Pro Blog | PK Tech

What Small Businesses Need to Know About Cyber Insurance Renewal

Written by Jordan Hetrick | September 7, 2026

A cyber insurance renewal used to be a formality. You paid the premium, signed a form, and moved on. That's not how it works anymore. Insurers spent the last few years paying out on ransomware claims, data breaches, and business interruption losses, and they've responded by tightening what they'll accept before writing or renewing a policy. If your business is coming up on renewal, expect a longer questionnaire, more documentation requests, and less patience for vague answers.

This shift matters because small businesses are the ones most exposed. The U.S. Small Business Administration reports that attacks against small businesses have caused billions of dollars in damage, with the numbers climbing every year. Ransomware in particular spreads through phishing emails and unpatched software, two problems that many small companies still haven't solved. Insurers know this, and it shows up in how they underwrite policies today.

Why Cyber Insurance Renewal Got Harder

The old cyber insurance application asked yes-or-no questions. Do you have antivirus software? Do you back up your data? A checked box was often enough. Carriers have moved away from that model because those checked boxes didn't match reality. A business could answer "yes" to having backups and still lose weeks of operations because nobody had tested whether those backups actually restored anything.

Underwriters now ask for proof. That might mean screenshots of multi-factor authentication settings, a report from your endpoint protection software, or documentation showing when you last tested a data restore. The Cybersecurity and Infrastructure Security Agency (CISA) recommends that small businesses set concrete goals for the percentage of systems patched, the percentage of accounts protected by multi-factor authentication, and the frequency of system backups. Insurers are essentially asking you to show your work against that same kind of standard.

Part of the pressure comes from outside the insurance industry itself. Reinsurers, the companies that insure the insurance companies, have tightened their own requirements after absorbing years of large payouts. That pressure flows downhill to every small business renewing a policy, regardless of whether that business has ever filed a claim.

The Controls Insurers Actually Want to See

Every carrier has its own questionnaire, but the core list has become fairly consistent across the industry. Multi-factor authentication tops it. CISA's guidance on this point is direct: businesses should require multi-factor authentication on email, remote access, and any account with administrative privileges, and should aim for phishing-resistant methods where possible. A password alone is not considered adequate protection by most carriers writing policies today.

Endpoint detection and response comes next. This goes beyond traditional antivirus software by watching for suspicious behavior on laptops and servers in real time, rather than just checking files against a list of known threats. Underwriters want confirmation that this kind of monitoring exists across your devices, not just on a handful of machines.

Tested backups come next. A backup that has never been restored is a guess, not a safety net. Carriers increasingly ask for evidence that a business has actually restored files from a backup within the last year, not just that backups run on a schedule.

Employee training rounds out the list. Verizon's 2026 Data Breach Investigations Report found the human element in 62% of breaches, whether through a phishing email, a reused password, or a phone call that talked someone into granting access. Insurers want to see recurring security awareness training, with records showing who completed it and when.

A written incident response plan ties these pieces together. This document doesn't need to be long, but it should say who calls the insurance carrier, who calls legal counsel, who talks to customers, and who makes technical decisions in the first hours after something goes wrong. Carriers ask for this because a business without a plan tends to make costly mistakes during a crisis, and those mistakes often lead to larger claims.

Where Small Businesses Get Tripped Up

Most small businesses that struggle with renewal are lacking documentation, not sophisticated security tools. A business owner might genuinely have multi-factor authentication enabled. Still, if no one can provide a screenshot or export showing which accounts have it enabled, the underwriter has no way to verify the claim. The same goes for patch management: a business might update software regularly, but without a record of what was patched and when, that practice doesn't show up anywhere an insurer can see it.

This is also where regulatory exposure can compound the problem. Businesses that handle certain types of financial data may fall under the FTC's Safeguards Rule, which requires a written information security program regardless of company size. The rule applies more broadly than most owners expect, covering not just banks but businesses like auto dealers, tax preparers, and mortgage brokers. A company that hasn't built the documentation required for Safeguards Rule compliance often finds it's missing the same paperwork a cyber insurance underwriter is asking for.

Another common gap involves the assumption that a general liability or business owner's policy already covers cyber incidents. It typically does not. Cyber coverage is usually a separate policy or a distinct endorsement, and a business that discovers this gap after a breach is in a far worse position than one that reviews its coverage before renewal.

How Managed Cybersecurity Services Fit Into Renewal

This is where managed cybersecurity services earn their keep. A qualified managed IT provider tracks the specific controls carriers ask about, maintains the logs and reports that prove those controls are active, and can hand a business owner a packet of evidence when a renewal questionnaire asks for it.

That has a direct effect on cost. In PK Tech's experience, clients who can demonstrate active controls, rather than just claiming to have them, have had an easier time holding premiums steady at renewal than businesses that show up without evidence. Some carriers also give weight to a completed third-party security assessment, which a managed provider can typically arrange or perform directly. The alternative, showing up to a renewal without documentation, tends to result in higher premiums, added exclusions, or an outright decline of coverage.

A managed provider also closes the gap between what a business believes about its security and what's actually true. It's common for an owner to assume backups are working or that every laptop has endpoint protection installed, only to discover gaps once someone actually audits the environment. Catching that before an underwriter does, or before a breach occurs, will always save a business money.

What to Do Before Your Next Renewal

Start the process well before your renewal date arrives. Pull your current policy and compare it against what carriers are asking for now, since requirements that were adequate two years ago may no longer be enough. If you don't already have documentation for multi-factor authentication, endpoint protection, backup testing, and employee training, start gathering it now rather than scrambling when the questionnaire arrives.

If your business handles financial data of any kind, check whether the FTC Safeguards Rule applies to you. Many business owners don't realize the definition of "financial institution" under that rule is broader than it sounds, and discovering this during a renewal review is better than discovering it during an investigation.

Finally, businesses should approach cyber insurance as an operational issue rather than focusing on cost. The businesses that renew smoothly and keep their premiums in check are the ones that treat security controls as an ongoing practice. Managed cybersecurity services exist largely to make that ongoing practice sustainable for businesses that don't have the staff to manage it alone. For most small companies, that support is what turns a stressful renewal into a routine one.

As a managed IT service provider, PK Tech brings nearly 17 years of experience serving small businesses. PK Tech holds AICPA SOC 2 Type II attestation, verified through an independent third-party audit of its security and privacy controls. Managed IT services through PK Tech are customized to the client, taking into account how large your organization is, your industry, compliance requirements, etc.

If you are interested in chatting with a member of our team, get in touch with us here.