The renewal email lands in your inbox and it looks routine — until you open the attachment. The questionnaire that used to be two pages is now twelve. The questions aren't "do you have a firewall" anymore. They're asking for proof.
If you haven't renewed a cyber insurance policy in the last year or two, you're in for a surprise. The carriers have stopped taking your word for it.
The market has shifted
The global cyber insurance market hit roughly $15 billion in 2025 and is projected to reach $28 billion by 2030, according to Munich Re's latest survey of 9,500 decision-makers across 20 countries. That's not growth driven by more businesses buying policies — it's growth driven by higher premiums and stricter terms.
The same survey found that a rising majority of business leaders believe their company doesn't defend itself adequately against cyber threats. The insurers have reached the same conclusion, and they're acting on it.
What they're actually asking for now
The questionnaire isn't a formality anymore. Here's what's showing up on renewals in 2026:
- Multi-factor authentication everywhere. Not just email. Not just the VPN. Every externally facing system, every administrative account, every cloud service. And they want to know which ones don't have it and why.
- Documented incident response plan. Not "we'd call our IT person." A written plan that names who does what, when, and how. Tested. Updated within the last year.
- Proof you're doing what you said you'd do. Saying you patch within 30 days isn't enough. They want to see the patch management reports. Saying you do backups isn't enough. They want to know when the last restore test happened and what the results were.
- Third-party risk management. Who has access to your systems? Which vendors touch your data? What happens when one of them gets breached? The Texas Parks and Wildlife breach — 3 million records lost through a vendor — is the kind of incident that put this question on every questionnaire.
- Security awareness training. Not a one-time onboarding video. Ongoing, documented, with phishing simulation results.
Why this is actually good news
This sounds like a burden, and in the short term it is. But the insurers are doing something that most small and mid-size businesses haven't had access to: a real security audit, conducted by people who have financial skin in the game.
Your managed service provider might tell you everything looks fine. Your internal IT person might be stretched too thin to push back. But an insurer who's on the hook for a six-figure ransomware payout? They have different incentives. When they say you need MFA on your payroll system, it's not because they read a white paper — it's because they paid out on a claim where that was the entry point.
What to do before the renewal lands
Don't wait for the questionnaire to arrive. If your renewal is in the next six months, do three things now:
First, turn on MFA everywhere you can. If you do nothing else, this is the one that moves the needle most with underwriters.
Second, write down your incident response plan. It doesn't need to be fifty pages. It needs to answer: who gets called first, who decides whether to pay a ransom, who talks to the lawyers, and who talks to the press. If those answers live in someone's head, they don't count.
Third, run a restore test. Pick one critical system, restore it from backup to a clean environment, and verify it actually works. Document the result. When the questionnaire asks, you'll have an answer that isn't "we're pretty sure."
The cyber insurance market isn't going to get softer. Premiums are rising, requirements are tightening, and the days of checkbox questionnaires are over. But a business that walks into renewal with MFA turned on, a tested response plan, and a recent restore test under its belt is going to have a very different conversation than one that's hoping nobody looks too closely.
If you're not sure where you stand, have a conversation with someone who reads these questionnaires for a living. The time to find out you're not ready isn't thirty days before your policy expires.