top of page
yava_white_logo.png

Evidence Underwriters Can Price Against at Renewal

  • 2 days ago
  • 5 min read

At renewal, most risk is still priced on what the insured chooses to declare. This article explains how a scored, evidenced assessment gives an underwriter something firmer to price against, why verified controls change the terms on offer, and how the same evidence turns renewal from an argument about rate into a conversation about the risk itself.


Four construction workers in hard hats and neon jackets review blueprints on site, smiling; YAVA logos visible.
A scored assessment gives an underwriter verified controls, not a self-completed form.

The Issue


For the first time in years, buyers hold the better hand. Marsh’s Global Insurance Market Index recorded a twelfth consecutive quarterly decline in cyber insurance rates in the second quarter of 2026, as global cyber rates fell by 4%. This formed part of a broader, though not universal, softening across commercial insurance lines. Marsh also noted that insurers were competing through broader coverage, expanded policy terms, and lower deductibles as well as price, while underwriting remained more selective in some areas.


The difficulty is what the underwriter has to work with. When the picture of an account comes mainly from a self-completed questionnaire, there is little to separate a well-run risk from a poorly-run one that answers the same questions the same way. Price becomes a blunt instrument. The careful operator subsidises the careless one, and the business that has invested in controls has little to show for it at renewal.


The sums are not small. IBM put the global average cost of a data breach at a record $4.99 million in 2026. Pricing exposure of that size on assertion alone is expensive guesswork, for the insurer and the insured alike.


How The Renewal Conversation Works Today


Renewal underwriting rests on three things: declared data from proposal forms and questionnaires, the account's loss history, and market benchmarks for its sector and size. The broker presents the risk, the underwriter applies rate and terms, and the cycle repeats each year.


Cyber insurance shows how underwriting requirements can influence security posture. During the hard market that began in 2021, insurers tightened requirements around controls including multi-factor authentication, endpoint detection and response and secured, tested backups. Industry analysis has linked wider adoption of these controls to improved underlying risk and reduced claim severity. Gallagher’s 2026 Cyber Insurance Market Outlook reported that 28% to 32% of ransomware victims paid in 2025, down from 37% in 2024, although it did not attribute that decline solely to insurer-required controls.


The episode proved two things: controls move loss, and underwriters will reward them, provided they can trust that the controls are real.


That proviso is the whole issue. Most of what an underwriter sees is still self-reported. In effect, the account is priced on a declaration.


What Is Often Missed: The Evidence Underwriters Need at Renewal


Declared data and priceable evidence are not the same thing. A questionnaire's answer is an assertion. An underwriter cannot verify it on the day and so tends to price in a margin for uncertainty. The insured pays for the doubt.


The gap has teeth. In 2022, US insurer Travelers asked a federal court to rescind a cyber policy after the insured stated that it used multi-factor authentication for administrative or privileged access. Following a ransomware attack, Travelers alleged that an investigation found MFA protected only the company’s firewall and no other digital assets. The court subsequently rescinded the policy and declared it null and void from inception. The case shows that inaccurate declarations about security controls can jeopardise coverage and highlights the importance of being able to substantiate those declarations with evidence an underwriter can assess.


The financial value associated with effective security controls can also be quantified, although IBM’s findings span several editions of its Cost of a Data Breach Report. Its 2022 research associated an incident response team and regularly tested response plan with $2.66 million lower average breach costs. The 2025 report found that extensive use of security AI and automation was associated with savings of $1.9 million, while earlier IBM research linked a mature zero-trust strategy to $1.76 million lower average costs.The condition attached to every one of those figures is that the control is actually in place. An underwriter can only price what it can trust.


IBM 2025 bar chart: tested incident response plan, security AI & automation, and zero-trust architecture reduce breach costs.
Figure 1. Controls associated with a materially lower average breach cost. Each is priceable evidence only when it is verified in place. 

Control

Lower average breach cost

Tested incident response plan 

$2.66M 

Security AI & automation (extensive) 

$1.90M 

Zero-trust architecture 

$1.76M 

Source: IBM Cost of a Data Breach Report 2025 (association with lower breach cost, not a guarantee).


The missing piece at renewal, then, is not more data. It is verified, scored and comparable evidence: a picture of the account the underwriter can act on rather than take on faith.


How YAVA Approaches It


YAVA produces that evidence. Engineers assess the asset on site and verify its controls across three layers, the external and physical, the internal and systems, and the human, scoring each and combining them into a single composite figure out of 100.


Every finding is tied to a consequence through a loss-pathway map, and where a finding touches a warranty, a sub-limit or an exclusion, that link is made explicit. The outputs are written for the people who price the risk: a scored report, a loss-pathway map, a prioritised remediation plan, and an underwriting brief.


As the score is refreshed at each reassessment, improvement is measured rather than asserted. A gap closed between one renewal and the next shows up as a higher score and a documented fall in exposure, which is exactly the kind of change an underwriter can act on.


Flowchart shows scored assessment to renewal: on-site assessment, score + evidence, remediation, re-score, renewal on verified risk.
Figure 2. Each renewal begins from verified evidence and a measured improvement, rather than a fresh questionnaire.

The insured funds the assessment and the insurer receives verified evidence. As YAVA works for the operator, findings can be held back from the insurer until the gaps are repaired, so the account arrives at renewal in its strongest evidenced position.


Two construction workers in hard hats at a muddy site, one pointing ahead while the other holds a tablet and radio; YAYA on jacket.
Controls are checked on the ground, so the evidence behind the score can be relied on.

Practical Application


The following scenario is illustrative and is not an account of an actual YAVA engagement.


A mid-market operator comes to renewal with a clean questionnaire and a flat to rising quote. An assessment scores the account, verifies most of its controls, and identifies three material gaps: multi-factor authentication missing on remote access, backups never tested by a live restore, and a segmentation weakness between the office and operational networks. Each gap is tied to a warranty or an exclusion in the policy.


The operator closes the two cheapest, highest-impact gaps before the renewal date. This time the submission carries a verified control set, a documented improvement in the score and two closed warranty triggers. The underwriter prices the account on evidence rather than assumption, and the discussion shifts from what rate applies to the sector to what is actually in place at this site.


What Decision-Makers Should Consider


A short set of questions separates a declared renewal from an evidenced one:


  • Does our submission give the underwriter verified evidence, or a declaration they have to take on trust?

  • Which of our controls would actually withstand a claims investigation?

  • Can we show measurable improvement since the last renewal, or only assert it?

  • Are our findings tied to the warranties, sub-limits and exclusions the policy is priced against?

  • In a soft market, what makes our account stand out beyond price?

  • For insurers: are we pricing this risk on evidence, or on the same form every applicant completes?


Conclusion


A soft market rewards the accounts that can prove they are well run and quietly penalises those that can only say so. A scored, evidenced assessment gives the underwriter something firm to price against, and gives the insured a documented record of improvement to negotiate with. It turns renewal from an argument about rate into a conversation about the risk itself. For operators and insurers who would rather price what is there than what is claimed, that shift is worth having before the next renewal, not after the next loss. YAVA is glad to talk it through.

Comments


bottom of page