The shape of the cyber liability renewal questionnaire in 2025 has converged. Different carriers package the questions differently, weight them differently, and require evidence in different formats, but the underlying set of things underwriters are asking about is now substantially the same across the major commercial cyber markets.

Open a Coalition renewal application from January 2025, set it next to Marsh's commentary on the twelve hygiene controls underwriters weigh, and lay both alongside Aon's commentary on what stricter underwriting now demands. The picture is consistent. The application has approximately ten categories of questions. Each category drives part of the underwriter's read. Each one has artifacts that either back up the answer or expose a gap.

Here's a guided tour of what's actually being asked, why, and what defensible answers look like.

01 · Identity and multi-factor authentication

This category is the single largest determinant of whether a quote will be offered at all. The 2025 carrier application asks where MFA is enforced: email, VPN, RDP, all cloud applications, all administrative accounts, all third-party remote access. The application is not satisfied by "yes." It wants to know the platform, the conditional access policy, and whether legacy authentication has been disabled.

Marsh's market commentary calls MFA the most consistent precondition for favorable terms. Aon's commentary echoes this: the market is buyer-friendly on price, but stricter on control requirements, and MFA leads the list.

A defensible answer in 2025 is enforcement across every authentication path with documentation. A weak answer is "yes" without specifying where, or yes with legacy authentication carve-outs still in place.

02 · Endpoint detection and response

The application asks whether EDR or MDR is deployed across endpoints, what platform, and what the coverage percentage actually is. "Coverage" is a question the underwriter will probe: a practice with 40 endpoints and EDR on 36 of them is a different risk than one with EDR on all 40.

The platform name matters less than the coverage and the alerting cadence. Carriers know which EDR vendors are deployed in working configurations and which are deployed and immediately ignored by the team meant to respond to alerts.

A defensible answer documents both the deployment percentage and the operational cadence: who reviews alerts, how often, what gets escalated. A weak answer is the platform name with no operational context behind it.

03 · Backup and recovery

The application has gotten substantially more specific about backups in the last two renewal cycles. The 2025 carrier application typically asks four sub-questions: are backups immutable, are they encrypted, are they tested for restoration on a defined cadence, and are they segregated from production credentials such that ransomware against production cannot also reach the backup environment.

The Insurance Journal's coverage of the Arctic Wolf Cyber Insurance Outlook Report flagged that 21% of claim rejections in the surveyed group cited insufficient documentation. Backup is one of the most common areas where the documentation gap shows up: backups exist, but restore testing was never recorded, or the immutability claim cannot be verified.

A defensible answer documents the configuration, the restore-test cadence, and the segregation. A weak answer is "we have backups" without proof of the last successful restore.

04 · Patch management

The application asks about patch cadence for operating systems, applications, and firmware. It asks specifically about end-of-life systems still in use. It asks whether there is an exception process for unpatched systems and whether compensating controls are documented.

Carriers know that end-of-life systems are correlated with ransomware exposure. They will weight the answer accordingly.

A defensible answer is a written patch policy, a recent patch compliance report, and an exception register. A weak answer is a number ("we patch monthly") with no policy or compliance evidence.

05 · Email security

The application asks about anti-phishing posture in two dimensions. First, the technical configuration: sender authentication via SPF, DKIM, and DMARC; attachment sandboxing; link rewriting; impersonation protection. Second, the user-side controls: training cadence, phishing simulation completion rates, and the workflow for users to report suspicious messages.

Coalition's 2024 claims data shows that business email compromise and funds transfer fraud are the most frequent claim categories in the SMB market. The underwriter weighs this category accordingly. Email security questions are not boilerplate.

A defensible answer lists the technical controls and provides recent phishing simulation metrics. A weak answer is "we have a spam filter."

06 · Remote access hardening

The application asks how external users (staff, vendors, contractors) connect to internal systems. It probes VPN configuration, RDP exposure, jump server posture, and third-party remote access tooling.

The Change Healthcare breach in February 2024 (initial access via a Citrix portal where MFA had not been enabled) is the case study every carrier underwriter has been carrying in mind through the 2024 and 2025 renewal cycles. The remote-access question is no longer a footnote.

A defensible answer enumerates every external access path and documents the controls on each. A weak answer is a single sentence about the VPN.

07 · Privileged access management

The application asks how administrative accounts are managed. Separation of duties, just-in-time elevation, vaulted credentials, audit logging of privileged sessions, service-account inventory. The questions are increasingly specific.

The reason for the depth here is that compromise of a privileged account is what turns a contained incident into a catastrophic one. Carriers know the loss math.

A defensible answer is an inventory of privileged accounts with the control posture documented per account category. A weak answer is "the IT person has admin."

08 · Security awareness training

The application asks about training cadence, completion tracking, and phishing simulation results. The underwriter wants to see a program, not a one-time training video.

This is also one of the easiest categories to back up with evidence: training platform completion reports, phishing simulation metrics, and the policy that defines the program cadence.

A defensible answer is a documented annual training program with completion data. A weak answer is the date of the last all-hands training.

09 · Incident response

The application asks whether the organization has a written incident response plan. The 2025 question goes further: when was the plan last tested, who participated in the test, and what was changed afterwards. Aon's commentary specifically notes that carriers now expect tested IR plans, not just authored ones.

The IR question is also where the carrier learns whether retainer arrangements are in place with breach counsel and IR firms. Pre-arranged retainers compress response time during an incident, and carriers know this.

A defensible answer is a written plan, a documented tabletop within the last twelve months, and identified retainer relationships. A weak answer is a yes-no on whether a plan exists.

10 · Vendor risk management

The final category of questions is about the vendor ecosystem. The application asks how third parties with access to systems or data are vetted, how their security posture is reviewed on an ongoing basis, and how contracts handle cyber liability.

For healthcare practices, this category overlaps directly with the HIPAA Business Associate Agreement inventory. For other industries, it touches the SOC 2 review process or the vendor security questionnaire program.

A defensible answer is a vendor inventory with risk tier classifications and a review cadence. A weak answer is "we trust our vendors."

What the renewal answer set actually says about you.

The Insurance Journal's coverage of the Arctic Wolf Cyber Insurance Outlook Report captured the underwriting reality in two numbers: 26% of cyber insurance rejections cited inadequate security controls, and 21% cited insufficient documentation. Both numbers describe the same problem from two angles: the carrier could not get comfortable with what the applicant claimed because the applicant could not back up the claim.

The ten categories above are the structure of every modern commercial cyber application. The renewal isn't a checkbox exercise. It's a conversation about whether your environment matches what the application says it does. The applications that get the best terms are the ones where every answer has an artifact ready to back it up, and the applicants who walk in with that posture are the applicants who renew on favorable terms.