A broker called me last month.
His client’s cyber insurance renewal came back with a 40% premium increase. The underwriter cited “inadequate access controls.”
The client had MFA. Had endpoint protection. Had a written IR plan. Checked every box.
So what happened?
The underwriter’s supplemental questionnaire asked: “Is MFA enforced on ALL user accounts, including service accounts?”
The answer was no. MFA was on the email portal. Not on the VPN. Not on the cloud console. Not on the admin service accounts the IT team used.
On paper, they had MFA. In reality, they had a gap.
This happens more than brokers realize. The application passes. The controls exist. But the implementation has holes that won’t show up until a claim is filed — or a renewal comes back with sticker shock.
What I do for brokers
- Pre-submission control reviews — I check what underwriters will actually ask
- Gap remediation — fix the implementation, not just the paperwork
- Supplemental questionnaire prep — so your clients answer confidently, not nervously
The result: cleaner submissions, fewer surprises, better terms.
If you’re tired of watching good clients get penalized for controls that exist but don’t work, let’s connect. I speak fluent underwriter.