Your E&O policy is up for renewal. You fill out the form the same way you have for years. A few weeks later, your agent calls. Your premium went up significantly. Or worse, coverage was denied.
More small businesses are running into this, and most of them didn’t see it coming.
What changed with cyber insurance renewals
A few years ago, getting E&O or cyber liability coverage meant answering some general questions and signing on the dotted line. Carriers took your word for it.
That’s changed. Insurance companies have paid out enough claims to know which businesses get hit and which ones don’t. Now they want to see that you’re actually doing something to protect your business before they agree to cover it.
At renewal, most carriers now ask about five things:
- Multi-factor authentication (MFA): a second verification step beyond the password, on your email, remote access, and administrator accounts. Not just one of the three: “MFA on some accounts” is a No, not a Yes. Email is what attackers actually target.
- Endpoint detection and response (EDR): the modern replacement for traditional antivirus. Instead of just matching known viruses, it watches for attacker behavior and can isolate a machine automatically. Many questionnaires now name EDR specifically and no longer accept “we have antivirus.”
- Tested, protected backups: do backups exist, are they separated from your network so ransomware can’t encrypt them too, and have you actually tested a restore. A backup you’ve never restored from is a hope, not a backup.
- Security awareness training: documented, recurring phishing training for staff, because most incidents start with a person clicking something, not a firewall failing.
- A patching process: a defined way security updates get applied. “We update when we notice” doesn’t qualify.
The questionnaire is an attestation, not a formality
Here’s the part that catches business owners off guard: when a claim comes in, the first thing the insurer’s forensics team does is check whether the controls you attested to were actually in place.
The most common failure looks like this: an owner checks “Yes, we have MFA” because their bank login has it, but their business email, the thing attackers actually target, doesn’t. After a breach, the insurer discovers this and denies the claim. The business paid premiums for coverage it never really had.
The rule is simple: answer the questionnaire as if it will be audited, because after a breach, it will be. If you’re not sure whether a control is really in place everywhere, find out before you sign, not after a claim.
Why documentation matters as much as the practice itself
Saying “I think we’re backed up” is not the same as having records that show your backups run nightly and were tested last month. Insurance carriers increasingly want evidence, not just intent.
This is where businesses without any formal IT support run into trouble. If you’ve been handling technology on your own or calling someone only when something breaks, there’s often nothing written down. No logs, no reports, no way to show an underwriter that your business takes cybersecurity seriously.
A managed IT plan changes that. Your systems get monitored, your backups get tested and logged, and when your renewal comes around you have documentation showing what’s been done and when.
What this costs: less than you’d expect
For a typical office of 5–25 employees, the numbers are smaller than most owners fear. MFA is often free to enable. It’s built into Microsoft 365 and just has to be turned on correctly. EDR and managed backups run modest per-device monthly fees, and training platforms cost a few dollars per user per month. All of it together is usually a fraction of one month’s premium, and every one of these controls comes standard in a managed IT plan.
Compare that to the alternative: a breach with a denied claim, where you cover the downtime, recovery, and notification costs yourself.
What this means for professional services firms
If you run an accounting firm, real estate office, or any business that handles client data, your exposure is higher. A breach doesn’t just cost you money. It costs you clients, and potentially your license or your coverage.
Accounting firms in particular are dealing with this from two directions. The FTC Safeguards Rule already requires tax preparers to have a written security plan in place. And now insurance carriers are asking the same kinds of questions at renewal. The two requirements overlap almost entirely, which means getting your IT in order handles both at once.
The practical bottom line
You don’t need to become an IT expert. You need to be able to show your insurance carrier that someone is paying attention to your cybersecurity and keeping records of it, and you need the answers on that questionnaire to be true.
A monthly IT plan gives you that. It gives you the practices, the documentation, and someone who can sit down and answer the renewal questionnaire with you rather than leaving you to guess.
If your renewal is coming up and you’re not sure what you’d say, or you’ve got a questionnaire sitting on your desk right now, that’s worth addressing before the call comes in. Before you sign it, not after a claim.
Who can help my business answer a cyber insurance questionnaire in Lake County, FL?
Intermachine Systems verifies which controls you actually have, closes the gaps, and produces the documentation before you sign the attestation. We work with small businesses and professional firms across Lake, Marion, and Sumter Counties.
If you want to know where your business stands before your next renewal, we’re happy to take a look. Give us a call at 352-561-8106 or send an email to hello@intermachine.io. No pressure, no jargon, just a straight answer.