Cyber Insurance Renewal: The CISO’s 2026 Checklist

Cyber Insurance

Cyber Insurance

Every year, cyber insurance renewal gets treated as a budget exercise: compare the premium, negotiate the deductible, sign. The trouble is that most bad surprises don’t surface at underwriting. They surface at claim time, when the insurer invokes an exclusion, a sub-limit, or a security warranty nobody had reread against how the business actually operates today. Renewal is the one moment each year when a CISO or risk director has real leverage to head that off, provided the right questions get asked before the contract rolls over rather than after an attack has already happened.

Does the policy still match the company you actually run?

A cyber policy is a snapshot of the organization at a single point in time: its systems, its critical vendors, its exposure. Between two renewals, that snapshot goes stale fast. A cloud migration, a new SaaS provider sitting in a critical position, AI tools creeping into sensitive workflows, or simply a larger footprint from an acquisition, all of it changes the nature of the risk without the policy necessarily being revisited to match. Renewal should be the moment to check that the coverage still mirrors the risk the company actually wants to share.

Exclusion clauses that can change everything the day they apply

Two categories of clauses deserve a close read, not just a glance when something feels off.

The first is exclusions, particularly the war and cyberwar clauses that have become standard across the market in recent years, a byproduct of a cyber insurance market that is still finding its footing. These clauses keep evolving to bring more clarity for both sides, but they remain a genuine source of uncertainty that should be questioned before signing, not during a crisis. Sanctions-related and regulatory non-compliance clauses also sit alongside coverage for ransom payments, which some companies are still tempted to make. Here too, understanding the insurer’s actual procedures early in the conversation matters more than assuming the wording is settled. Disputes over this have already reached court: in 2023, a ransomware victim sought payment under its cyber policy, and the insurer refused, arguing the attackers were linked to the Russian group Evil Corp, which is under US sanctions. Swiss courts ruled the link wasn’t sufficiently proven and that no concrete sanctions risk existed, forcing the insurer to pay out (source: Centre de droit bancaire et financier, cdbf.ch/fr/1303).

The second category concerns what actually triggers coverage: the contractual definition of what counts as a cyber event or an insurable incident. A perfectly real loss can end up outside the scope of the policy simply because it doesn’t fit the strict definition the contract uses.

Security warranties: a contract inside the contract

Most cyber policies make coverage conditional on a baseline of security controls declared at underwriting: multi-factor authentication rolled out broadly, EDR deployed, immutable and tested backups, privileged account management. These warranties are effectively a contract inside the contract. The usual trap isn’t overstating security posture at signing, it’s failing to keep pace with what was declared as the environment drifts over time, rarely by decision, more often by neglect. An insurer who discovers during post-incident forensics that MFA wasn’t actually enforced across the declared scope has solid grounds to reduce or deny the payout. Renewal is the moment to check with technical teams that operational reality still matches what was signed, not simply to roll forward last year’s declaration.

Does your coverage limit reflect your actual exposure, or just last year's number rolled forward?

Quantify your financial exposure

Coverage limits: gut feel versus the numbers

Many companies renew their coverage limit year after year without questioning it, or adjust it at the margins based on available budget rather than actual exposure. Benchmarking against peers has real limits. Knowing what comparable companies buy tells you something about the market, not about your own risk. Two organizations in the same sector can have very different dependence on digital operations, a different attack surface, or a very different financial capacity to absorb a loss.

Take a simple example: two similarly sized companies in the same sector each carry ten million euros of coverage. A quantified assessment built on realistic risk scenarios might show that one faces a probable maximum loss of twenty five million from an extended business interruption, while the other, less digitally dependent, tops out at six million. The same coverage limit protects the second company and leaves the first badly underinsured, and neither would know it without running the numbers.

What peers in the same sector buy reflects their own trade-offs, with no guarantee that choice was itself grounded in a rigorous read of their exposure. This is exactly where the conversation with an insurer or broker can shift most, once a company shows up with an estimate built on an up to date, quantified risk assessment. The same logic applies when demonstrating organizational resilience to insurers directly: a company that can document its risk level and its reduction trajectory with facts walks into that negotiation with a far stronger hand than its peers.

Claim day is when the contract proves what it’s actually worth

Two last points don’t get settled on paper, they get tested in the middle of a real crisis. First, the insurer’s incident response setup: a mandated vendor panel or free choice, a designated expert, guaranteed mobilization timelines. A major incident leaves little room for improvisation, and finding out mid-crisis that the forensics firm the insurer requires isn’t the one the company normally works with adds friction nobody needs. Second, how the cyber policy interacts with the company’s other coverage: professional liability, D&O, property, fraud. A cyber incident rarely stays inside one risk category, and a lack of coordination across multiple insurers can slow the payout considerably, or create grey zones where each policy points to the other.

Before signing a renewal, these questions deserve a formal answer:

  • Does the declared scope (systems, critical third parties, subsidiaries) still match the organization as it stands today?
  • Have the war, state-actor, and regulatory non-compliance exclusions been reread and understood for what they actually rule out?
  • Are the security controls declared as prerequisites still genuinely in place across the whole covered scope?
  • Is the coverage limit backed by a quantified estimate of exposure, or just last year’s number carried forward?
  • Is the insurer’s incident response setup compatible with the company’s own internal response process?

Asking these questions upfront, with data rather than gut feel, changes the nature of the negotiation with the insurer. It’s also one of the clearest use cases where financial cyber risk quantification becomes a concrete decision-making tool exactly when it matters most: cyber insurance renewal.


For more on how quantifying cyber risk strengthens a CISO’s standing in strategic decisions, see the complete guide to Cyber Risk Quantification.

 

Pouya Canet, VP Strategy at Citalid

More content

Related content