Guide
Cyber Insurance Readiness Guide
Cyber-insurance applications are not really security questionnaires. They are a list of controls the insurer believes reduce claim frequency, written as yes/no questions that punish uncertainty. This guide covers what they ask, why, and how to answer without guessing.
Why it is hard
The application is a verification exercise
Most companies with 50–300 employees can technically answer every question on a cyber application. The difficulty is that the person filling in the form usually cannot verify the answers. “Do you enforce multi-factor authentication on all remote access?” has a real answer, and it is frequently “on email, yes; on the VPN, for most people.”
That gap matters because an application is a representation. If a claim is later disputed, the insurer will compare what happened to what you said. So the goal is not to answer favourably; it is to answer accurately, then close the gaps the accurate answers reveal.
Control checklist
What applications commonly ask about
Wording varies by carrier, but the underlying controls repeat. Verify each one before answering.
| Control area | What verifying it actually means | Common gap at this size |
|---|---|---|
| Multi-factor authentication | Confirm enforcement policy coverage, not just that MFA is available | Service accounts, shared mailboxes, and VPN excluded |
| Email security | Check filtering, external-sender warnings, and forwarding rules | Auto-forwarding to personal addresses still permitted |
| Endpoint protection | Compare installed agent count against device inventory | No reliable device inventory to compare against |
| Backup and recovery | Confirm scope, frequency, offline or immutable copies, and a tested restore | Backups exist; restores have never been tested |
| Privileged access | List every account with administrative rights and why | Long-departed roles still hold admin access |
| Patching | Report current compliance percentage for OS and browsers | No reporting, so the answer is a feeling |
| Remote access | Enumerate every path in: VPN, RDP, remote tools, vendor access | Forgotten vendor or legacy remote access still live |
| Network segmentation | Show separation between office, guest, and production or shop-floor systems | One flat network across everything |
| Security awareness training | Show completion records, not enrollment | Training bought, completion untracked |
| Incident response plan | A written plan with contacts, decision rights, and escalation steps | Plan is institutional memory in one person's head |
| Logging and monitoring | Know what is logged, retained for how long, and who reviews it | Default retention, nobody reviewing |
| Vendor and third-party access | Maintain a list of vendors with access and its scope | No list exists |
Sequence
What to fix first when the deadline is close
Ranked by exposure reduction per unit of effort, not by what is easiest to buy.
- Close MFA gaps on email, remote access, and administrative accounts
- Disable external auto-forwarding and review existing forwarding rules
- Reconcile endpoint protection coverage against a real device list
- Run one restore test and write down the result, including how long it took
- Remove administrative rights nobody can justify today
- Revoke access for departed employees and unused vendor connections
- Write a one-page incident response plan with names and phone numbers
Segmentation, logging retention, and formal training programs are real projects. Start them, but do not claim them as complete on an application because they are underway.
Timeline
A realistic renewal timeline
| Weeks before renewal | Focus | Output |
|---|---|---|
| 8–10 | Pull last year's application and list every question you cannot verify | Gap list |
| 6–8 | Verify controls against configuration, not memory | Current-state record |
| 4–6 | Close the fast items and start the slow ones | Remediation log |
| 2–4 | Draft answers with evidence noted beside each one | Answer pack |
| 0–2 | Submit, and record what is in progress accurately | Filed application |
What this is not
Honest limits
- This guide is not insurance advice; your broker and carrier own that.
- No control set prevents a breach, and no provider can promise one will not happen.
- A readiness assessment is not an audit or a certification.
- Completing these items does not guarantee coverage, pricing, or claim outcomes.
FAQ
Common questions
Can an assessment guarantee coverage or a lower premium?+
No. Underwriting decisions and pricing belong to the insurer and depend on factors outside your control, including your industry and claims environment. What readiness work changes is the accuracy and completeness of your answers.
What if we answer a question wrong?+
Inaccurate answers on an application are a serious problem, because coverage can be disputed later on the basis of what you represented. That is the main reason to verify rather than estimate.
How long does it take to close common gaps?+
Multi-factor authentication on email and remote access is often days. Full endpoint coverage, backup restore testing, and privileged access cleanup are usually weeks. Segmentation and logging projects can take a quarter or more.
Do we need to buy new tools first?+
Usually not immediately. Most companies at this size have partly deployed capabilities they already pay for. Coverage gaps and configuration are more common findings than missing products.
Next
If the gap list is longer than expected
Our Security Readiness engagement produces the current-state record and ranked remediation plan described above. If the gaps turn out to be operational habits rather than one-time fixes, Managed IT is usually the follow-on. Not sure which? The staffing guide covers that decision.