A lot can change in 12-months. Your business may have added new systems, suppliers, or employees. The amount of data you hold may have increased. Your security controls may have changed. And your current insurance policy may no longer offer the protection you think it does.
Before you auto-pilot into renewing your current cyber insurance policy, review our comprehensive cyber insurance checklist. We cover the questions to ask about your business, your security, and your policy before you sign for another year.
Be prepared for a few questions throughout; they are crucial in understanding if your policy is right for you.
Start with what has changed in your business
Pulling out last year’s application and updating a few answers is not enough. You need to look at the business as it operates today.
Have you opened new locations? Added a subsidiary? Moved more services into the cloud? Changed key suppliers? Introduced new software or AI tools? Are you processing more customer or employee data than you were twelve months ago?
Changes like these can alter both your cyber risk and the amount of cover you need. One particularly useful question is:
What would one full day without our IT systems cost us now?
Consider lost revenue, employees unable to work, delayed production or deliveries, and the cost of getting systems operational again. Then consider what happens if the outage lasts several days. The answer gives you something far more useful to take into renewal discussions than last year’s figures.
“Cyber insurance was designed for a world where security and insurance operated separately. You purchased protection, you purchased coverage, and you hoped the two would align when an incident occurred. This model is no longer fit for purpose.
Cyber attacks are faster, ever-changing, more targeted, and more damaging than ever. A single incident can halt production, destroy data, trigger regulatory action, and cause reputational harm that lasts long after systems are restored. The financial impact is consistently underestimated, often by a factor of ten”
– Dr. Kennet K. Otto, Eye’s Managing Director/ Chief Underwriting Officer
Check that your security answers are still accurate
Cyber insurance applications usually ask about the security controls you have in place. The important thing is that your answers reflect what is happening across the business today.
Before renewal, check:
- Is multi-factor authentication (MFA) enforced for email, cloud services, and remote access?
- Are all of your endpoints actively monitored?
- Are backups taken regularly, encrypted, and protected against alteration or deletion?
- Have your backups been tested within the past 12 months?
- Do you have a documented disaster recovery and business continuity plan?
- Has that plan actually been tested?
- Are any internet-facing systems running software that is no longer supported?
- Do you know what sensitive data you hold and how it is protected?
- Are critical vulnerabilities being identified and patched?
Security controls are not just a hurdle to clear on renewal day, either. Many cyber policies require certain controls to be maintained throughout the policy period. A gap that appears six months after renewal can matter just as much as one identified during the application.
Cyber risk is no longer an IT issue that can be delegated or ignored. It is a management responsibility. Under NIS2, management bodies of essential and important entities are required to approve cybersecurity risk management measures, oversee their implementation, and ensure they have the knowledge needed to understand and manage cyber risk.
Look beyond the headline coverage figure
A €5 million policy does not necessarily mean you have €5 million available for every type of cyber loss. Individual areas of cover can have their own limits, known as sublimits. Business interruption, ransomware, regulatory defence or other losses could therefore be capped at a much lower amount.
Before renewing, ask your broker to show you exactly where these limits apply and then compare them with the risks you identified earlier. If several days of disruption would create a substantial financial loss, for example, does the business interruption cover realistically meet that exposure?
The same applies to your deductible. Know how much you would be expected to absorb yourself and, importantly, when that deductible starts to apply. Does it apply to first-response activities, or only to subsequent losses?
Not sure what else to look for? Our Cyber Insurance Buyer’s Checklist covers five areas worth reviewing to understand how your cover would respond when you need it.
Download our Cyber Insurance Buyer’s Checklist
Know whom you would call at 2 am
Imagine somebody in your business discovers a serious cyber incident tonight. Whom do they call?
You should understand who provides your incident response, whether they are available 24/7, and what they are authorised to do immediately. Some policies require insurer approval before certain external specialists or costs can be authorised. That might include forensic investigators, legal advisors or other support.
Those details become significant when systems are down and every minute matters.
Find out exactly what requires insurer approval
The next question to ask is what can your response team do without waiting for approval?
Can they immediately investigate and contain an attack? Can forensic work begin? What happens if legal or communications support is needed?
Also establish when your deductible applies. The point is not simply to confirm that “incident response” appears somewhere in the policy wording. You need to understand how that response would work.
Review your exclusions as carefully as your cover
Naturally, we focus on what a cyber insurance policy includes, but how often do you notice what it does not? That may seem daunting when the average application poses around 100 questions, but it also highlights why renewal is a great opportunity to revisit what might be missing.
Eye Security recommends: what to look for
- Look at exclusions and conditions relating to areas such as ransomware, unsupported software, security controls and unpatched vulnerabilities. This is particularly important if your policy places ongoing security obligations on the business.
- If a critical vulnerability is published halfway through your policy term, for example, who is responsible for spotting it? How quickly are you expected to act? And what happens to your coverage if it is missed?
- Incident response typically requires advance insurer approval before costs are incurred, introducing delays at critical times – check the wording and process around this
Read more in our Cyber Insurance for a New Era of Risk Report
Your IT or security team should understand these requirements too. They should not sit solely within an insurance document that nobody looks at until next year’s renewal.
Check your business interruption cover
Business interruption is often one of the biggest financial consequences of a serious cyber incident, so look closely at how your policy approaches it.
Consider:
- How is a business interruption loss calculated?
- Is there a separate sublimit?
- How long is the recovery period?
- Does cover apply to disruption caused by your own systems?
- What about disruption caused by a third-party provider?
- Are system and data restoration costs covered?
- Does the policy account for revenue losses that continue after systems have been restored?
A cyber incident does not necessarily stop costing money the moment your network comes back online.
Do not forget third-party liability
A cyber incident can create costs outside your own organisation too. If customer, employee or partner data is exposed, you may face third-party claims, legal costs or regulatory action.
Check whether your policy covers privacy and network security liabilities and what support is available for regulatory proceedings.
For European organisations, this also means considering your obligations under GDPR and any additional regulations that apply to your organisation or sector.
Check exactly who and where is insured
If you have acquired another company, opened an overseas office, or changed your corporate structure, do not assume those entities automatically fall within your existing policy.
Confirm which subsidiaries, locations and legal entities are named or included.
It is also worth checking how your cyber policy interacts with other insurance, particularly Directors’ and Officers’ (D&O) cover. They address different risks, so reviewing them together can help identify gaps or unnecessary overlaps.
Bringing security and insurance closer together
“Buyers who treat MDR and cyber insurance as separate procurement decisions leave both value and coverage on the table. The most resilient mid-market programmes bring them together.”
– Forrester, The State of Cyber Insurance in Europe, 2025
Eye Seamless Cyber Cover combines cyber insurance with Eye Cyber Guard and incident response, rather than treating each as a separate service.
Eye Cyber Guard continuously monitors endpoints and cloud environments, while Eye Security’s 24/7 team can detect and respond to threats. Critical insurance-relevant vulnerabilities are proactively raised with customers, helping businesses address issues that could otherwise affect their cover.
If an incident occurs, Eye Security handles the initial response, including triage, containment, and forensic investigation. First-response activities do not require insurer pre-approval, and the policy deductible does not apply to Eye Security’s incident response work.
For businesses tired of treating cybersecurity, incident response and insurance as three separate conversations, bringing them together can make renewal and responding to a real incident considerably simpler.
Your 2027 cyber insurance renewal checklist
Before renewing, make sure you can confidently tick these off:
- We’ve reviewed how our business and technology have changed during the past year.
- We understand the financial impact of a serious IT outage.
- Our insurance application accurately reflects our current security controls.
- MFA, endpoint monitoring, and backups are in place and working as described.
- Our disaster recovery and business continuity plans have been tested.
- We understand our total cover, sublimits, exclusions, and deductible.
- We have checked business interruption and third-party service provider cover.
- We know exactly who to contact during a cyber incident.
- We understand which response activities require insurer approval.
- We know our obligations around vulnerabilities and patching throughout the policy period.
- All relevant subsidiaries, locations and people are covered.
- Our cyber and D&O policies have been reviewed for gaps or overlaps.
- We understand how our security posture will affect future renewals.
Cyber insurance renewal should not simply answer the question, “Can we get insured for another year?”
The more useful question is whether the policy, security controls and incident response arrangements you have in place would actually work together if something went wrong.
If your 2027 renewal is approaching, speak to your broker about your current cover or learn more about Eye Seamless Cyber Cover.