The cyber-insurance questionnaire, question by question
Every carrier's application asks roughly the same dozen control questions. Here is what each one is really testing, what a defensible "yes" requires, and which document you need on file.
Renewals used to be a signature and a cheque. Since ransomware and business-email-compromise losses climbed, applications for cyber-liability cover have turned into control audits. Answer "no" to the wrong question and you get a higher premium, a ransomware sub-limit, or an exclusion for exactly the claim you're most likely to make. Answer "yes" without evidence and you risk a denied claim later, because the application forms part of the policy.
The wording varies by carrier, but the questions map to the same handful of controls. Treat the list below as the checklist you work through before you open the form.
1. Is multi-factor authentication enforced on email?
This is the single most-weighted question on most forms. "Enforced" means no user can sign in without it, including the owner, the bookkeeper and any shared mailbox. "Available" or "enabled for most staff" is a no. Evidence: a screenshot of the tenant-wide MFA or conditional-access policy, and a written Password & MFA policy that makes it mandatory.
2. Is MFA enforced on remote access and administrator accounts?
VPN, remote desktop tools, cloud admin consoles and the firewall's own login. Carriers ask this separately because attackers go for the admin console when the mailbox is locked down. Evidence: the same policy, plus a list of admin accounts from your access register with the MFA column filled in.
3. Do you have written information-security policies, acknowledged by employees?
Two parts: the documents exist, and each employee has signed to say they've read them. A one-page "be careful with email" memo doesn't satisfy this any more. The minimum defensible set is eight short policies; the policy guide lists them. Keep the signed acknowledgement forms with HR records; that is what the adjuster asks for after a claim.
4. Do you have a documented incident response plan?
Written, with named people and phone numbers, stored somewhere reachable when the network is down. The plan needs to cover who decides what, how you classify severity, and what the first hour looks like. See the incident response outline.
5. Is the plan tested?
A tabletop exercise counts. Thirty minutes, twice a year, one scenario read aloud, notes taken. Record the date, attendees and gaps found; that record is the evidence. Untested plans are increasingly scored as "no".
6. Are backups performed, stored offline or immutable, and tested?
Three separate claims: backups run (daily for critical systems), at least one copy cannot be deleted with production credentials (immutable cloud storage or genuinely offline media), and you have restored from them recently. Keep a log of restore tests with dates and time taken. A backup that has never been restored is an assumption, not a control.
7. Is endpoint detection and response (EDR) deployed on all devices?
Modern forms ask for EDR/MDR by name rather than "antivirus". If you run Microsoft Defender for Business, SentinelOne, CrowdStrike or similar on every laptop, desktop and server, answer yes and keep the device count from your asset register handy; carriers compare it to your stated headcount.
8. Do you maintain an inventory of hardware, software and user accounts?
A spreadsheet is fine. It has to exist, be dated, and show every device (with encryption and EDR status), every SaaS tool holding company data, and every person with a login. The asset inventory guide lists the columns that make it credible.
9. Are user access rights reviewed periodically, and is offboarding prompt?
Quarterly or semi-annual review of who has access to what, with a record of the review date. Offboarding: accounts disabled on the last day, not "when we get to it". Your access register should have a "last reviewed" column and an offboarding checklist with dates ticked.
10. Do you verify payment and bank-detail changes out of band?
Business email compromise claims are now the most common small-business loss, so carriers ask whether a request to change a supplier's bank details is verified by phone to a known number before anyone acts on it. This needs to be a written rule in your phishing/payments policy and, ideally, dual approval for new payees.
11. Is security awareness training delivered?
At least annually, with a record of who completed it. Simulated phishing is a bonus, not a requirement, for most SMB policies. A 20-minute briefing using your own policies as the material satisfies this if you keep the attendance record.
12. Are systems patched within a defined window?
Automatic updates on endpoints, and a stated window (commonly 14 days for critical patches, 30 for the rest) for servers, firewalls and network gear. Firewalls and VPN appliances are the ones people forget; they are also the ones attackers scan for.
How to work through this before the renewal
- Print the list above and mark each item yes / no / partial, honestly.
- Fix the technical "no"s first: MFA everywhere, EDR on every device, immutable backup. These are configuration, not paperwork, and they move the premium most.
- Then produce the paperwork: policies with acknowledgements, the incident plan, the asset and access register. This is where most small businesses stall, because writing from a blank page takes days.
- Keep an "evidence" folder: screenshots, signed forms, restore-test log, tabletop record. When a claim happens, this folder is what you hand the adjuster.