The letter doesn't look like a threat. It comes from your broker, or straight from the carrier, a few weeks before your policy lapses. "Time to renew your cyber coverage. Please complete the attached application so we can finalize your terms."
Attached is a form. And if you actually read it, you'll notice it stopped being about your revenue and your claims history a while ago. Now it's page after page of security questions. Do you enforce this. Do you encrypt that. When did you last test the other thing. Yes or no.
Here's what that form really is: a security questionnaire with your insurance attached to it. Same kind of questions your biggest client sends before they'll renew the account — only this time the thing on the line is whether you're covered at all when something goes wrong. And unlike a client review, the deadline isn't a suggestion. Your policy has an end date.
I've watched agencies treat this as paperwork, sign it, and move on. That's the dangerous move. Because every "yes" on that form is a promise you're making in writing — and if you ever file a claim, the carrier gets to check whether the promise was true. Answer "yes, we have that" for a control you don't actually have, and you can pay premiums for years and still watch a claim get denied on the day you need it most. Let me walk you through what they're really asking, and what "having" each one honestly means.
The renewal form isn't a formality anymore. It's an audit.
For a long time, buying cyber insurance was easy — check a few boxes, pay the premium, done. That era is over. Carriers got hit with too many claims, so now they underwrite like your client's security team reviews you: they want proof the controls exist before they'll write the policy, and proof they were working before they'll pay a claim.
When agencies come up short on the form, three things tend to happen, none of them good: the premium jumps hard, the coverage quietly gets carved back so the parts you actually needed are excluded, or the renewal is denied outright and you're scrambling for a new carrier at the last minute. The frustrating part is that it's rarely the work or the risk that sinks you. It's not being able to prove a handful of controls you may already half-have.
The controls insurers commonly ask you to attest to — in plain English
Strip out the jargon and the modern cyber application circles the same short list. Here's each one, and what actually having it means — because "we sort of do that" is exactly the answer that gets a claim denied later.
1. Multi-factor sign-in — everywhere that matters. Not just "we turned it on." Carriers want it enforced on email, on anything your team logs into from outside the office, and especially on the admin accounts that control everything. Having it means nobody's slipping in with just a password, and you can show it's switched on for the whole team, not the two people who bothered.
2. Real protection and monitoring on every laptop and server. Basic antivirus doesn't clear the bar anymore. They want active protection that actually watches for trouble on the machines your people work on — and the servers, which is the piece everyone forgets. Having it means something is watching around the clock, not just an icon in the corner of the screen.
3. Backups that are separated, protected, and actually tested. The question isn't "do you back up." It's "if you got hit tonight, could you restore — and when did you last prove it?" Having it means your backups can't be reached and wrecked in the same breach, and you've actually run a restore recently instead of assuming it would work.
4. Encryption on your devices and data. So a laptop left in a cab, or a stolen phone, isn't a reportable loss of client work. Having it means the data on the machine is scrambled to anyone who isn't supposed to have it — turned on across the fleet, not device by device when someone remembers.
5. Email protection against the fakes. The filtering that catches phishing and the "please update the wire details" impersonation emails. Agencies get targeted precisely because you touch valuable brands and move money and files around. Having it means incoming mail is screened before it reaches an inbox, and your team knows the drill when something slips through.
6. Locked-down access, and a clean joiner/leaver routine. Admin rights kept to the few who truly need them, and access shut off fast when a freelancer rolls off. Having it means the contractor who left six months ago can't still open the drive — and you can show how you know that.
7. A written incident plan. If something goes wrong, is there a plan on paper — who's called, how fast, what happens next? Having it means a real document, not a hope that everyone would figure it out in the moment.
None of these is exotic. The reason the form is hard is the same reason a client review is hard: it asks all of them at once, on a deadline, and every "yes" is supposed to have proof standing behind it.
Here's the part that should make your week easier
Look back at that list. Now think about the last security questionnaire a client sent you — or the one that's coming. It's the same list. Who can get in, the devices, the backups, email, access, incidents, the paperwork. The insurer and the Fortune-500 client are asking you to prove the exact same handful of things.
That's the quiet gift buried in a stressful renewal: the work you do to get insurable is the same work that gets you through a client's review. One effort, two payoffs. Get these controls genuinely in place and keep the proof in a folder, and you've simultaneously answered the carrier who decides your coverage and the client who decides your contract. Skip it, and you're exposed on both fronts at once — a claim that won't pay and an account that quietly walks.
So the move is the same one that beats a client review. Get the controls actually in place — don't fake them on the form, because a carrier checking a denied claim is far less forgiving than a client's procurement team. Write down what you do, in your agency's name. Keep one piece of proof for each control in a folder before anyone asks. Then a renewal application is something you fill out and send back with your coverage intact — not a landmine you signed without reading.
What this should feel like
A cyber renewal should be a calm afternoon, not a gamble. When the controls are real and the evidence is already sitting in a folder, you answer the carrier honestly, your coverage holds, and if you ever do file a claim, it pays — because everything you attested to was true.
That readiness is the whole of what we do at PDRight. We get creative and advertising agencies ready for both reviews that matter — your enterprise clients' security questionnaires and your own insurer's renewal application — with the proof standing behind every answer. Same controls, same folder, both boxes checked. So a form never quietly costs you an account, and never quietly costs you your coverage.
If a renewal or a client review is on your desk right now, or you'd just rather be ready before either one lands, I'm happy to walk you through where you stand. No pitch — just a straight read on how close you already are.