From a paperwork exercise to a control inventory
A few years ago a cyber application asked whether you had a firewall and whether you trained people. The forms in front of law firms, advisers, and SaaS companies now read like a short audit. Underwriters are pricing a control inventory: what is actually on, for whom, and whether you can show it. A “yes” with no owner is an answer they have learned to discount.
That does not mean you need an enterprise program before you renew. It means the application is easier, and the conversation with the broker is shorter, when IT and whoever owns compliance have already agreed on the same facts.
The questions that get repeated
The forms are not identical. The subjects are. Expect to be asked, in some wording:
- Whether multi-factor authentication is on for email, for remote access, and for the administrator accounts that can change those settings.
- Whether backups exist, whether they are separate from the systems they protect, and whether anyone has restored from them.
- Whether there is a written incident response plan, and whether the people named in it know they are named.
- Whether someone is accountable for the program, even if that person is not a full-time security hire.
- Whether staff are trained, and whether that training is more than a slide deck nobody finished.
Line up IT and compliance before you submit
The failure mode is not ignorance. It is two honest people with two different answers. The office manager says backups run nightly. The person who runs them knows the cloud copy sits in the same tenant as the files. The application asks a question that only one of those statements can survive.
Before the broker sends the form, sit the people who would have to sign it in one conversation and walk the repeated questions. Write the answer you will both give. Where the true answer is partial, write the partial answer and the date it becomes whole. A broker can work with a partial answer. A broker cannot work with a contradiction that surfaces after binding.
An incident response plan sized to the headcount
Underwriters ask for a plan because the application asks who declares an incident, who calls the carrier and counsel, who talks to clients, and how you restore. The plan they will accept from a 40-person firm is not the plan a bank keeps. It names those four things and leaves the bank's committees out.
The Incident Response Plan Starter Kit is that shape of document: $349, edited to your names and your systems, credited in full toward an advisory engagement booked within 90 days. It is a starting point you can attach. It is not a tabletop, and it is not a promise that a claim will be paid. If the carrier wants a facilitated exercise and a written after-action, that is a quoted engagement, not a download.
A readiness review ahead of renewal
Cyber insurance readiness is scoped when the renewal is the deadline and you want someone else to find the answers that will move premium or coverage before the underwriter does. The work is quoted. It is usually a short engagement: the application, the controls you will be asked to attest to, and defensible language for the gaps you cannot close in time. Closing a gap is better than describing it. Describing it cleanly is better than discovering it in a reservation of rights.
A directional check, not a submission
The free readiness assessment is organized on NIST CSF 2.0, including the questions that map to the controls applications ask about: governance, access, detection, response, recovery. It takes about five minutes. It will not fill in the application. It will show you which of those themes you are about to answer from memory. Answer the application from the inventory, not from memory.