What cyber insurance applications ask, and how to answer

Cyber insurance applications ask a short, consistent set of control questions: MFA, backups, endpoint detection and response, privileged access, patching, incident response planning and email security. Answer each one with what is true today across the whole estate, and keep the evidence that proves it. A false “yes” can cost you far more at claim time than an honest “no” costs at application.

The controls underwriters ask about

Wording varies between insurers. The substance barely does.

  • MFA. On email, remote access such as VPN and remote desktop, cloud admin consoles and every privileged account. “All users” includes the old service account nobody logs into.
  • Backups. At least one copy that is offline or immutable, held under separate credentials, with a restore that has actually been tested.
  • Endpoint detection and response. Installed on every laptop and server, and watched by someone who will act on an alert at night.
  • Privileged access. Separate admin accounts, no shared domain admin password, and a short list of people who hold it.
  • Patching. How fast critical fixes land, especially on systems facing the internet.
  • Incident response plan. Written, approved, tested, and listing the insurer’s hotline.
  • Email security. Filtering, attachment handling and DMARC and email authentication.

The Canadian Centre for Cyber Security’s baseline controls for small and medium organizations cover most of the same ground and make a sensible starting checklist.

Why an inaccurate “yes” is dangerous

Picture the form: “Is MFA enforced for all remote access?” Someone ticks yes, because the main VPN has it. The attacker comes in through an older appliance kept for one supplier, which never did.

The claim investigation will find that appliance, and the insurer will read the finding next to your form. How your policy treats the gap is a question for your broker and counsel.

The person signing is rarely lying. Usually they answered for the systems they knew about. That is why the answers need an inventory behind them.

How to answer with evidence

Treat each question as a small claim you will have to prove later. For every answer, record the scope it covers, where the evidence came from, the date, and who owns the control.

When the honest answer is “mostly”, say so, with the scope of the exception and the date it closes. Underwriters see partial answers all the time. A stated exception with a plan reads very differently from one discovered after a loss.

The same file serves customer security reviews. Our evidence pack shows the shape.

What to do about a “no”

Some gaps close in weeks. MFA on remote access and admin accounts is usually the fastest, and why MFA decides your insurance renewal explains why it carries so much weight.

Others take longer. Start them before renewal and disclose them with a date. Where the gaps are strategic rather than technical, the answer belongs in enterprise risk management and cyber insurance readiness: what you retain, what you transfer, and what you fix first.

Questions we are asked

What happens if we answer an insurance application incorrectly?

After an incident, the investigation establishes your real control state and the insurer reads it next to your application. A gap between the two can put the claim in dispute; how your policy treats that is a question for your broker and counsel.

Do we need MFA everywhere to get cyber insurance?

Not everywhere, but underwriters consistently expect it on email, on remote access and on privileged or administrator accounts. Those three are where a missing control draws the hardest questions.

Can we answer “yes” if a control is almost fully deployed?

No. Answer what is true, and use the notes field or a covering note to your broker to state the exception, its scope and the date it will be closed.

What evidence should we keep for each answer?

Keep a dated record for each answer: an MFA enrolment report, backup job logs and a restore test, an EDR console count against your asset list, and the approved incident response plan.

Getting the next application right

Send the application form and your renewal date. The reply says which answers need evidence and which need a closer look. More of our writing is at writing.

Discuss a scope