Bramvia — Business Central Experts

Your unsupported ERP could cost you your cyber insurance — and most CFOs don't know it yet

Cyber underwriting in 2026 is a technical audit. One question — do you run unsupported software in production? — can disqualify a policy outright. If your ERP runs on an old Windows Server, your renewal is a business risk, not an IT detail.

Short answer: cyber insurance underwriting stopped being a form-filling exercise. In 2026 carriers run it as a technical audit, and one question on most questionnaires can void an application outright: "do you have any unsupported operating systems in production?" A yes there — Windows Server 2012, an unpatched SQL instance, a Dynamics NAV or GP installation nobody can update — can disqualify entire policies. Carriers also now require phishing-resistant MFA on every account that touches business data, the ERP explicitly included, and they ask what percentage of revenue depends on a single system, which drives sub-limits and exclusions. Worse: if a forensic audit after a breach finds that required controls were missing or inconsistently applied, the carrier can reduce or deny the claim. So the question "should we migrate off our old ERP?" has quietly become a question about whether your insurance will pay.

What changed in underwriting

The cyber market hardened after the ransomware and business-email-compromise waves, and carriers stopped treating cyber as an ordinary commercial line. Underwriting is now handled by people who can read a network diagram — and who will fact-check your application against what they find if they ever audit you post-breach. Some carriers install their own verification software to confirm the controls you claimed are actually in place.

The eight controls that appear as required, not preferred, on most 2026 questionnaires include:

The three questions that hurt legacy ERP users

1. "Unsupported operating systems in production?" This is the one that disqualifies. An on-premises ERP is rarely just the ERP: it is a Windows Server, a SQL Server, sometimes a terminal server, and often a version chosen when the system was installed. Dynamics NAV 2013 or 2016 running on Server 2012 R2 is a common and unanswerable combination.

2. "MFA on every account touching business data?" Many legacy ERP deployments authenticate against an old Active Directory with no modern MFA path, or use shared accounts on the shop floor. Both are honest answers that underwriters will not like.

3. "What percentage of revenue depends on a single system or vendor?" If one on-premises instance, maintained by one consultant who may retire, runs your entire order-to-cash, concentration risk drives sub-limits. This is also the question that makes the talent-pool problem a financial one.

Why this is a CFO conversation, not an IT one

Three consequences, all financial:

Premium and coverage. Missing controls mean higher premiums, lower limits, or sub-limits on the exposures that matter most. Some applications simply do not get written.

Claim denial after the fact. This is the one people miss. A policy issued on an application that overstated controls, or on controls that were not maintained, can be reduced or denied when the forensic report lands. You discover it at the worst possible moment.

Customer and lender requirements. Large customers increasingly require proof of cyber cover, and lenders and PE sponsors ask for it in diligence. A gap here can cost a contract, not just a premium.

Put plainly: if your ERP cannot be patched, it is no longer only a productivity or compliance question. It is an insurability question with a renewal date attached.

What the cloud actually changes here

Moving to Business Central online removes several of these answers from your questionnaire entirely:

None of that makes you secure on its own — your endpoints, your email and your people still carry most of the risk. What it does is remove the answers that disqualify applications, and replace "we think we're covered" with evidence.

What to do before your next renewal

  1. Get the questionnaire early. Ask your broker for the 2026 version now, not two weeks before renewal.
  2. Inventory production operating systems and database versions. Write the honest answer down. If it includes anything unsupported, you have a decision, not an opinion.
  3. Pull the MFA coverage report from your identity provider and look at what the ERP accounts show.
  4. List shared and service accounts on the shop floor and in integrations. These are usually the gap.
  5. Check whether an ex-employee is still active anywhere. Carriers check.
  6. Price the migration against the insurance exposure, not just against productivity. For a NAV or GP shop, the numbers are here — and Microsoft's Bridge to Cloud discount is open for enrolment until 31 December 2027.

What we do and don't do

We are not insurance brokers or a security firm, and we do not advise on policy terms — talk to your broker and, if needed, a security assessor. What we do is the part that shows up on the questionnaire: moving the ERP off unsupported infrastructure, onto identity you can prove, with an update path that doesn't break. If your current system can be brought to that standard where it is, we will tell you so.

If you want the numbers before the conversation, the free assessment covers your version, your customisations, your integrations and what a move would take — in five working days, and each part of any project invoiced only after you accept it.

FAQ

Can a carrier really refuse us over one old server? An affirmative answer on unsupported software in production can disqualify an application with some carriers and drive exclusions with others. It is one of the highest-weighted questions on the form.

We have MFA on email. Is that enough? No. Requirements now read "every account that accesses business data" — explicitly including ERP — and underwriters increasingly ask for the coverage report rather than your word.

Our ERP is on-premises but behind a VPN. Doesn't that cover it? VPN access is itself one of the accounts requiring phishing-resistant MFA, and it does not change the answer about unsupported software in production.

Is cloud ERP automatically insurable? No. It removes some disqualifying answers and makes several controls evidenceable. Endpoints, email and staff training remain yours.

How long does a migration take? 3-9 months for a typical mid-market company. If your renewal is sooner, tell your broker what is in progress — carriers treat a documented remediation plan differently from nothing.

Renewal coming and an ERP you can't patch? Free assessment, no commitment — first reply within one working day.


Bramvia · bramvia.net