Compliance
Cyber insurance readiness: what the application asks and how to answer truthfully
Cyber-insurance applications have become detailed security questionnaires. Here are the controls underwriters commonly ask about, how to check whether your answers are actually true, and why a hopeful yes can be worse than an honest no.
Not long ago, a cyber-insurance application for a small business was a page or two of general questions. Today it often reads like a security audit. Do you enforce multi-factor authentication on email? On remote access? On administrator accounts? Do you run endpoint detection and response? Are your backups offline or immutable, and when did you last test one?
Owners tend to fill these in the way they fill in most forms: quickly, optimistically, and without checking with whoever runs their IT. That is a mistake, and potentially an expensive one. The answers on that form are statements the insurer relies on when deciding to cover you and what to charge. If they turn out to be wrong when you make a claim, you may find your coverage is not what you thought.
This post walks through what applications commonly ask, how to find out whether your honest answer is yes, and what to do when it is not.
A note before we start: this is general information for business owners, not legal or insurance advice. Policies, applications, and requirements vary between insurers and change over time. Read your own policy carefully, and talk to your broker or a lawyer about anything specific to your situation.
Why the questions got harder
Insurers have paid out on a great many ransomware and email-fraud claims, and they have learned which controls tend to separate the businesses that recover quickly from the ones that do not. The applications reflect that learning. They are, in effect, a list of what underwriters think matters most.
That makes the application useful even if you are not buying insurance. It is a reasonably good checklist of the basics, written by people who see the cost of getting them wrong.
What underwriters commonly ask about
Wording differs between insurers, but the same themes come up again and again.
Multi-factor authentication. Usually asked separately for email, remote access (VPN, remote desktop, remote-control tools), administrator and privileged accounts, and sometimes cloud applications and backups. “We have MFA” is not the question. The question is whether it is enforced on each of those, for every account.
Endpoint detection and response (EDR). Whether your computers and servers run security software that watches for suspicious behaviour and can isolate a device, rather than traditional antivirus alone. Some applications also ask whether that tool is monitored by someone.
Backups. Whether you back up critical data, whether at least one copy is offline, separated from your network, or immutable (cannot be altered or deleted for a set period), whether backups are protected by separate credentials, and whether you have tested restoring from them recently.
Patching. How quickly you apply security updates to operating systems and software, and whether you have any systems that no longer receive updates.
Security awareness training. Whether staff receive regular training on phishing and fraud, and sometimes whether you run simulated phishing tests.
Incident response plan. Whether you have a written plan for what happens during a cyber incident, including who to call.
Email and payment controls. Whether you verify changes to payment details out of band, and whether email filtering and authentication are in place.
Administrator access. Whether everyday accounts are separate from admin accounts, and how many people hold admin rights.
How to answer truthfully
For each question, the goal is not a yes. The goal is an accurate answer you can back up. Here is how to check each one.
MFA. Ask your IT provider for a report from Microsoft 365 or Google Workspace showing MFA status for every account, including shared mailboxes and service accounts. Then separately confirm your remote access tools and any admin consoles. One unprotected account can make a “yes, all accounts” answer untrue.
EDR. Confirm the product name, which devices have it installed, and whether it is actually running on all of them. If you are not sure whether your product is EDR or traditional antivirus, ask the vendor or your provider directly.
Backups. Find out where every copy lives, whether any copy is offline or immutable, and when a restore was last tested, not just when a backup last ran. If the answer is “never,” that is your answer until it is not.
Patching. Ask for a list of devices with outstanding updates and any running unsupported operating systems.
Training. Note when training last happened, who attended, and whether it is documented.
Incident response. If there is a written plan, find it and check it is current. If it is only in someone’s head, it does not count as written.
Keep the evidence. Screenshots, reports, and dated notes of what you checked become very useful if a claim is ever questioned.
The misrepresentation risk
This is the part owners most often underestimate. Insurance applications are generally treated as material representations. If an insurer later finds that an answer was inaccurate, depending on the policy and the circumstances they may be able to deny a claim, reduce what they pay, or in some cases void the policy. The specifics depend on your policy wording and the law that applies, which is exactly why your broker and a lawyer are the right people to ask.
The practical lesson is simple. An honest “no” or “partially” usually leads to a conversation, perhaps a higher premium or a condition to fix something by a certain date. An inaccurate “yes” may not surface until the worst possible moment: after an incident, when you need the coverage most.
If you are partway through a control, say so. Many applications have room for explanation, and brokers can often help you present a plan to close the gap.
A readiness checklist
Work through this with whoever manages your IT before your next application or renewal.
- MFA enforced on every email account, including shared and service accounts
- MFA enforced on all remote access tools
- MFA enforced on every administrator account, which is separate from everyday accounts
- EDR installed and running on every computer and server
- At least one backup copy offline or immutable, with separate credentials
- A restore test completed recently, and documented
- Security updates applied promptly, and no unsupported systems in use
- Security awareness training delivered and documented
- A written incident response plan, with contact details for your insurer, broker, and IT provider
- Out-of-band verification required for payment-detail changes
- Evidence saved for each answer
Where this fits
The controls insurers ask about are the same ones that keep a small business running after a bad day. Our guides to MFA and ransomware-resilient backups cover two of the biggest items in detail. If you want someone to check the whole list and document what is true, a business tech checkup is a good place to start, and our cybersecurity service keeps those controls in place between renewals.
Write us a short brief about your renewal date and what the application is asking, and we will reply in writing within one business day.