Resource
Cyber insurance requirements checklist
Cyber insurance questionnaires have quietly become the de facto security baseline for small and medium businesses, and they get stricter every renewal. The genuine risk is not failing to meet a requirement. It is describing a control you do not fully have.
The eight controls that appear on almost every form
| Control | Scope expected |
|---|---|
| Multi factor authenticationThe most commonly required control, and the most commonly partial | Email, remote access, admin accounts |
| Endpoint detection and responseSignature antivirus alone increasingly fails the question | All endpoints and servers |
| Offsite or immutable backupsInsurers ask about testing, not just about running | Tested within a stated period |
| Patch cadenceUsually expressed as a timeframe for critical vulnerabilities | Documented and applied |
| Security awareness trainingRecorded is the operative word | With recorded completion |
| Incident response planSome insurers require notification to them within a set period | Written, with named roles |
| Email filteringOften bundled into a broader email security question | Attachment and link inspection |
| Privileged access managementIncreasingly appearing on larger policies | Limits on standing admin rights |
Five ways businesses answer optimistically
None of these are dishonest. All of them are the kind of answer that looks reasonable when filling in a form and different when examined after a claim.
- Answering yes to MFA when it covers email but not remote access or administrative accounts
- Describing a backup as tested when the last restore attempt was during the original installation
- Claiming a documented patch cadence that exists as a habit rather than a written standard
- Counting a one off training session from two years ago as an ongoing programme
- Answering on behalf of systems your IT provider manages without confirming with them first
The MFA question is the one to read twice
Multi factor authentication is the most commonly required control and the most commonly partial. Businesses enable it on email, which is the obvious place, and leave two gaps that matter more.
Remote access is the first. A VPN or remote desktop reachable with a password alone is precisely the entry point that produces the incidents these policies exist to cover.
Administrative accounts are the second, and they are often exempted deliberately because the additional prompt is inconvenient for the people using them most. That exemption inverts the logic: the accounts with the most authority end up with the least protection.
Before answering yes, confirm all three are covered. If only one is, the accurate answer is partial, and it is worth closing the gap before renewal rather than explaining it after an incident.
Common questions
Answered before you ask.
What happens if we answer a question inaccurately?
It can affect whether a claim is paid, which turns a bad week into a far worse one. The application is part of the contract, and an insurer investigating a claim will look at whether the controls you described were actually in place at the time of the incident. This is the reason to answer conservatively: a higher premium is a known, budgeted cost, while a declined claim after a serious incident is not survivable for some businesses.
Our provider manages most of this. Who answers the questionnaire?
You sign it, so you own the answer, but you should not complete it alone. Send it to your IT provider and ask them to confirm each technical answer in writing, ideally with evidence. A provider unable or unwilling to do that is telling you something useful. Keep their written confirmation, because it matters if an answer is ever questioned.
We cannot meet all of these. Should we still apply?
Yes, and answer honestly. Insurers price risk rather than refusing everything imperfect, and many will quote with conditions or with a requirement to implement something within a period. What causes problems is not a gap, it is a gap described as a control. If a requirement is genuinely unaffordable, say so and ask what the premium difference looks like, because the answer is sometimes smaller than expected.
How often do these requirements change?
Every renewal cycle, and they have been tightening consistently. Controls that were optional differentiators a few years ago are now baseline expectations, and privileged access management is currently moving in that direction. The practical implication is to treat the questionnaire as a moving standard rather than a one time exercise, and to review your position ahead of renewal rather than during it.
Related
Read next.
Cybersecurity services
Endpoint detection, email security, monitoring and user training.
Managed detection and response
24 by 7 human review of security alerts, with authority to contain.
Backup and disaster recovery
Immutable backups with tested restores and a defined recovery window.
Ransomware protection for small business
How attacks actually start, which controls stop them, and what to do in the first hour.
What managed IT services cost in Tacoma
Per user pricing bands, what moves the number up, and how to read a quote.
Start with the assessment, not the contract.
We document what you have, test whether your backups restore, and give you the findings in writing. Yours to keep either way.