Cyber insurance carriers with a January-effective book start their pre-quoting cycle in mid-August. If your policy renews January 1 and you are researching what carriers are asking about now, you are not late; you are exactly on the timeline the carriers themselves are running. This piece is about what changed in the 2026 renewal questionnaires, what carriers now verify with evidence rather than accept on attestation, and what a buyer can do between August and December to move premium in the right direction.
The 2026 questionnaire is substantially different from the 2024 one. The difference is not that the questions are harder. It is that the "please attest" bucket got smaller and the "please provide evidence" bucket got bigger, part of the broader policyholder-visibility shift the market has been walking through since 2024. The three incidents that drove the rewrite are the Change Healthcare outage in early 2024, the MOVEit exposure that continued reverberating through 2024, and the OpenClaw supply-chain incident in Q1 2026. Each one produced a control-family category that carriers now require documentary evidence for.
What changed in the 2026 questionnaires
Multi-factor authentication is no longer a yes-or-no question. Carriers now ask which privileged systems have MFA (named), what MFA method (phishing-resistant vs. push vs. SMS), and how MFA is enforced on service accounts. Backup posture moved from "do you have backups" to "when did you last restore a production system from backup" with a date and evidence. Third-party incident-response coverage moved from "do you have an IR retainer" to "which vendor, when was your last tabletop, and what were the findings." AI usage is new entirely; most carriers added it in Q1 2026 and have asked about it in every renewal since.
The three incidents that rewrote the questionnaire
Understanding what changed is easier if you understand what losses drove each change. Insurance products get rewritten in response to loss experience, not to hypothetical risk, and the last two years produced enough loss experience to reshape the entire mid-market cyber underwriting model.
Change Healthcare (Feb 2024). The ransomware event that took down a payments backbone used by roughly one third of US healthcare providers. What carriers learned: business-interruption exposure in vendor-dependent architectures was larger than any model had priced. What changed in the questionnaire: vendor concentration analysis moved from aggregate to named, with critical vendors and their SLAs pulled into the underwriting file individually.
MOVEit (2023-2024). The mass-exploit of a file-transfer product used by hundreds of enterprises. What carriers learned: point-in-time compliance attestation did not correlate with actual patching discipline. Companies with current SOC 2 reports were among the most-affected because the SOC 2 process did not enforce patch cadence at the depth the exploit required. What changed: patch discipline moved from attestation ("we patch monthly") to evidence-verified ("show me the last three months of patch reports with time-to-patch metrics").
OpenClaw (Q1 2026). The supply-chain incident that ran through a widely-used developer toolchain and reached hundreds of downstream companies before detection. What carriers learned: their model had assumed developer toolchain compromise was tail risk; the incident showed it was body-of-distribution risk. What changed: software-supply-chain questions became a discrete section in every mid-market questionnaire, covering SBOM production, dependency scanning, and build-pipeline attestation.
What carriers verify vs. what they take on faith
The "verified" column changed substantially. Two years ago, the verified fields were basically: is your SOC 2 or ISO 27001 current, does your policy include prior acts coverage, and has your organization suffered a reportable breach in the last five years. Everything else was attestation.
The 2026 verified column includes: current SOC 2 Type II report received in full (not just the letter); a named list of privileged systems and their MFA enforcement method, with the carrier's underwriter running a small sample of external verification against public authentication endpoints; the date of the last successful production-system restore from backup, with a supporting artifact if the number is under twelve months old; the incident-response retainer contract, with the SLA terms and named-vendor extracted; and, for organizations over a certain revenue threshold, a statement of what AI systems have production-data access and what governance is in place around them.
What carriers still take on attestation: your patching cadence, your vulnerability-management program's coverage, your data-classification policy, and your employee security-awareness training frequency. These get self-attested because the verification cost exceeds the actionable signal, at least for now.
The verification shift is not adversarial. Carriers moved things into the verified column because losses in those categories were the ones that most consistently differed from what the insured had attested. It is a reasonable underwriter response, not a hostile one.
What a January renewer should do between now and December
Three things move premium in the direction the buyer wants. All three take longer than the 30 days most buyers give themselves before renewal.
Restore a production system from backup, and keep the evidence
Not a full DR drill, not a tabletop, an actual restore of an actual system to an actual isolated environment, with the restoration verified against a known-good baseline. Do this by the end of October. The evidence artifact is the log of the restoration process plus a screenshot of the post-restore validation. If your last real restore was more than twelve months ago, this alone will move premium.
The carrier ask, verbatim: "Date of last successful restore of a production system from backup to an isolated recovery environment, with the recovery timing and data integrity verified." The answer they want to see is a date within the last ninety days, a named system, and a recovery-time observation. Any answer more than twelve months old triggers additional scrutiny and typically adds 10-20% to premium.
The failure mode most companies fall into: they have backups that they trust based on the backup software's status page and have never actually tested. The Change Healthcare and MOVEit experiences taught carriers to distrust that pattern specifically. A backup you haven't restored is a hypothesis, not a control.
Enforce phishing-resistant MFA on the two or three most privileged systems
Not "everywhere in one sprint." Pick the systems whose compromise would be catastrophic (production identity provider, code-repository admin, cloud-billing account, financial-systems admin) and move those to hardware-key or platform-authenticator MFA. Document the enforcement in your identity policy and include screenshots of the enforcement configuration in your renewal packet. This addresses the highest-frequency change in the 2026 questionnaire.
Phishing-resistant means WebAuthn/FIDO2 hardware keys, platform authenticators (Touch ID, Windows Hello), or PKI-based smart cards. It does NOT mean SMS codes, push notifications, or TOTP codes, which are all still susceptible to real-time phishing kits and SIM-swap attacks. The distinction matters to carriers because 2024-2025 breach data showed push-fatigue and SIM-swap incidents dominating the MFA-bypass category, which is the loss pattern the 2026 questionnaire is trying to price.
The order to enforce phishing-resistant MFA, in a resource-constrained rollout: identity provider first (Okta admins, Azure AD Global Admins, Google Workspace super admins); then code-repository admin (GitHub organization admin, GitLab maintainer, Bitbucket admin); then cloud-billing (AWS root, Azure billing admin, GCP billing admin); then financial-systems admin (NetSuite admin, QuickBooks admin, Stripe root). Four systems, all top-tier privilege. Enforcing on those four moves the carrier's underwriting model even if the broader employee MFA program is still on push-based. MFA on privileged systems is one of the five controls that most-move premium in the 2026 model.
Sign a real AI-governance policy and instrument the highest-exposure workflows
Carriers are asking about AI because the loss patterns have moved from theoretical to actuarial: data exfiltration through paste-into-model workflows (Samsung's April 2023 employee source-code leak into ChatGPT is the widely-cited example), agent-driven infrastructure destruction (Replit's coding agent wiped a live production database in July 2025 despite explicit instructions not to), and model-substitution supply-chain attacks on Hugging Face and PyPI. The carrier response is well documented: WTW's 2026 cyber outlook and Fenwick's analysis of the emerging silent-AI exclusion both track the 2026 shifts: AI security riders requiring proof of red-teaming, AI sublimits capping payouts at roughly a tenth of policy limit, and deliberate ring-fencing of AI liability away from the base cyber policy. Sources at the end of this piece.
A written AI-usage policy is table stakes; an inventory of which workflows actually use AI and what data flows through them is what moves premium. The floor here is naming which AI vendors have access to which data categories. The ceiling is a deterministic gate on agent actions with a written change record.
The AI-governance questions on the 2026 questionnaires: (1) which AI vendors have production-data access, named; (2) what data categories flow to each named vendor (customer PII, financial data, health data, source code, credentials); (3) what enforcement mechanism prevents employees from routing unsanctioned data to unsanctioned AI (a DLP rule, a proxy filter, a written policy with training, or none); (4) what governance exists on autonomous agents that can take actions on production systems (a named policy, a runtime gate, or a code review after the fact); (5) any AI-related incidents in the last twelve months, including "near misses" like credential exposure through paste-into-model or agent errors caught before customer impact.
Answering these coherently, with named systems, named data flows, and named governance, is what moves premium. Most renewers cannot do this today because their AI usage happened faster than their AI governance did. The gap is the opportunity.
What does not move premium, even though your broker may say it does
New tool acquisitions in the ninety days before renewal do not move premium in a defensible way. Carriers know that a tool bought in October to answer a questionnaire in December has not had time to change loss experience, and they price it as such. If you are going to buy a new detection capability, buy it in Q1 for the following year's renewal, not in Q4 for this year's.
Adding new compliance certifications in the last quarter also does not move premium. A SOC 2 Type II in progress at renewal is worth the same as no SOC 2. The carrier will underwrite based on what is finished on the day of renewal, not what is planned.
Security awareness training campaigns added between the questionnaire and the quote have no effect on premium in 2026 questionnaires. Carriers found no correlation between training frequency and loss experience in their 2024-2025 book. The section is still on the questionnaire because underwriters ask it out of habit; it does not affect the number.
The largest single thing that moves premium, in our experience with renewers under 1,000 employees, is being able to answer the AI section coherently with named systems, named data flows, and named governance. Most renewers cannot do this today because their AI usage happened faster than their AI governance did. The gap is the opportunity.
The renewers who get the worst quotes are not the ones with the most incidents. They are the ones whose renewal packet does not answer the questions the carrier actually asked in the format the carrier asked for. The 2026 questionnaire is longer, more granular, and more evidence-oriented than any prior year. Prepare against the current questionnaire, not the one your broker used last year.
The renewal packet: what to include, in what order
The renewal packet you hand your broker in November follows an order that survives underwriter review. The ordering matters because it maps to how underwriters actually score what they receive, section by section: (1) current SOC 2 Type II report (the full report, not just the auditor letter, and only if it is dated within the last twelve months and covers the scope the carrier is quoting against); (2) the executive summary of your incident-response plan with named vendor and current SLA terms, extracted from the retainer contract; (3) the evidence of your most recent production restore from backup with the date, the system, and the recovery-time observation; (4) the MFA enforcement inventory naming each privileged system and the MFA method in use; (5) the AI-systems inventory covering the five governance questions above; (6) any material changes since the last renewal (new subsidiaries, new geographies, new data categories, new regulated jurisdictions); and (7) prior-year loss experience, either a clean "no reportable events" statement or a summary of what happened, what was recovered, and what changed as a result.
Everything else is optional. Do not bulk up the packet with marketing content or aspirational program descriptions. The underwriter reads for signal-to-noise, not for volume, and every extra document dilutes the strong material.
What to do if your carrier is non-renewing
Non-renewal notices in the cyber book have gone up sharply since 2024, part of the broader hardening cycle the market has been in for two years. If your renewal packet gets a non-renewal notice in October, you have options. Some move faster than others, and some have long-term consequences for coverage availability.
Option 1: appeal the non-renewal with new evidence. Non-renewals are sometimes triggered by a specific control-family gap that the underwriter flagged. If you can close the gap and document the fix within thirty days, some carriers will reconsider. This works best if the flagged issue was a specific finding rather than a broad posture assessment.
Option 2: seek a mid-tier carrier alternative. The primary carriers non-renewing does not mean coverage is unavailable. Excess and surplus lines carriers, MGA-backed programs, and cyber-specific specialty carriers often write coverage the primary market has declined. Coverage terms may be less favorable and premium will be higher, but coverage is available.
Option 3: self-insured retention with a stop-loss layer. For companies with strong balance sheets and specific loss data, taking a $500K or $1M self-insured retention against a $5M-$10M stop-loss policy is often more economical than paying full-primary premium for a program the carrier prices as marginal. This requires actuarial modeling of the target's specific loss distribution, not a generic industry benchmark.
Option 4: accept the non-renewal and reassess in twelve months with improved posture. This is only viable if the company can operate without cyber coverage for a period, which is a decision that involves board-level risk appetite, not just insurance strategy.
The window for changing what carriers see about your posture closes in early November. Anything done in November or December is inventory management, not posture change. The buyers who get better renewals in January started their evidence work in August.
The bottom line
The 2026 questionnaire is the carriers' response to two years of loss experience that did not match what insureds had attested to. The response is documentary evidence for the control families where the mismatch was worst: MFA on privileged systems, backup restore-testing, IR retainer specifics, and AI usage. None of these is difficult if you start the work in August. All of them are impossible to fabricate in the week before renewal.
If you are a January renewer, the practical shape of your next twelve weeks is a short list: pick the two or three privileged systems where phishing-resistant MFA is missing and enforce it; restore a production system from backup and keep the artifact; write the AI-usage policy and inventory the workflows that actually touch it. Your renewal packet lands in November with those three things done, or it lands without them. Carriers price the difference.
Sources
- Willis Towers Watson, Cyber risk: A look ahead to 2026, February 2026: wtwco.com. Broker/consulting analysis of the 2026 underwriting shift, including AI-usage additions to applications and the AI-conditions-to-payouts trend.
- Fenwick & West, The End of "Silent AI"? Emerging AI Exclusions, Coverage Fragmentation, and Practical Implications for Policyholders: fenwick.com. Legal-market analysis of 2026 AI Security Riders, AI sublimits (roughly a tenth of policy limit), and the ring-fencing of AI liability from base cyber cover.
- PCMag, Vibe Coding Fiasco: Replit AI Agent Goes Rogue, Deletes Company's Entire Database, July 2025: pcmag.com. Contemporary reporting on the agent-driven infrastructure destruction referenced above.
- Bloomberg / Forbes coverage of Samsung's April 2023 ChatGPT source-code leak, the widely-cited paste-into-model data exfiltration event that first put AI-usage on carrier questionnaires.