Cyber insurance is one of the few operating costs at a mid-market portfolio company that has no floor. Premiums can double at renewal. Sub-limits can be added that quietly gut ransomware coverage. Whole markets can decline to renew. And unlike most operating expenses, the timing is fixed — the renewal date arrives, and the portfolio company either has coverage the fund is comfortable with, or it doesn’t.
For PE-owned companies specifically, renewals are harder than they were three years ago and harder than they are for privately-held peers at the same revenue. Underwriters price PE ownership as an incremental risk factor, and most portfolio company CFOs and IT managers don’t know that.
This is a playbook for what underwriters actually look at, which controls move premiums, and the 90-day pre-renewal workstream that produces a controlled renewal instead of a scramble.
Why PE Portfolio Companies Get Priced Differently
Three reasons cyber underwriters treat PE-owned companies as incrementally higher-risk at renewal.
Aggregated fund breach history. Some markets are pricing at the fund level, not just the portfolio company level. If any other portfolio company in the fund had a claim in the last three years, that history is part of the renewal narrative. Underwriters don’t publish this, but application questions and follow-up diligence make it clear. A portfolio company can have a clean loss history and still be affected by another portfolio company’s breach.
Change-of-control uncertainty. Underwriters know PE-owned companies acquire and get acquired. That instability affects control continuity, particularly when the acquired entity operated on different security stacks. Renewal quotes now often include change-of-control language that either narrows coverage at close or triggers repricing.
Portfolio integration risk. When multiple portfolio companies share fund-level MSPs, IT platforms, or identity providers, a breach at one propagates risk across the fund. Some carriers explicitly ask about shared infrastructure across portfolio companies. Most operating partners haven’t been asked this yet. They will be.
The practical effect: a $50M revenue privately-held company and a $50M revenue PE portfolio company with identical security controls will often be priced differently by the same carrier. That gap is fixable, but only if the renewal is treated as a project, not as a form to fill out three weeks before the deadline.
What Changed in Cyber Underwriting Since 2022
For years, cyber insurance underwriting was a light-touch process. A questionnaire, vague statements about MFA and backups, and a policy issued at a rate reflecting general industry loss ratios. Ransomware changed that.
The 2020–2022 ransomware wave produced loss ratios that put multiple carriers into single-year unprofitability. What followed was a rapid tightening of underwriting standards that is now the norm.
- Application questionnaires expanded from ten questions to sixty-plus. Some carriers now require attestation-level detail on twenty or more specific controls.
- Sub-limits on ransomware became standard. Where policies once paid full limit for ransomware losses, most now cap ransomware-specific coverage at a fraction of aggregate, sometimes 25%, sometimes lower.
- Coinsurance on ransomware. Some carriers require the insured to bear a percentage of the ransomware loss even after retention is met. Separate from sub-limits and often stacked with them.
- Attestation-based coverage. Certain controls — MFA on all remote access, EDR on all endpoints, immutable backups — must be attested. If the attestation was inaccurate, the carrier can deny the claim regardless of what caused the loss.
- Retroactive dates and prior-acts limitations. Coverage for incidents discovered during the policy period but caused before it began has narrowed. This matters at acquisition, when historical exposure is often unknown.
The renewal that fails is rarely a surprise attack. It’s a renewal where the portfolio company answered the questionnaire the same way it did last year, and the market has moved.
The 12 Questions Underwriters Actually Ask
The specific questions vary by carrier and program, but the underlying controls converge on the same twelve areas.
- MFA on all remote access, VPN, and privileged accounts. Coverage on all, not most, not “in progress.” Any gap here shows up as either a coverage exclusion or a premium load.
- EDR (endpoint detection and response) on 100% of endpoints. Servers, workstations, laptops, virtual machines. Deployment below 95% typically triggers additional diligence.
- Immutable backup with a documented offline or air-gapped copy. Backup existence isn’t enough. The backup must be resistant to a domain-admin-level attacker.
- A tested incident response plan with an outside IR retainer. Underwriters strongly prefer named IR firms with active retainers. Retainer relationships also produce faster response during actual incidents, so this is genuine risk reduction, not just an insurance requirement.
- Privileged access management with rotation and session recording. Static admin credentials with password reuse across systems are a red flag.
- Patch cadence with a documented SLA on critical vulnerabilities. Time-to-patch on CVSS-critical vulnerabilities is now a specific application question in some programs.
- Phishing simulation program with tracked failure rates and remediation. Not just annual training. A program with metrics.
- Third-party and vendor access controls. Contractor access, MSP access, SaaS integrations. Who has access to what, and how it’s monitored.
- Cloud configuration monitoring for the identity provider and key SaaS platforms. M365 or Google Workspace, plus critical business SaaS. Misconfiguration monitoring, not just baseline security.
- Log retention and monitoring — SIEM or equivalent coverage. How long logs are retained, what’s monitored, and who receives alerts.
- Tabletop exercises with executive participation. Not tabletop with the IT team. Tabletop with the CEO and CFO in the room. Underwriters increasingly ask when the last executive tabletop was held.
- Business continuity plan with defined RTO/RPO and validated recovery procedures. Written plans are common. Validated recoveries within the last twelve months are less common, and that’s what underwriters actually ask about.
Each has a documentation trail attached. The application asks. The follow-up asks for evidence. Portfolio companies that keep evidence current renew at rate. Companies that treat controls as attestations first and implementation second get discovered.
Controls That Move Premiums vs. Controls That Are Theater
Not all controls move premiums equally. Some produce meaningful pricing improvement. Some produce compliance but zero pricing benefit. Knowing the difference matters when the security budget is finite.
Controls that consistently move premiums:
- Full-coverage MFA on remote access and privileged accounts (large impact)
- 24/7 EDR with active MDR service, not just tool deployment (large impact)
- Immutable, tested backup (large impact)
- Named IR retainer with a top-tier firm (moderate impact)
- SIEM or equivalent with staffed 24/7 monitoring, not just log storage (moderate impact)
Controls that are compliance theater without moving premiums:
- Annual employee training with no metrics
- Antivirus without EDR
- On-premises backups without offline separation
- Written IR plan without tabletop or retainer
- “SIEM in place” without staffed monitoring
The pattern is clear. Implementation quality is what underwriters price. A well-implemented four-control stack — MFA, EDR/MDR, immutable backup, IR retainer — typically produces better renewal pricing than a poorly-implemented ten-control checklist. For a portfolio company operating with a finite security budget, this is the sequencing question that matters. Invest in depth on the four controls that move pricing before adding breadth.
The Sub-Limits and Exclusions That Quietly Gut Coverage
The premium is what most CFOs look at. The sub-limits and exclusions are what actually determine whether the policy pays when it matters.
Ransomware sub-limit. Most policies now cap ransomware payments at a fraction of aggregate limits. Read the specific dollar figure, not the aggregate.
Business interruption sub-limit and waiting period. BI coverage that requires a 24-hour or 48-hour waiting period effectively excludes most business interruption from ransomware. Average recovery is longer than the waiting period, but the largest losses happen in the first 48 hours.
Contingent business interruption. Coverage for losses caused by a breach at a vendor or supplier. Often sub-limited well below aggregate. Increasingly relevant as SaaS dependencies grow.
Widespread event and war exclusions. The 2022–2024 war exclusion updates matter. Some are narrow — state-sponsored, attributable attacks. Some are broad — any attack tied to a nation-state actor, whether attributed or not. Read the specific language.
Biometric information exclusions. For any portfolio company using fingerprint, facial recognition, or voice authentication, this exclusion can eliminate coverage for exactly the type of breach that is most likely and most expensive.
Cryptocurrency and sanctions exclusions. Any coverage element that requires payment of cryptocurrency (typical for ransomware) may be excluded under sanctions-related policy language.
Regulatory fines and penalties. GDPR, HIPAA, state privacy laws. Some carriers cover fully, some sub-limit, some exclude.
The renewal review should include a written comparison of these terms year-over-year. A renewal that keeps premium flat but introduces a lower ransomware sub-limit is a rate increase disguised as flat pricing.
The 90-Day Pre-Renewal Playbook
Renewals go well when they are treated as a project, not a form. The workstream that produces a controlled outcome runs ninety days.
Days 90–75: Baseline the current state.
Pull the current policy — the actual document, not the certificate of insurance — and read it. Note the sub-limits, exclusions, retroactive date, coinsurance percentages, and warranty language. Compare to the last renewal application. Whatever was attested last year is now the baseline. Identify gaps between attestation and current-state implementation. That is the honest inventory.
Days 75–60: Fix the material gaps.
Focus on the four controls that move pricing: MFA gaps, EDR coverage, backup immutability, IR retainer. Do not attempt to fix everything. Fix the material items. Document the fixes with dates, screenshots, and named owners. This becomes the evidence packet.
Days 60–45: Market strategy.
Decide whether to test the market or stay with the incumbent. In hardening markets, testing produces surprises — sometimes upside, sometimes not. Brief the broker on the changes since last renewal. Brokers who go into a renewal without a narrative get default quotes; brokers who go in with a documented improvement story get better pricing. Assemble the application packet. Answer questions accurately and with evidence.
Days 45–30: Underwriter engagement.
Underwriters increasingly want a call with the portfolio company, not just an application review. Prepare the CEO or CFO for a 30-minute conversation on security posture and improvement roadmap. If material additional questions arrive at this stage, answer them fully. Non-response or partial response is now a common reason for quotes to widen.
Days 30–15: Quote review.
Compare quotes across markets. Do not compare on premium alone. Sub-limits, exclusions, and retention structure matter more than the topline number. Negotiate specific terms. Sub-limits are negotiable. Retention is negotiable. Exclusions are sometimes negotiable if the specific risk can be documented as unusually low.
Days 15–0: Bind and renew.
Bind the chosen quote. Verify that the bound policy matches the quote — errors happen at this stage. Document the renewal narrative for next year: what changed, what was attested, what evidence is filed where.
What to Do at 60 Days If You’re Not Ready
Sometimes renewals sneak up. The renewal date is sixty days out and the honest gap inventory reveals meaningful problems — no EDR on servers, backups without offline separation, no IR retainer. Three moves at sixty days:
Triage. Rank the gaps by pricing impact, not by breadth. The four pricing controls come first. Everything else is deferred.
Bridge with process, not tooling. Deploying a new EDR platform in sixty days is unrealistic. Attesting to an aggressive deployment plan with weekly progress reporting to the underwriter is realistic. Underwriters price against improvement trajectory, not just current state.
Signal the broker early. Brokers who learn about a coverage issue at bind time have no options. Brokers who learn at sixty days can shop and structure the placement around imperfect current state.
The worst outcome at sixty days is the portfolio company that says nothing, submits an incomplete application, and receives a decline or a punitive quote at fifteen days out. At that point the negotiation window is closed.
When to Walk a Market vs. Accept Degraded Terms
Not every renewal quote is worth binding. Walk when:
- A ransomware sub-limit below 25% of aggregate. That’s not real ransomware coverage.
- A war or nation-state exclusion broad enough to exclude typical cybercrime attribution. Some post-2022 war exclusions were written to exclude any incident linked to a nation-state actor, even indirectly. That’s most cybercrime.
- A retention increase beyond what the balance sheet can absorb.
- Coinsurance on ransomware above 20%.
Better to accept a lower aggregate with better terms than a higher aggregate with sub-limits that make the coverage illusory.
Accept degraded terms when:
- The whole market has moved. If every carrier is quoting similarly, walking gets a worse quote elsewhere. Accept the terms and prepare for the following year.
- A narrowed retroactive date at a time of active known exposure. Sometimes narrowing prior-acts coverage is the price of getting a renewal at all.
- Increased retention if it produces materially better sub-limits and premium.
The judgment call is whether the coverage that remains after the degradation is coverage worth having. A policy that pays 40% of the ransomware loss with 20% coinsurance is materially worse than no policy at all in some cases, because the certification cost of the policy exceeded the expected recovery.
What This Means for the Operating Partner
Cyber insurance renewal at a portfolio company is rarely on the operating partner’s calendar until it goes badly. Three things justify moving it into the operating rhythm.
Renewal outcomes are a leading indicator of security posture. A portfolio company whose renewal deteriorates year-over-year is telling the fund something about its security investments, whether the CEO says so or not.
Renewal narratives compound across the fund. Every portfolio company that shows measurable improvement in its renewal narrative — controls implemented, evidence documented, executive engagement demonstrated — helps every other portfolio company in the fund the next year.
Post-close diligence should include renewal date and prior renewal narrative. The upcoming renewal is a known risk on the operating plan. Pre-close diligence catches this. Most confirmatory diligence does not.
The operating partner doesn’t need to run the renewal. What the operating partner needs is (a) visibility into which portfolio company renewals are approaching, (b) confidence that each portfolio company has a named owner for the renewal workstream, and (c) escalation authority when a renewal starts going sideways at day forty-five rather than being discovered at bind time.
Vertex CIO Advisory sits in this role for fund clients that want portfolio-wide renewal oversight without hiring a full-time CISO at every portfolio company. The workstream is scoped to ninety days per renewal, priced fixed, and coordinated across the portfolio when multiple companies share carriers or brokers.
Learn how Vertex CIO covers cybersecurity oversight and renewal readiness →