Skip to content

Resource

Cyber insurance requirements checklist

Cyber insurance questionnaires have quietly become the de facto security baseline for small and medium businesses, and they get stricter every renewal. The genuine risk is not failing to meet a requirement. It is describing a control you do not fully have.

The eight controls that appear on almost every form

Controls commonly required by cyber insurers
ControlScope expected
Multi factor authenticationThe most commonly required control, and the most commonly partialEmail, remote access, admin accounts
Endpoint detection and responseSignature antivirus alone increasingly fails the questionAll endpoints and servers
Offsite or immutable backupsInsurers ask about testing, not just about runningTested within a stated period
Patch cadenceUsually expressed as a timeframe for critical vulnerabilitiesDocumented and applied
Security awareness trainingRecorded is the operative wordWith recorded completion
Incident response planSome insurers require notification to them within a set periodWritten, with named roles
Email filteringOften bundled into a broader email security questionAttachment and link inspection
Privileged access managementIncreasingly appearing on larger policiesLimits on standing admin rights

Five ways businesses answer optimistically

None of these are dishonest. All of them are the kind of answer that looks reasonable when filling in a form and different when examined after a claim.

  • Answering yes to MFA when it covers email but not remote access or administrative accounts
  • Describing a backup as tested when the last restore attempt was during the original installation
  • Claiming a documented patch cadence that exists as a habit rather than a written standard
  • Counting a one off training session from two years ago as an ongoing programme
  • Answering on behalf of systems your IT provider manages without confirming with them first

The MFA question is the one to read twice

Multi factor authentication is the most commonly required control and the most commonly partial. Businesses enable it on email, which is the obvious place, and leave two gaps that matter more.

Remote access is the first. A VPN or remote desktop reachable with a password alone is precisely the entry point that produces the incidents these policies exist to cover.

Administrative accounts are the second, and they are often exempted deliberately because the additional prompt is inconvenient for the people using them most. That exemption inverts the logic: the accounts with the most authority end up with the least protection.

Before answering yes, confirm all three are covered. If only one is, the accurate answer is partial, and it is worth closing the gap before renewal rather than explaining it after an incident.

Common questions

Answered before you ask.

What happens if we answer a question inaccurately?

It can affect whether a claim is paid, which turns a bad week into a far worse one. The application is part of the contract, and an insurer investigating a claim will look at whether the controls you described were actually in place at the time of the incident. This is the reason to answer conservatively: a higher premium is a known, budgeted cost, while a declined claim after a serious incident is not survivable for some businesses.

Our provider manages most of this. Who answers the questionnaire?

You sign it, so you own the answer, but you should not complete it alone. Send it to your IT provider and ask them to confirm each technical answer in writing, ideally with evidence. A provider unable or unwilling to do that is telling you something useful. Keep their written confirmation, because it matters if an answer is ever questioned.

We cannot meet all of these. Should we still apply?

Yes, and answer honestly. Insurers price risk rather than refusing everything imperfect, and many will quote with conditions or with a requirement to implement something within a period. What causes problems is not a gap, it is a gap described as a control. If a requirement is genuinely unaffordable, say so and ask what the premium difference looks like, because the answer is sometimes smaller than expected.

How often do these requirements change?

Every renewal cycle, and they have been tightening consistently. Controls that were optional differentiators a few years ago are now baseline expectations, and privileged access management is currently moving in that direction. The practical implication is to treat the questionnaire as a moving standard rather than a one time exercise, and to review your position ahead of renewal rather than during it.

Start with the assessment, not the contract.

We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.

CallFree assessment