I got a call once from an organization with a problem that wasn’t really an insurance problem.
Their cyber insurance renewal questionnaire had arrived.
At first, nobody was particularly concerned.
Then they started reading the questions.
“Do you use multi-factor authentication?”
Yes.
Well…mostly.
“Do you regularly test your backups?”
We have backups.
But when did we last test a full recovery?
“Do you provide cybersecurity awareness training?”
We did some training.
Was that this year or last year?
“Do you have an incident response plan?”
Somebody has one.
Don’t they?
Pretty soon, what looked like an insurance application had turned into a cybersecurity assessment.
And that’s the lesson.
The worst time to prepare for your cyber insurance renewal is when the renewal questionnaire lands on your desk.
For a credit union, preparing should begin months before renewal by reviewing your security controls, documentation, backups, employee training, vendor relationships, and incident response capabilities.
Not because you’re trying to give an insurance company the “right” answers.
Because those answers should reflect what you’re actually doing to protect your members.
Cyber Insurance Has Changed
There was a time when obtaining cyber insurance could feel relatively straightforward.
Fill out an application.
Answer some questions.
Get a quote.
That’s changed.
Cyberattacks have become more sophisticated, and insurance carriers have become much more interested in how organizations actually manage cybersecurity risk.
Depending on the carrier and policy, you may be asked detailed questions about your security environment.
That’s why I tell credit union leaders:
Don’t think of cyber insurance as a substitute for cybersecurity.
Think of it as one layer of your overall risk management strategy.
Insurance may help your organization financially after certain covered incidents.
Good cybersecurity helps reduce the likelihood and impact of those incidents in the first place.
You need both conversations.
Start 90 to 120 Days Before Renewal
If there’s one practical recommendation I’d give every leadership team, it’s this:
Don’t wait until 30 days before renewal.
Consider beginning your internal review roughly 90 to 120 days before your renewal date.
That gives your credit union time to identify potential gaps, talk with your insurance professional, gather documentation, and address appropriate technical issues without turning everything into an emergency.
I’d organize that review around six areas.
1. Make Sure Multi-Factor Authentication Is Really Everywhere It Needs to Be
Most leaders have heard of multi-factor authentication, or MFA.
You enter your password.
Then you verify your identity another way.
Simple enough.
The problem is that organizations sometimes believe they’ve fully implemented MFA when there are still gaps.
Maybe Microsoft 365 is protected, but another remote access system isn’t.
Maybe employees have MFA, but certain administrative accounts are handled differently.
Maybe a legacy application can’t support the same controls.
So don’t simply ask:
“Do we have MFA?”
Ask:
“Where is MFA required, where is it actually enforced, and are there exceptions we need to understand?”
That’s a much better conversation.
2. Look Closely at Your Backups
I’ve said this before, and I’ll keep saying it.
Having backups and being able to recover are two different things.
A cyber insurance review is a good reason to revisit your backup and disaster recovery strategy.
Ask:
- What systems are being backed up?
- How frequently?
- Where are those backups stored?
- How are backups protected from an attacker?
- When did we last test a restore?
- How quickly could we recover critical systems?
Don’t answer those questions based on assumptions.
Verify them.
The time to discover a backup problem is Tuesday afternoon during a scheduled test.
Not Saturday morning during a ransomware incident.
3. Review Endpoint and Security Monitoring
Every laptop and workstation connected to your environment represents a potential doorway.
That’s why modern cybersecurity requires more than traditional antivirus.
Your technology team should understand what protections are deployed across endpoints and how suspicious activity is detected, investigated, and escalated.
Depending on your environment, that conversation may include:
- Endpoint detection and response
- Managed detection and response
- Email security
- Vulnerability management
- Security monitoring
- Patch management
- Administrative privileges
You don’t necessarily need to become an expert in all those terms.
You do need someone who can explain what you’re using, why you’re using it, and what happens when something suspicious occurs.
4. Train Your Employees
Technology can block a lot of attacks.
It can’t eliminate human judgment.
Cybercriminals know that.
That’s why they target people.
A convincing email appears to come from the CEO.
A fake Microsoft login page asks for credentials.
Someone pretending to be a vendor requests a payment change.
One rushed decision can create a very long week.
That’s why security awareness training shouldn’t be something employees complete once and forget.
Training should be ongoing, practical, and relevant to the threats they’re actually seeing.
Phishing simulations can also help identify where additional education may be needed.
The purpose isn’t to embarrass employees who make mistakes.
It’s to make everyone a stronger part of your defense.
5. Have an Incident Response Plan You Can Actually Use
Here’s a question worth asking at your next leadership meeting:
“If we discovered ransomware at 8:15 tomorrow morning, who makes the first five phone calls?”
If nobody knows, you’ve identified an opportunity.
Your incident response plan should clearly identify responsibilities.
That may involve:
- Executive leadership
- Internal IT
- Your managed IT/security partner
- Your cyber insurance broker or carrier contacts
- Legal counsel
- Compliance personnel
- Communications resources
- Other appropriate outside specialists
The exact response depends on the incident and your organization’s policies.
What’s important is that people aren’t meeting one another for the first time during the emergency.
6. Review Your Vendors
Your credit union doesn’t operate alone.
You depend on a network of outside organizations.
Core processors.
Cloud providers.
Internet providers.
Software companies.
Fintech partners.
Technology providers.
Each relationship can affect your security environment.
That’s why vendor management belongs in the cyber insurance conversation too.
Leadership should understand:
- Which vendors have access to sensitive systems or information
- How that access is controlled
- Whether unused access is removed
- Who owns each vendor relationship
- How critical vendors fit into incident response and business continuity plans
You can’t outsource accountability.
Even when you outsource technology.
Don’t Guess on the Application
This may be one of the most important points in this article.
When you’re completing a cyber insurance application, don’t guess.
And don’t answer based on what you think your technology is doing.
Verify.
If the application asks about a technical control you don’t understand, bring together the appropriate people—your insurance professional, internal technology resources, managed IT/security partner, legal or compliance advisers as appropriate—and make sure everyone understands what is actually in place.
A checkbox on an application isn’t just a checkbox.
Accuracy matters.
Build a Cyber Insurance Readiness Folder
Here’s a practical idea that can make renewal season much easier.
Create a centralized location for the information your leadership team may need during the process.
Depending on your organization and insurer, that could include:
- Current cybersecurity policies
- Latest risk assessment
- Employee training records
- Backup testing documentation
- Incident response plan
- Business continuity documentation
- Vendor management information
- Network or asset documentation
- Security assessment results
- Evidence of key security controls
Don’t wait until renewal week to hunt through emails and shared drives.
Prepare throughout the year.
That helps with more than insurance.
It can also make audits, examinations, and board reporting easier.
What About Cyber Insurance Costs?
This is usually the next question.
“If we improve cybersecurity, will our premium go down?”
Maybe.
But I wouldn’t build your cybersecurity strategy around that promise.
Insurance pricing can depend on many factors outside your IT team’s control, including the carrier, coverage, limits, claims history, organization size, risk profile, market conditions, and other underwriting considerations.
The better reason to improve security is much simpler.
You want a stronger credit union.
If better security also improves your insurability or helps your broker present your risk more effectively, that’s valuable.
But protecting members comes first.
The Board Should Understand This Too
Cyber insurance shouldn’t be a once-a-year conversation between the CFO and the insurance broker.
It belongs inside the broader discussion about organizational risk.
Board members don’t need to understand every security tool.
They should understand the bigger picture.
Ask:
- What are our biggest cybersecurity risks?
- What controls are we using to reduce them?
- What risks are transferred through insurance?
- What risks remain with the credit union?
- Are we prepared to respond if an incident occurs?
- When did we last test that response?
Those are governance questions.
Not technical questions.
And they’re exactly the kinds of conversations strong leadership teams should be having.
A Story I’ve Seen More Than Once
Imagine two credit unions.
Both receive their cyber insurance renewal questionnaire on the same Monday.
The first starts sending emails.
“Does anybody know whether we have this?”
“Who manages that?”
“When did we last test the backups?”
“Can someone call IT?”
The next few weeks become a scramble.
The second credit union opens its cybersecurity documentation.
Leadership already knows what controls are in place.
Backup tests have been documented.
Employee training is current.
The incident response plan has been reviewed.
The technology team verifies the technical answers.
Questions still come up.
But the process feels completely different.
One organization is reacting.
The other is prepared.
That’s the difference a technology strategy makes.
The 10 Questions I’d Ask Before Your Next Renewal
If your renewal is coming up, start with these:
1. When does our cyber insurance policy renew?
Put the date on the technology calendar.
2. Have our security controls changed since the last application?
Don’t simply reuse last year’s answers.
3. Is MFA appropriately deployed and enforced?
Verify it.
4. Are critical systems protected by appropriate endpoint and security monitoring?
Know what’s installed and who’s watching it.
5. When did we last test our backups?
Document the result.
6. Is employee cybersecurity training current?
Keep records.
7. Have we reviewed our incident response plan?
Make sure names and contact information are current.
8. Have we reviewed third-party access?
Remove access that is no longer necessary.
9. Can we document the answers we’re providing?
Evidence creates confidence.
10. Have the right advisers reviewed the application?
Technology, insurance, compliance, legal, and leadership may each have a role depending on the questions being asked.
Don’t Treat Renewal Like an Annual Fire Drill
Here’s the bigger lesson.
If you’re only thinking about cybersecurity when your insurance application arrives, you’re approaching the problem backwards.
The work happens all year.
Patch systems.
Train employees.
Test backups.
Review vendors.
Update documentation.
Assess risk.
Practice incident response.
Report meaningful information to leadership.
Then, when renewal season arrives, you’re not trying to become secure in 30 days.
You’re simply documenting the security program you’ve been operating all along.
That’s a much better place to be.
Final Thoughts
Cyber insurance matters.
But it isn’t the thing protecting your credit union every morning when the doors open.
Your people are.
Your processes are.
Your technology is.
Your preparation is.
Insurance is there to help manage certain financial risks when something goes wrong.
Your cybersecurity program is there to help prevent that day from happening—and help you respond effectively if it does.
After more than 26 years in technology, I’ve learned that preparation rarely feels urgent until suddenly it is.
So don’t wait for the renewal questionnaire.
Don’t wait for an examiner.
And certainly don’t wait for a cyberattack.
Start the conversation now.
Understand where you stand.
Fix what needs fixing.
Document what you’re doing.
And give your leadership team the confidence to say:
“We know our risks, and we have a plan.”
Because that’s what cybersecurity maturity really looks like.
Not perfection.
Preparation.
Is Your Credit Union Ready for Its Next Cyber Insurance Renewal?
If your renewal is 90 to 120 days away, now is a good time to start reviewing your technology environment.
CTG can help your team evaluate the technology side of cyber insurance readiness, identify potential security gaps, review backup and recovery capabilities, assess your current security controls, and organize technology documentation so leadership has clearer information when working with its insurance and professional advisers.
For more than 26 years, CTG has helped organizations make practical technology decisions, backed by a team with more than 200 years of combined experience.
We’re vendor-agnostic, which means the conversation starts with your credit union’s needs—not with a product we’re trying to sell.
Let’s start the conversation before the questionnaire arrives.
CTG
Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net
Your members trust you to protect what matters to them.
Let’s make sure your technology is ready to help you keep that promise.
Recent Blog Posts...
What Every Ohio Credit Union Board Should Know About Cybersecurity
How Should an Ohio Credit Union Prepare for a Cyber Insurance Renewal?
The AI Receptionist for Legal Practices: Automating Client Intake Without Losing the Human Touch
Artificial Intelligence for Ohio Credit Unions: Where Should You Start?
Breach Readiness: The Cybersecurity Checkup Every Growing Business Should Consider
- AI6
- Application Integration6
- Application Performance16
- Artificial Intelligence1
- Asset Management2
- Bandwidth Management8
- Business Continuity / Disaster Recovery41
- BYOD7
- Cloud58
- Collaboration18
- Communication20
- Compliance4
- Contact Center1
- Credit Unions11
- Cyber Liability Insurance2
- Cybersecurity37
- Dark Web1
- Hosted Phone47
- Hybrid Working2
- Internet7
- Internet of Things6
- IT Infrastructure26
- Managed Network Services20
- Managed Services19
- Microsoft Teams2
- Network Performance29
- Network Security34
- News11
- Phishing1
- Press Release2
- Risk Assessment3
- security1
- SIP Trunking3
- surveillance1
- Technology Audit3
- Telehealth3
- TruLinx7
- Uncategorized38
- Unified Communications51
- VoIP36
- Work From Home3

