Cyber Hygiene, Properly: The Habits That Actually Reduce Risk (and Keep Your Cover Valid)

Most of the firms we talk with that get a rough ride at cyber insurance renewal aren’t missing anything obvious on paper. MFA is turned on, and a backup job runs somewhere overnight. What trips them up is a follow-up question from a broker or an underwriter that nobody inside the firm can answer with real confidence. Has anyone tried restoring from that backup in the last few months, or is everyone just trusting that the job was completed? 

We see this across firms of every size in the region, from a fifteen-attorney practice to a two-office accounting firm that’s grown fast enough to lose track of what’s running where. Somebody configured things correctly at the start. Eighteen months later, nobody had gone back to check any of it. The stakes have climbed, too. Verizon’s 2026 Breach Impact Study, based on insurance claims data, shows the median insurable loss per cyber incident roughly doubled between 2019 and 2024, from around sixty thousand dollars to a hundred and ten thousand. Underwriters have priced that shift in, and it shows up in how closely they now check the details on a renewal application. 

Auditing what’s true right now 

An IT provider can tell you what was configured when a firm first signed on or when a policy last renewed. Inside the firm, that’s a harder question to answer about right now. An employee who left eight months ago still has a disabled account nobody removed. A satellite office that opened last spring backs up on whatever schedule got set up in the rush of moving in, and nobody has touched it since. 

This kind of thing rarely gets caught right away. It tends to surface later, during a renewal or when a client sends over a security questionnaire. Treating the check as a standing habit, something reviewed on a calendar the same way a firm reviews client engagement letters, means a renewal questionnaire gets answered from memory. Our IT audits and assessments work is built around that running rhythm, a look every quarter or so, which means nothing goes more than a few months without someone checking it. 

Assigning ownership 

When we ask who’s responsible for security at most firms we work with, the honest answer is typically some version of the IT company handles that. It’s a vague answer, and vagueness is precisely what catches up with a firm eventually, once an insurer or a client wants a specific name attached to a specific check. 

IT support responds when something breaks or someone submits a ticket. Ownership is narrower than that. It’s a specific person, confirming on a schedule that a backup restores and that an account gets removed when someone leaves, and being able to say when that confirmation last happened. 

In a good number of our client relationships, that person ends up being a virtual CIO. Part of that comes down to timing. A firm’s own staff are close enough to the daily work that a quarterly check is easy to push back a week, and then just as easy to forget about after that. A step removed from that daily pressure, the role holds up better, and it’s easier to report honestly on what an audit turns up. The requirement doesn’t change depending on who fills it. One person’s name is attached to a specific, checkable set of confirmations on a calendar. Our vCIO services exist for firms that want that kind of ownership without adding to internal headcount. 

Building a review cadence 

Insurance renewal tends to focus hardest on two things, and neither is about whether a tool is installed. Backup testing and patch verification are both, at bottom, questions about whether something still works the way it did when it was first set up. 

CISA has been blunt about backups for years now. Running the job on schedule tells you the job ran. Only a restore test tells you whether the data comes back. The agency’s guidance is to run that test on a recurring basis and log the result each time. That log is what turns a hope into a fact. 

Patching runs into the same issue. Verizon’s 2026 Data Breach Investigations Report puts vulnerability exploitation at 31 percent of confirmed breaches now, a jump of 55 percent from the year before, with the median time to fully close a critical vulnerability stretching to 43 days. A patch schedule that exists in a policy document but hasn’t been checked against what’s installed on actual machines is mostly theoretical. The habit that matters here is the comparison itself, checking what should be patched against what has been patched on a set schedule and fixing whatever shortfall turns up. 

Keeping evidence ready 

All of this only matters if a firm can produce it on request. The American Bar Association’s 2023 Legal Technology Survey found that the share of firms with a documented incident response plan fell from 42 percent to 34 percent in a single year. Something built once and never revisited simply stops matching reality within a year or two. 

Keeping evidence current works the same way. A record of a restore test or a patch review needs to live somewhere specific, refreshed on the same schedule as the checks themselves. That way, someone can answer a renewal questionnaire or a claim inquiry by pulling a file that already exists. Several of the firms we support keep that record next to their backup and disaster recovery documentation. The location matters less than whether one specific person knows where it is and checks it regularly. 

Where this leaves you 

A calendar with a name attached to each item, and a place to keep the proof once a check is done, costs less than most firms assume. The firms that get an easy renewal, year after year, are usually the ones where someone specific checks whether last year’s setup still holds and can back that up inside five minutes if asked. 

If it’s been a while since anyone in your firm has done that kind of check, reaching out to our team is one place to start. So is pulling your last renewal questionnaire and counting how many answers you could still support today, without guessing at any of them. 

Book a meeting with BASE Solutions.

Get a Free Consultation

Contact our experts today

Recent Posts:

Managed IT Services Can Cut IT Costs by 40% and Boost Efficiency by 50-60%.

Discover how the right IT partner can transform your business!