Skip to content
KANSOIT

Guide

Cyber Insurance Readiness Guide

Cyber-insurance applications are not really security questionnaires. They are a list of controls the insurer believes reduce claim frequency, written as yes/no questions that punish uncertainty. This guide covers what they ask, why, and how to answer without guessing.

Why it is hard

The application is a verification exercise

Most companies with 50–300 employees can technically answer every question on a cyber application. The difficulty is that the person filling in the form usually cannot verify the answers. “Do you enforce multi-factor authentication on all remote access?” has a real answer, and it is frequently “on email, yes; on the VPN, for most people.”

That gap matters because an application is a representation. If a claim is later disputed, the insurer will compare what happened to what you said. So the goal is not to answer favourably; it is to answer accurately, then close the gaps the accurate answers reveal.

Control checklist

What applications commonly ask about

Wording varies by carrier, but the underlying controls repeat. Verify each one before answering.

Control · what an honest answer requires · common gap
Control areaWhat verifying it actually meansCommon gap at this size
Multi-factor authenticationConfirm enforcement policy coverage, not just that MFA is availableService accounts, shared mailboxes, and VPN excluded
Email securityCheck filtering, external-sender warnings, and forwarding rulesAuto-forwarding to personal addresses still permitted
Endpoint protectionCompare installed agent count against device inventoryNo reliable device inventory to compare against
Backup and recoveryConfirm scope, frequency, offline or immutable copies, and a tested restoreBackups exist; restores have never been tested
Privileged accessList every account with administrative rights and whyLong-departed roles still hold admin access
PatchingReport current compliance percentage for OS and browsersNo reporting, so the answer is a feeling
Remote accessEnumerate every path in: VPN, RDP, remote tools, vendor accessForgotten vendor or legacy remote access still live
Network segmentationShow separation between office, guest, and production or shop-floor systemsOne flat network across everything
Security awareness trainingShow completion records, not enrollmentTraining bought, completion untracked
Incident response planA written plan with contacts, decision rights, and escalation stepsPlan is institutional memory in one person's head
Logging and monitoringKnow what is logged, retained for how long, and who reviews itDefault retention, nobody reviewing
Vendor and third-party accessMaintain a list of vendors with access and its scopeNo list exists

Sequence

What to fix first when the deadline is close

Ranked by exposure reduction per unit of effort, not by what is easiest to buy.

  • Close MFA gaps on email, remote access, and administrative accounts
  • Disable external auto-forwarding and review existing forwarding rules
  • Reconcile endpoint protection coverage against a real device list
  • Run one restore test and write down the result, including how long it took
  • Remove administrative rights nobody can justify today
  • Revoke access for departed employees and unused vendor connections
  • Write a one-page incident response plan with names and phone numbers

Segmentation, logging retention, and formal training programs are real projects. Start them, but do not claim them as complete on an application because they are underway.

Timeline

A realistic renewal timeline

Weeks before renewalFocusOutput
8–10Pull last year's application and list every question you cannot verifyGap list
6–8Verify controls against configuration, not memoryCurrent-state record
4–6Close the fast items and start the slow onesRemediation log
2–4Draft answers with evidence noted beside each oneAnswer pack
0–2Submit, and record what is in progress accuratelyFiled application

What this is not

Honest limits

  • This guide is not insurance advice; your broker and carrier own that.
  • No control set prevents a breach, and no provider can promise one will not happen.
  • A readiness assessment is not an audit or a certification.
  • Completing these items does not guarantee coverage, pricing, or claim outcomes.

FAQ

Common questions

Can an assessment guarantee coverage or a lower premium?+

No. Underwriting decisions and pricing belong to the insurer and depend on factors outside your control, including your industry and claims environment. What readiness work changes is the accuracy and completeness of your answers.

What if we answer a question wrong?+

Inaccurate answers on an application are a serious problem, because coverage can be disputed later on the basis of what you represented. That is the main reason to verify rather than estimate.

How long does it take to close common gaps?+

Multi-factor authentication on email and remote access is often days. Full endpoint coverage, backup restore testing, and privileged access cleanup are usually weeks. Segmentation and logging projects can take a quarter or more.

Do we need to buy new tools first?+

Usually not immediately. Most companies at this size have partly deployed capabilities they already pay for. Coverage gaps and configuration are more common findings than missing products.

Next

If the gap list is longer than expected

Our Security Readiness engagement produces the current-state record and ranked remediation plan described above. If the gaps turn out to be operational habits rather than one-time fixes, Managed IT is usually the follow-on. Not sure which? The staffing guide covers that decision.