimit that no longer matches the size of your wire transfers. Industry matters too — the exposure profile for medical practices looks nothing like that of a construction firm, and your limits should reflect that.
Remarketing every year is not automatically the right move. Some carriers reward continuity, and switching can reset prior-acts coverage or change how a claim in progress is handled. If you have an open matter, moving carriers is usually a bad idea until it closes.
That said, cyber is competitive enough that a market check every two or three years is prudent, and every year if your renewal increase is significant, your controls improved materially, or your business changed shape. When you do shop, compare forms side by side rather than premiums alone. Two quotes within a few hundred dollars of each other can differ enormously on ransomware terms, breach response services, and who chooses the forensics firm. Working with an independent agent who can compare cyber markets at once saves you from filling out the same questionnaire five times.
Why did my cyber premium go up when I had no claims?
Cyber pricing responds to overall market loss trends, not just your individual history. Carriers also re-rate against your current revenue and record counts, so growth alone can increase premium. If your controls improved during the year, document them and ask the underwriter to reconsider.
Can a carrier non-renew my cyber policy?
Yes. Cyber is not subject to the same non-renewal protections as some personal lines, and carriers regularly exit classes of business or decline accounts that no longer meet their control requirements. You should receive advance notice under state law, but plan for the possibility by starting renewal work early.
What is the single control most likely to affect my renewal?
Multifactor authentication on email and remote access. Most carriers treat it as a threshold requirement, and its absence can mean a declination rather than just a higher price. Tested backups are a close second.
Do I need to report an incident that did not become a claim?
Usually yes, if the application asks. Disclose known incidents and any circumstance that could reasonably lead to a claim. Full disclosure protects the policy; silence creates grounds for a coverage dispute later.
Put your cyber renewal on the calendar ninety days out and treat it as a full underwriting exercise rather than a signature. Gather written confirmation of your security controls, compare this year's form against last year's for new sublimits and exclusions, and decide whether your limits still match your revenue and data volume. A Truscott coverage review can walk through the form changes line by line and tell you whether a market check makes sense this cycle. Reach out before your renewal date so there is time to act on what we find.
A HIPAA breach starts a federal notification clock, a penalty assessment, and a cascade of costs. Here is what happens at each stage and which parts of a cyber policy respond.
Cyber InsuranceWhen a cyber policy responds, it sends a team: a breach coach, a forensics firm, and a notification vendor. Here is who does what, why you call the insurer first, and how the response unfolds hour by hour.