What Cyber Insurance Expects You to Have in Place
Renewal questionnaires have quietly become a security standard. What insurers ask, what an honest yes requires, and why a wrong answer can void the policy.
By Cohesive Security
The renewal form arrives and it is longer than last year. Somewhere around question fourteen, “do you enforce multi-factor authentication on all remote access and privileged accounts”, the exercise stops feeling like paperwork and starts feeling like an exam nobody told you to study for.
That is roughly what has happened. After several expensive years, insurers stopped asking whether you have cyber insurance in mind and started asking what you actually run. The questionnaire has quietly become a security standard, and it is worth treating it as one, because the answers you give are part of the contract.
A note before the detail: we are not insurance brokers or lawyers, policy wording varies enormously between carriers, and coverage questions belong with your broker. What follows is the security side of the form, which is the part we do know.
Key takeaways:
- The application is a gap list. Work it as one: find what you cannot honestly answer yes to, fix those things, then fill in the form.
- Answering inaccurately is not a technicality. A carrier has already had a policy rescinded from inception over a misstated MFA answer, after a ransomware claim.
- “Do you have MFA” almost never means email alone. It means remote access, administrator accounts, and usually your backup system too.
- Insurance pays for recovery. It does not prevent the incident, and it will not repair the client relationship that ends because of one.
The questions, and what an honest yes requires
The wording differs by carrier, but the same controls come up again and again. For each one, the useful question is not “can we say yes” but “would this survive someone checking”.
Multi-factor authentication. The single most-asked control, and the one most often over-claimed. Insurers generally want it on email, on any remote access into your network, and on administrator accounts. Turning it on for staff mailboxes and leaving the domain administrator account on a password is the classic gap, and so is the service account nobody wants to touch. Increasingly the backup system is named too, for good reason.
Endpoint protection that can act. Not the antivirus that came with the machine. What is being asked about is software that watches behavior, flags something acting like ransomware, and can isolate that machine from the network automatically at 3 a.m. without waiting for a human. That last part is why it matters: the tooling contains the problem overnight, and a person reviews it in the morning.
Backups that are separated and tested. Expect three sub-questions: are backups kept offline or otherwise beyond reach, are they encrypted, and when did you last test a restore. The third one is where most small businesses have nothing to say. We wrote about why backups fail quietly and what a real restore test looks like, and the test log is exactly the evidence this question wants.
Patching, with a timeframe. Not “do you update” but “how quickly do critical updates get installed”. A truthful answer requires knowing, which requires something tracking it. If the answer is “when someone gets to it”, that is a real finding, not a wording problem.
Email filtering and staff training. Filtering that catches impersonation and malicious links, plus training people actually receive rather than a policy they signed once at induction. Some carriers ask about phishing simulations specifically.
Separated administrator accounts. Whether the people with administrative rights use those accounts for everyday work. They should not: day-to-day email and browsing belong on an ordinary account, with the privileged one used deliberately.
A written incident response plan. Who declares an incident, who they call, in what order, and where that document lives when the network is down. This one costs nothing but an afternoon and is very commonly missing.
Why a wrong answer is worse than a “no”
Owners sometimes treat the questionnaire as a formality, ticking optimistic boxes to get the renewal done. That instinct is expensive.
In July 2022, Travelers filed suit in federal court to rescind a cyber policy it had issued to an Illinois manufacturer, alleging the company had stated on its application that it used multi-factor authentication for administrative access when in fact it used MFA only to protect its firewall. The misstatement surfaced when the company suffered a ransomware attack and claimed. The following month the parties agreed to rescission, and the court declared the policy null and void from its inception, with no coverage available under it at all.
Read that outcome carefully. The company did not lose an argument about the size of a payout. It ended up, after a ransomware attack, having never been insured. A “no” on an application costs you a higher premium or a requirement to fix something first. An inaccurate “yes” can cost you the entire policy at the exact moment you need it.
So the sequence matters. Find the questions you cannot honestly answer yes to, close those gaps, then answer. If a gap cannot be closed before the renewal date, say so accurately and talk to your broker about it. That conversation is survivable. The other one is not.
What a policy actually covers
Worth knowing before you need it, because the assumptions are usually generous.
Most policies pay for the response: forensic investigation, legal counsel, notifying affected people, credit monitoring, public relations, and often the direct costs of business interruption while you are down. Many include an incident response team you can call, which for a small business is genuinely valuable, because knowing who to phone at 6 a.m. is half the battle.
The gap that catches people is funds transfer fraud. If someone tricks your bookkeeper into wiring money to an attacker, that is frequently covered under a separate sub-limit far smaller than the policy’s headline number. A business with a million-dollar policy can discover its wire fraud cover is capped at fifty thousand. If invoice fraud is a live risk for you, and for anyone paying vendors it is, ask your broker specifically about that sub-limit, and read how the scam actually runs so you can judge the exposure.
Insurance is not a control
The UK’s National Cyber Security Centre puts this plainly in its cyber insurance guidance: insurance “will not instantly solve all of your cyber security issues, and it will not prevent a cyber breach/attack”. Its other line is the one we would underline for any owner about to fill in a form: “Do not limit yourself to meeting the minimum cyber security requirements specified by an insurer; these might not adequately protect the things your organisation cares about.”
That is the right frame. The questionnaire is a floor built from what carriers have learned by paying claims, which makes it a decent starting checklist and a poor finishing one. The controls on it are worth having because they work, not because a form asks for them.
Turning the form into a plan
If your renewal is coming up, the practical version is short. Go through the questionnaire and mark every question amber or red rather than answering it. Fix the reds that are cheap and fast, which is usually MFA coverage gaps, administrator account separation, and writing the incident response plan down. Put a date against the rest.
Then answer the form from what is actually true on the day you sign it.
That gap-closing work is most of what our compliance and vCISO service does day to day, alongside the security controls and backup and recovery the questions are asking about. If you would like someone to walk the questionnaire with you before you commit answers to it, that is part of our free assessment, or email hello@cohesivesecurity.com with the form and we will tell you honestly where you stand.