Table of Contents

Your Cyber Insurance Renewal Is in Q4. Start This 90-Day Prep Now.

Picture of CyberDuo
CyberDuo

Cyber insurance renewals have a rhythm, and for a huge share of businesses that rhythm lands in the fourth quarter. It also collides with everything else in Q4: budget season, holidays, year-end closes. Which is exactly why so many renewals go badly. The application arrives, someone answers it in an afternoon from memory, a box gets checked that is not quite true, and the business either pays too much, gets narrower coverage, or, worst of all, buys a policy that will not pay out when it matters because the answers did not match reality.

Here is a better way: treat the renewal as a 90-day project with a clear week-by-week plan. Start in early September and you walk into a December renewal with every answer honest, every control real, and the evidence to prove it. That is how you get better terms, and it is also how you make sure the coverage actually holds.

Why the prep matters more than the premium

Carriers have turned the application into a security audit, and the controls they demand are specific: multifactor authentication everywhere, endpoint detection and response, isolated and tested backups, email security, security awareness training, a tested incident response plan, privileged access controls, and disciplined patching. We broke down the full list in our guide to the controls carriers now require.

The part that keeps us up at night on clients’ behalf is the attestation. The application is a legal document. If you attest to MFA on all remote access and a post-breach investigation finds one server without it, the carrier can deny the claim as misrepresentation. Years of premiums, zero payout. The 90-day plan exists to make sure you never check a box you cannot prove.

Days 90 to 61: know where you stand

Pull last year’s application and policy. Read every question you answered yes to, and read the exclusions and sublimits you probably skimmed. Note any control you attested to that you are not certain is fully deployed today.

Run a gap assessment against the carrier’s control list. Walk your environment control by control. Is MFA truly on every account, including service accounts and that one legacy VPN? Is the endpoint tool on every device, including the servers? When did anyone last actually restore from backup? This is where most businesses discover their attestations were optimistic.

Get quotes moving early. Talk to your broker now about the renewal timeline and whether other carriers should quote. Better-prepared applicants get better rates, and brokers can tell you which carriers are rewarding which controls this year.

Days 60 to 31: close the gaps

Fix the controls that take time. MFA rollouts, EDR or MDR deployment, and backup isolation are the three most common gaps and the three that cannot be finished in a week. Start them in this window so they are fully operational, not merely started, by the time you attest.

Run and document a backup restore test. Not “we have backups.” An actual restore, with a record of when it was done and what it proved. Carriers increasingly ask, and it is the single control most often misrepresented.

Deliver security awareness training and a phishing test. Most applications ask for it, and it produces a clean, dated record you can point to.

Get your incident response plan on paper and rehearse it. A written plan naming roles, contacts (including your carrier’s breach hotline), and steps, then a one-hour tabletop exercise. Now “we have a tested IR plan” is true.

Days 30 to 1: prove it and apply

Assemble your evidence file. For each control you will attest to, keep the proof: MFA enforcement reports, endpoint coverage reports, backup and restore logs, training completion records, the IR plan and tabletop notes, patch compliance data. Carriers may not ask for all of it, but you want it ready, and you want it in case of a claim.

Complete the application slowly, with your IT and security lead in the room. Every yes should be a verified yes. Where you cannot honestly say yes, say so and note remediation in progress. A truthful no costs you a little premium. A false yes can cost you the entire claim.

Review coverage, not just price. Confirm limits, sublimits for ransomware and social engineering (wire fraud coverage is often shockingly low), business interruption terms, and whether your vendors and cloud services are covered. Ask your broker what has changed in the policy language since last year, because carriers revise wording constantly.

The payoff

Businesses that run this playbook consistently see three results: lower or held-flat premiums when the market is rising, broader coverage because underwriters reward demonstrated maturity, and, most importantly, a policy that will actually respond, because every attestation is backed by a control that exists and a record that proves it. As a side effect, the exact controls the carrier demanded are the ones that stop breaches, so the renewal prep doubles as a real security upgrade.

Where we fit

We run this 90-day plan for clients every renewal season: the gap assessment against your carrier’s questionnaire, the remediation of the controls that take time, the evidence file, and a second set of eyes on the application so nothing gets attested that is not true. Our in-house 24/7 SOC and managed detection and response also check several of the hardest boxes outright. See the full approach on our cybersecurity services page.

We do this for businesses across San Diego, Los Angeles, Orange County, and New York City, with the heaviest lift for regulated firms like financial services and law firms, where carriers look hardest. If your renewal is in Q4 and you have not started, September is the right week to reach out.

Talk to our team