The short answer
Every insurer and policy is different, but cyber insurance applications and renewal questionnaires commonly ask whether you have:
- Multi-factor authentication (MFA) on email, remote access and administrator accounts.
- Endpoint detection and response (EDR) on devices and servers, and who monitors it.
- Backups that are separated from your network and tested.
- Patching on a defined schedule, and no unsupported systems exposed to the internet.
- Security awareness training, often including phishing simulations.
- An incident response plan, and when it was last tested.
- Controls on payments, such as call-back verification for changes to supplier banking details.
Insurers assess risk by asking about security audits, safeguards for systems access and how data is handled, and organizations with strong risk management may be offered coverage on better terms. It is also worth keeping in mind that a policy is one part of a risk strategy, not a replacement for cyber resilience. CISA's Secure Our World guidance covers many of the same basics in plain language.
Why the answers matter more than they used to
A questionnaire can look like a formality. It is not. Your answers help the insurer decide whether to offer coverage and on what terms, and the policy wording may refer back to them. If you tick "MFA on all remote access" and a breach later starts through a VPN account without MFA, you could face a difficult conversation at claim time.
We are not insurance advisers, and nothing here is legal or insurance advice. How any policy responds depends on its wording, which your broker and counsel should explain. Our role is narrower and practical: making sure that what you tell your insurer is true, and that you can show it.
The controls, and what "yes" should really mean
MFA. "Yes" should mean every user, not most users. Check shared mailboxes, service accounts, break-glass administrator accounts and remote access for third-party support. Government and industry guidance, including from CISA, favors phishing-resistant options such as FIDO-based security keys, and number matching to resist MFA fatigue attacks. See rolling out MFA without a staff revolt if coverage is patchy.
EDR and monitoring. Insurers increasingly distinguish between having an EDR product installed and having someone who responds to its alerts. Know which devices are covered, which are not (servers and Mac devices are often missed), and who acts on an alert at night. Our comparison of managed EDR and running it yourself covers the options.
Backups. Expect questions about offline or immutable copies, separate credentials, encryption and restore testing. A backup job that reports success is not evidence that you can recover. Record the date and result of your last full restore test. CISA's #StopRansomware guidance explains why tested, isolated backups matter.
Patching and end-of-life systems. Be ready to say how quickly critical updates are applied and whether any unsupported operating systems remain. If an old system must stay, document how it is isolated.
Privileged access. Separate administrator accounts, a short list of people who hold them, and MFA on all of them.
Email and payment fraud. Filtering, SPF, DKIM and DMARC, and a written rule that changes to banking details are confirmed by phone using a number you already hold.
Training and planning. Dates of the last training cycle and the last incident response exercise, with attendance.
The NIST Cybersecurity Framework gives a recognized structure for these controls, and its guidance for small organizations lines up closely with the questions insurers ask. Many organizations also review whether their coverage includes incident response and recovery costs, not just liability.
Rather talk it through? If your renewal questionnaire is on someone's desk right now, we can verify the answers and gather the evidence with you. Talk to a Promatics specialist
Build an evidence pack before renewal
Brokers and underwriters ask better questions every year. A short evidence pack saves time and reduces the risk of a wrong answer:
Cyber insurance evidence pack
- MFA report showing enrollment for all users and administrators, with exceptions explained
- List of devices and servers with EDR, and who monitors alerts after hours
- Backup design summary and the date and result of the last full restore test
- Patch compliance report and a list of any unsupported systems with compensating controls
- List of privileged accounts and who holds them
- SPF, DKIM and DMARC status for each domain
- Payment change verification procedure
- Training records and phishing simulation summary
- Incident response plan with the date of the last exercise
- Contact details for your IT provider, counsel and the insurer's breach line
Keep it current. The same pack helps when a large client sends you a security questionnaire.
What usually goes wrong
- Answering from memory. Someone remembers turning MFA on and does not know that a group of users was excluded.
- Confusing licenses with controls. You own an EDR license, but the agent was never deployed to the servers.
- Last-minute changes. MFA is switched on for everyone the day before the renewal, staff are locked out, and exceptions are added that nobody removes.
- Forgetting suppliers. Your IT provider's or software vendor's remote access to your systems counts too.
When to bring in help
If you have a small environment and a clear-headed IT person, you can gather most of this evidence yourself using the admin consoles you already have. It is worth bringing in a professional when:
- You are not sure the answers are accurate, or different people give different answers.
- The insurer has declined, added exclusions or asked for controls you do not have.
- You need gaps fixed within weeks, not months.
- You want someone accountable for the evidence, not just a document.
A chatbot can explain what a questionnaire means. It cannot check your tenant, confirm the servers are covered, or stand behind the answer when the insurer asks. A Promatics security assessment does exactly that: we review how your organization is really set up, rank the gaps and give you evidence and a remediation plan in plain language.
Limitations
Insurer requirements vary and change. This article describes commonly asked controls in general terms. It is not insurance or legal advice, and we do not predict whether any insurer will offer, renew or pay under a policy. Discuss coverage and wording with your broker.
Sources and further reading
Product capabilities and guidance change. These are the primary sources this article relies on, checked on the review date above.
- Secure Our World (cybersecurity guidance for individuals and small organizations), Cybersecurity and Infrastructure Security Agency (CISA)
- #StopRansomware guidance, Cybersecurity and Infrastructure Security Agency (CISA)
- NIST Cybersecurity Framework, National Institute of Standards and Technology (NIST)
This article is general information, not legal, accounting or security advice for your specific situation. Examples are hypothetical unless stated otherwise.