Cyber insurance used to be a short form and a credit card. It is not that any more. Renewal applications now run to several pages of specific technical questions, and the answers do two things: they set your premium, and they become the basis on which a future claim is paid or refused.
That second part is the one businesses underestimate.
The Questions That Come Up Every Time
Wording varies between carriers, but the substance has converged. Expect to be asked, in some form:
- Do you enforce multi-factor authentication on email, remote access, and administrative accounts?
- Do you maintain offline or immutable backups, and when did you last test a restore?
- Do you have endpoint detection and response deployed across all endpoints?
- Is your network segmented, particularly between guest, payment, and internal systems?
- Do you have a written incident response plan, and has anyone rehearsed it?
- Do you run security awareness training, and can you evidence completion?
- How quickly do you apply critical patches?
Every one of those is a yes-or-no question with a factual answer. The risk is that the person filling in the form is not the person who would know.
Why “Mostly” Is a Dangerous Answer
The question asks whether MFA is enforced. The honest answer at a lot of businesses is “on most accounts.” There is a service account somewhere with a password from 2019, an old shared mailbox, a legacy protocol still enabled because something broke last time somebody turned it off.
Ticking yes is easy. It is also a material misstatement on an insurance application, and the one account that was not covered is statistically the one that gets compromised. Insurers investigate claims. They read the application.
Treat the Application as a Free Audit
Here is the more useful way to look at it. Your insurer has just handed you a prioritized list of the controls that measurably reduce the chance of a serious incident, assembled from claims data across thousands of businesses. That is genuinely valuable information, and it arrived for free.
Rather than answering from memory, go and check. Each question becomes a small project:
- Pull the actual list of accounts and confirm MFA coverage, including the forgotten ones
- Perform a test restore and keep the report with a date on it
- Confirm endpoint protection is installed everywhere, not just on the machines you remember
- Write the incident response plan if it does not exist, even a short one
The Documentation Is the Deliverable
Most businesses we assess are in better technical shape than they are on paper. The controls exist. What does not exist is anything written down, dated, and owned.
When a claim is being assessed, or an auditor asks, or a corporate client sends a security questionnaire before signing, “we do that” is not evidence. A dated policy, a restore test report, and an access review are.
Do This Before Renewal, Not During
The worst time to discover a gap is the week the policy expires, because the only options left are to answer inaccurately or to accept a worse premium. Start six to eight weeks out. Closing straightforward technical gaps is usually quick. Building documentation that has never existed takes longer.
Can You Evidence What Your Application Claims?
A compliance gap review tells you what you can prove today, what you cannot, and what it takes to close the difference.
